Pilot document
This document applies during the FiosAI pilot. It is written to reflect what the product actually does under the GDPR and the EU AI Act, and is kept current as the product changes. If anything here is unclear, contact us before you proceed.
Privacy Policy
Last updated 7 July 2026
This policy explains what personal data FiosAI collects, why, on what legal basis, who we share it with, how long we keep it, and the rights you have over it. It covers candidates who take an AI-assisted assessment and the recruiters who use the platform.
1. Who is the data controller
The data controller for the FiosAI recruitment platform is FiosAI is a trading name of MJL Executive Ltd, Dublin, Ireland (“FiosAI”, “we”, “us”). FiosAI is established in Ireland. MJL Executive Ltd is registered in Ireland under company registration number 616079, registered office 27 Charlestown Park, St. Margaret's Road, Dublin 11, D11 E2FY, Ireland.
Where a recruiting organisation invites you to an assessment, that organisation and FiosAI each have a role under data protection law. In general the recruiting organisation decides to assess you for a role (and is a controller for that decision), while FiosAI provides and operates the assessment system. The precise split is set out in our written agreement with each recruiting organisation.
You can reach us about any privacy matter at privacy@fiosai.io.
2. What personal data we process
We only collect the data needed for the modules a recruiting organisation has enabled for your assessment. Depending on the role, this may include:
Identity and contact details
Your name, email address, and the invitation that links you to a specific role.
CV and application data
The CV or profile information provided to the recruiting organisation, and any answers you give during the assessment.
Assessment responses
Your answers to skills, judgement and ability tests, and the scores derived from them.
Interview recording and transcript
If you consent, the video and audio of your AI interview and its transcript. This involves your image and voice, which are special-category (biometric) data.
Identity verification
If enabled, an image of an identity document and a selfie, used only to confirm a 1:1 match and that a live person is present (liveness). This is special-category (biometric) data. We do not use your face to infer emotions, demographics, or any sensitive characteristic.
Integrity / proctoring data
If enabled, a short scan of your room or desk before and after a test, and detections used to confirm the test environment.
Location and technical data
At capture steps, an approximate location (IP, and device location where enabled) used as an integrity signal, plus standard technical data such as device and browser information. IP and user-agent are stored as one-way hashes in our consent records, not in the clear.
3. Our lawful basis for processing
We rely on the following lawful bases under Article 6 (and Article 9 for special-category data) of the GDPR:
Consent — Article 6(1)(a)
For recording your interview, for the AI-assisted assessment of your responses, and as the basis we capture before any candidate-facing step begins. You can withdraw consent at any time (see “Your rights”).
Explicit consent for biometric data — Article 9(2)(a)
For identity verification (face match and liveness) and for the interview recording, both of which involve biometric data. We ask for this separately and clearly.
Contract / legitimate interests — Article 6(1)(b) / (f)
For running the assessment you applied for and producing a structured result for the recruiting organisation to review. Where we rely on legitimate interests, we balance them against your rights and apply the safeguards described in this policy.
We do not use your assessment data to train AI models, and we do not use it for any purpose beyond the role you applied for.
4. AI, automated processing and human decisions
FiosAI is an AI-assisted recruitment system. Under the EU AI Act this is a high-risk use of AI in employment, and we design the product accordingly.
You are told you are interacting with AI — EU AI Act Article 50
Your interview is conducted by an AI interviewer (Aoibheann), and reports are generated by an AI system. We disclose this clearly before and during the interaction. AI-generated content is labelled as such.
A human always makes the decision — GDPR Article 22 / EU AI Act Article 14
No decision about your application that produces legal or similarly significant effects is made by AI alone. The AI produces a recommendation; a named human reviewer at the recruiting organisation reviews the evidence and records the actual decision with a reason. You have the right not to be subject to a decision based solely on automated processing.
No emotion or affect inference — EU AI Act Article 5
We do not use AI to infer your emotions, mood, or intentions, and we do not categorise you by sensitive characteristics. Behavioural indicators in a report are derived from the content of your answers, presented as signals for a human to weigh, not as personality verdicts.
Your right to a human, an explanation and to contest
You may ask for meaningful information about the logic involved, express your point of view, and ask a human to review or reconsider a decision. Contact us or the recruiting organisation using the details in this policy.
5. Who we share data with (sub-processors)
Your assessment result is shared with the recruiting organisation that invited you. To run the service we also use the following sub-processors, each under a data processing agreement and acting only on our instructions:
Supabase
Database, authentication and encrypted file storage (recordings, documents). Processing region: European Union.
Vercel
Application hosting and content delivery. Processing region: United States — safeguarded by the EU-US Data Privacy Framework (Vercel is certified) and Standard Contractual Clauses..
Anthropic
AI model (Claude) used to generate the structured assessment from interview transcripts. Processing region: United States — safeguarded by EU Standard Contractual Clauses under Anthropic’s Data Processing Addendum (incorporated into Anthropic’s Commercial Terms)..
NavTalk
AI interview avatar, real-time interaction and session recording. Processing region: United States (pre-launch: being replaced by FiosAI / Tógáil sovereign stack).
Resend
Transactional email (invitations, notifications). Processing region: United States — safeguarded by EU Standard Contractual Clauses under Resend’s data processing agreement..
Stripe
Billing and subscription payments (recruiting organisations only — not candidates). Processing region: United States — safeguarded by the EU-US Data Privacy Framework (Stripe is certified) and Standard Contractual Clauses..
Where a sub-processor is outside the European Economic Area, we rely on an appropriate transfer safeguard under Chapter V of the GDPR: either the recipient’s certification under the EU-US Data Privacy Framework, the European Commission’s Standard Contractual Clauses, or both. The specific safeguard for each sub-processor is shown in the list above.
You can request a copy of the safeguards that apply to any transfer of your data by emailing privacy@fiosai.io.
6. Our impact assessment
Because this processing is large-scale, uses AI to evaluate people, and can involve special-category (biometric) data, we have carried out a Data Protection Impact Assessment under Article 35 of the GDPR to identify and reduce the risks to you. It is reviewed before the service goes live and kept up to date as the product changes. You can ask us about it using the contact details in this policy.
7. How long we keep your data
We keep personal data only as long as needed for the purposes above:
Interview recordings
Deleted after 90 days by default. A recruiting organisation may set a different period within the limits of the law.
Other candidate assessment data
Retained for up to 730 days by default, so the recruiting organisation can consider you for the role and for similar roles during a normal hiring cycle, then deleted or anonymised. You can ask us to delete it sooner at any time, and we keep it longer only where the law requires it.
Consent and oversight records
Records that prove consent was given and that a human made the decision are kept for as long as needed to demonstrate compliance, then deleted.
8. Your rights
Under the GDPR you have the right to:
Access — Article 15
Obtain a copy of the personal data we hold about you.
Rectification — Article 16
Have inaccurate data corrected.
Erasure — Article 17
Ask us to delete your data, subject to any legal retention obligations.
Portability — Article 20
Receive your data in a structured, machine-readable format.
Withdraw consent — Article 7
Withdraw any consent you gave, at any time, without affecting processing done before you withdrew it.
Object and restrict — Articles 18 and 21
Object to, or ask us to restrict, certain processing.
Not be subject to solely automated decisions — Article 22
A human reviews and makes any significant decision; you may request that human review.
To exercise any right, email privacy@fiosai.io. You also have the right to complain to a supervisory authority. In Ireland this is the Data Protection Commission (DPC), Ireland — dataprotection.ie.
Where we rely on legitimate interests as our lawful basis, you can ask us for a copy of our legitimate-interests assessment for that processing.
9. How we protect your data
We apply technical and organisational measures appropriate to the sensitivity of the data: encryption at rest, access controls and row-level security so each organisation only sees its own data, short-lived signed links for recordings, and append-only audit logs of consent and decisions. No system is perfectly secure, and we keep these measures under review.
10. Data protection contact and age
Our point of contact for any data protection matter is our Data Protection contact, reachable at privacy@fiosai.io. We are not required to appoint a statutory Data Protection Officer at our current scale; if that changes, we will name one here.
FiosAI is a recruitment service intended for adults. It is not directed at, and we do not knowingly process the data of, anyone under 16.
11. Contact and changes
Questions about this policy or how we handle your data can be sent to privacy@fiosai.io. We may update this policy as the product changes; the date at the top shows the current version, and material changes will be notified where appropriate.
