Trust center

Quebec-ready trust for AI-assisted hiring

Cofeeds publishes its privacy, language, consent, audit, and employer-responsibility posture so hiring teams can review the evidence behind each candidate workflow before they scale.

Compliance posture

Law 25, PIPEDA, and Bill 96 in one review path

The trust model combines privacy law readiness, French-language service commitments, candidate consent, security controls, and human hiring accountability.

Law 25 and PIPEDA readiness

Candidate profiles, interview recordings, consent records, access controls, retention schedules, deletion requests, and privacy contact workflows are designed to support Quebec Law 25 and Canadian PIPEDA review with counsel.

Bill 96 language-of-service posture

Cofeeds supports a French-first candidate and employer experience in Quebec, including French onboarding, French commerce paths, French legal pages, and bilingual parity checks for key hiring workflows under Bill 96 / Loi 96.

AI interview consent

Candidates are asked to consent before starting an AI voice interview. The consent posture covers recording, transcription, automated analysis, employer access after unlock, and the option not to proceed.

Retention and deletion controls

Account data, resumes, interview media, transcripts, scores, embeddings, payment records, and audit logs are governed by published retention windows and deletion handling.

Bias review and human judgment

Cofeeds treats AI scores as decision support. Employers remain responsible for hiring decisions, and candidates may request human review or an explanation of automated assessment results.

Security controls

The service uses encryption in transit, private storage for resumes and interview recordings, role-based access patterns, audit logs, rate limits, and operational monitoring.

Operational proof

Data handling reviewers can inspect

Cofeeds maps sensitive hiring data to a purpose, retention posture, deletion path, and review owner so privacy counsel and employers can evaluate the workflow beyond a policy statement.

Data type

Purpose

Processor/category

Storage and transfer posture

Retention and deletion posture

CV and profile data

Profile creation, matching, employer review

Cloud hosting provider and AI/document-processing providers

Private storage with access controls; cross-border processors reviewed before use

Active account; deleted or de-identified within 30 days after account deletion unless law requires retention

Interview recording and transcript

AI interview evidence, scoring support, employer unlock review

Cloud hosting provider, voice/transcription providers, and AI providers

Private media storage and limited processor access for transcription and scoring

Up to 24 months from interview or until account deletion, whichever comes first

Scores, explanations, and embeddings

Ranking, source-linked explanations, auditability, and match quality

Cloud hosting provider, AI providers, and embedding providers

Stored as profile/match artifacts; used as decision support, not as an autonomous hiring decision

Active account; removed or de-identified after deletion handling

Consent and audit records

Proof of notices, candidate choices, employer access, and operational review

Cloud hosting provider and server-side audit logging

Access-limited records used for compliance, security, support, and dispute review

Up to 24 months unless needed for security, disputes, or legal obligations

Payment and transaction records

Billing, accounting, tax, and unlock records

Payment processor and cloud hosting billing references

Payment processor systems plus Cofeeds transaction references

As required by tax and accounting law, typically up to 7 years

Data processors

Published processor and transfer review

Cofeeds tracks processor categories, data handled, and transfer posture so new sensitive processing, subprocessors, and cross-border changes can be reviewed before production use.

Employer responsibilities

AI support does not replace accountable hiring

  • Use candidate data only for legitimate recruiting purposes
  • Keep unlocked candidate profiles confidential
  • Apply human review before contacting, rejecting, or hiring a candidate
  • Comply with employment, privacy, accessibility, and anti-discrimination obligations
  • Respect French-language service expectations for Quebec candidates and teams

Category

Provider

Data handled

Review posture

Hosting, database, authentication, and private storage

Cloud hosting & database provider

Account, profile, resume, interview, audit, and application records

Access is role-based. Cross-border hosting or storage changes should receive privacy and transfer review before production use.

Payments, invoices, and billing records

Payment processor

Billing contacts, checkout sessions, invoices, and payment events

Payment processing is handled by a dedicated payment processor. Cofeeds does not store full card numbers.

Transactional email

Transactional email provider

Email address, message metadata, and transactional email content

Used for service and contact communications. Optional marketing use should be separated and consent-aware.

Error and performance monitoring

Error & performance monitoring provider

Operational logs, error traces, route context, and diagnostics

Personal information in logs should be minimized and reviewed through retention and access controls.

AI, voice, transcription, document processing, and embeddings

AI/LLM and voice providers

Resume text, interview transcript/audio context, scoring support, and embeddings

Sensitive AI processing and cross-border transfers should receive privacy impact and vendor/subprocessor review.

Incident response

Confidentiality incident process

Cofeeds maintains a privacy contact and incident review path for suspected unauthorized access, disclosure, loss, or use of personal information.

  • Triage security or privacy reports through the privacy contact at support@cofeeds.com
  • Record material confidentiality incidents in an internal incident register
  • Assess risk, affected data types, users, processors, and mitigation steps
  • Notify affected people and regulators when applicable law requires notice
  • Review root cause and update safeguards, access controls, or retention practices

Proof artifacts

What reviewers should be able to inspect

The trust center now names the artifacts Cofeeds should be able to produce during customer diligence, privacy review, or a candidate rights request.

AI interview consent disclosure

Candidate-facing notice should state that the interview may be recorded, transcribed, analyzed by AI, connected to profile scores, and shared with employers after unlock.

Candidate visibility controls

Candidates should be able to review profile status, interview completion, account settings, and request access, correction, deletion, consent withdrawal, or human review.

Employer unlock event

Unlock records should connect employer, candidate, timestamp, billing context, and access purpose so profile access remains auditable.

Score explanation sample

A reviewable explanation should show the score dimension, weight, confidence, and supporting CV or transcript evidence where available.

Processor and transfer review

New processors, sensitive AI processing, and cross-border transfers should be checked for contract terms, subprocessors, retention, security posture, and privacy impact.

Audit trail

Evidence, consent, and human review stay visible

Cofeeds is built around source-linked profile evidence, configurable role criteria, consent records, access events, human override, and reviewable score explanations rather than an opaque hiring recommendation.