Skip to main content
Alex is operated by Apriora Inc. We act as a processor of candidate data on behalf of our customers, who remain the controller and the hiring decision-maker. The answers below describe how the platform behaves by default; your agreement with Alex (MSA and DPA) governs where it differs. Need a document that isn’t linked here? Visit our Trust Center or email [email protected].

Data deletion and retention

How long does Alex keep candidate data?

Candidate data is retained for the duration of your contract with Alex, or until you or the candidate request that it be deleted.

How is candidate data deleted?

You can delete a candidate from the dashboard or through the Delete Candidate API. Deleting a candidate permanently removes all of their data from Alex, including from our backups.
Deleting a single interview removes it from your dashboard but does not erase the candidate’s data. To permanently erase a candidate’s data, delete the candidate.

Can we configure our own retention period?

Yes. You can delete candidates at any time, individually from the dashboard or in bulk through the API, to enforce any retention schedule your policies require. A custom retention period can also be set in your agreement with Alex. You can also limit how long shared interview report links stay valid, account-wide or per job.

AI and data use

Does Alex analyze biometric data?

No. Alex doesn’t use facial recognition, facial analysis, voiceprints, or any other biometric analysis to evaluate candidates, and it doesn’t profile candidates by their appearance or voice. Interview evaluations are based only on the content of what the candidate says.

Does Alex use candidate data to train or fine-tune AI models?

No. Alex doesn’t train or fine-tune AI models on customer or candidate data, including resumes, recordings, transcripts, and assessments. Candidate data is used only to provide the Alex service to the customer it belongs to. It isn’t shared across customers or used for marketing.

Do Alex’s third-party AI providers train on our data?

No. Alex uses enterprise AI services (Microsoft Azure OpenAI, OpenAI’s API, Google Cloud Vertex AI, and AWS Bedrock) under business terms that prohibit the provider from using customer data to train its models.

Where can we find the list of subprocessors?

Our current subprocessor list is part of our Data Processing Agreement and is available on request from your Alex contact or [email protected]. The main categories are cloud hosting and database, video infrastructure, speech-to-text and text-to-speech, AI model providers, fraud and identity verification, messaging (email, SMS, WhatsApp), and monitoring.

Hosting and security

Where is captured data stored?

The Alex application runs on Microsoft Azure, and our database and file storage run on Supabase.
  • US customers: data is stored in the United States.
  • EU customers: data is stored in the European Union.
  • UK: data can be stored in the United Kingdom.
  • Other locations: other geographic locations can be configured on request.
Some processing, such as AI model inference, monitoring, and video infrastructure, runs through subprocessors that may operate outside your region. International transfers are covered by Standard Contractual Clauses.

What certifications does Alex hold?

  • SOC 2 Type 2, covering Security, Availability, and Confidentiality
  • ISO/IEC 27001:2022, for our information security management system
  • ISO/IEC 42001, for our AI management system
  • Annual third-party penetration testing
  • Independent, ongoing AI bias audits by Warden AI
We’re happy to share our SOC 2 report, bridge letter, penetration test summary, and EU AI Act conformity assessment under NDA. See our Trust Center for policies and documentation.

Who is responsible if a data breach occurs on Alex’s side?

Alex is responsible for securing the Alex platform and the data we process on your behalf. We maintain a documented incident management and breach notification process. If a breach affects your data, we notify you without undue delay, within 72 hours of becoming aware of it where feasible, and work with you on containment, investigation, and any notices you owe. Liability terms are set out in your agreement with Alex.
Before a web interview starts, the candidate sees that they’ll be interviewed by AI, and must confirm they agree to participate under Alex’s Terms of Service and Privacy Policy. You can add links to your own terms and privacy policy. During a video interview, candidates can see their own camera feed and are reminded that the interview is recorded.

Can candidates request an alternative to an AI interview, or accommodations?

Yes.
  • Request a human interview. The interview welcome page includes a Request non-AI screening instead option, on by default. The request goes to your team, or into your workflow if you’ve set one up to handle it.
  • Accommodations. Candidates see a Need an accommodation? link that emails your team directly.
  • During the interview. If a candidate asks for a human or an accommodation mid-interview, Alex flags the request to your team. It doesn’t approve or deny accommodations itself.
You choose who receives these requests: set the accommodation contact in your settings, and route human-interview requests to the right person with a workflow. You decide and provide the alternative pathway.

How does an individual candidate opt out, or request access, correction, or deletion?

A candidate can opt out of the AI interview with Request non-AI screening instead, and can opt out of messages at any time. For requests about their data, candidates should contact the employer they applied to, since the employer controls that data. Candidates can also email [email protected], and we’ll pass the request to the right customer and help carry it out. Customers can act on these requests directly in Alex:
  • Access: download the candidate’s interview report and recording from the dashboard.
  • Correction: update the candidate’s details in Alex or in your ATS.
  • Deletion: delete the candidate from the dashboard or through the Delete Candidate API.
Link candidates to the Alex Privacy Policy and, for security and compliance documentation, the Alex Trust Center. The interview welcome page already links to Alex’s Terms of Service and Privacy Policy, and to our candidate FAQ.

Fairness

How does Alex test for and reduce bias in AI scoring?

Alex scores every candidate for a role against the same structured criteria your team defines, using only what the candidate said, and never on protected characteristics. Warden AI independently audits Alex for bias every month. Model changes are version-pinned and tested before release, and we continuously run evaluations and monitor scoring in production to catch drift or bias early.

Has Alex had an independent bias audit, for example for NYC Local Law 144?

Yes. Warden AI, an independent AI assurance provider, audits Alex’s AI interviewer monthly. Its methodology aligns with the bias audit requirements of NYC Local Law 144 and is mapped to other frameworks, including the EU AI Act, California FEHA, Colorado, and Illinois. A public summary is available on Alex’s Warden AI assurance page, and the full reports are available on request. Under NYC Local Law 144, the employer is responsible for its own bias audit, publishing the summary, and giving candidates notice. Warden’s audit of Alex can support that work.