Legal

Compliance,
privacy & trust.

What the Kuzooo Find ecosystem does, what it does not do, and the human-in-the-loop guarantees that frame every candidate and recruiter workflow.

For a buyer-friendly summary of the same posture, visit the Kuzooo Trust Center.

Find Candidates by Kuzooo

Find Candidates by Kuzooo is a public web sourcing intelligence tool for recruiters. Recruiters paste a role or job description and receive a ranked slate of public-profile candidate leads for human review.

The product uses visible public search-result evidence such as profile URL, snippet, title, company, location if visible, and public skills. It does not extract private contact details.

Candidate lead cards can include recruiter review plans with visible evidence, verification steps, outreach preparation, and risk checks. Recruiters must verify the public profile before saving, shortlisting, or marking contacted; Kuzooo does not send outreach automatically.

Find Jobs by Kuzooo

Find Jobs by Kuzooo is a private, resume-first job-search workspace for candidates. Candidates upload or paste a resume, receive matching jobs, see fit explanations, review job quality signals, save jobs, and track applications.

Job details can include application preparation plans with resume focus, proof points, missing evidence, verification checks, a short note draft, and follow-up timing. The candidate remains the decision-maker and applies manually.

The application tracker can suggest stage-aware next actions and follow-up dates. Kuzooo does not send follow-up messages, reply to recruiters, negotiate, or apply automatically.

Candidate resume profiles are private by default. Future recruiter discovery must be consent-based and must not expose a candidate resume or contact details unless the candidate has clearly opted in.

Future discovery settings are treated as consent signals, not an active recruiter marketplace. Kuzooo records the candidate's visibility choice and opt-in timestamp before any future discovery workflow can be considered.

What Kuzooo does NOT do

  • Does not scrape private profile pages
  • Does not automate third-party login or browsing
  • Does not collect emails, phone numbers, or contact details from public profiles
  • Does not infer protected attributes such as gender, age, religion, race, or disability
  • Does not make automated hiring decisions
  • Does not automatically apply to jobs for candidates
  • Does not share candidate resume data with recruiters by default
  • Does not store recruiter-side raw profile data beyond public search-result evidence needed for review

Human-in-the-loop requirement

Recruiter results are candidate leads, not verified profiles or hiring decisions. A qualified human recruiter must review all leads before outreach, screening, or any hiring decision.

Candidate-side job scores are application guidance, not employment advice, guarantees, or automated decisions. Candidates decide what to save, ignore, tailor, and apply to.

Employment AI governance

Kuzooo treats matching, ranking, fit scores, and risk scores as decision-support signals. They are designed to help people prioritize review, not to approve, reject, screen out, or automatically act on a person.

Operators monitor score quality, outcome alignment, audit events, support escalations, data boundaries, and protected-attribute controls before expanding enterprise use or any future candidate-discovery workflow.

Kuzooo also maintains deterministic matching validation benchmarks for candidate job matches and recruiter slates, so known strong matches, role mismatches, risky listings, explanation coverage, and protected-attribute boundaries can be reviewed before live customer outcomes are large enough for calibration.

AI system cards

Kuzooo maintains product-level system cards so intended use, prohibited use, data inputs, outputs, oversight, user controls, monitoring, escalation, and limitations are documented in one place.

Find Candidates by Kuzooo

Convert a role or job description into a ranked slate of public-profile candidate leads for recruiter review.

Intended use

  • Find publicly visible candidate leads that appear relevant to a role brief.
  • Prioritize review using visible role, skill, seniority, company, location, and evidence-confidence signals.
  • Provide recruiter-owned lead review plans with visible evidence, verification steps, outreach preparation, and risk checks.
  • Help recruiters save, shortlist, reject, or mark leads as contacted after human review.

Prohibited use

  • Automated hiring, screening, rejection, interview selection, or employment decisions.
  • Private profile scraping, third-party login automation, or background checks.
  • Private email, phone, or contact extraction from public profiles.
  • Protected-attribute targeting, inference, filtering, or optimization.

Human oversight

  • Recruiters must review each lead before outreach or hiring-process use.
  • Recruiters must open and verify the public source profile before saving, shortlisting, contacting, or rejecting based on the lead.
  • Administrators review search reliability, evidence quality, and calibration before scale decisions.
  • Support escalation is available for corrections, complaints, or misuse concerns.

Monitoring

  • Recruiter operating readiness.
  • Recruiter employment-AI readiness.
  • Matching validation benchmarks.
  • Recruiter score governance and outcome calibration.
  • Platform launch readiness and enterprise audit-pack export.

Find Jobs by Kuzooo

Turn a private resume profile into ranked job opportunities, fit explanations, job quality signals, application preparation plans, and an application tracker.

Intended use

  • Help candidates discover roles that match their skills, goals, location, and work-mode preferences.
  • Explain fit, freshness, apply effort, quality, risk, and response potential in simple language.
  • Provide candidate-owned application preparation plans with truthful resume focus, proof points, missing evidence, verification checks, and note drafts.
  • Help candidates save, ignore, apply, and track application follow-up without automatic applications.

Prohibited use

  • Employer screening, rejection, shortlisting, or hiring decisions.
  • Sharing candidate resume, profile, or contact data with recruiters by default.
  • Automatic job applications, automatic follow-up messages, negotiation, or third-party login automation.
  • Protected-attribute inference, targeting, or optimization.

Human oversight

  • Candidates decide what to save, ignore, tailor, and apply to.
  • Operators review risky listings, search reliability, consent posture, and calibration before scale decisions.
  • Support escalation is available for privacy, correction, billing, and job-quality concerns.

Monitoring

  • Candidate operating readiness.
  • Candidate consent and discovery readiness.
  • Candidate employment-AI readiness.
  • Matching validation benchmarks.
  • Candidate score governance and outcome calibration.

Regulatory context

AI tools used in employment contexts may be subject to applicable law, including the EU AI Act's high-risk treatment for recruitment and employment systems, NYC Local Law 144 on automated employment decision tools, and U.S. equal-employment guidance on AI and selection procedures.

Kuzooo is designed as a decision-support and workflow tool. Customers remain responsible for lawful use, notices, audits, accommodations, and employment-process compliance in their jurisdictions.

Data minimization

Recruiter search results and candidate leads are stored only as long as needed for review. Default retention is 90 days, after which scheduled cleanup removes expired search jobs. Recruiters can also delete searches from workspace history at any time.

Candidate resume and job-search records are account data used to power the candidate workspace. Candidates can keep their profile private and should not upload resumes they are not allowed to process.

Candidate job-search activity has a separate retention lifecycle. The scheduled operations cleanup removes old job views, stale search runs, inactive resume snapshots, unsaved low-value matches, and orphan job postings while preserving active resumes, saved jobs, applications, and profile records.

Candidates can export their candidate workspace data and delete resume, profile, search, saved-job, application, match, and view records from the resume privacy controls. Billing, credit, account, and audit records may be retained where needed for service history and compliance.

Candidate reminder emails are controlled from the resume profile. Candidates can turn off application follow-up reminders and saved-job freshness digests while keeping the product workspace active.

Operational controls

  • Authenticated workspaces and account-scoped candidate job data
  • Billing and credit ledgers for commercial traceability
  • Support tickets for customer escalation and admin review
  • Audit events for key recruiter and candidate workflow actions
  • Timestamped candidate discovery-consent events before any future recruiter discovery expansion
  • Employment-AI readiness checks for human oversight, protected-attribute boundaries, calibration evidence, audit trails, notices, and escalation paths
  • Provider abstractions for live search, AI, and billing configuration

Evidence verification

Superusers can export redacted enterprise audit packs and customer-ready procurement response packets. These artifacts include SHA-256 integrity metadata and generation-record provenance.

Customers and operators can use the Kuzooo evidence verifier to check whether an exported JSON packet still matches its recorded digest and whether Kuzooo can validate its signature.

Support and incident response

Kuzooo publishes default operational support targets by priority and keeps formal SLA terms customer-specific. Security or privacy support tickets are escalated to at least High priority when submitted.

Critical

First response within 4h. Resolution or stabilization target within 24h.

High

First response within 24h. Resolution or stabilization target within 72h.

Normal

First response within 48h. Resolution or stabilization target within 120h.

Low

First response within 72h. Resolution or stabilization target within 240h.

These are operating targets for product support. Customer-specific legal SLAs, support hours, remedies, and named contacts must be captured in the order form, MSA, or support addendum.

Incident response follows a preparation, detection and analysis, containment/recovery, and post-incident review lifecycle. Customer notice depends on confirmed impact, customer scope, applicable law, and customer-specific agreement terms.

  • Preparation: Keep controls, access, backups, provider configuration, support paths, and evidence exports ready before incidents occur.
  • Detection and analysis: Classify the event, scope affected customers, and preserve evidence without expanding data exposure.
  • Containment, eradication, and recovery: Limit impact, correct the defect or configuration, restore service, and keep customers informed.
  • Post-incident review: Record what happened, what changed, and what control or product improvement prevents recurrence.

Subprocessor and vendor transparency

Kuzooo maintains a vendor register covering the provider categories used to run the platform. Customer-specific authorizations, objection periods, regions, DPAs, and legal commitments should be reviewed during enterprise contracting.

Vercel

active

Application hosting and edge/runtime delivery. Serve the Kuzooo web application, APIs, and scheduled jobs.

Data categories: Account metadata, Workspace metadata, Application telemetry, HTTP request metadata.

Configured Postgres database provider

active

Durable relational data storage. Store authenticated user, workspace, billing, support, audit, recruiter search, and candidate job-search records.

Data categories: Account and workspace records, Candidate resume/profile/job-search records, Recruiter public-profile lead evidence, Billing, usage, support, and audit records.

Resend

active

Transactional email delivery. Send signup, password reset, invite, support, and candidate reminder emails.

Data categories: Email address, Workspace name, Invite metadata, Reminder metadata, Support notification metadata.

Razorpay

active

Payment and subscription processing. Create checkout sessions, verify payments, reconcile webhooks, and maintain commercial traceability.

Data categories: Billing plan, Payment reference ids, Transaction amounts, Workspace billing metadata.

Serper

active

Public web search API. Retrieve public-profile search evidence for recruiter sourcing and public job postings for candidate search.

Data categories: Recruiter JD-derived search terms, Candidate job-search terms, Public search result snippets and URLs, Job posting URLs and public job metadata.

OpenRouter

active

AI model API for parsing, matching, scoring, and explanations. Support JD understanding, resume/profile understanding, job matching, fit explanations, and safe plain-language summaries.

Data categories: Recruiter job descriptions, Public-profile evidence snippets, Candidate resume/profile text when candidates use Find Jobs, Public job descriptions and score explanation context.

Official references