How Black Star AI Ltd handles candidate personal data on a customer's behalf when the customer uses Hikari. It forms part of the Hikari terms of service (clause 7), and can also be signed separately with an agency that wants its own copy.
Between the Customer (the business that accepted the Hikari terms of service, or that is named when this agreement is signed) ("Controller") and Black Star AI Ltd, a company registered in England and Wales, company number 15408552, registered office 1 Coldbath Square, Farringdon, London, EC1R 5HL, England, ICO registration ZB803206 ("Processor").
The Customer is the controller of candidate personal data uploaded to Hikari. Black Star AI Ltd is the processor, acting only on the Customer's documented instructions. The Customer confirms it has a lawful basis for processing the candidate data it uploads.
Data subjects: job candidates and applicants whose details the Customer uploads.
Personal data: name; contact details; employment history; education; skills; and any other information in a CV or supporting document the Customer chooses to upload, together with the assessments, notes and client feedback recorded against it.
Special category data: Hikari does not request it. CVs may nonetheless contain it incidentally (for example health information, trade union membership, or data from which ethnicity or religion may be inferred). The Customer should minimise this where practical. It is not used as an evaluation input.
Nature and purpose: storing CVs and job descriptions; generating an AI assessment, score and ranking of candidates against a role; producing screening questions and reports; and sending messages to the Customer's clients and candidates at the Customer's direction.
Duration: for the term of the agreement, plus the retention period in clause 6.
We will: process only on documented instructions; ensure personnel are bound by confidentiality; apply the security measures in clause 5; assist the Customer with data subject requests and with data protection impact assessments; and make available the information needed to demonstrate compliance.
The Customer authorises the following sub-processors:
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Railway Corp. | Application hosting and storage | Data stored in the EU (Amsterdam). Railway is a US company; its control plane, support and primary operations are in the US, and traffic routes via a global edge network. | SCCs / UK Addendum; DPA signed |
| OpenAI, L.L.C. | AI assessment of CVs against job descriptions | US | SCCs / UK Addendum |
| Plus Five Five, Inc. (trading as Resend) | Delivering Hikari's emails, which can contain candidate names | Sent from the EU (Ireland); Resend is a US company | SCCs / UK Addendum |
Data submitted through OpenAI's API is not used to train its models. Stripe (payments) handles only the Customer's own billing details, not candidate data, so it is covered by our privacy notice rather than listed here.
We will give 30 days' notice before adding or replacing a sub-processor, and the Customer may object on reasonable data-protection grounds.
Candidate data is retained for 90 days from upload, enforced automatically by the platform, or until the Customer deletes it, whichever is sooner. On termination we will delete or return all candidate personal data within 30 days, except where retention is required by law.
Hikari produces scores and rankings as decision support. It does not make automated decisions about candidates, and the Customer must not use it as the sole basis for a decision producing legal or similarly significant effects on a candidate (such as rejecting an application) without meaningful human review, as required by Article 22 UK GDPR.
The Customer is responsible for ensuring a human reviews outputs before any decision affecting a candidate, and for informing candidates about the use of automated tools in its own privacy notice.
Where personal data is transferred outside the UK, the parties rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism.
We will notify the Customer without undue delay and within 48 hours of becoming aware of a personal data breach, with the information needed for the Customer to meet its own obligations.
We will make available the information necessary to demonstrate compliance, and allow audits by the Customer or its auditor, on reasonable notice, no more than once a year unless a regulator requires it.