Privacy Policy

Last updated: March 2026

This policy describes how Talentika collects, uses, and protects your personal data in compliance with GDPR and the EU AI Act.

1. Introduction

Talentika (operated by [Company Name] S.R.L., a company registered in Romania, hereinafter "Talentika", "we", "our", or "us") operates the Talentika platform available at talentika.ai (the "Service").

This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website or use our Service. It applies to all users of the platform, including recruiters, hiring managers, administrators, and job candidates.

We are committed to protecting your privacy in full compliance with the General Data Protection Regulation (GDPR), the EU AI Act (Regulation 2024/1689), and applicable Romanian data protection legislation.


2. Data We Collect

2.1 Personal Data You Provide

  • Account information: name, email address, company name, job title, phone number
  • Payment information: billing address, payment method details (processed securely by Stripe)
  • Communications: emails, support tickets, feedback, and messages you send us

2.2 Recruitment Data

  • Candidate profiles: resumes/CVs, cover letters, professional qualifications
  • Interview data: AI video interview recordings, assessment responses, evaluation scores
  • Application data: job preferences, availability, salary expectations
  • AI-generated data: parsed CV fields, matching scores, interview assessments

2.3 Usage Data

  • Device and browser information, IP addresses, operating system
  • Pages visited, features used, timestamps, referring URLs
  • Performance data, error logs, and diagnostic information

3. How We Use Your Data

3.1 Service Delivery

We process your data to provide, maintain, and improve the Talentika platform, including candidate screening, AI-powered interviews, CV parsing, analytics dashboards, and career page hosting.

3.2 AI Processing

Our AI features process recruitment data to generate candidate assessments, parse CVs, match candidates to positions, and provide hiring recommendations. All AI processing is subject to human oversight requirements outlined in Section 5.

3.3 Analytics & Improvement

We use aggregated and anonymized usage data to analyze platform performance, improve our algorithms, monitor for bias, and develop new features.

3.4 Communications

We may contact you regarding service updates, security alerts, support responses, and (with your consent) marketing communications. You can opt out of marketing emails at any time.


5. AI & Automated Decision-Making

Talentika uses artificial intelligence for candidate screening, CV parsing, interview assessment, and matching. We are committed to responsible AI use:

5.1 Explainable AI

All AI-generated assessments include explanations of the reasoning and factors that influenced the result. Candidates and recruiters can request detailed explanations of any AI-based evaluation.

5.2 Human Oversight

AI provides recommendations only. Final hiring decisions always remain with human decision-makers. No candidate is rejected solely on the basis of automated processing without meaningful human review.

5.3 Bias Monitoring

We conduct regular audits of our AI systems for fairness and bias across protected characteristics. Results are documented and remediation measures are implemented as needed.

5.4 EU AI Act Compliance

Our AI systems used in recruitment are classified as high-risk under the EU AI Act. We maintain conformity assessments, technical documentation, risk management systems, and human oversight mechanisms as required by Regulation 2024/1689.

5.5 Right to Contest

Candidates have the right to contest AI-based decisions, request human review, and obtain an explanation of the logic involved (GDPR Art. 22).


6. Data Sharing

We share personal data only as necessary to provide the Service and as described below. We do not sell your data.

6.1 Sub-processors

  • AWS (Ireland) β€” Cloud infrastructure and data hosting
  • SendGrid β€” Transactional email delivery
  • Stripe β€” Payment processing
  • Mixpanel β€” Product analytics (anonymized data)
  • Backblaze β€” Encrypted backups

6.2 Legal Requirements

We may disclose data when required by law, court order, or governmental authority, or to protect our rights, property, or safety.

6.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before your data becomes subject to a different privacy policy.


7. International Transfers

7.1 EU Data Residency

All primary data processing and storage occurs within the European Union, specifically in the AWS Ireland (eu-west-1) region. We are committed to keeping your data within the EU wherever possible.

7.2 Standard Contractual Clauses

Where data must be transferred outside the EU/EEA (e.g., to certain sub-processor locations), we rely on EU-approved Standard Contractual Clauses (SCCs) and conduct Transfer Impact Assessments to ensure adequate protection.

7.3 Adequacy Decisions

We transfer data to third countries only where the European Commission has issued an adequacy decision or where appropriate safeguards are in place.


8. Data Retention

We retain personal data only for as long as necessary for the purposes outlined in this policy:

Data TypeRetention Period
Account dataDuration of agreement + 3 years
Candidate dataAs specified in DPA, typically up to 2 years
Interview recordingsUp to 12 months or as agreed
Usage & analytics data12 months (anonymized thereafter)
Billing recordsAs required by Romanian tax law (10 years)
Support tickets2 years

You may request earlier deletion of your data at any time, subject to legal retention obligations.


9. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of Access (Art. 15) β€” Obtain confirmation of whether we process your data and request a copy.
  • Right to Rectification (Art. 16) β€” Correct inaccurate or incomplete personal data.
  • Right to Erasure (Art. 17)β€” Request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
  • Right to Restrict Processing (Art. 18) β€” Limit how we use your data in certain circumstances.
  • Right to Data Portability (Art. 20) β€” Receive your data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21) β€” Object to processing based on legitimate interests or for direct marketing purposes.
  • Rights Related to Automated Decisions (Art. 22) β€” Request human review of decisions made solely by automated means.

To exercise any of these rights, contact us at dpo@talentika.ai. We will respond within 30 days. You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) or the supervisory authority in your jurisdiction.


10. Security Measures

We implement comprehensive technical and organizational security measures:

  • Encryption β€” All data encrypted in transit (TLS 1.3) and at rest (AES-256). Sensitive fields receive additional application-level encryption.
  • Access Controls β€” Role-based access control (RBAC), multi-factor authentication for staff, principle of least privilege.
  • Infrastructure β€” EU-hosted infrastructure with network isolation, firewalls, intrusion detection, and DDoS protection.
  • Audits β€” Regular third-party security assessments, penetration testing, and vulnerability scanning.
  • Incident Response β€” Documented incident response procedures with 72-hour breach notification as required by GDPR Art. 33.
  • Employee Training β€” All personnel receive regular data protection and security awareness training.

11. Cookie Policy

We use cookies and similar technologies on our website:

11.1 Strictly Necessary Cookies

Essential for the website to function properly, including authentication tokens, session management, and security cookies. These cannot be disabled.

11.2 Functional Cookies

Enable enhanced functionality such as language preferences and user interface customization. Require your consent.

11.3 Analytics Cookies

Help us understand how visitors interact with our website using aggregated, anonymized data (Mixpanel). Require your consent.

11.4 Managing Cookies

You can manage your cookie preferences through our cookie banner or your browser settings. Disabling certain cookies may affect website functionality.


12. Contact & DPO

For any privacy-related inquiries or to exercise your data protection rights:

Data Protection Officer:dpo@talentika.ai
General Privacy Inquiries:privacy@talentika.ai
Postal Address:[Company Name] S.R.L., [Street Address], Bucharest, Romania

You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) or the relevant supervisory authority in your EU member state.

This Privacy Policy may be updated from time to time. We will notify you of significant changes by email or through a prominent notice on our Service. Your continued use of the Service after such modifications constitutes your acceptance of the updated Privacy Policy.