Responsible AI

Responsible AI, configured around your organisation.

CapoFine uses AI across hiring, onboarding, and learning. Each AI feature has a defined purpose, receives only the data needed for that task, and follows the processing setup approved for your organisation.

Governance applied before AI processing begins
  1. Purpose is defined
  2. Necessary data is selected
  3. Approved location is used
  4. Output returns to its workflow

One governance standard

Different AI features follow the same controls.

Hire, Onboard, and Grow use AI for different jobs. Purpose, data scope, processing location, access, and records stay governed at platform level.

Hire

Recruitment assistance

AI can prepare candidate information and support application review within the recruitment workflow.

Onboard

Employee assistance

AI Buddy can answer first-line questions using the company knowledge available to that experience.

Grow

Learning assistance

AI can help learning teams prepare module content inside the authoring workflow.

Data minimisation

Only the data the AI task needs.

Each AI feature receives a task-specific input. Information from another product, record, or workflow is not added simply because it exists elsewhere in CapoFine.

Illustrative governance viewData scope for an AI task
PurposeAnswer an onboarding policy question
IncludedThe question and relevant company knowledge
ExcludedUnrelated employee, candidate, and learning records
Scope status

Purpose defined Minimum data

The data scope is limited before the request is sent.

Data location and jurisdiction

Know where platform data, AI processing, and backups sit.

AI processing follows the location setup approved for your organisation. The standard CapoFine platform baseline keeps processing described in the DPA within the EEA, with core data and uploaded files in Frankfurt and application hosting in Amsterdam.

  1. 1Organisation policy
  2. 2Approved AI processing location
  3. 3Task-specific AI request
  4. 4Output returns to CapoFine
Standard processing

European Economic Area

Standard platform processing described in the DPA takes place within the EEA.

Core data and files

Frankfurt, Germany

The core database and uploaded-file storage use Frankfurt infrastructure.

Application hosting

Amsterdam, the Netherlands

The CapoFine application is hosted in Amsterdam.

Encrypted backups

Frankfurt and Amsterdam

Backups are encrypted, geographically replicated, and retained for at least 30 days under the standard baseline.

Purpose limitation

Keep each AI request inside its product workflow.

An AI feature receives the context required for its defined job. The output returns to the workflow that requested it instead of becoming open context for every other AI feature.

Selected inputOnly the context required for this task
Controlled outputReturned to the originating workflow

Access remains tied to the product and the user's permissions

Controls by use

Apply the same governance questions to every AI feature.

The exact input changes by feature. The control questions do not: what is the purpose, which data is necessary, who can use it, and what is recorded?

AI useNecessary inputGovernance boundary
Prepare candidate informationRelevant application informationRecruitment workflow and access controls
Answer an onboarding questionThe question and relevant company knowledgeOnboarding access and company knowledge boundary
Prepare learning contentAuthor instructions and selected source materialLearning-author access and publication workflow
Support a configured workflowOnly the fields required for that actionProduct permissions and available audit records

Platform governance

Apply clear boundaries across every AI feature.

CapoFine combines task-specific data controls with role-based access, approved processing locations, and package-dependent audit records.

Minimum necessary data

Limit each AI request to the information required for its defined purpose.

Approved processing locations

Keep AI processing inside the location setup agreed for your organisation.

Access and records

Keep AI features within product permissions and review the audit coverage available in your package.

Explore security and governance
Review your AI setup

Map every AI feature to purpose, data, and location.

Bring your data-handling requirements, approved jurisdictions, retention questions, and access model. We will map them across Hire, Onboard, and Grow and document the controls behind each configured AI feature.