Little Bo Peep

Trust Centre

Plain-language privacy, retention, subprocessor and security information for managed pilots.

Privacy

Little Bo Peep processes candidate documents and extracted candidate information on behalf of recruitment customers. The customer determines why candidate data is processed and acts as controller; the Little Bo Peep operator acts as processor for the managed service.

Data processed

Uploaded documents, extracted contact and career information, review decisions, provenance, audit events and account information. Sensitive candidate fields are disabled by default and must be explicitly enabled by a tenant administrator.

Candidate rights

Tenant administrators can export, correct and delete candidate records. Requests should first be sent to the recruiting organisation that collected the candidate's information.

This pilot notice must be reviewed and adapted by qualified legal counsel before broad production use.

Retention

Tenant administrators configure retention for original uploads and extracted working files. The service runs the policy automatically and also provides a manual run control. Public demo uploads and sessions are removed on a short demo schedule.

DataDefault pilot settingControl
Original CV files30 daysTenant configurable
Extracted working files30 daysTenant configurable
Candidate records365 daysExplicit export, correction and deletion workflow
Public demo data1 dayAutomatic cleanup
Audit eventsRetained for accountabilityAppend-only storage; contract policy required

Subprocessors

The local managed-pilot stack is self-hosted. It uses the following software components within the operator-controlled deployment:

ComponentPurposeCandidate content
PostgreSQLTenant, candidate, audit and configuration recordsYes
RedisDurable processing queueIdentifiers and job metadata
Apache TikaDocument text extractionYes, during processing
ClamAVMalware scanningUploaded files during scanning

Infrastructure hosts, transactional email providers, object storage providers and external connectors must be added here before they receive production customer data.

Security

Managed pilots require HTTPS at the public edge, unique production secrets, encrypted backups, monitored patching and a tested incident process.