Regulatory compliance
Built for compliance across the EU, the US, and the UK.
Recruitment AI is now regulated as high-risk in the EU and audited annually in NYC. Here is how Ready handles consent, recording, retention, residency, and rights.
Under New York City Local Law 144, an automated employment decision tool used on an NYC-resident candidate must be bias-audited by an independent third party, the audit summary posted publicly, candidates notified before the assessment runs, and an opt-out made available.
Ready is designed to support this cooperatively. The customer remains the legal deployer. Before the first NYC-resident candidate is screened, an independent third-party bias audit will be commissioned for the deployment, with Ready supplying the impact-ratio data and the public posting template, and the audit refreshed annually thereafter. Demographic data is never imputed.
- Audit commitment. An independent third-party bias audit will be commissioned for the deployment before the first NYC candidate is screened, and refreshed annually.
- Public posting. Audit summary made available at the deployer's careers site for the legally required period from the date of completion.
- Candidate notice and opt-out. Candidates are notified before the assessment runs. An opt-out or alternative assessment is arranged with the employer on request, with no negative inference applied. A built-in in-product opt-out is on the roadmap.
The EU AI Act classifies AI used to analyse, filter, or evaluate job applications as high-risk. Ready operates as the provider and supports the deployer's obligations. Human oversight, transparency to the candidate, and record-keeping are live in the product today. The remaining provider obligations, the formal risk management file, technical documentation, data governance, accuracy and cybersecurity testing, post-market monitoring, conformity assessment, EU database registration, and CE marking, are being completed per deployment ahead of the August 2026 enforcement date for high-risk systems.
- Human oversight (live). Every score is advisory to a human reviewer, not a final decision. Ready never auto-rejects and never auto-hires.
- Transparency and record-keeping (live). The candidate is told before the session that an AI scores it and a human decides. Consent, attempts, and deletions are written to an audit log.
- Technical documentation (in progress). Data sources, methodology, and validation results compiled for the deployer ahead of conformity assessment.
- Risk management and monitoring (in progress). The formal risk file and post-market drift and impact-ratio monitoring are being established with each deployment, not yet running automatically in-product.
Voice recordings and transcripts are personal data under GDPR, UK GDPR, CCPA, and CPRA. Ready operates on consent paired with a data protection impact assessment maintained per deployment. Each candidate sees a consent screen before the simulation begins; it identifies the recording, the AI assessment, the use, and the retention window. Consent is logged with the version of the notice, the timestamp, and the IP address.
At the consent screen, the candidate picks one of two retention options. Six months, or until the role closes, whichever comes first, with the recording used only for this role. Or twelve months, where the candidate chooses which partner companies may review them; only the companies the candidate selects can see them, no other company can discover them, and the candidate can stop sharing at any time. Either option can be revoked at any time, and erasure is honored within thirty days.
Voiceprints and speaker recognition templates are not retained beyond the live session. The artifacts kept are the transcript, the scenario state, and the rubric scores.
- Pre-session consent. Versioned and logged. No silent recording.
- Candidate-chosen retention. Six months or until the role closes, used for this role only. Or twelve months, where the candidate chooses which partner companies may review them; only the selected companies can see them, and the candidate can stop sharing at any time. The candidate picks, and either choice can be revoked.
- No voiceprint retention. Voice embeddings and speaker templates are discarded at the end of the session.
- Self-service access and erasure. Candidates download, correct, shorten, or delete their own data from the data and rights page. Deletion removes the record from the live store immediately; no separate backup copy is kept.
All traffic between the candidate's browser and the service is encrypted in transit. Audio, transcripts, and scoring evidence are held on infrastructure PrompX operates, with role-based access inside the employer console. Candidate audio is not used to train external models.
The AI subprocessors, OpenAI for scoring and Deepgram for speech-to-text, process candidate data in the United States. For UK candidates, that transfer is made lawful through the international data transfer terms in our data processing agreements with those providers (the UK Addendum or the providers' Data Privacy Framework certification). US candidate data stays within the US and is not subject to a transfer restriction.
- Encryption in transit. Modern transport-layer encryption (HTTPS) on all candidate and console traffic.
- Processed in the United States. OpenAI and Deepgram process candidate audio and transcripts in the US. This is disclosed to the candidate before the session.
- Lawful UK transfers. UK-to-US transfers rely on the UK international data transfer terms in our subprocessor agreements, available to the deployer on request.
- Role-based access, no external training. Scoped console views per role, and candidate data is not used to train external or third-party models.
Where local employment law requires works council co-determination or employee-representative consultation before a candidate assessment is deployed, Ready provides the documentation, consultation templates, and timing guidance the deployer needs.
Where local law requires meaningful human oversight on any candidate-facing AI, Ready already operates as an advisory layer to a human reviewer. The legal framework varies by country; the product posture is the same everywhere.
- Germany. Works council consultation templates and timing guidance for the deployer's HR and legal teams.
- France. Human reviewer required for every adverse decision. CNIL guidance reflected in the consent flow.
- United Kingdom. UK GDPR treated to EU GDPR standards. ICO guidance on AI in employment reflected in the deployment review.