Privacy Policy

Last updated September 15, 2026

Your privacy matters to us. This Privacy Policy explains what personal data we collect, how we use it, and your rights. It applies when you contact us about Kit or use Kit as an account holder (employer, recruiter, or team member). This Privacy Policy forms part of our Terms of Service.

1. Who We Are

Kit is operated by Ernest Bursa (sole proprietorship), Dabrowskiego 96/5b, 60-576 Poznan, Poland. We are the data controller for the personal data described in this Privacy Policy.

  • Email: [email protected]
  • Data Protection Officer: We have not appointed a DPO as we do not meet the thresholds requiring one under Article 37 of the GDPR. For data protection inquiries, contact us at the email above.
  • Supervisory authority: Our lead supervisory authority is the Polish Data Protection Authority (UODO), ul. Stawki 2, 00-193 Warsaw, Poland (uodo.gov.pl).

2. Scope and Our Dual Role

Kit serves two types of users, and our role under data protection law differs for each:

  • Employers, recruiters, and team members (you): You create accounts and use Kit to manage recruitment. We are the data controller for your account data. This Privacy Policy governs that relationship.
  • Candidates and applicants: When candidates apply to your job postings, their data is processed by Kit on your behalf. You are the data controller for candidate data, and Kit acts as a data processor. This relationship is governed by our Data Processing Agreement, not this Privacy Policy.

If you are a candidate, please contact the employer you applied to in order to exercise your data protection rights. They are the controller of your data.

3. Information We Collect

3.1 Account Information

When you create an account, we collect:

  • Name and email address
  • Password (stored as a cryptographic hash, not in plain text)
  • Organisation name and team role
  • Profile information you choose to provide
  • Preferred language and notification preferences

If you send a sales inquiry, we collect your email address, the problem you describe, your preferred follow-up timing, and any name or company you choose to provide.

3.2 Information from Third-Party Login

If you sign in using a third-party service (such as Google or GitHub OAuth), we receive your name, email address, and profile picture from that service. We do not receive or store your third-party password.

3.3 Usage Information

When you use Kit, we automatically collect:

  • Log data (IP address, browser type, device information)
  • Pages visited and features used
  • Time and date of your visits
  • Referring website or source

3.4 Payment Information

Payment is processed by Stripe, Inc. We do not store full credit card numbers. We receive only limited information such as the last four digits of your card, card type, and billing address. Stripe's privacy policy governs their processing of your payment data.

4. Lawful Basis for Processing

We process your personal data on the following lawful bases under Article 6(1) of the GDPR:

Purpose Lawful Basis Details
Providing and maintaining the Service Contract (Art. 6(1)(b)) Necessary to perform our contract with you
Processing payments and billing Contract (Art. 6(1)(b)) Necessary to fulfil our billing obligations
Sending transactional emails (account notifications, security alerts) Contract (Art. 6(1)(b)) Necessary to operate your account
Sending product updates and onboarding emails Legitimate interest (Art. 6(1)(f)) Our interest in helping you get the most from Kit. You can unsubscribe at any time.
Responding to sales inquiries Steps at your request before a contract and legitimate interest (Art. 6(1)(b), (f)) To understand your request and reply at the time you select
Improving the Service and developing new features Legitimate interest (Art. 6(1)(f)) Our interest in making Kit better for all users, using aggregated and anonymised usage data
Usage analytics and session recordings (Microsoft Clarity) Legitimate interest (Art. 6(1)(f)) Our interest in seeing where people get stuck on our website and in Kit. Clarity runs without asking for consent. See Section 6.
Fraud prevention and security monitoring Legitimate interest (Art. 6(1)(f)) Our interest in protecting the Service and its users from abuse
Compliance with legal obligations (tax records, law enforcement requests) Legal obligation (Art. 6(1)(c)) Required by Polish and EU law

5. How We Share Your Information

We do not sell your personal data. We share your data only with the following categories of recipients:

5.1 Sub-processors

We use the following service providers to operate Kit. A full list with transfer mechanisms is maintained in our Data Processing Agreement (Annex 3).

Provider Purpose Location
Hetzner Online GmbH Infrastructure hosting, storage Nuremberg, Germany (EU)
Cloudflare, Inc. CDN, DNS, security Global (DPF + SCCs)
Stripe, Inc. Payment processing United States (DPF + SCCs)
Functional Software, Inc. (Sentry) Error monitoring United States (DPF + SCCs)
Google Cloud Poland Sp. z o.o. (Gemini API) Default AI model for Kit's AI features Global (SCCs)
Axiom, Inc. Application logs EU (AWS Frankfurt), US company (SCCs)
TypeSafe AI, Inc. Prompt-injection scan and classification of security reports United States (SCCs)
Microsoft Ireland Operations Limited (Clarity) Usage analytics and session recordings, as an independent controller (see Section 6) Microsoft Azure, may transfer to the United States (SCCs)

5.2 Other Disclosures

  • Legal requirements: When required by law, court order, or governmental authority
  • Business transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the successor entity
  • With your consent: When you explicitly agree to share information

6. Cookies and Tracking

We use cookies and similar technologies on our website. Here is what we use:

Cookie Type Purpose Duration
_session_id Essential Keeps you logged in and maintains your session Session
locale Essential Remembers your language preference 1 year
theme Essential Remembers your dark/light mode preference 1 year
_clck, _clsk Analytics (no consent prompt) Microsoft Clarity: recognises your browser on return visits and joins your page views into one session recording 1 year / 1 day
CLID Analytics (third-party, clarity.ms) Microsoft Clarity: records when Clarity first saw your browser on any website that uses Clarity 1 year

Essential cookies are necessary for the Service to function and do not require consent. We do not show a cookie banner, and Microsoft Clarity does not wait for consent: it loads on our website, documentation and onboarding pages, in the signed-in Kit app, and on the public job boards and security pages we host for our customers. It records how each page renders and how you use it: clicks, scrolling, mouse movement, the page address, device and browser details, and an approximate location derived from your IP address. Page text is masked in recordings, except on our marketing pages, public documentation and public job ads. Clarity is not loaded on pages whose address carries a sign-in link, token or search text, on the candidate, researcher, training and reference portals, at checkout, or while a Kit administrator is signed in as you. When you are signed in, we label your recordings with your Kit user ID (never your email) so we can find them when we help you. We tell Clarity to keep its advertising storage switched off.

Microsoft Ireland Operations Limited acts as an independent data controller for Clarity data under its own terms. Microsoft stores this data in its Azure cloud and may transfer it to Microsoft Corporation in the United States under Standard Contractual Clauses.

To opt out of Clarity, block cookies or scripts from clarity.ms in your browser; Kit works normally without them. You can control cookies through your browser settings. Disabling essential cookies may prevent you from using the Service.

7. Data Retention

We retain your personal data for as long as necessary for the purposes described in this policy:

  • Account data: For the duration of your account. If you delete your account, we delete your personal data within 30 days.
  • Unpaid accounts: If an account has no active paid subscription for 45 days, we notify the account owner and, after a further 14-day period, automatically delete the account and its personal data unless a subscription is restored. See our Terms of Service for details.
  • Server logs: Retained for up to 90 days for security and debugging purposes.
  • Sales inquiries: Retained for up to 180 days. If you create an account, your account data follows the account retention periods above.
  • Payment and billing records: Retained for 7 years as required by Polish tax law.
  • Email communication records: Retained for the duration of your account, then deleted with your account.
  • Analytics data: Microsoft Clarity keeps recordings for 30 days. Recordings marked as favourites, and a random sample Microsoft selects, are kept for up to 9 months.
  • Backup data: Backups containing your data are retained for up to 30 days after the primary data is deleted.

8. International Data Transfers

Kit's primary infrastructure is hosted in the European Union (Hetzner Cloud, Nuremberg, Germany). Your core account data is stored and processed within the EU.

Some of our providers are based in the United States or may transfer data there: Stripe, Sentry, Cloudflare, Axiom, Google (Gemini API, which may cache prompts in any country where Google has facilities), TypeSafe AI and Microsoft (Clarity). For these transfers, we rely on:

  • The EU-US Data Privacy Framework (DPF) where the provider is DPF-certified
  • Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914)

Details of transfer mechanisms per provider are listed in our DPA (Annex 3).

9. AI and Automated Processing

Kit's AI features run on Kit's own Google Gemini key by default (see section 5.1). You can switch them to your own Gemini, Anthropic or OpenRouter API key in your AI settings; search embeddings always use Gemini.

  • Automatic: spam screening and component matching of each new security report, a prompt-injection scan and classification of each security report (always on TypeSafe AI, even with your own key), extraction of each uploaded CV, summaries of hiring emails and, with the Outreach add-on, prospect research, reply classification and reply drafts. There is no switch per feature.
  • Only when set up or asked: extraction of custom application fields, on job postings where you set up AI-extracted fields, and the AI assistant and chat, when a user asks them something.
  • When you use your own key, data goes to the provider you chose, under your agreement with that provider.
  • Kit does not use your data to train AI models.
  • No solely automated decisions with legal or similarly significant effects are made about individuals without human review.
  • You have the right to request human review of any decision that was informed by AI-generated output.

9.1 AI Assistants You Connect

You can connect an AI assistant, such as Claude, ChatGPT, or Claude Code, to your Kit account through the Model Context Protocol (MCP). When you do:

  • What we collect: the name and redirect address the assistant registers with Kit, the account and modules you grant on the consent screen, the access tokens we issue, and when the connection was authorized and last used. Kit receives only the requests the assistant sends to Kit. It does not receive your conversations with the assistant.
  • How we use it: to authenticate the assistant, to carry out each request within your role and the modules you granted, to list your connected assistants in your settings, and to limit request volume to prevent abuse.
  • Sharing: Kit sends the result of each request to the assistant you connected. The assistant's provider (for example, Anthropic for Claude) then processes it under your agreement with that provider and its privacy policy. You choose which assistant to connect; Kit does not select or control it. We share data received through these connections with no one else, other than the sub-processors listed in section 5.1.
  • Audit log: when the assistant uses a tool that emails or messages someone outside your account (a candidate, researcher, or invitee), we log which tool ran, your user and account IDs, the outcome, and, where the tool sets one, a masked recipient address. Message content is never logged. This log follows the server-log retention in section 7.
  • Retention: Tokens are kept while the connection is active. A connection ends when you revoke it or after 90 days without use, and its token records are deleted 30 days later. The authorization records created when you connect (your user ID, the assistant, the modules granted, and the time) are kept until the Kit account is deleted. An assistant's registration (its name and redirect address) contains no personal data and is kept so the assistant can reconnect. Data you create or change through an assistant is account data and follows section 7.

Candidate data returned to your assistant is processed on your behalf under our Data Processing Agreement (see section 2). For questions about connected assistants, contact us as described in section 17.

10. Your Rights

Under the GDPR, the UK GDPR, and applicable data protection laws, you have the following rights regarding your personal data:

  • Right of access (Art. 15): You can request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): You can ask us to correct inaccurate or incomplete data.
  • Right to erasure (Art. 17): You can request that we delete your personal data.
  • Right to restrict processing (Art. 18): You can ask us to limit how we use your data.
  • Right to data portability (Art. 20): You can request your data in a structured, machine-readable format.
  • Right to object (Art. 21): You can object to our processing of your data where we rely on legitimate interest. We will stop processing unless we demonstrate compelling legitimate grounds.
  • Right to withdraw consent (Art. 7): Where processing is based on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
  • Right regarding automated decisions (Art. 22): You have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you.

To exercise any of these rights, contact us at [email protected]. We will respond without undue delay and within one calendar month. If your request is complex, we may extend this by up to two additional months with notice.

You also have the right to lodge a complaint with your supervisory authority. For users in Poland, this is UODO (Urzad Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.

11. Email Communications

We send the following types of emails:

  • Transactional emails (account notifications, security alerts, billing receipts): These are necessary to operate your account and cannot be unsubscribed from.
  • Product updates and onboarding emails: You can unsubscribe from these at any time using the unsubscribe link in each email or from your notification preferences in account settings. We support one-click unsubscribe per RFC 8058.

12. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption of data in transit (TLS 1.2+) and at rest
  • Application-level encryption of sensitive data fields (Active Record Encryption)
  • All core infrastructure hosted within the EU (Hetzner Cloud, Nuremberg, Germany)
  • Database traffic isolated on a private network
  • Regular security scanning and dependency auditing
  • Role-based access controls and API token scoping

No method of transmission or storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security.

13. Children's Privacy

Kit is a business tool not intended for use by children. We do not knowingly collect personal information from anyone under 18 years of age. If you believe a child has provided us with personal information, please contact us and we will delete it.

14. CCPA Notice (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA provides you with additional rights:

  • We do not sell or share your personal information as defined by the CCPA.
  • You have the right to know what personal information we collect and how it is used.
  • You have the right to request deletion of your personal information.
  • You have the right to non-discrimination for exercising your privacy rights.

To exercise these rights, contact us at [email protected].

15. Google User Data

If you connect a Google account, Kit accesses only the data covered by the permissions you grant, and only for the purposes below. You choose which Google account to connect and which calendars, if any, Kit may use.

  • Email address, basic profile, and OpenID identity (email, profile, openid): used to authenticate you and to create or match your Kit account, and to display your name and avatar inside the application.
  • Google Calendar (calendar): used to list the calendars on your account and store their metadata (name, time zone, access role); to query free/busy windows so interview booking pages only offer times you are actually free; to subscribe to change notifications so your availability stays current; and, for calendars where you switched on "Allow creating events in this calendar", to create, update, and delete the calendar entry for an interview you are assigned to. We do not read the contents of your calendar events. Free/busy results are used to compute available times and are not stored.
  • Google Meet (meetings.space.created, meetings.space.readonly): used to create a Meet space for a scheduled interview, and to read details of those meetings — including participant display names, join and leave times, and total duration — so hiring teams can review attendance after an interview. Where a meeting was transcribed, we also retrieve the transcript text through the Meet API and store it encrypted against the interview, so the hiring team can review what was said. We do not access Google Drive, and we do not retrieve meeting recordings or the transcript document itself.

Limited Use. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

Specifically, data obtained through Google APIs is:

  • never sold, and never used for advertising or ad targeting;
  • never transferred, sold, or used to create, train, or improve any machine learning or artificial intelligence model — including generalised or non-personalised models (see also section 9);
  • never read by a human, except where you explicitly ask us to, where it is necessary for security purposes or to investigate abuse, or where we are legally required to;
  • used only to provide or improve the features described above, and not transferred to third parties for any other purpose.

You can disconnect a Google account at any time from your connected accounts page in Kit, or revoke Kit's access directly at myaccount.google.com/permissions. Disconnecting deletes the stored OAuth tokens and the calendar metadata Kit held for that account. To request deletion of Meet conference records or any other Google-derived data we still hold, contact us at [email protected] and we will delete it as described in section 7.

16. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email at least 30 days before the changes take effect. For changes affecting the lawful basis for processing, we will seek your consent where required.

17. Contact Us

If you have questions about this Privacy Policy or our data practices:

  • Email: [email protected]
  • Address: Ernest Bursa, Dabrowskiego 96/5b, 60-576 Poznan, Poland

You also have the right to lodge a complaint with your local data protection authority if you believe we have not handled your personal data appropriately.