Privacy Policy
Last updated: 10/2026
Definitions
For purposes of this Privacy Policy:
"Candidate Data" means any information relating to a candidate, applicant, interview participant, or assessment participant processed through the Services.
"Controller" means the entity that determines the purposes and means of processing personal data.
"Customer" means any organization, company, business, institution, or other entity using the Services.
"Customer Data" means any information submitted to, stored within, or processed through the Services by or on behalf of a Customer.
"Personal Data" means information relating to an identified or identifiable natural person and shall have the meaning assigned under applicable privacy laws.
"Processor" means an entity that processes personal data on behalf of a Controller.
"Services" means all websites, software applications, APIs, assessments, interviews, diagnostics, reports, platforms, and related services provided by NebulaOne.
1. Introduction
(1) NebulaOne ("NebulaOne", "we", "us", or "our") is committed to protecting the privacy, confidentiality, and security of personal data processed through our Services.
(2) This Privacy Policy explains how NebulaOne collects, uses, stores, discloses, transfers, and otherwise processes personal data.
(3) This Privacy Policy is intended to comply with applicable privacy and data protection laws, including, where applicable:
- (a) the General Data Protection Regulation (EU) 2016/679 ("GDPR");
- (b) the UK General Data Protection Regulation ("UK GDPR");
- (c) the Swiss Federal Act on Data Protection ("FADP");
- (d) the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA");
- (e) other applicable international privacy and data protection laws.
(4) By accessing or using the Services, you acknowledge the practices described in this Privacy Policy.
2. Data Controller and Contact Information
(1) NebulaOne is the product name of a service operated by KuN Holding GmbH. References to “NebulaOne”, “we”, “us” or “our” in this Privacy Policy refer to KuN Holding GmbH. Unless otherwise stated, KuN Holding GmbH acts as the Controller of personal data processed under this Privacy Policy.
(2) In certain circumstances, including candidate assessments, hiring workflows, organizational diagnostics, and workforce planning engagements, NebulaOne may act as a Processor or service provider on behalf of a Customer.
(3) Questions regarding this Privacy Policy may be directed to:
3. Scope of this Privacy Policy
(1) This Privacy Policy applies to:
- (a) website visitors;
- (b) prospective customers;
- (c) customers;
- (d) employees, contractors, and representatives of customers;
- (e) candidates;
- (f) assessment participants;
- (g) interview participants;
- (h) users of the Services.
(2) This Privacy Policy applies to personal data collected through:
- (a) websites;
- (b) software applications;
- (c) APIs;
- (d) assessments;
- (e) interviews;
- (f) voice sessions;
- (g) video sessions;
- (h) customer communications;
- (i) any other Services offered by NebulaOne.
4. Categories of Personal Data We Collect
4.1 Account and User Information
(1) NebulaOne may collect:
- (a) name;
- (b) email address;
- (c) telephone number;
- (d) company name;
- (e) job title;
- (f) account credentials;
- (g) profile information;
- (h) support requests;
- (i) communications with NebulaOne.
4.2 Customer Information
(1) NebulaOne may process information relating to customers, including:
- (a) organizational information;
- (b) business information;
- (c) workforce information;
- (d) hiring requirements;
- (e) diagnostic inputs;
- (f) service usage information.
4.3 Candidate Information
(1) NebulaOne may process:
- (a) resume or CV information;
- (b) employment history;
- (c) educational background;
- (d) professional qualifications;
- (e) skills and competencies;
- (f) assessment responses;
- (g) interview responses;
- (h) evaluation materials;
- (i) candidate profile information.
4.4 Organizational Assessment Data
(1) Customers may provide information regarding:
- (a) organizational structures;
- (b) leadership structures;
- (c) team composition;
- (d) workforce challenges;
- (e) hiring challenges;
- (f) operational constraints;
- (g) business objectives;
- (h) strategic priorities;
- (i) organizational assessments.
4.5 Voice and Video Information
(1) Certain Services may involve voice or video interactions.
(2) NebulaOne may process:
- (a) audio recordings;
- (b) video recordings;
- (c) voice transcripts;
- (d) interview transcripts;
- (e) meeting metadata;
- (f) session analytics.
(3) Recordings shall only be created where legally permitted and, where required by law, after appropriate notice or consent has been provided.
4.6 Automatically Collected Information
(1) NebulaOne may automatically collect:
- (a) IP addresses;
- (b) device identifiers;
- (c) browser information;
- (d) operating system information;
- (e) usage information;
- (f) log information;
- (g) performance information;
- (h) security information.
4.7 Cookies and Similar Technologies
(1) NebulaOne may use cookies and similar technologies to:
- (a) provide Services;
- (b) maintain security;
- (c) remember preferences;
- (d) improve performance;
- (e) analyze usage patterns.
(2) Additional information is available in our Cookie Policy.
5. Purposes of Processing
NebulaOne may process personal data for the following purposes:
- (a) providing and operating the Services;
- (b) authenticating users;
- (c) conducting organizational assessments;
- (d) generating diagnostic insights;
- (e) creating role definitions and Anti-JDs;
- (f) facilitating hiring workflows;
- (g) conducting candidate assessments;
- (h) generating reports and recommendations;
- (i) providing customer support;
- (j) improving user experience;
- (k) maintaining security;
- (l) preventing fraud, abuse, and unauthorized access;
- (m) complying with legal obligations.
6. AI-Assisted Processing
(1) NebulaOne uses artificial intelligence and machine learning technologies to support the Services.
(2) AI systems may be used to:
- (a) analyze assessment responses;
- (b) summarize interviews;
- (c) identify patterns and trends;
- (d) generate reports and recommendations;
- (e) support organizational diagnostics;
- (f) assist candidate evaluation.
(3) AI-generated outputs are intended solely to support human decision-making.
(4) NebulaOne does not make autonomous employment, promotion, compensation, disciplinary, or termination decisions on behalf of customers.
(5) Final decisions remain solely the responsibility of the relevant customer organization.
7. Legal Bases for Processing
Where NebulaOne acts as a Controller, the legal basis depends on the purpose of the processing:
- (a) Business contacts, customer support and service security: We process business contact details, support communications and security logs where necessary for our legitimate interests in managing customer relationships, responding to enquiries and preventing misuse of our services (Article 6(1)(f) GDPR), provided these interests are not overridden by the interests or fundamental rights and freedoms of the individuals concerned.
- (b) Contract performance: Where the individual is personally a party to a contract with us, we process personal data necessary to perform that contract or to take steps at the individual's request before entering into it (Article 6(1)(b) GDPR). This basis does not automatically apply to employees or representatives of a corporate customer.
- (c) Legal obligations: We retain invoice and accounting information to the extent necessary to comply with applicable tax and accounting obligations (Article 6(1)(c) GDPR).
- (d) Optional cookies and tracking: If we use optional analytics or marketing cookies or similar technologies, we obtain consent before using them and process the associated personal data on that basis (Article 6(1)(a) GDPR). Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.
Where NebulaOne processes assessment data on behalf of a Customer as a Processor, the Customer is responsible for determining the applicable legal basis and providing the required information to individuals. NebulaOne processes that data only on the Customer's documented instructions, as set out in the applicable Data Processing Addendum. The processor arrangements under Article 28 GDPR do not themselves constitute a legal basis under Article 6 GDPR.
8. Disclosure and Sharing of Personal Data
(1) NebulaOne may share personal data with:
- (a) cloud infrastructure providers;
- (b) hosting providers;
- (c) analytics providers;
- (d) communication providers;
- (e) AI processing providers;
- (f) security providers;
- (g) customer support providers.
(2) NebulaOne may share candidate and assessment information with the customer organization conducting the relevant hiring, evaluation, workforce planning, or assessment process.
(3) NebulaOne may disclose information where required by law, legal process, court order, or governmental request.
(4) Personal data may be transferred in connection with mergers, acquisitions, financing transactions, reorganizations, or asset transfers.
(5) NebulaOne does not sell personal data.
9. International Data Transfers
(1) Hosting: NebulaOne uses AWS infrastructure in Frankfurt am Main, Germany to host Customer Data and Candidate Data. This hosting location does not mean that all processing by other service providers takes place in Germany.
(2) OpenAI: NebulaOne uses OpenAI with the European region selected. OpenAI defines this region as the EEA and Switzerland. Regional storage and processing apply to eligible customer content within the scope of the supported services and configuration. They do not cover all data: system data, such as account, usage and support information, and certain third-party services may be processed outside the selected region.
(3) Perplexity: NebulaOne uses the Perplexity API. Processing is governed by the applicable API terms and Data Processing Addendum, subject to any product-specific terms. Use of the API does not constitute a commitment to processing exclusively within the EEA. Perplexity may engage subprocessors, and processing outside the EEA may occur as provided for in the applicable service arrangements.
(4) Transfer safeguards: The applicable AWS and Perplexity Data Processing Addenda provide for EU Standard Contractual Clauses for qualifying transfers to countries without an applicable adequacy decision. OpenAI's Data Processing Addendum provides for Standard Contractual Clauses or an applicable European Commission adequacy decision for relevant onward transfers. An adequacy decision applies only where the particular recipient and transfer fall within its scope. Additional safeguards may be necessary depending on the transfer and destination.
(5) Further information: Information about the recipients, processing locations and safeguards relevant to your data, including how to obtain a copy of applicable contractual safeguards, may be requested at legal@nebulaone.co. Copies may be redacted where necessary to protect confidential information or the rights of others.
10. Data Retention
(1) NebulaOne retains personal data only for as long as reasonably necessary to:
- (a) provide the Services;
- (b) fulfill contractual obligations;
- (c) comply with legal requirements;
- (d) resolve disputes;
- (e) maintain security;
- (f) enforce agreements.
(2) Upon expiration of applicable retention periods, information may be deleted, anonymized, or aggregated.
(3) Retention by Data Category
- (a) Invoice and Accounting Records: Generally retained for 7 years from the end of the relevant calendar year, or longer where required by applicable law, including for pending judicial or administrative proceedings.
- (b) Account Information and Support Requests: Retained for as long as necessary to manage the customer relationship, provide support and complete account closure and related contractual matters. Thereafter, the data is deleted unless specific information remains necessary to comply with legal obligations or to establish, exercise or defend legal claims, in which case it is retained only for that purpose and for as long as necessary.
- (c) Assessments, Reports and Transcripts Processed on Behalf of Customers: Retained and deleted in accordance with the Customer's documented instructions and the retention and deletion arrangements agreed in the applicable Data Processing Addendum. Transcripts are retained only to the extent and for as long as necessary to understand and verify the corresponding report within those arrangements.
- (d) Audio and Video Recordings and Technical Logs: Audio and video recordings used for assessment processing are deleted once processing is complete and they are no longer needed for that purpose, in accordance with the agreed Customer instructions where applicable. Security and audit logs are subject to separately defined and documented retention periods proportionate to their security, investigation and accountability purposes and are deleted when no longer required, unless a specific legal obligation requires further retention.
11. Security Measures
(1) NebulaOne maintains administrative, technical, and organizational safeguards designed to protect personal data.
(2) Such measures may include:
- (a) encryption in transit;
- (b) encryption at rest;
- (c) role-based access controls;
- (d) authentication controls;
- (e) audit logging;
- (f) security monitoring;
- (g) vendor security reviews.
(3) No method of transmission or storage can be guaranteed to be completely secure.
12. Candidate Privacy Notice
(1) Candidates participating in assessments, interviews, or hiring workflows should be aware that:
- (a) the hiring organization may act as the primary Controller;
- (b) NebulaOne may act as a Processor on behalf of the hiring organization;
- (c) assessment outputs are advisory in nature;
- (d) NebulaOne does not make employment decisions.
(2) Certain privacy requests may need to be directed to the relevant hiring organization.
13. Sensitive Information
(1) Users should avoid providing sensitive personal information unless necessary and legally permitted.
(2) Sensitive information may include:
- (a) health information;
- (b) genetic information;
- (c) biometric information;
- (d) religious beliefs;
- (e) political opinions;
- (f) sexual orientation;
- (g) trade union membership.
(3) NebulaOne does not intentionally collect or analyze such information except where voluntarily provided and permitted by applicable law. In relation to health data, voluntarily providing such data does not, by itself, authorize its processing. Where the GDPR applies, processing health data requires both an applicable legal basis under Article 6 GDPR and a condition permitting that processing under Article 9(2) GDPR.
14. AI Training and Model Development
(1) NebulaOne does not use customer confidential information, organizational assessment data, candidate information, interview content, voice recordings, video recordings, or proprietary business information to train public foundation models.
(2) Customer Data remains isolated and protected.
(3) Information provided by one customer is never used to generate recommendations, diagnostics, assessments, or outputs for another customer.
(4) NebulaOne may use anonymized and aggregated information that cannot reasonably identify individuals or organizations for:
- (a) service improvement;
- (b) analytics;
- (c) security purposes;
- (d) research and development;
- (e) platform optimization.
15. Privacy Rights
15.1 European Economic Area, United Kingdom and Switzerland
Individuals may have the right to:
- (a) access personal data;
- (b) rectify inaccurate personal data;
- (c) erase personal data;
- (d) restrict processing;
- (e) object to processing;
- (f) data portability;
- (g) withdraw consent.
You also have the right to lodge a complaint with a competent data protection supervisory authority, in particular in the EU/EEA country of your habitual residence, place of work or the alleged infringement. In Austria, you may contact the Austrian Data Protection Authority (Österreichische Datenschutzbehörde) at www.dsb.gv.at. You do not need to contact us before lodging a complaint.
15.2 California Privacy Rights
California residents may have rights relating to:
- (a) access;
- (b) deletion;
- (c) correction;
- (d) disclosure;
- (e) non-discrimination.
15.3 Other U.S. State Privacy Rights
Residents of certain U.S. states may have additional privacy rights under applicable state laws.
Requests may be submitted to:
16. Children's Privacy
(1) The Services are intended for businesses, professionals, and job candidates.
(2) The Services are not directed to children and are not intended for individuals who are not legally able to provide consent under applicable law.
17. Changes to this Privacy Policy
(1) NebulaOne may update this Privacy Policy from time to time.
(2) Material changes may be communicated through the website, platform, email notifications, or other appropriate means.
(3) The updated version becomes effective on the date indicated at the top of this Privacy Policy.
18. Contact Information
Questions, requests, or concerns regarding this Privacy Policy may be directed to: