1. Data controller
Controller: TalentyGo LLC.
Address: 30 N Gould St Ste N, Sheridan, WY 82801, USA
Privacy Officer email: [email protected]
EU Representative (Art. 27 GDPR): being appointed, contact privacy email for updated details.
2. Data we collect
2.1 Data provided directly by the user
- Identification data: name, last name, email, password (hashed).
- Resume: professional data (experience, education, skills, languages).
- Preferences: role sought, location, expected compensation, employment type.
- Payment data: handled directly by Stripe, Inc. (TalentyGo does not store credit card data).
2.2 Data collected automatically
- Navigation data: IP, user-agent, pages visited, session duration.
- Cookies: necessary, analytics, marketing (see Cookie Policy).
- Device data: device type, OS, browser, language.
2.3 Data we do NOT collect
We do not collect special categories of personal data under Art. 9 GDPR (race, religion, health, sexual orientation, etc.) unless voluntarily included in the resume. We recommend omitting such data from resumes where possible.
3. Purposes of processing
Your data is processed for the following purposes:
- a) Service delivery: AI matching between resume and aggregated listings, roster generation, cover letter, mock interview and Apply Pack preparation (a resume tailored to the posting + cover letter + pre-filled fields/answers, generated from your resume; submitting the application remains the user's responsibility). Legal basis: contract performance (Art. 6.1.b GDPR / CCPA business purpose).
- b) Account management: authentication, support, billing. Legal basis: contract + legal obligations.
- c) Service communications: match notifications, deadlines, ToS updates. Legal basis: contract.
- d) Marketing: newsletter, commercial communications. Legal basis: explicit consent, revocable at any time.
- e) Analytics and product improvement: anonymized usage statistics. Legal basis: legitimate interest.
- f) Security and anti-fraud: abuse prevention, access logs. Legal basis: legitimate interest.
- g) Legal compliance: billing, accounting record retention, responses to authorities. Legal basis: legal obligation.
4. Automated decisions and AI profiling
Pursuant to Art. 22 GDPR and the EU AI Act 2024 (for EU users), and applicable US state privacy laws (CCPA/CPRA, VCDPA):
- TalentyGo uses an AI system ("Charlie AI") to analyze your resume and extract skills, experience, and preferences.
- The AI profiles your resume for matching purposes with aggregated listings.
- Matching decisions do not produce significant legal effects on the user: the roster is a recommendation, not a binding decision. Applications are always decided by the user.
- The user has the right to opt out of AI matching and use TalentyGo as a traditional search engine. To exercise this right, email [email protected].
- The user has the right to request human intervention on AI decisions and express their point of view.
- For complete AI operation details see our AI Transparency Policy.
5-bis. Profile visibility to companies and matching (optional feature)
If you turn on "Make my profile visible to companies", companies and recruiters registered on TalentyGo can see an anonymous card of your profile: years of experience, role, sector, skills, languages, availability and country-level area.
At this stage we never show your name, contacts, employers, exact city or the full text of your resume. The card is built solely from structured data and contains no identifying information.
- Legal basis: explicit, specific and revocable consent (Art. 6(1)(a) GDPR).
- Optional feature: it is not a condition for using the service; you can search and apply without turning it on.
- Revocable at any time: you can turn visibility off from your profile settings, with immediate effect on subsequent views.
Match requests and disclosure of identifying data
A company interested in your anonymous profile can send you a match request. You receive it with the company name hidden and you are free to accept, decline or ignore it.
Your identifying data (name, email, professional profile) is shared with that specific company only if you accept the request: your acceptance constitutes your specific consent to the disclosure. Until then, no identifying data leaves the platform.
After you accept, the company accesses your data and contacts you acting as an independent data controller for its own recruitment purposes. Companies are bound to use the data solely for recruitment, not to attempt to re-identify candidates from anonymous cards, not to disclose it to third parties, and to delete it at the end of the process.
Retention
- Match requests not accepted: expire automatically and are removed after the applicable period.
- Accepted matches: retained for the duration of the selection process and for the period needed to meet obligations and defend rights.
You can turn visibility off at any time and withdraw your consent to disclosure: withdrawal stops any further sharing of your data.
6. International data transfers
For EU users, transfers occur in compliance with Chapter V GDPR (Arts. 44-50):
- Standard Contractual Clauses (SCC) approved by EU Commission (Implementing Decision 2021/914) executed with our US providers.
- EU-US Data Privacy Framework: for providers adhering (e.g., Stripe), transfer occurs under this adequacy mechanism (EU Decision 2023/1795).
- Supplementary measures: end-to-end encryption, resume pseudonymization before sending to external LLMs, access audit logs.
You may request a copy of the SCCs by contacting [email protected].
7. Retention periods
- Active account: data retained for account duration.
- Deleted account: data removed within 30 days of request.
- Inactivity: accounts inactive for over 24 months may be closed with 60 days email notice.
- Billing data: 7 years (US tax requirements) or 10 years (EU bookkeeping).
- Access and security logs: 12 months (for fraud prevention and security).
- Marketing: until consent revocation.
- AI audit logs (Art. 12 EU AI Act): 24 months for matching system audit.
8. Your GDPR rights (EU users)
As a data subject, you have the following rights (Arts. 15-22 GDPR):
- Art. 15 — Access: request a copy of your personal data processed.
- Art. 16 — Rectification: correct inaccurate data.
- Art. 17 — Erasure: "right to be forgotten".
- Art. 18 — Restriction: request temporary processing suspension.
- Art. 20 — Portability: receive your data in structured format (JSON, CSV) to transfer to third parties.
- Art. 21 — Objection: object to processing based on legitimate interest or marketing.
- Art. 22 — No AI: object to automated decisions / profiling (AI matching opt-out).
- Consent withdrawal: withdraw consents at any time.
- Complaint: file complaint with your local Data Protection Authority.
To exercise these rights email [email protected]. We respond within 30 days.
9. US user rights (CCPA/CPRA, VCDPA)
Residents of California (CCPA/CPRA), Virginia (VCDPA), Colorado, Connecticut, Utah have equivalent rights:
- Right to know what personal data we collect about you
- Right to delete (with certain exceptions)
- Right to opt-out of "sale" of personal information (TalentyGo does NOT sell)
- Right to non-discrimination for exercising rights
- Right to correct inaccurate information
- Right to limit use of sensitive personal information
To exercise these rights: [email protected]. We respond within 45 days (CCPA) or 45 days (VCDPA).
TalentyGo does not sell personal information as defined by CCPA §1798.140(t)(1).
10. Minors
TalentyGo is intended for users aged 18 years and older.
We do not knowingly collect data from minors. If we discover we have collected data from a minor without authorization, we will delete it within 48 hours.
For US: TalentyGo is COPPA-compliant — users under 13 are not permitted.
11. Data security
We adopt appropriate technical and organizational measures (Art. 32 GDPR / NIST CSF for US):
- TLS 1.3 encryption in transit + AES-256 at-rest
- Passwords hashed with bcrypt/Argon2
- Two-factor authentication (2FA) available
- Privileged access logs
- Encrypted backups with 30-day retention
- Periodic penetration testing
- Incident management procedures with 72-hour notification to relevant authorities (Art. 33 GDPR)
12. Changes to this Privacy Policy
Material changes to this Privacy Policy will be notified via email at least 30 days in advance. The "Last updated" date at the top of the document reflects the most recent change.
13. Contacts
- Privacy: [email protected]
- DPO: [email protected]
- For EU complaints: contact your local Data Protection Authority
- For California (CCPA): oag.ca.gov/privacy/ccpa