This document gives customers, acting as data controllers, technical and processing information about the Candidate Insights Assistant to support their own privacy, security, and legal assessments.
Note: Nothing in this document is legal advice, and it does not override your own legal counsel. Your organization is responsible for determining how to use the Candidate Insights Assistant in compliance with applicable law.
Feature overview
What is the Candidate Insights Assistant?
The Candidate Insights Assistant is an assistive AI feature that lets a Greenhouse user ask natural-language questions about a single candidate and receive plain-language answers synthesized from that candidate's existing Greenhouse data. It retrieves and summarizes information; it does not evaluate, score, rank, or make decisions about candidates, and it has no mechanism to take action on a candidate.
What technology powers it?
The Assistant uses a large language model provided by OpenAI to interpret the user's question and generate a natural-language response from the candidate data retrieved from Greenhouse.
Can the feature be turned off?
Yes. Customers can toggle the Candidate Insights Assistant on or off from the AI Features menu in Greenhouse Recruiting. This is a per-feature control, independent of other AI features.
Data processing details
What are the roles of the parties?
Greenhouse acts as the data processor. The customer is the data controller and is responsible for determining the legal basis for processing, meeting data-subject obligations, and providing any required notices.
What are the data sources?
The Assistant draws only on candidate data that already exists in your Greenhouse account — such as applications and prospect records, scorecard feedback, stage history, and offer and salary details. It does not introduce external data sources.
Which personal-data categories are processed?
The Assistant processes the candidate personal data contained in the records above, limited in every case to what the requesting user is already permitted to see. This can include self-reported structured information a candidate has provided (for example, responses to questions such as veteran status) where that information exists in the record and the user has permission to view it. The Assistant does not infer or assume protected characteristics about a candidate — it reflects only what is present in the data it is permitted to read.
Is special-category data processed?
The Assistant does not derive, infer, or generate sensitive or special-category characteristics about a candidate. Where a candidate has self-reported structured information that may be sensitive (such as veteran status), the Assistant may surface that information if it exists in the record and the user is permitted to see it, because it reflects the underlying data rather than making assumptions about the individual.
Data retention and storage
How is Assistant chat content stored?
Each message in an Assistant conversation is stored as its own record. Messages are mapped to a chat (a chat contains many messages), each chat is associated with the specific application it relates to, and each chat records the Greenhouse user who created it.
How long is chat content retained?
Because chat content is associated with a specific application, it is governed by the same candidate data retention framework as other candidate data in your account. You control retention as the data controller: you set your own data retention rules in Greenhouse Recruiting (per office, and separately for rejected and, if enabled, hired candidates), and after your contract with Greenhouse ends, all personal data in your account is automatically deleted 90 days after expiration or termination, subject to a short backup period.
Does deleting or anonymizing a candidate also remove the associated chat content?
Yes. Because chat and message records are associated with the candidate's application, they are deleted or anonymized along with the candidate's other personal data when that data is deleted or anonymized under your retention rules.
Is any data retained by OpenAI?
Greenhouse is subject to OpenAI's 30-day retention policy, which states that OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse. After 30 days, API inputs and outputs are removed from OpenAI's systems, unless they are legally required to retain them. No customer data, personal data or otherwise, is used to train external models.
Third-party processing (sub-processors)
Which sub-processors receive data?
OpenAI processes data as a sub-processor to generate the Assistant's responses. To answer a question, the user's question and the candidate data retrieved to answer it are sent to OpenAI.
What contractual protections apply?
OpenAI receives data under a Data Processing Addendum that flows down data-protection obligations and prohibits OpenAI from using the data for its own purposes, including model training. Greenhouse does not use any personal data that we store or process on behalf of our customers to train our internal LLMs/ML or third-party models. Furthermore, outputs generated by Greenhouse AI features are treated as customer data, protected under and governed by our Master Subscription Agreement and Data Processing Addendum.
International transfers
Greenhouse is certified to the EU-U.S. Data Privacy Framework and the UK Extension to the EU-US. Data Privacy Framework. Any cross-border transfers of personal data from the EEA or the UK are subject to the EU-U.S Data Privacy Framework or the UK Extension to the EU-US. Data Privacy Framework. Greenhouse secondarily relies on Standard Contract Clauses and additional safeguards for data transfers.
Security measures
Customer data is encrypted in transit between customers and Greenhouse using Transport Layer Security (TLS) 1.2 or higher.
Customer data is encrypted at rest using a minimum Advanced Encryption Standard (AES) 256-bit encryption.
Automated decision-making
Is the Candidate Insights Assistant automated decision-making under GDPR Article 22?
No. The Assistant does not make decisions, produce evaluations, or score, rank, or categorize candidates. It retrieves and summarizes information the user already has access to, and it has no mechanism to advance, reject, or otherwise action a candidate. When asked to advise on a decision, it declines and returns factual status only. Because the Assistant produces no decision and no evaluation, it does not perform automated decision-making, and all decisions — and responsibility for them — remain with your team.
Individual rights implementation
Supporting data-subject rights is a Customer Action owned by you as the data controller. The Assistant does not create a separate store of candidate personal data beyond the chat content described above; because that content is associated with the application, it is handled through the same candidate data mechanisms as your other candidate data. You are responsible for establishing and operating your processes for access, correction, and deletion requests, using Greenhouse's candidate data tools and your configured retention rules.
Legal basis and compliance
Customer Action: As the data controller, you determine the legal basis for processing candidate data with the Assistant, your data-subject obligations, and any candidate notice required, in consultation with your legal counsel.
Risk assessment, monitoring, and governance
Customer Action: Documenting risks and safeguards, and establishing ongoing monitoring and a review cadence for your use of the Assistant, are your responsibility as the data controller.
Documentation and audit support
Customer Action: You are responsible for maintaining your own records of how your organization uses the Assistant. For sub-processor documentation and Greenhouse's security and compliance certifications, refer to your Greenhouse Data Processing Addendum and the Greenhouse Trust materials.
Additional resources
For more detailed information regarding Greenhouse's overall approach to AI features, including sub-processors, OpenAI policies, and data training, please refer to the AI/ML Security & Privacy article.
For help enabling the Assistant, understanding permissions, and using it day to day, see the Candidate Insights Assistant guide.