Skip to the document
FeaturesBlogBook a demo
ENFR
Log inStart free
FeaturesBlogBook a demoLog in
Start free
ENFR

Privacy Policy

Last updated: Still to be filled in: EFFECTIVE DATE

Draft

This draft is not binding yet.

We are publishing our Privacy Policy while counsel is still reviewing it, so you can read how we handle data instead of finding a blank page. It does not yet govern our processing, and parts of it are still being verified. Two things are marked so you can see the gaps for yourself: facts we still have to fill in appear as highlighted tokens, and clauses still being settled carry an "Under legal review" note. We will publish the reviewed version at this address, and tell account holders before it takes effect.

If you are a job candidate and need something now, section 15 tells you where to start. Anything else: contact@talentino.io.

Contents

  1. Introduction
  2. 1About this policy
  3. PART A — When we are the controller
  4. 2What we collect and why
  5. 3Where this data comes from
  6. 4How long we keep it (Part A)
  7. PART B — When we are the processor: candidate data
  8. 5The split, in plain terms
  9. 6Who we share data with
  10. 7How the AI works, and what it does not do
  11. 8International transfers
  12. 9Cookies and similar technologies
  13. 10Talentino Scout (browser extension)
  14. 11Pages candidates interact with directly
  15. 12Security
  16. 13Children
  17. 14Your rights
  18. 15If you are a job candidate
  19. 16Changes to this policy
  20. 17Contact us

Introduction

1About this policy

This policy explains how Still to be filled in: LEGAL ENTITY NAME ("Talentino", "we", "us") handles personal data in connection with:

  • the website talentino.io and its subdomains;
  • the Talentino application at app.talentino.io;
  • the Talentino Scout browser extension; and
  • our sales, support, and marketing activities.

Talentino is a company incorporated in the Kingdom of Morocco, with its registered office at Still to be filled in: REGISTERED ADDRESS. We sell to customers worldwide, including in the European Economic Area and the United Kingdom.

1.1The single most important thing to understand

Talentino plays two different roles, and your rights depend on which one applies.

RoleWhose dataWho decides how it is used
Part AWe are the controllerWebsite visitors, prospects, people who book a demo, our customers' account users, billing contacts, support requestersWe do
Part BWe are the processorJob candidates whose resumes and profiles our customers put into the platformOur customer does (the recruiter or employer)

If you are a job candidate and you want to know why an employer or recruiter holds your data, how long they will keep it, or you want it deleted, that employer or recruiter is the controller and you should contact them. We will help them respond, and we will point you to them if you contact us. See Part B and section 15.

PART A — When we are the controller

This part covers people we deal with directly: website visitors, prospective customers, users of our customers' accounts, and people who contact us.

2What we collect and why

2.1Website visitors (talentino.io)

WhatWhyLegal basis (GDPR Art. 6)
IP address, browser and device type, pages viewed, referring page, approximate location derived from IPTo serve the site, keep it secure, detect abuse, and understand aggregate trafficLegitimate interests (Art. 6(1)(f)): running and securing our website
Cookies and similar technologiesSee section 9Consent for non-essential cookies; legitimate interests for strictly necessary ones

2.2People who contact us or book a demo

WhatWhyLegal basis
Name, work email, company, job title, phone (if given), the message or form content, and any notes we make about the conversationTo respond, to run the demo, to answer questions, and to keep a record of the discussionSteps at your request prior to a contract (Art. 6(1)(b)); legitimate interests in responding to enquiries (Art. 6(1)(f))

2.3Account users (our customers' staff)

WhatWhyLegal basis
Name, work email, password credential, role and permissions, organization, profile settings, languageTo create and administer the account, authenticate users, apply permissionsPerformance of a contract (Art. 6(1)(b)); our legitimate interests where the contract is with the employer rather than the individual (Art. 6(1)(f))
Login times, IP address, device and browser, session records, security event logsTo secure accounts, investigate suspicious activity, and keep an audit recordLegitimate interests (Art. 6(1)(f)): security; legal obligation (Art. 6(1)(c)) where applicable
Product usage: features used, actions taken, credits consumed, errors encounteredTo operate and improve the Services, to bill accurately, and to provide supportContract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))
Support correspondence and its attachmentsTo provide supportContract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))

2.4Billing contacts

WhatWhyLegal basis
Billing name, address, tax identifiers, invoices, payment status, last four digits and expiry of a payment cardTo take payment, issue invoices, and meet accounting and tax obligationsContract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))

We do not store full payment card numbers. Card details are handled by our payment provider (see section 6).

2.5Marketing recipients

WhatWhyLegal basis
Work email, name, company, and records of which messages you opened or clickedTo send product and company updates you asked for, or that are relevant to an existing business relationshipConsent (Art. 6(1)(a)) where required; legitimate interests in business-to-business marketing to existing contacts (Art. 6(1)(f)), subject to local law

You can unsubscribe from any marketing email using the link in it, or by emailing Still to be filled in: PRIVACY CONTACT EMAIL. We will act on that promptly and it will not affect service messages you need to receive (for example, billing or security notices).

3Where this data comes from

Mostly from you. We may also receive:

  • account user details from the customer organization that invited them;
  • billing details from the customer's finance contact;
  • business contact details from publicly available professional sources, where we are prospecting, in which case we will tell you the source if you ask.

4How long we keep it (Part A)

Under legal review

The retention periods below are not set. Treat this table as a draft, not as a description of what happens today.

DataRetention
Account and profile dataFor the life of the account, then Still to be filled in: e.g. 90 days after the account closes, unless a longer period below applies
Demo requests and sales enquiries that do not become customersStill to be filled in: e.g. 24 months from last contact
Support correspondenceStill to be filled in: e.g. 24 months from closure of the request
Security and access logsStill to be filled in: e.g. 12 months
Invoices and accounting recordsFor the period required by Moroccan and other applicable tax and accounting law, currently Still to be filled in: e.g. 10 years
Marketing contact recordsUntil you unsubscribe, then a suppression record indefinitely so we do not contact you again
Website analyticsStill to be filled in: e.g. 14 months
Records needed to establish, exercise or defend legal claimsFor as long as that need lasts, up to the applicable limitation period

When a period ends, we delete the data or irreversibly anonymize it. Backups are overwritten on our normal rotation cycle of Still to be filled in: BACKUP RETENTION PERIOD.

PART B — When we are the processor: candidate data

5The split, in plain terms

When a customer uploads resumes, receives applications through a form, or captures a professional profile using Talentino Scout, the customer decides what to collect, why, how long to keep it, and what to do with the result. The customer is the controller. We host and process that material on the customer's instructions, under a written Data Processing Agreement. We are the processor.

That means:

  • We do not decide which candidates a customer evaluates, or what happens to them.
  • We do not use candidate data for our own purposes.
  • We do not sell candidate data, and we do not share it with other customers.
  • We do not use candidate data to train AI models. See section 7.4.
  • If you are a candidate exercising your rights, the customer is the right place to start. See section 15.

5.1What candidate data typically passes through the platform

Depending on what the customer supplies, this can include: name; contact details; the full text and file of a resume or CV; work history, employers, job titles and dates; education and qualifications; skills and certifications; languages; links to professional profiles and portfolios; a professional profile page captured by Talentino Scout; answers to application questions, including recorded video or audio answers where the customer uses that feature; the customer's notes, statuses, and ratings; and the outputs our system generates, such as scores, per-requirement assessments, written strengths and concerns, extracted citations, suggested interview questions, and drafted outreach emails.

5.2Special category data

We do not ask for, and our customers are contractually prohibited from deliberately submitting, special category data under Article 9 GDPR (for example, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, or genetic or biometric data), or data about criminal convictions and offences.

Resumes and professional profiles are free-text documents and may nonetheless contain such information because a candidate chose to include it. Where that happens, we process it only as an incidental part of the document, on the customer's instructions. Our customers are required not to configure requirements, filters, scoring, or searches that target such information.

6Who we share data with

We do not sell personal data. We share it only as described here.

6.1Sub-processors and service providers

We use the following categories of provider to run the Services. Each is bound by a written contract that limits them to processing on our instructions, imposes confidentiality and security obligations, and, where relevant, includes the transfer safeguards described in section 8.

Under legal review

This list is assembled from our own systems and is not verified yet. Every row has to be confirmed, and any provider that does not receive personal data will be removed rather than listed defensively. The final list will live at a stable address you can subscribe to, as Article 28(2) GDPR requires.

The table below is a starting point assembled from the codebase, not a verified list. Every row must be confirmed, and any provider that does not actually receive personal data should be removed rather than listed defensively.

ProviderPurposeProcessing location
Amazon Web ServicesCloud hosting, storage, database, content delivery, email delivery, and real-time messagingApplication, storage and email: eu-central-1 (Frankfurt). Still to be filled in: REAL-TIME CHANNEL REGION TO CONFIRM
Amazon Bedrock (AWS)Running the AI models that parse resumes and generate scores, explanations, questions and drafted emailseu-central-1 (Frankfurt), EU regional inference profile
Still to be filled in: FURTHER AI PROVIDERS TO NAME
Google Cloud (Cloud Run)The service that composes and sends "missing information" emails to candidates and receives their repliesus-central1 (United States). Still to be filled in: TRANSFER MECHANISM TO CONFIRM
NeonPostgreSQL database hostingStill to be filled in: REGION
PolarSubscription billing, payment processing, and invoicingStill to be filled in: REGION, AND MERCHANT OF RECORD
PostHogProduct analytics, error diagnostics, and application log storageStill to be filled in: REGION
UpstashRate limiting and cachingStill to be filled in: REGION
Google Maps PlatformLocation lookup and normalizationStill to be filled in: CONFIRM whether this receives any personal data
Firebase (Google)Push notificationsStill to be filled in: CONFIRM whether this is active and what it receives
BrandFetch, ClearOutCompany logo and company data lookupStill to be filled in: CONFIRM whether these receive any personal data or only company domains
TrueGuardEmail risk scoring at signupStill to be filled in: REGION
Still to be filled in: SUPPORT / CRM TOOLINGHandling support requests and sales correspondenceStill to be filled in: REGION

The current list is maintained at Still to be filled in: SUB-PROCESSOR LIST URL. Customers can subscribe there to be notified before we add or replace a sub-processor, and may object as set out in the DPA.

6.2Others

  • Our own staff and contractors, on a need-to-know basis, bound by confidentiality.
  • Professional advisers (lawyers, accountants, auditors) where necessary.
  • Authorities, where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims. Where we are a processor, we will tell the customer first unless the law prohibits it.
  • A buyer or successor, in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality and to this policy continuing to apply.

7How the AI works, and what it does not do

7.1What the system produces

The platform reads candidate documents and produces scores, rankings, per-requirement assessments (met, partially met, not met), written strengths and concerns, extracted structured fields, citations pointing back to the source document, suggested interview questions, and draft emails. Requirements and their weightings are set by the customer, either directly or by accepting a suggestion from the system.

7.2A person makes every decision

The platform does not reject, eliminate, hire, or notify any candidate automatically. It does not send an email unless a user chooses to send it. It does not change a candidate's status unless a user chooses to change it. Requirements a customer marks as must-haves cause a candidate to be flagged and shown as not meeting that requirement; they do not remove the candidate or take any action against them.

The interface is built so that a reviewer can see the evidence behind every score: which requirement was assessed, what the assessment was, and the lines from the source document the assessment relies on.

Under legal review

We are verifying that every configuration of the product matches this clause. Read it as our intent, not yet as a commitment.

7.3Automated decision-making (Article 22 GDPR)

Because a person on the customer's team reviews candidates and takes every candidate-affecting action, the platform is designed so that decisions are not based solely on automated processing within the meaning of Article 22 GDPR.

Whether that holds in practice depends on how the customer uses it. The Court of Justice of the European Union held in SCHUFA (Case C-634/21, 7 December 2023) that producing a score that a decision-maker relies on heavily can itself be an automated decision, even where a human formally signs off. A recruiter who accepts or rejects candidates on the strength of a ranking, without looking at the underlying material, is not providing meaningful human involvement.

Our contracts therefore require customers to keep a genuine human review in the process, and to give candidates the information and safeguards Article 22(3) requires if their own use of the platform ever crosses that line. The customer, as controller, is responsible for that assessment and for informing candidates.

7.4We do not train models on candidate data

We do not use candidate data, or any other Customer Data, to train, fine-tune, or otherwise improve any general-purpose AI or machine learning model, whether ours or a third party's. Where we send content to a third-party AI provider to generate an output, we do so under contractual terms that prohibit that provider from retaining the content for its own model training.

Under legal review

We are checking this clause against each AI provider's contract and API settings before it takes effect.

7.5Anonymization before AI processingWithheld

Under legal review

This section is withheld. It described a processing step our own review could not confirm, and publishing it, even in draft, would not be honest. The claim has also been removed from our marketing. What we do say about security is in section 12.

7.6EU AI Act position

Systems used for the recruitment or selection of natural persons, in particular to filter applications and evaluate candidates, are listed in Annex III of Regulation (EU) 2024/1689 (the AI Act). Because the platform evaluates and profiles individuals, we treat it as falling within that category. Article 6(3) provides a narrow exemption for some Annex III systems, but that exemption is expressly unavailable to systems that perform profiling of natural persons, and we do not rely on it.

Under the AI Act, we are the provider of the system and our customers are its deployers. Each role carries its own obligations.

The timetable was amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), published in the Official Journal on 24 July 2026 and in force from 27 July 2026. On the current schedule:

  • 2 August 2026 — the AI Act's general date of application, including the Article 50 transparency obligations. The Article 4 AI literacy obligation has applied since 2 February 2025.
  • 2 December 2027 — the obligations for stand-alone high-risk systems listed in Annex III, including risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, conformity assessment, and registration.

We state plainly what is and is not true today:

  • We have not completed a conformity assessment for the Services, we do not hold a CE marking for them, and they are not registered in the EU database of high-risk AI systems. Those obligations are not yet applicable, and we make no claim to have satisfied them in advance.
  • We do not hold SOC 2, ISO/IEC 27001, ISO/IEC 42001, or any comparable certification, and we do not claim to.
  • We do build the product on the principle that a person stays in the loop and can see the evidence behind every output, which is the substance of the human oversight requirement in Article 14.
  • We will provide deployers with the instructions for use and the information the AI Act requires, on the applicable timetable.

If your organization needs a specific compliance artefact, ask us at Still to be filled in: PRIVACY CONTACT EMAIL and we will tell you honestly whether it exists.

8International transfers

8.1The position

We are established in Morocco. Morocco is not the subject of an adequacy decision by the European Commission under Article 45 GDPR. Personal data that reaches us from the EEA or the UK is therefore transferred to a country without an adequacy decision.

8.2The safeguard we rely on

For those transfers we rely on the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 under Article 46(2)(c) GDPR, using the module appropriate to the transfer:

  • Module Two (controller to processor) where an EEA customer, as controller, transfers candidate personal data to us as processor;
  • Module Three (processor to processor) where an EEA customer is itself a processor for its own client;
  • Module One (controller to controller) for the limited controller-to-controller data described in Part A, where applicable.

For UK transfers we use the UK International Data Transfer Addendum to those clauses. For Swiss transfers we apply the clauses with the amendments the Swiss authority requires.

We carry out and document a transfer impact assessment for these transfers, as Clause 14 of the Standard Contractual Clauses and the Schrems II judgment (Case C-311/18) require. Customers may request a copy of the executed clauses and a summary of that assessment at Still to be filled in: PRIVACY CONTACT EMAIL.

8.3Where data is actually stored

The Services are operated on Amazon Web Services. The application, its database, file storage, email delivery and AI inference through Amazon Bedrock run in the eu-central-1 (Frankfurt) region.

Under legal review

The scope of this statement is still being verified, component by component. Until that finishes, the only hosting statement we stand behind is the one on our homepage: the application, file storage, and email delivery run on AWS in Frankfurt (eu-central-1).

Our staff, contractors, and support personnel are located in Morocco and access the Services from there. That access is itself a transfer, and it is covered by the safeguards in section 8.2.

Some sub-processors may process data outside the EEA. Where they do, an Article 46 transfer mechanism is in place.

8.4Moroccan law

As a Moroccan company we are also subject to Law No. 09-08 on the protection of individuals with regard to the processing of personal data and its implementing Decree No. 2-09-165, supervised by the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP).

Under Articles 43 and 44 of Law 09-08, transferring personal data from Morocco to another country requires either that the destination country provides a sufficient level of protection, or a prior authorization from the CNDP, or that a statutory derogation applies. Where we host or transmit data outside Morocco, we address that requirement.

Under legal review

Our CNDP filings are being confirmed. Nothing in this section should be read as a claim that a registration or an authorization is already in place.

9Cookies and similar technologies

We use:

  • Strictly necessary cookies to log you in, keep your session, balance load, and protect against abuse. These cannot be switched off without breaking the Services.
  • Preference cookies to remember settings such as your language.
  • Analytics cookies to understand how the site and product are used.

What is currently known from the codebase, as a starting point for a proper audit:

TechnologyProviderPurposeNotes
Session cookieTalentino (self-hosted authentication)Keeps you signed inStrictly necessary. Session lifetime 7 days; a short-lived signed session cache is also stored in the cookie.
Locale cookieTalentinoRemembers your languagePreference
Sign-in state cookiesTalentinoComplete a Google sign-in securelyStrictly necessary, set only during sign-in
Product analytics storagePostHogUnderstand product usage and diagnose errorsStored in browser local storage rather than cookies. Not strictly necessary.

Under legal review

We are building the consent controls this section describes, and the table below is a starting point rather than a completed audit. Read it as where we are going, not where we are.

Where consent is required, we ask for it before setting non-essential cookies, and you can change or withdraw it at any time through Still to be filled in: COOKIE SETTINGS LINK. Most browsers also let you block or delete cookies.

10Talentino Scout (browser extension)

Talentino Scout is a Chrome extension that lets a logged-in Talentino user save a professional profile they are viewing into their own Talentino candidate database.

10.1How it works

  • Scout runs only when the user opens it, in the user's own browser, using the user's own session on the site they are visiting.
  • When the user chooses to save a profile, the extension reads the content of the page the user is currently viewing and sends it to Talentino, together with the page URL, so that it can be parsed into a candidate record.
  • For bulk capture from a search results page, the extension collects the profile links on that page and then visits each one in the same browser tab, in sequence, capturing each page in turn.
  • The extension stores a short-lived local record of which profiles have already been captured, so the same person is not imported twice. That record contains the profile identifier and timestamps, and expires after 24 hours.

Under legal review

This description is being rewritten to be more precise about what the extension reads. Do not rely on the current wording.

10.2Permissions

The extension requests browser permissions in order to read the page the user is viewing, to navigate the tab during a bulk capture, and to confirm the user's Talentino login.

Under legal review

The permissions the extension requests are being reviewed against this description, and narrowed to its single purpose, before this section takes effect.

10.3Limited Use disclosure

Talentino's use of information received from Google APIs, and from the Chrome Web Store, adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use the data the extension collects only to provide the extension's single purpose, which is saving professional profiles into the user's own Talentino candidate database. We do not sell it, we do not use it for advertising, and we do not transfer it to third parties except as necessary to provide that purpose, to comply with law, to protect against fraud and abuse, or in connection with a merger or acquisition with the user's consent.

10.4Roles and responsibility

When a customer uses Scout, the customer is the controller of the profile data they capture, and we are their processor. It is the customer's responsibility to:

  • have a lawful basis for capturing and holding that person's data, and to document the balancing assessment if they rely on legitimate interests under Article 6(1)(f);
  • give that person the information Article 14 GDPR requires, because the data was not collected from the person directly, generally within one month of collection or at the first communication with them;
  • respect any objection or erasure request; and
  • comply with the terms of the website they are capturing from.

Talentino is not affiliated with, endorsed by, or connected to LinkedIn Corporation or Microsoft Corporation.

11Pages candidates interact with directly

Some parts of the platform are seen by candidates rather than by our customers' staff. In every case the customer, not Talentino, is the controller of what is collected there.

Career pages and application forms. A customer can publish a branded careers page and a branded application form hosted by us. When a candidate applies, the form collects whatever the customer configured it to collect, which may include contact details, a resume file, answers to written questions, and recorded video or audio answers. That information goes into the customer's candidate database. The customer is responsible for displaying its own privacy notice on that page and for identifying its lawful basis.

Outreach emails and reply links. Where a customer uses the platform to email a candidate, the email is composed by the customer's user, with AI assistance, and sent on the customer's behalf. The customer is the sender and the controller. We provide the sending infrastructure as a processor. A reply link in such an email leads to a page where the candidate can supply the specific information the customer asked for, which is then added to the customer's record for that candidate.

Video and audio answers. Where a customer uses video or voice screening, the recording and any evaluation of it are Customer Data. Several jurisdictions regulate AI analysis of video interviews specifically, including notice, consent, explanation, and deletion duties. Meeting those duties is the customer's responsibility as controller and employer.

12Security

We apply technical and organizational measures appropriate to the risk, including:

  • encryption of data in transit using TLS, and encryption of stored data at rest;
  • access control, with least-privilege access for staff and multi-factor authentication for administrative access;
  • separation of each customer's data, with every request scoped to the customer's own organization and stored files held under a per-customer prefix;
  • an activity and modification history within the product, so changes to a candidate record can be traced;
  • logging and monitoring of access to production systems;
  • backups, and restoration testing;
  • vendor review before we engage a sub-processor; and
  • confidentiality obligations on everyone with access.

Under legal review

Every line above is a representation. Each one is being confirmed, and any that is not implemented today will be removed before this section takes effect.

We do not hold SOC 2, ISO/IEC 27001, ISO/IEC 42001, or any equivalent certification. We do not claim certification we do not have. A current description of our security measures is available to customers on request at Still to be filled in: SECURITY CONTACT EMAIL.

No system is completely secure. We cannot guarantee that unauthorized access will never occur.

12.1If something goes wrong

If we become aware of a personal data breach:

  • Where we are the processor, we will notify the affected customer without undue delay after becoming aware of it, and give them the information they need to meet their own obligations under Articles 33 and 34 GDPR. Specific notification timeframes, where agreed, are set out in the DPA.
  • Where we are the controller, we will notify the competent supervisory authority where required under Article 33 GDPR, and will inform affected individuals where Article 34 requires it.

13Children

The Services are not directed at children. We do not knowingly collect personal data from anyone under 16. Candidates evaluated through the platform are expected to be of working age in their jurisdiction. If you believe a child's data has been submitted, contact us at Still to be filled in: PRIVACY CONTACT EMAIL and we will work with the relevant customer to have it removed.

14Your rights

Where the GDPR or UK GDPR applies, you have the right to:

  • access the personal data we hold about you, and get a copy;
  • have inaccurate data rectified, and incomplete data completed;
  • have data erased in certain circumstances;
  • restrict processing in certain circumstances;
  • object to processing based on legitimate interests, and to object at any time to direct marketing;
  • receive data you gave us in a portable format, and have it transmitted to another controller, where processing is based on consent or contract and is automated;
  • withdraw consent at any time, where processing is based on consent, without affecting processing done before withdrawal; and
  • not be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you, subject to Article 22 GDPR. See section 7.3.

Under Moroccan Law 09-08 you have rights of information, access, rectification, and objection, and you may complain to the CNDP.

We do not charge for responding, unless a request is manifestly unfounded or excessive. We will respond within one month, and will tell you if we need to extend that by up to two further months because of complexity, as Article 12(3) GDPR permits. We may need to verify your identity first.

14.1Complaints

If you are unhappy with how we have handled your data, please tell us first at Still to be filled in: PRIVACY CONTACT EMAIL. You also have the right to complain to a supervisory authority:

  • in the EEA, the authority in the country where you live, work, or where the issue arose;
  • in the UK, the Information Commissioner's Office;
  • in Morocco, the CNDP.

15If you are a job candidate

If your resume or profile is in Talentino, it is there because an employer or recruiter put it there. That organization decides what happens to your data, not us.

  • To ask what data is held, to correct it, to object, or to have it deleted, contact that organization. Their privacy notice should tell you how, and they are required to give you that information.
  • If you do not know who holds your data, or you cannot reach them, contact us at Still to be filled in: PRIVACY CONTACT EMAIL. We will identify the customer where we can and forward your request to them without undue delay, and we will tell you that we have done so. We are contractually required to assist them in responding.
  • We will not delete or change your data on our own initiative, because it is not ours to change. Where the customer instructs us to act, we will act promptly.

If a customer captured your professional profile without contacting you first, that customer is responsible for telling you it holds your data and why, under Article 14 GDPR.

16Changes to this policy

We may update this policy. If a change is material, we will notify account users by email or through the Services Still to be filled in: NOTICE PERIOD, e.g. 30 days before it takes effect. The "Last updated" date at the top always reflects the current version, and we keep prior versions available at Still to be filled in: POLICY ARCHIVE URL.

17Contact us

Still to be filled in: LEGAL ENTITY NAME
Still to be filled in: REGISTERED ADDRESS, Morocco

  • Privacy and data protection: Still to be filled in: PRIVACY CONTACT EMAIL
  • Security: Still to be filled in: SECURITY CONTACT EMAIL
  • Data Protection Officer: Still to be filled in: DPO CONTACT, or state that no DPO is required and why
  • EU representative under Article 27 GDPR: Still to be filled in: EU REPRESENTATIVE NAME AND ADDRESS, or a documented and defensible statement of why the Article 27(2) exemption applies
  • UK representative under Article 27 UK GDPR: Still to be filled in: UK REPRESENTATIVE, or the same

Under legal review

Whether we need a representative under Article 27 GDPR in the EU and the UK is still with counsel.

Back to top

AI recruitment that shows its work, from first import to final shortlist.

Product

FeaturesHow it worksThe candidate storyTalentino ScoutSecurity

Company

BlogBook a demoLog inContact
© 2026 Talentino. All rights reserved.TermsPrivacy