Privacy

This service researches real people. That places obligations on us and on the customers who commission the research, and this page states plainly which are whose.

Last updated 20 July 2026

Two roles

Zero One Labs LLC operates recruiting.no. We act in two different roles, and almost every question about your data has a different answer depending on which one applies.

Your account — we are the controller

If you hold an account on recruiting.no, we decide what we hold about you and why. That is your name, your work email, the practice you belong to, the records of your sign-ins, and what you did in the console — which specs you approved, which candidates you decided on, which lists you signed. For that data we are the data controller and this page is your privacy notice.

Research you commission — you are the controller, we are the processor

When a practice commissions research on candidates, the practice decides which role is being filled, which people are worth researching, and what happens to the result. Those are the decisions that define a data controller under the GDPR, and they are the customer’s decisions, not ours. The practice is the controller. We run the research on its documented instructions and are its data processor. The terms governing that are the data processing terms, which form part of our Terms.

The practical consequence: if you were researched and want something changed or erased, the practice that commissioned the research is the party that decides. We will help you reach them, and we act on their instruction — see If you were researched below.

What we hold about account holders

  • Identity and contact — name, work email, the practice you belong to. Provided by you at signup or by whoever invited you.
  • Authentication — we never hold a password. Signing in sends a six-digit code to your email address; we keep the session record and the sign-in history.
  • Your work in the console — the specs you approved, the decisions you recorded with their stated reasons, and the lists you signed. Decisions are kept as an append-only record because a shortlist has to be defensible after the fact: it is the audit trail of your own review.
  • Billing — for self-serve customers, payment is handled by Stripe. We hold the record that a purchase happened and the credit it granted. We never see or store card numbers.

Our lawful bases: performing our contract with you, and our legitimate interest in operating and securing the service. We do not use your account data to advertise, and we do not sell it.

Candidate research data

When a practice commissions a list, the pipeline researches candidates against a role specification the practice has approved. This is the part of the service that touches people who never signed up for anything, so it is worth describing exactly.

Where the data comes from

  • Search indexes — Exa, a search index of public web pages and professional profiles.
  • Public professional profiles — LinkedIn profile data retrieved through Bright Data, a licensed data vendor, in the logged-out public view.
  • The Norwegian business register — Brønnøysundregistrene, public authority data, used to check whether a claimed employer actually exists and whether a person holds the role they claim.
  • Public web pages — company sites, conference programmes, press coverage, public code repositories on GitHub, and similar pages the pipeline reads and then cites.
  • Public DNS records— resolved through Cloudflare, to check whether a claimed company’s domain exists. This is context for reasoning, never evidence about a person.

We do not use logged-in accounts, stored cookies, or credential-based access to any platform. We do not buy candidate lists, we do not run browser automation against sites that forbid it, and we do not attempt to reach anything a member of the public could not reach.

How claims are handled

Accuracy is a legal obligation under the GDPR and it is also the whole product, so the discipline is built into the machinery rather than promised in prose:

  • Every claim in a delivered profile carries a source you can open. A claim whose source cannot be cited does not reach the page.
  • What could not be established is printed as Not established, not guessed at and not quietly dropped.
  • Where two sources disagree about the same person, the conflict is flagged on the page. It is never silently resolved in favour of the tidier answer.
  • A person’s own published claims about themselves can never, on their own, be recorded as verified.
  • Scoring is computed in code from the agreed role specification, not decided inside a language model.
  • A named human reviews every candidate and signs every delivered list. Nothing is delivered on a machine’s judgement alone.

Photographs

Candidate photographs are never stored. When the console shows a profile image it is streamed from the origin CDN at the moment of display, with caching disabled, and nothing is written to our database or to file storage. If the image cannot be fetched, the console shows initials instead. Where a person has set their profile photo to be visible to members only, no channel available to us receives that photo — and the initials are the correct outcome.

Separation between customers

Each practice’s research is isolated from every other practice’s. Every record carries the practice it belongs to, all access is filtered by it, and the identity records that carry contact history and notice state are kept per practice rather than shared across them — because two customers researching the same person are two independent controllers, and their records should not touch.

If you were researched

If you have learned that you appear in research produced through this service, this section is for you.

The practice that commissioned the research is the controller of it. Under Article 14 of the GDPR that practice is responsible for telling you that it holds data about you, and for answering your requests. Our product tracks notice state per person so that a practice can meet that obligation — but the notifying is theirs to do, and we do not do it on their behalf.

You have the right to:

  • ask what data is held about you, and get a copy;
  • have inaccurate data corrected;
  • ask for erasure;
  • object to the processing — research of this kind is normally carried out on the controller’s legitimate interest, and you may object to it;
  • lodge a complaint with a supervisory authority, in Norway Datatilsynet.

Where the research reached you, the sources it relied on are cited in the delivered document itself, so a controller answering your access request can tell you exactly where each statement came from.

If you do not know which practice commissioned the research, write to privacy@01.inc and we will identify the controller and pass your request to them without delay. Where we hold the data as processor, we act on that controller’s instruction — including deleting a person’s record on request.

Where the data lives and who touches it

Research artifacts and account data are held in a Postgres database hosted by Neon in the EU (AWS Frankfurt, eu-central-1). The application itself runs on hosted infrastructure operated by Vercel.

We use a small number of processors to run the service — search, profile verification, database, hosting, email, the language models that perform the research and write the profiles, and payments. Each one, and what it does, is listed in the data processing terms.

How long we keep things

Account data is deleted or anonymised within twelve months of your account closing. The exception is what accounting law requires us to keep — invoices and the records behind them — which is retained for as long as that law demands and no longer.

Candidate research is deleted twenty-four months after the engagement it was produced for ends. That period exists for one reason: a delivered list must stay auditable — including against a claim that someone was set aside unfairly — and that exposure lives in the first couple of hiring cycles. A controller may instruct us to delete a person’s record sooner at any time, and we act on that instruction.

Security

Access to the console requires a verified email address and an active membership of a practice; a confirmed account with no membership can open nothing. Every read and write passes through a single org-scoped data layer, and an automated isolation test runs against the codebase to check that no query can reach another practice’s rows. Data is encrypted in transit. Candidate photographs are never written to storage at all.

We do not claim certifications we do not hold, and there is no audited compliance programme behind this page. What is described here is what the system does.

Contact

For anything on this page, including access, correction, erasure and objection requests, write to privacy@01.inc.

Zero One Labs LLC, a limited liability company organised in Texas, United States · 5900 Balcones Dr, STE 100, Austin, TX 78731 · Texas Taxpayer No. 32098806634.