Compliance & AI governance
Last updated: August 12, 2026
DevParser is an AI system used in hiring, so before it touches a candidate your legal and security reviewers need a straight answer about it. This page is that answer, written to be forwarded. Where something is not done, it says so — a vendor page that claims everything is compliant is the one your reviewer stops trusting.
Roles and the DPA
You are the data controller; R1 TECH sp. z o.o. (KRS 0001222088, Kraków, Poland), operating DevParser, is the processor. Our DPA covers GDPR Art. 28(3), serves as the Auftragsverarbeitungsvertrag for German controllers, and for UK controllers the ICO's International Data Transfer Addendum (B1.0) is executed alongside the EU SCCs — the EU SCCs alone do not legitimise a transfer out of the UK. The full text is published at /dpa; email privacy@devparser.it for a signed counterpart.
A human decides every adverse outcome
No candidate is rejected by the system. Any adverse disposition is blocked until a person confirms or overrides it, and each automated decision is logged with the model used, an input hash, the score, the review status and the override reason, retained for two years. This is the Art. 14 human-oversight control, not a policy promise — it is enforced in the code path.
Candidate transparency and data-subject requests
Candidates are told an automated tool is being used and when they were told, and they can request human review. A full Art. 15/20 export is available per candidate through the API, and candidates can be deleted at any time, so you can answer access, portability and erasure requests without contacting us.
No model training on candidate data
Candidate CVs and code submissions are never used to train foundation models. They are sent to model providers under contract solely to run your evaluations. Retention periods run on a scheduled job against the table published in our privacy policy; the current subprocessor list, with processing locations, is published rather than supplied on request.
Integrity signals are evidence, not verdicts
We do not claim to detect AI authorship from writing style, and style-only signals are capped so they cannot decide a flag on their own. What a reviewer sees is process evidence — editor telemetry, optional public-git commit history, peer similarity and public-code matches — which they can inspect and disagree with. If your bias or fairness review asks how a candidate could contest a flag: a human reviews it, and the override is logged.
EU AI Act
Candidate evaluation is a high-risk use under Annex III(4)(a), and provider obligations apply from 2 August 2026. The in-product obligations are built: Art. 12 record-keeping, Art. 13 transparency, Art. 14 human oversight, Art. 15 robustness measures including prompt-injection mitigation, and Annex IV technical documentation in draft. The conformity assessment, EU declaration of conformity, CE marking and Art. 49 registration in the EU high-risk database are external legal steps and are not yet complete. Ask us for the current Annex IV document and we will send it as it stands.
Security posture
Data is encrypted in transit and at rest, ATS credentials are encrypted at rest, every query is scoped to your tenant from a signed token rather than a request parameter, code execution is sandboxed and rate-limited, and application errors are monitored. We do not hold SOC 2 and we have no third-party penetration test report to hand you. If your procurement requires either, tell us where you are in the process and we will tell you honestly whether we can meet your timeline.
Accessibility
Candidates sit assessments under time pressure, so this is a product question and not only a procurement one. The application targets WCAG 2.2 AA: semantic headings, keyboard-operable controls with visible focus, labelled form fields and alt text are checked on every public page by an automated test in our end-to-end suite. We have not commissioned an independent audit and hold no VPAT or EN 301 549 conformance statement. If the European Accessibility Act is in scope for your procurement, tell us what evidence you need and we will tell you honestly whether we have it.
NYC Local Law 144 bias audit
LL144 requires an independent auditor's bias audit within the last twelve months, and no amount of engineering substitutes for one. Ours is not yet commissioned. If you are hiring for a role located in New York City, do not rely on DevParser as an automated employment decision tool until we can hand you an audit summary. The in-product candidate notice exists; the ten-business-day advance notice and the alternative-process offer remain the employer's obligations. Colorado SB 205 and the Illinois AI Video Interview Act may add duties depending on your jurisdiction.
Ask for the full pack
The DPA, the subprocessor annex, the EU AI Act Annex IV technical documentation and the UK DPIA support pack are available to prospects and customers. Email privacy@devparser.it and say which you need.
This page describes how the product is built and where our compliance work stands. It is not legal advice, and it does not by itself make your use of DevParser compliant — you remain the controller and, under the EU AI Act, the deployer.