Privacy Policy

Last updated: 27 April 2026 (version 2.0)

Introduction

Talentika is a recruitment platform operated by SSIT, MB ("we", "our", or "us"). We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. For information about our use of cookies, please see our Cookie Policy at talentika.lt/cookies.

Data Controller

SSIT, MB (legal form: mažoji bendrija; company registration no. 306676561; registered address: Blindžių g. 24-5, LT-08110 Vilnius, Lithuania), operating the Talentika platform, is the data controller for personal data processed through our platform. When companies use our platform to manage recruitment, SSIT, MB acts as a data processor on behalf of the company (the data controller) for candidate personal data. A Data Processing Agreement (DPA) governs this relationship. For any questions regarding data protection, please contact us at info@talentika.lt.

Data We Collect

We collect the following types of personal data:

Account Data

When you create an account, we collect your email address, name, company information, and role within the organisation.

Application and Candidate Data

When candidates apply for jobs through career pages, we collect their name, email address, phone number, CV, cover letter, and any additional information provided in the application form. During the recruitment process, recruiters may add notes, ratings, interview schedules, tags, GDPR consent records, and file attachments to candidate profiles.

Usage Data

We collect information about how you use our platform, including page views, actions taken, and technical data such as IP addresses and browser information.

Artificial Intelligence (AI) Processed Data

When you use our AI features (career page generation, job advertisement creation, CV analysis), the content you provide is sent to OpenAI for processing. We do not use this data to train AI models. AI-generated content may require human review for accuracy.

Legal Basis for Processing

We process personal data based on the following legal grounds:

Consent (Article 6(1)(a) GDPR)

For candidate applications, we process data based on explicit consent provided when submitting an application. Consent records, including the method and date of consent, are stored for compliance purposes.

Contract Performance (Article 6(1)(b) GDPR)

We process your account data to provide our services and fulfil our contractual obligations.

Legitimate Interest (Article 6(1)(f) GDPR)

We process usage data and analytics to improve our services, ensure security, and prevent fraud.

Third-Party Data Processors

We use the following third-party services that process personal data on our behalf:

  • Supabase (database, authentication, file storage) - EU-based server infrastructure. Note: Supabase Inc. is a US-incorporated company; data processing is governed by Standard Contractual Clauses.
  • Vercel (hosting and CDN) - global infrastructure with EU data centres.
  • Resend (transactional emails) - sends email notifications on behalf of the platform.
  • OpenAI (AI content generation) - processes content for AI features (US-based; see "International Data Transfers").
  • Upstash (rate limiting) - processes IP addresses for security purposes.
  • CV Online (job board integration) - job postings and application data are shared when the integration is enabled by the company.
  • Google LLC (Google Calendar API) - interview scheduling and calendar availability when the integration is enabled by the user.
  • Pexels (stock images) - provides stock photos for career pages and job advertisements when selected by the user.
  • Unsplash (stock images) - provides stock photos for career pages and job advertisements when selected by the user.
  • Google Fonts (font delivery) - loads custom fonts on career pages; may transmit visitor IP addresses to Google servers.
  • Vercel Analytics (web analytics) - collects anonymised usage data to improve the platform (only with cookie consent).
Google Calendar Integration

When you choose to connect your Google Calendar to Talentika, we request access to your Google Calendar data solely to enable interview and meeting scheduling within the platform. Specifically, we use this access to: display your calendar availability when scheduling interviews; create, update, and cancel calendar events on your behalf; and add interview participants (colleagues and candidates) as event guests. Our use of Google Calendar data is strictly limited to providing this scheduling functionality. We do not use Google user data for advertising purposes, we do not sell Google user data to third parties, and we do not use Google user data to train AI or machine-learning models. You may revoke Talentika's access to your Google Calendar at any time by navigating to Settings > Integrations > Disconnect Google Calendar, or directly via your Google Account permissions at myaccount.google.com.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

International Data Transfers

Some of our third-party processors (notably OpenAI, Vercel, and Supabase Inc.) may process data outside the European Economic Area (EEA). Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, to protect your personal data.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this policy. Companies can configure candidate data retention periods in their settings. By default, candidate application data is retained for up to one year (365 days) from the date of application, after which it is automatically deleted; companies may extend this period in their settings. Account data is retained until you delete your account.

Automated Decision-Making

Our AI features may assist recruiters with content generation, candidate data analysis, and CV screening. The platform also offers automation features that recruiting teams can configure, including automatic candidate status changes and automated email notifications (such as rejection emails). These automations are set up and controlled entirely by the recruiting team and may be disabled or overridden at any time. Positive hiring decisions (shortlisting, interviews, job offers, and hiring) always require a human action. No solely automated decision with a legal or similarly significant effect is made about any individual without human involvement. You have the right to request human review of any automated processing that significantly affects you, in accordance with Article 22 GDPR.

Your Rights

Under the GDPR, you have the following rights:

  • Right of access - request a copy of your personal data (available via Settings > Data Export).
  • Right to rectification - correct inaccurate or incomplete data.
  • Right to erasure - request deletion of your data (available via Settings > Account).
  • Right to restriction - limit how we process your data.
  • Right to data portability - receive your data in JSON, XLSX, or TXT format.
  • Right to object - object to certain types of processing.
  • Right to withdraw consent - withdraw consent at any time without affecting the lawfulness of prior processing.
Data Security

We implement appropriate technical and organisational measures to protect your personal data, including: encryption in transit and at rest; role-based access controls; audit logging of sensitive actions; rate limiting; input sanitisation; and security headers (Content Security Policy, HSTS).

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority (the State Data Protection Inspectorate of Lithuania) within 72 hours of becoming aware of the breach, and will inform affected individuals without undue delay.

Right to Lodge a Complaint with a Supervisory Authority

If you believe that our processing of your personal data infringes the GDPR or Lithuanian data protection law, you have the right to lodge a complaint with the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija - VDAI), L. Sapiegos g. 17, 10312 Vilnius, Lithuania, ada@ada.lt, ada.lt. You also have the right to lodge a complaint with the supervisory authority of the EU Member State where you reside, work, or where the alleged infringement occurred.

Contact Us

For any questions about this Privacy Policy or to exercise your rights, please contact: SSIT, MB Blindžių g. 24-5, LT-08110 Vilnius, Lithuania Email: info@talentika.lt

Privacy Policy | Talentika