Map the information entrusted to the ATS
Applications include contact details, career history, documents, exchanges and interview observations. List forms, storage, analysis, messaging and internal review.
These functions may use different services. Asking only where the main database sits may miss attachments and AI processing. Even a small company benefits from this map.
Distinguish location, control and compliance
Location concerns storage and processing. Operational control concerns actors, access, contracts and recovery of information. GDPR addresses purposes, lawful grounds, rights and appropriate safeguards.
French hosting does not define a suitable retention period, and a French interface does not reveal processing locations. Examine each current product and contract rather than making market-wide assumptions.
Examine jurisdiction carefully
Server location is not the only consideration for foreign-authority requests. The EDPB’s Article 48 guidelines address conditions surrounding requests from third-country authorities.
Do not infer absolute immunity from one hosting choice. Review the actors, access and response procedure with appropriate security or data protection advisers when sector-specific requirements apply.
Check the full chain
Ask about each function and what changes when options are enabled. Also establish how changes to subprocessors are communicated.
| Area | Question |
|---|---|
| Core records | Which countries and regions process them? |
| Attachments | Do storage and access follow the same scope? |
| AI | Which service receives which information? |
| Backups | Where and for how long are copies kept? |
| Support | Who can intervene and under what conditions? |
| Subprocessors | Which contractual list describes the services? |
| Exit | What can be recovered and what happens to remaining data? |
Review your own team’s access
Shared passwords, unused accounts and uncontrolled exports can weaken an otherwise suitable setup. Define roles and remove obsolete access.
Test a restricted user, not only an administrator. aiKip documents workspace roles and security controls so you can examine the actual boundaries.
Understand exit procedures
Ask which structured records, documents and history are recoverable, in what format and with what limits. An export button does not guarantee that every workflow can be reconstructed elsewhere.
Business migration and individual data rights may use different procedures. Also address trial copies and retained exports when leaving a tool.
aiKip’s documented choices
aiKip uses Scaleway infrastructure in France’s fr-par region. Its Sovereignty, DPA and Trust pages describe processing choices and measures.
Read their precise scope. Employers retain responsibilities for purposes, information, access and retention. AI use has a separate transparency page and human-oversight context.
Maintain a decision record
Keep dated responses, documents and unresolved points together. Review them when significant product, provider or organizational changes occur.
Sovereignty involves ongoing choices rather than a one-time pre-purchase checkbox.
-
Describe
List actual data and functions.
-
Examine
Connect functions to actors, locations and access.
-
Decide
Record satisfied requirements and open points.
-
Maintain
Review material changes.
Frequently asked questions
Does French hosting automatically establish GDPR compliance?
No. Purposes, lawful grounds, information, rights, permissions and retention also need assessment.
Does a French interface prove sovereignty?
No. Language does not describe the architecture or contractual chain.
Where can I review aiKip’s information?
Use the Sovereignty, DPA, AI Transparency and Trust pages, including the buyer pack.