Last updated on 28th August 2026
Allsorter is committed to protecting customer, user and candidate data across its Services, including Nexus, through robust security controls, responsible AI governance, privacy-by-design principles and transparent compliance practices.
For security, privacy, compliance or data protection enquiries, contact:
Certifications and Compliance
Allsorter maintains the following certifications and compliance commitments:
- ISO 27001 certified
- Cyber Essentials Plus certified
- EU GDPR compliant
- UK GDPR compliant
- Data Processing Agreement (DPA) available
- Modern Slavery and Forced Labour Statement
- Responsible AI Governance Framework
Security Controls
Infrastructure Security
- Core platform infrastructure hosted on AWS
- Core platform data stored in Ireland, with backups in Germany
- Feature-specific processing through vetted subprocessors in the locations disclosed below and in the applicable DPA
- Network segmentation and access controls
- Firewalls and access control lists
- Secure backup procedures
- Business continuity and disaster recovery planning
Product Security
- TLS 1.3 encryption in transit
- AES-256 encryption at rest
- Multi-factor authentication
- Role-based access controls
- Least-privilege access model
- Access logging and monitoring
- Periodic penetration testing
- Periodic vulnerability scanning
- Segregated production, backup and testing environments
Organisational Security
- Information Security Management System (ISMS)
- Mandatory security awareness training
- Mandatory data protection training
- Confidentiality obligations for all personnel
- Periodic access reviews
- Incident response procedures
- Security governance programme
- Supplier security reviews
Data Privacy Controls
- Privacy by design and by default
- Data minimisation principles
- Automated retention controls
- Contractual and customer-instructed retention periods
- Secure deletion procedures
- GDPR-aligned processing controls
Nexus Data Processing & Privacy
Allsorter processes candidate CVs and profiles, customer user information, recruitment workflow data, chat messages, user instructions, Portal Data and related service outputs only to provide, operate, secure, support and troubleshoot the Services in accordance with customer instructions and the applicable DPA for Allsorter Nexus.
Nexus Data Protection Roles
Customers remain Controllers of their recruitment activity, Customer Data, Saved Candidate Data, Customer Recruitment Workflow Data and Portal Data. Allsorter acts as Processor on behalf of the customer when processing this data.
For NexusSourcing, the relevant sourcing provider acts as an independent Controller of its underlying candidate database. Allsorter does not determine the purposes or means by which the sourcing provider collects, compiles or maintains that underlying candidate data.
We do not:
- Sell customer data
- Sell candidate data
- Share customer data for advertising purposes
- Use personal data submitted to or generated through the Services to train, fine-tune or improve AI models for Allsorter’s own independent purposes
The Nexus DPA permits processing strictly necessary to provide the Services in accordance with customer instructions, processing with the customer’s prior written consent and the use of data that has been irreversibly anonymised in accordance with applicable data protection law.
Nexus Data Retention
Before a candidate profile is saved, shortlisted, enriched or exported through NexusSourcing, sourcing-provider candidate data may be processed transiently to display search results and enable the customer to determine whether to take further action.
Unless otherwise agreed in writing:
- Uploaded, saved or enriched candidate profiles are retained for 90 days from the date they are uploaded, saved or enriched. They are deleted in the automated deletion job on the Saturday immediately following the end of that period.
- Hiring Manager Connector Portal Data and Portal Output are retained for seven days from the date the Hiring Manager Portal is created. The underlying candidate profile remains subject to the applicable candidate-profile retention period.
- Chat messages, workflow records, task history, system responses, user instructions, access permissions, session identifiers, audit logs, account activity records and related operational metadata are retained for the Subscription Term and deleted thereafter in accordance with the Nexus DPA.
- Customers may agree a shorter candidate-data retention period with Allsorter.
Deleting Saved Candidate Data from Allsorter does not automatically delete or suppress the corresponding candidate profile in a sourcing provider’s underlying database. Requests concerning that underlying database must be addressed to the relevant sourcing provider, although Allsorter may facilitate this where supported by the Services and permitted by law.
Responsible AI and EU AI Act
Allsorter uses artificial intelligence to support CV formatting, text extraction, chat-driven recruitment workflows and the retrieval, organisation, summarisation and comparison of candidate information against customer-supplied requirements.
Nexus supports human-led recruitment processes. It does not independently determine candidate selection criteria or make hiring, rejection, advancement, interview or eligibility decisions.
Our AI Principles
Candidate First
Our technology is designed to support accurate and relevant candidate presentation and comparison while keeping recruitment decisions with people.
Human Oversight
Customers must independently review the accuracy, relevance, completeness and fairness of AI-assisted outputs before using them. Customers must not rely solely on an AI-generated, automated, algorithmic or ranked output to make a decision that produces legal or similarly significant effects concerning a candidate.
Nexus outputs support recruitment workflows and do not replace independent judgement or human decision-making.
Transparency
We provide information about where AI-assisted functionality is used, its intended purpose and known limitations.
Fairness
Nexus is not designed to identify, infer, assess, score, rank or make recommendations based on special category or sensitive personal data. Such data may be processed incidentally if it is present in customer-provided materials, but it is not intentionally made usable for candidate ranking or decision-making.
Privacy and Security
Saved Candidate Data, Customer Recruitment Workflow Data and Hiring Manager Connector Portal Data are protected by the technical and organisational measures set out in the Nexus DPA. A sourcing provider’s own security measures apply to its underlying candidate database and systems.
No AI Training for Independent Purposes
Allsorter does not use personal data submitted to or generated through Nexus to train, fine-tune or improve AI models for Allsorter’s own independent purposes. OpenAI processes service requests under a Zero Data Retention arrangement.
No Data Resale
Allsorter does not sell or resell customer or candidate data.
Controlled Processing
Subprocessors are subject to written data protection obligations and may process data only for authorised service-delivery purposes. Processing locations and retention periods vary by provider and are disclosed in the Nexus DPA and the subprocessor summary below.
Continuous Improvement
We regularly review our AI governance practices, supplier controls and security measures.
EU AI Act
Allsorter assesses its AI-enabled functionality against applicable EU AI Act obligations and maintains a risk-based approach to AI governance.
Nexus is designed to enable users to review, interpret and, where appropriate, override or disregard AI-assisted outputs before acting. Customers remain responsible for lawful deployment, required notices, appropriate AI literacy and human oversight, and verifying outputs before use.
Modern Slavery and Forced Labour
Allsorter is committed to preventing modern slavery, human trafficking and forced labour within its operations and supply chain.
Our Commitment
We maintain a zero-tolerance approach to:
- Modern slavery
- Human trafficking
- Forced labour
- Bonded labour
- Child labour
- Exploitative labour practices
Supplier Due Diligence
As part of supplier onboarding and periodic review activities, we may assess:
- Supplier policies and public statements
- Modern slavery commitments
- Industry and geographic risk factors
- Adverse media and regulatory findings
- Labour-intensive operating models
Where elevated risks are identified, additional review or remediation measures may be applied.
Reporting Concerns
Employees, contractors and suppliers are encouraged to report concerns relating to unethical labour practices, modern slavery or human trafficking.
Reports are reviewed appropriately and without retaliation against individuals raising concerns in good faith.
Third-Party Subprocessors
Allsorter uses vetted subprocessors under written data protection terms. Customers receive advance notice of intended additions or replacements and may object on reasonable data protection grounds.
For NexusSourcing, NinjaHire acts as an independent Controller of its underlying candidate database. It is also authorised as a subprocessor for the processing required to provide NexusSourcing.
Resources
The following documents are available on request:
- ISO 27001 Certificate
- Cyber Essentials Plus Certificate
- Latest Penetration Test Report
- Signed Nexus Data Processing Agreement (DPA)
- Insurance policy
- Modern Slavery and Forced Labour Policy
To request documentation, contact: dataprotection@allsorter.com. You will be asked to sign an NDA for confidential documents.
Contact
Contact point for data protection inquiries:
Current DPO: Ms. T Latta
dataprotection@allsorter.com
Datalive Ltd.
NexusUCD
Belfield Innovation Park
Dublin 4, Dublin, Ireland