It depends entirely on the vendor and the contract, which is why you must ask directly and get the answer in writing. Check whether customer data is used to improve or train models, whether that is on by default, whether it can be disabled for your account, and which third-party model providers receive candidate data during processing.
Four precise questions, because general assurances about privacy do not answer any of them. Is customer content used to train, fine-tune or improve models, and does that include candidate resumes, interview responses and recruiter notes. If so, is it opt-in or opt-out, and can it be disabled for our account contractually rather than by a setting someone might change. When AI features run, does candidate data leave the vendor's systems and reach a third-party model provider, and if so which one, in which region, and under what terms. Is data used for training separated from data used to deliver the service. Ask for the answers in the contract or an appendix, since a support email is not a durable commitment and the person who wrote it may not have authority to give one.
Because candidate data is personal data you hold as a controller, and using it to improve a vendor's product is a different purpose from delivering the service to you. That distinction affects your privacy notice, your lawful basis analysis and your data processing agreement, and in some jurisdictions it requires more than a quiet clause in standard terms. There is also a commercial dimension worth noticing: your hiring data has value, and pipeline information, interview feedback and outcome data are sensitive competitively as well as legally. None of this means training is unacceptable, and some customers deliberately allow it for better model performance. It means the decision should be deliberate, documented and made by someone with the authority to make it. Include the question in [your standard vendor security review](/ats).
Read the terms rather than the marketing page. Look in the main agreement, the data processing agreement, any AI-specific addendum and the privacy policy, since the relevant clause frequently sits in the least prominent of those. Search for language about aggregated data, anonymised data, service improvement and derived data, which are the usual formulations. Pay attention to whether aggregated or anonymised is defined, because a weak definition can permit more than it appears. Then ask the vendor to confirm your reading in writing. Where the answer is that training occurs and cannot be disabled, that is a legitimate finding to weigh rather than an automatic disqualification, but you should know it before signing rather than during a later privacy review of your own organisation.
Your privacy notice should describe what happens to their data in terms they can follow, including whether automated tools assist in evaluating applications and whether data is shared with processors that support those tools. Vague notices are a common weak point, partly because they were written before AI features were enabled and never revisited. Review the notice whenever you turn on a new capability. In some jurisdictions you may also need to tell candidates specifically that an automated tool is being used in the process and offer a route to human review, so check the requirement with counsel for each market you hire in. Keeping the notice accurate is straightforward if it is part of your change process rather than a document nobody owns.
Get a personalized walkthrough of Pitch N Hire on your own roles and workflow. No slides, no obligation.
Prefer to talk? Book a demo · View pricing
Free 1-user plan · No credit card · Talk to a real hiring expert
See your true cost-per-hire and how much Pitch N Hire could save you — our free Recruitment ROI Calculator gives you the numbers in under a minute. No signup required.
Open the free ROI calculatorPrefer a tailored walkthrough on your real roles? Drop your work email:
★ Free 1-user plan · No spam · Talk to a real hiring expert