Compliance & Responsible AI

German and EU buyers need a clear answer on three topics: GDPR, where candidate data lives, and how AI is used under the EU AI Act. This page is that answer. Virkla GmbH is a Berlin-based processor. Platform data is hosted in the EU. AI rankings never hire or reject on their own. The sections below are written for DPOs, Works Councils, and hiring leads — not as a substitute for legal advice.

Last updated: 10 September 2026

GDPR: who is responsible for candidate data

For recruiting data processed in Virkla, the employer is the controller and Virkla GmbH is the processor under GDPR. That split is the same model German DPOs expect from an ATS. We process applicant data only on the employer's documented instructions, under a Data Processing Agreement (AVV / Art. 28 GDPR). We do not use candidate or employer data to train or fine-tune AI models.

  • Controller: the hiring organisation using Virkla
  • Processor: Virkla GmbH, Kolonnenstr. 8, 10827 Berlin, Germany
  • DPA / AVV available to customers — request it at privacy@virkla.de
  • Candidate rights (access, rectification, erasure, restriction, portability, objection) are exercised against the employer; we support the employer operationally
  • Default candidate-data retention is configurable; the default after an application closes is 6 months unless the employer sets a different period
  • Full legal text is in the Privacy Policy

Data residency: EU hosting, Frankfurt region

Production application and candidate data for the Virkla platform is hosted in the European Union. Our production infrastructure runs in AWS eu-central-1 (Frankfurt, Germany). Edge delivery for the public website uses a CDN; origin data remains in the EU. Where a sub-processor processes data outside the EEA, Standard Contractual Clauses or equivalent safeguards apply — as listed in the Privacy Policy.

  • Primary platform hosting: EU / EEA, Frankfurt region (Germany)
  • Encryption in transit (TLS 1.2+) and at rest
  • Role-based access so recruiters and hiring managers only see what their role allows
  • Activity history on stage changes and reviews to support audits and candidate rights requests
  • Sub-processor categories and locations are published in the Privacy Policy and updated when they change

EU AI Act positioning

AI used to recruit or evaluate people can fall under the EU AI Act's high-risk rules for employment. Virkla does not claim a completed notified-body certification. We design the product so employers can operate as deployers with human oversight, transparency, and logging — and we act as a provider of those tools with corresponding documentation.

  • AI Score Matching ranks candidates against recruiter-defined role criteria. It does not hire, reject, or auto-advance anyone
  • Every AI-assisted step has a human decision point. Recruiters can override scores at any time
  • Outputs are explainable relative to the role profile, not a black-box pass/fail
  • AI scores and recruiter decisions (advance, reject, override) are both stored on the candidate record, so what the AI suggested and what the recruiter decided are always visible side by side
  • Employers using AI Score Matching receive candidate-facing disclosure language for job ads and privacy notices
  • Risk classification for your organisation still depends on how you use the tool — involve your counsel and DPO

Our principles

We hold ourselves to six core principles in every AI feature we build and operate:

  • Transparency: users can always see where AI has been applied and what output it produced
  • Explainability: AI outputs are accompanied by reasoning that makes them interpretable — not just a score
  • Human oversight: every AI-assisted step has a human decision point — AI prioritises and summarises, humans decide
  • Fairness by design: we reduce bias at the points we control — job-language checks, optional anonymised early screening, and scoring prompts that ignore protected characteristics. We do not claim a certified bias-free model
  • Data minimisation: AI features are operated using the minimum candidate and job data necessary for the task
  • Accountability: AI Score Matching outputs and recruiter decisions are both stored on the candidate record, and we take responsibility for the impact of our systems

How AI is used in Virkla

AI features in Virkla are applied at specific, defined points in the hiring workflow. They do not operate autonomously or make binding decisions.

  • AI Score Matching: scores candidates against role-specific criteria defined by the recruiter. Produces a ranked shortlist, not a hire or reject decision. Scores are visible, overridable, and tied to specific criteria
  • Fair hiring workflow — job posting analysis: scans job descriptions for language patterns associated with reduced candidate pool diversity. Flags items for human review; does not automatically edit content
  • Fair hiring workflow — blind CV screening: removes personal identifiers from CV display during early pipeline stages when activated by the recruiter per role
  • AI summarisation: generates short summaries of candidate profiles and evaluation notes to reduce reading time. Summaries are always shown alongside the full source material

Bias monitoring and mitigation

We take the risk of algorithmic bias in hiring seriously. We focus on reducing bias at the points in the workflow where it is introduced — job language and candidate screening — rather than claiming a one-time certification.

  • AI Score Matching prompts explicitly instruct the model to score only skills, experience, and role fit — never to infer or use gender, age, nationality, or other protected characteristics
  • The fair hiring workflow scans job postings for exclusionary or biased language before you publish, and flags identity-revealing language in candidate profiles for review — available on every plan, per job
  • Blind CV features are designed to reduce the influence of identity-correlated signals in early screening
  • We do not use protected characteristics as model inputs or scoring factors
  • We do not currently offer an automated, organisation-level bias impact report; this is on our roadmap

Human oversight requirements

Virkla does not make solely automated hiring decisions. Recruiters review AI rankings and record a human decision on each application. That is the design GDPR Article 22 requires when processing can significantly affect a person. Whether Article 22 applies to your process depends on how your team uses the tool — involve your DPO.

  • No candidate can be rejected, advanced, or hired based on AI output alone
  • AI Score Matching produces a ranked list; the recruiter decides who to contact, advance, or reject
  • All AI-generated outputs are presented as inputs to human decision-making, not decisions
  • Recruiters can override AI suggestions at any point in the workflow
  • AI scores and recruiter decisions are both stored on the candidate record, so the two are always distinguishable

Data practices for AI

AI Score Matching, CV parsing, and the fair hiring workflow's language suggestions run on OpenAI's foundation model (GPT-4o-mini, via the OpenAI or Azure OpenAI API) — Virkla does not train or operate its own machine learning model. Our core commitment: Virkla does not use employer or candidate data to fine-tune or train any AI model. Our full data practices are:

  • We do not fine-tune, train, or improve any AI model on employer or candidate data — for any customer
  • Before a job or candidate profile is sent for AI processing, direct identifiers (candidate name, employer name, institution names) are removed; only skills, experience, and role-relevant fields are included
  • Under OpenAI's standard API terms, data submitted via the API is not used to train OpenAI's models
  • Customer data is never used to improve or train models that benefit other customers
  • All AI-related data processing, including the role of our AI sub-processor, is documented in our Data Processing Agreement and the Privacy Policy's sub-processor list

Transparency for candidates

Candidates have a right to know when AI has been used in a process affecting their application. Virkla provides employers with the information they need to disclose AI use, as required by GDPR and EU AI Act obligations.

  • Employers using AI Score Matching receive candidate-facing disclosure language for job postings and privacy notices
  • Candidates can request information about AI use in their application through their prospective employer
  • We publish and update this Responsible AI Statement publicly when practices change materially
  • We actively monitor EU AI Act implementation and update our practices as requirements become enforceable

Accountability and continuous improvement

Responsible AI is an ongoing operational commitment, not a one-time certification. We have not completed external security or bias certifications (for example ISO 42001) — we describe our current, actual practices below and will update this page as that changes.

  • Internal review of AI feature prompts and outputs as the product evolves
  • A public commitment to update this statement when our practices change, and to say so plainly if a claim no longer holds
  • An escalation path for customers who observe unexpected AI behaviour: responsible-ai@virkla.de
  • We have not completed external security or bias assessments (for example ISO 42001). This page describes current practice; we will update it if that changes

Documents and contacts

Use this page for buyer due diligence. The Privacy Policy is the legally binding description of processing. For AVV, sub-processor lists, or a demo focused on DPO questions, contact us.

  • Privacy and data-subject requests: privacy@virkla.de
  • Legal and compliance: legal@virkla.de
  • Responsible AI escalation: responsible-ai@virkla.de
Back to home

Cookies and analytics consent

We use Google Analytics to understand usage and improve the product. You can accept or reject analytics tracking.