Introduction
1About this policy
Talentino is a service operated by CAPITALETECH SARL ("Talentino", "we", "us"). This policy explains how we handle personal data in connection with:
- the website talentino.io and its subdomains;
- the Talentino application at app.talentino.io;
- the Talentino Scout browser extension; and
- our sales, support, and marketing activities.
CAPITALETECH SARL is a company incorporated in the Kingdom of Morocco, with its registered office at 21, Place Abou Baker Essedik, Appt n° 8, Agdal, Rabat. We sell to customers worldwide, including in the European Economic Area and the United Kingdom.
1.1The single most important thing to understand
Talentino plays two different roles, and your rights depend on which one applies.
| Role | Whose data | Who decides how it is used | |
|---|---|---|---|
| Part A | We are the controller | Website visitors, prospects, people who book a demo, our customers' account users, billing contacts, support requesters | We do |
| Part B | We are the processor | Job candidates whose resumes and profiles our customers put into the platform | Our customer does (the recruiter or employer) |
If you are a job candidate and you want to know why an employer or recruiter holds your data, how long they will keep it, or you want it deleted, that employer or recruiter is the controller and you should contact them. We will help them respond, and we will point you to them if you contact us. See Part B and section 15.
PART A. When we are the controller
This part covers people we deal with directly: website visitors, prospective customers, users of our customers' accounts, and people who contact us.
2What we collect and why
2.1Website visitors (talentino.io)
| What | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| IP address, browser and device type, pages viewed, referring page, approximate location derived from IP | To serve the site, keep it secure, detect abuse, and understand aggregate traffic | Legitimate interests (Art. 6(1)(f)): running and securing our website |
| Cookies and similar technologies | See section 9 | Consent for non-essential cookies; legitimate interests for strictly necessary ones |
2.2People who contact us or book a demo
| What | Why | Legal basis |
|---|---|---|
| Name, work email, company and, if you choose, the ATS you use, together with a record of your submissions to the form | To respond, to run the demo, to answer questions, and to keep a record of the discussion | Steps at your request prior to a contract (Art. 6(1)(b)); legitimate interests in responding to enquiries (Art. 6(1)(f)) |
2.3Account users (our customers' staff)
| What | Why | Legal basis |
|---|---|---|
| Name, work email, password credential, role and permissions, organization, profile settings, language | To create and administer the account, authenticate users, apply permissions | Performance of a contract (Art. 6(1)(b)); our legitimate interests where the contract is with the employer rather than the individual (Art. 6(1)(f)) |
| Login times, IP address, device and browser, session records, security event logs | To secure accounts, investigate suspicious activity, and keep an audit record | Legitimate interests (Art. 6(1)(f)): security; legal obligation (Art. 6(1)(c)) where applicable |
| Product usage: features used, actions taken, credits consumed, errors encountered | To operate and improve the Services, to bill accurately, and to provide support | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Support correspondence and its attachments | To provide support | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
2.4Billing contacts
| What | Why | Legal basis |
|---|---|---|
| Billing name, address, tax identifiers, invoices and payment status | To take payment, issue invoices, and meet accounting and tax obligations | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
Payments are processed by our payment provider (see section 6); we hold the billing and transaction records we need to invoice you and to meet accounting obligations.
2.5Marketing recipients
| What | Why | Legal basis |
|---|---|---|
| Work email, name, company | To send product and company updates you asked for, or that are relevant to an existing business relationship | Consent (Art. 6(1)(a)) where required; legitimate interests in business-to-business marketing to existing contacts (Art. 6(1)(f)), subject to local law |
You can ask us to stop sending you marketing at privacy@talentino.io. We will act on that promptly, and it will not affect service messages you need to receive (for example, billing or security notices).
3Where this data comes from
Mostly from you. We may also receive:
- account user details from the customer organization that invited them;
- billing details from the customer's finance contact;
- business contact details from publicly available professional sources, where we are prospecting. Where we obtain your details indirectly, we give you the information Article 14 GDPR requires, including the source or the category of source, no later than our first communication with you.
4How long we keep it (Part A)
We keep personal data for as long as we need it for the purposes described in this policy; for as long as applicable law requires us to keep it; and for as long as we need it to establish, exercise or defend legal claims. In practice the main criteria are these. Account and account-user data is kept for the life of the account and for a period afterwards, so that an account can be restored and any dispute about it resolved. Billing and accounting records are kept for the period Moroccan tax law sets for accounting records, which is ten years. Candidate data in Part B is kept on the customer's instructions, because the customer is its controller.
PART B. When we are the processor: candidate data
5The split, in plain terms
When a customer uploads resumes, receives applications through a form, or captures a professional profile using Talentino Scout, the customer decides what to collect, why, how long to keep it, and what to do with the result. The customer is the controller. We host and process that material on the customer's instructions, under the data protection terms agreed with that customer. We are the processor.
That means:
- We do not decide which candidates a customer evaluates, or what happens to them.
- We do not use candidate data for our own purposes.
- We do not sell candidate data, and we do not share it with other customers.
- We do not use candidate data to train AI models. See section 7.4.
- If you are a candidate exercising your rights, the customer is the right place to start. See section 15.
5.1What candidate data typically passes through the platform
Depending on what the customer supplies, this can include: name; contact details; the full text and file of a resume or CV; work history, employers, job titles and dates; education and qualifications; skills and certifications; languages; links to professional profiles and portfolios; a professional profile page captured by Talentino Scout; answers to application questions, including recorded video or audio answers where the customer uses that feature; the customer's notes, statuses, and ratings; and the outputs our system generates, such as scores, per-requirement assessments, written strengths and concerns, extracted citations, suggested interview questions, and drafted outreach emails.
5.2Special category data
We do not ask for, and our customers are contractually prohibited from deliberately submitting, special category data under Article 9 GDPR (for example, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, or genetic or biometric data), or data about criminal convictions and offences.
Resumes and professional profiles are free-text documents and may nonetheless contain such information because a candidate chose to include it. Where that happens, we process it only as an incidental part of the document, on the customer's instructions. Our customers are required not to configure requirements, filters, scoring, or searches that target such information.
6Who we share data with
We do not sell personal data. We share it only as described here.
6.1Sub-processors and service providers
We use service providers to run the Services. Article 13(1)(e) GDPR allows a controller to describe recipients by category rather than by name, and these are the categories we use: cloud hosting, storage and content delivery; database hosting; AI model providers; email delivery; real-time messaging; payment, billing and invoicing; product analytics, error diagnostics and log storage; rate limiting and caching; company-data and email-verification lookups; and scheduling for demo bookings.
6.2Others
- Our own staff and contractors, on a need-to-know basis, bound by confidentiality.
- Professional advisers (lawyers, accountants, auditors) where necessary.
- Authorities, where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims. Where we are a processor, we will tell the customer first unless the law prohibits it.
- A buyer or successor, in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality, to applicable law, and to any notice or choice required before materially different processing.
7How the AI works, and what it does not do
7.1What the system produces
The platform reads candidate documents and produces scores, rankings, per-requirement assessments (met, partially met, not met), written strengths and concerns, extracted structured fields, citations pointing back to the source document, suggested interview questions, and draft emails. Requirements and their weightings are set by the customer, either directly or by accepting a suggestion from the system.
7.2What a reviewer can see
The interface is built so that a reviewer can see the evidence behind every score: which requirement was assessed, what the assessment was, and the lines from the source document the assessment relies on.
7.3Automated decision-making (Article 22 GDPR)
Whether a decision taken with the platform is "based solely on automated processing" within the meaning of Article 22 GDPR depends on how the customer configures and uses it. The Court of Justice of the European Union held in SCHUFA (Case C-634/21, 7 December 2023) that producing a score that a decision-maker relies on heavily can itself be an automated decision, even where a human formally signs off. A recruiter who accepts or rejects candidates on the strength of a ranking, without looking at the underlying material, is not providing meaningful human involvement.
Our contracts therefore require customers to keep a genuine human review in the process, and to give candidates the information and safeguards Article 22(3) requires if their own use of the platform ever crosses that line. The customer, as controller, is responsible for that assessment and for informing candidates.
7.4We do not train models on candidate data
We do not use candidate data, or any other Customer Data, to train, fine-tune, or otherwise improve any general-purpose AI or machine learning model, whether ours or a third party's.
7.5EU AI Act position
Systems used for the recruitment or selection of natural persons, in particular to filter applications and evaluate candidates, are listed in Annex III of Regulation (EU) 2024/1689 (the AI Act). Because the platform evaluates and profiles individuals, we treat it as falling within that category. Article 6(3) provides a narrow exemption for some Annex III systems, but that exemption is expressly unavailable to systems that perform profiling of natural persons, and we do not rely on it.
Under the AI Act, we are the provider of the system and our customers are its deployers. Each role carries its own obligations.
The timetable was amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"). On the current schedule, the obligations for stand-alone high-risk systems listed in Annex III apply from 2 December 2027. The AI Act's general provisions, including the Article 50 transparency obligations and the Article 4 AI literacy obligation, already apply.
We have not completed a conformity assessment for the Services, we do not hold a CE marking for them, and they are not registered in the EU database of high-risk AI systems. Those obligations are not yet applicable on that timetable, and we make no claim to have satisfied them in advance.
7.6Information for deployers: how an evaluation is put together
Article 13(2)(f) GDPR requires meaningful information about the logic involved in an automated evaluation, and Article 13 of the AI Act requires a provider to give deployers instructions for use. A customer who has to give candidates that information cannot write it without us. Those instructions are not finished. What we can state today is set out here.
- Requirements come from your job description. The system reads it and proposes a set of requirements grouped by category. You confirm, edit, or remove them, and you mark each one essential or optional.
- Each requirement is scored on its own. The label shown beside a requirement — met, partially met, not met — is a fixed numeric band applied to that requirement's score. It is not a separate judgement.
- A weighting across the requirement categories decides how much each category counts. You can set that weighting yourself, or leave it to the system, which is what happens if you do not change it.
- Candidates are ranked against one another by the resulting score, within one job and against the requirements configured for that job.
- Where an assessment relies on a passage of the resume, that passage is quoted beside the requirement. Not all requirement types carry a quoted passage.
And what we do not claim about it:
- A resume is processed as you supply it. We do not strip out names, contact details, or other identifying information before it is evaluated.
- The result is not guaranteed to be reproducible. The same resume and the same job configuration are not guaranteed to produce identical results, and section 6.4 of the Terms says so.
- We hold no measurement of the accuracy of the Services, and no bias or fairness audit of them. We claim neither, and section 6.5 of the Terms disclaims both.
- A reviewer records their own decision about a candidate. A reviewer does not edit a score the system produced.
If you need this for a data protection impact assessment before the instructions for use exist, ask us at privacy@talentino.io and we will tell you what we have.
8International transfers
8.1The position
We are established in Morocco. Morocco is not the subject of an adequacy decision by the European Commission under Article 45 GDPR. Personal data that reaches us from the EEA or the UK is therefore transferred to a country without an adequacy decision.
8.2The safeguard we rely on
For those transfers we rely on the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 under Article 46(2)(c) GDPR.
Equivalent arrangements apply to transfers to the United Kingdom and Switzerland.
Customers may request a copy of the safeguards that apply to their transfers at privacy@talentino.io.
8.3Where data is actually stored
Some processing takes place outside the EEA, including in Morocco and the United States — in particular AI model inference.
Our staff, contractors, and support personnel are located in Morocco and access the Services from there. That access is itself a transfer, and it is covered by the safeguards in section 8.2.
8.4Moroccan law
As a Moroccan company we are also subject to Law No. 09-08 on the protection of individuals with regard to the processing of personal data and its implementing Decree No. 2-09-165, supervised by the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP).
Under Articles 43 and 44 of Law 09-08, transferring personal data from Morocco to another country requires either that the destination country provides a sufficient level of protection, or a prior authorization from the CNDP, or that a statutory derogation applies.
9Cookies and similar technologies
We use:
- Strictly necessary cookies to log you in, keep your session, balance load, and protect against abuse. These cannot be switched off without breaking the Services.
- Preference cookies to remember settings such as your language.
- Analytics cookies to understand how the site and product are used.
The technologies set through this website and the Services include:
| Technology | Provider | Purpose | Notes |
|---|---|---|---|
| Session cookie | Talentino | Keeps you signed in | Strictly necessary. Session lifetime 7 days. |
| Locale cookie | Talentino | Remembers your language | Preference |
| Sign-in state cookies | Talentino | Complete a Google sign-in securely | Strictly necessary, set only during sign-in |
| Product analytics storage | PostHog | Understand product usage and diagnose errors | Stored in browser local storage rather than cookies. Not strictly necessary. |
| Booking calendar embed | Cal.com | Show and take demo bookings on our demo page | Loaded only when you choose to open the booking calendar, and not before. Cal.com then sets its own cookies and storage in your browser, under its own privacy notice. Not strictly necessary. |
Most browsers let you block or delete cookies.
10Talentino Scout (browser extension)
Talentino Scout is a Chrome extension that lets a signed-in Talentino user save a LinkedIn profile they are looking at into their own Talentino candidate database. We publish it and the user installs it; it is not part of this website. What follows describes the current version of Scout.
10.1How it works, and what it does not do
- Scout does nothing until you open it. It declares no content script, so none of its code runs on the pages you visit, and it does no work in the background when you are not using it.
- It can act on two kinds of LinkedIn page only: a profile page (
linkedin.com/in/…) and a people-search results page (linkedin.com/search/results/people/…). Everywhere else its icon is grey and clicking it does nothing. - Saving one profile. When you choose to save the profile you are looking at, Scout injects a short script into that LinkedIn tab, which returns the page's HTML as your browser has rendered it for you. It sends that, together with the profile's web address, to Talentino at app.talentino.io, so it can be turned into a candidate record.
- Saving from a search page. On a people-search results page, Scout reads the profile links on that one page and the name shown beside each, so it can list them for you. It reads no more than 50 in a single run. Before a run, it sends those profile addresses to Talentino to report which ones are already in your database.
- During a bulk run, Scout moves your own browser tab to each profile you selected, one after another, reads each page the same way as above, and returns your tab to the search page when it has finished.
- Confirming you are signed in. Scout reads one cookie — your Talentino session cookie — and reads it on app.talentino.io only. It never reads cookies on LinkedIn or on any other site, and it does not handle a separate password.
- What it stores on your device. One thing: a local list, held in the extension's own storage in your browser, of the profiles you have already captured — the profile identifier and a timestamp — so that the same person is not imported twice. Entries expire automatically after a short period. Scout sets no cookies of its own and stores nothing else on your device.
Scout does not do the following:
- It does not look up, find, reveal or enrich anyone's contact details. It is connected to no data broker and to no contact-lookup or enrichment service. Where the extension shows an email address or a telephone number for a candidate, that value comes from the record your own Talentino database already holds for that person.
- It does not read any site other than LinkedIn, it does not read the addresses of the tabs you visit, and it does not record your browsing history. It reads a page's address only on LinkedIn: when you open Scout there, and during a bulk run you have started.
- It does not run in the background, on a schedule, or when you are not using it.
- It contains no analytics, advertising or tracking code, and it loads no code from the internet — everything it runs is inside the package you install.
- It does not contact, message, reject or take any other action towards a candidate. What the platform does with a saved profile afterwards is described in Part B of this policy.
10.2Permissions
Scout is a Manifest V3 extension and asks for four browser permissions: activeTab and scripting, to read the LinkedIn page you chose to save, after you click; declarativeContent, so the browser itself can show the icon as active on the LinkedIn pages Scout works on, without Scout watching your browsing; and cookies, to read your Talentino session cookie on app.talentino.io and nowhere else. Scout reads the content of pages only on LinkedIn. It communicates with Talentino's own services — the application at app.talentino.io and the service that reports the status of an upload back to you — and with no other website.
One service operated by Talentino reports progress back to you, and it does not receive the page content Scout captures. AWS AppSync, hosted in the United States, delivers the status of your own upload: Scout sends an identifier for the profile being saved and receives a status and a short message. The service providers behind the rest of the platform are described by category in section 6.1.
Scout requests only the permissions and host access described in its Chrome Web Store listing and in this notice. We will update this notice before materially expanding its access.
10.3Limited Use disclosure
Talentino's use of information received from Google APIs, and from the Chrome Web Store, adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use the data the extension collects only to provide the extension's single purpose, which is saving professional profiles into the user's own Talentino candidate database. We do not sell it, we do not use it for advertising, and we do not transfer it to third parties except as necessary to provide that purpose, to comply with law, to protect against fraud and abuse, or in connection with a merger or acquisition with the user's consent.
10.4Roles and responsibility
When a customer uses Scout, the customer is the controller of the profile data they capture, and we are their processor. It is the customer's responsibility to:
- have a lawful basis for capturing and holding that person's data, and to document the balancing assessment if they rely on legitimate interests under Article 6(1)(f);
- give that person the information Article 14 GDPR requires, because the data was not collected from the person directly, generally within one month of collection or at the first communication with them;
- respect any objection or erasure request; and
- comply with the terms of the website they are capturing from.
Talentino is not affiliated with, endorsed by, or connected to LinkedIn Corporation or Microsoft Corporation.
11Pages candidates interact with directly
Some parts of the platform are seen by candidates rather than by our customers' staff. For candidate data collected through pages and workflows the customer configures, the customer generally acts as controller and we act as processor, as set out in the data protection terms agreed with that customer. We act as controller only where we independently determine a purpose of processing, as described in Part A.
Career pages and application forms. A customer can publish a branded careers page and a branded application form hosted by us. When a candidate applies, the form collects whatever the customer configured it to collect, which may include contact details, a resume file, answers to written questions, and recorded video or audio answers. That information goes into the customer's candidate database. The customer is responsible for displaying its own privacy notice on that page and for identifying its lawful basis.
Outreach emails and candidate replies. Where a customer uses the platform to ask a candidate for information missing from their file, the email is composed by the customer's user, who may include interview questions suggested by AI, and sent on the customer's behalf. The customer is the controller of that communication. Depending on the feature used, the email may be sent from the customer's own address or from a Talentino service address; we provide the sending infrastructure as a processor either way. The email invites the candidate to answer by replying to it in the ordinary way, at the address it was sent from; the platform gives the candidate no link, no portal and no form to fill in. When a reply arrives, it is analysed by AI, and the information it supplies is added to the customer's record for that candidate.
Video and audio answers. Where a customer uses video or voice screening, the recording and any evaluation of it are Customer Data. Several jurisdictions regulate AI analysis of video interviews specifically, including notice, consent, explanation, and deletion duties. Meeting those duties is the customer's responsibility as controller and employer.
12Security
We apply technical and organizational measures appropriate to the risk, as Article 32 GDPR requires. They include encryption of data in transit, and separation of each customer's data, with every request scoped to that customer's own organization.
We do not hold SOC 2, ISO/IEC 27001, ISO/IEC 42001, or any equivalent certification. We do not claim certification we do not have.
No system is completely secure. We cannot guarantee that unauthorized access will never occur.
12.1If something goes wrong
If we become aware of a personal data breach:
- Where we are the processor, we will notify the affected customer without undue delay after becoming aware of it, and give them the information they need to meet their own obligations under Articles 33 and 34 GDPR. Specific notification timeframes apply where we have agreed them with the customer.
- Where we are the controller, we will notify the competent supervisory authority where required under Article 33 GDPR, and will inform affected individuals where Article 34 requires it.
13Children
The Services are intended for business users and are not directed at children. We do not knowingly collect personal data from children through our own website or sign-up. Candidates evaluated through the platform are expected to be of working age in their jurisdiction. Where candidate data concerns a minor, the customer is responsible for the lawful basis and for any additional safeguards their law requires.
PART C. Applies whichever role we are in
14Your rights
Where the GDPR or UK GDPR applies, you have the right to:
- access the personal data we hold about you, and get a copy;
- have inaccurate data rectified, and incomplete data completed;
- have data erased in certain circumstances;
- restrict processing in certain circumstances;
- object to processing based on legitimate interests, and to object at any time to direct marketing;
- receive data you gave us in a portable format, and have it transmitted to another controller, where processing is based on consent or contract and is automated;
- withdraw consent at any time, where processing is based on consent, without affecting processing done before withdrawal; and
- not be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you, subject to Article 22 GDPR. See section 7.3.
Under Moroccan Law 09-08 you have rights of information, access, rectification, and objection, and you may complain to the CNDP.
We do not charge for responding, unless a request is manifestly unfounded or excessive. We will respond within one month, and will tell you if we need to extend that by up to two further months because of complexity, as Article 12(3) GDPR permits. Where Moroccan Law 09-08 sets a shorter deadline — including ten clear days for rectification — we meet that shorter deadline. We may need to verify your identity first.
14.1Complaints
If you are unhappy with how we have handled your data, please tell us first at privacy@talentino.io. You also have the right to complain to a supervisory authority:
- in the EEA, the authority in the country where you live, work, or where the issue arose;
- in the UK, the Information Commissioner's Office;
- in Morocco, the CNDP.
15If you are a job candidate
If your resume or profile is in Talentino, it is there because an employer or recruiter put it there. That organization decides what happens to your data, not us.
- To ask what data is held, to correct it, to object, or to have it deleted, contact that organization. Their privacy notice should tell you how, and they are required to give you that information.
- If you do not know who holds your data, or you cannot reach them, contact us at privacy@talentino.io. We will pass your request to the customer without undue delay. We are contractually required to assist them in responding.
- We will not delete or change your data on our own initiative, because it is not ours to change. Where the customer instructs us to act, we will act promptly.
If a customer captured your professional profile without contacting you first, that customer is responsible for telling you it holds your data and why, under Article 14 GDPR.
16Changes to this policy
We may update this policy. If a change is material, we will notify account users by email or through the Services at the time the change takes effect. The "Last updated" date at the top always reflects the current version.
17Contact us
CAPITALETECH SARL
21, Place Abou Baker Essedik, Appt n° 8, Agdal, Rabat, Morocco
- Privacy and data protection: privacy@talentino.io
- Security: security@talentino.io