To your candidates, your clients, your auditors and your regulator. CloudFlow was designed so that for every screening decision you can answer the hard question: show me how you reached it.
Candidates want to know a human saw their application. Clients want to know shortlists can be justified. Regulators want transparency, oversight and records. Most AI screening fails these tests not because AI is banned — it isn't — but because the tool can't show its working. CloudFlow can: every score is broken down per requirement, backed by evidence quoted from the CV, kept in a full audit trail, and the final decision always belongs to a human.
These aren't policies bolted on afterwards — they're how the product works
CloudFlow ranks and evidences — it never rejects. Your recruiters review the shortlist and make every hiring decision
Each requirement marked met, partial or missing, with the supporting evidence quoted directly from the CV — no black box
Every application, every score and every piece of evidence is recorded and reviewable — for your team, your clients and any audit
Secure storage, data minimization and processing that supports your transparency obligations to candidates
You decide how long application data is kept, matched to your policies and your clients' requirements
100% of applications assessed against the same criteria — no reviewer fatigue, no order effects, nobody skipped
General information, not legal advice — always take advice on your specific circumstances.
GDPR requires candidates to be told how their data is processed, including AI-assisted screening, and requires that processing be fair and accountable. CloudFlow supports this: what was assessed, against which criteria, and with what evidence is recorded for every application — so your privacy notice can be honest and your answers to candidates specific.
Article 22 restricts decisions with significant effects made solely by automation. CloudFlow is built for meaningful human involvement by design: it scores, ranks and evidences, but rejection and progression decisions are made by your recruiters, with the full analysis in front of them.
The EU AI Act treats recruitment AI as high-risk, with obligations around transparency, human oversight and record-keeping phasing in. CloudFlow's architecture — explainable per-requirement scoring, complete audit trails and human final decisions — is aligned with exactly those expectations.
AI CV screening can absolutely be run in a GDPR-compliant way — compliance depends on how the tool is deployed, not on whether AI is involved. The key requirements are a lawful basis for processing, transparency with candidates, meaningful human involvement in decisions, data minimization and appropriate retention. CloudFlow is built for exactly this: explainable scores, full audit trails, configurable retention, and recruiters — not the AI — making every final decision.
Yes. There is no UK law prohibiting AI-assisted screening. What UK GDPR restricts (in Article 22) is decisions with significant effects made solely by automation, without meaningful human involvement. Because CloudFlow ranks and evidences applications but leaves rejection and progression decisions to your recruiters, it is designed to keep you on the right side of that line. This is general information rather than legal advice — take advice on your specific setup.
Under GDPR's transparency principles, candidates must be told how their personal data is processed — and if AI-assisted screening is part of that, your privacy notice should say so. Most employers cover this with a clear line in the application privacy notice. Because CloudFlow records what was assessed and why, you can go beyond the minimum and actually explain an outcome to a candidate who asks.
With CloudFlow every application carries its own audit record: the role requirements it was assessed against, each requirement marked met, partial or missing, the evidence quoted from the CV, the resulting score, and the human decision that followed. That gives your team, your clients and any auditor a complete, reviewable trail for every shortlisting outcome.
Yes — this is CloudFlow's core design principle. Every score breaks down per requirement with supporting evidence quoted directly from the CV. There is no unexplained number: if a candidate scored 72%, you can see exactly which requirements were met, which were partial, which were missing, and the CV text behind each judgment.
CloudFlow applies the same explicit, role-based criteria to 100% of applications — removing reviewer fatigue, time-of-day effects and the lottery of whose CV gets read first. Every judgment is tied to a stated requirement with quoted evidence, so it can be challenged and reviewed by a human. You control the criteria, and your team reviews the output — structured, consistent and transparent screening is the foundation of fairer hiring, though no tool removes the need for human oversight.
No — and with CloudFlow it structurally can't: the platform has no ability to reject a candidate. It removes the lowest-value work (reading every CV) and hands recruiters a ranked, evidence-backed shortlist. People decisions stay with people; that's both better recruiting and what regulators expect.
The EU AI Act classifies AI used in recruitment and employment as high-risk, which brings obligations around transparency, human oversight, accuracy and record-keeping as its provisions phase in. If you hire in the EU, choosing tools designed for explainability and human control matters now. CloudFlow's per-requirement evidence, audit trails and human-final-decision design align directly with those obligations.
Run a real job spec and a real CV through the live demo — every score comes back with its reasoning attached. That's the audit trail your clients and candidates will see.