Privacy Policy

Last updated: 3/19/2026

Introduction

Talentika ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.

Data Controller

Talentika is the data controller for personal data processed through our platform. When companies use our platform to manage recruitment, Talentika acts as a data processor on behalf of the company (the data controller) for candidate personal data. A Data Processing Agreement (DPA) governs this relationship. For any questions regarding data protection, please contact us at info@talentika.lt

Data We Collect

We collect the following types of personal data:

Account Data

When you create an account, we collect your email address, name, company information, and role within the organization.

Application & Candidate Data

When candidates apply for jobs through career pages, we collect their name, email, phone number, CV, cover letter, and any additional information provided in the application form. During the recruitment process, recruiters may add notes, ratings, interview schedules, tags, GDPR consent records, and file attachments to candidate profiles.

Usage Data

We collect information about how you use our platform, including page views, actions taken, and technical data such as IP addresses and browser information.

AI-Processed Data

When you use our AI features (career page generation, job ad creation, CV analysis), the content you provide is sent to OpenAI for processing. We do not use this data to train AI models. AI-generated content may require human review for accuracy.

Legal Basis for Processing

We process personal data based on the following legal grounds:

Consent (Article 6(1)(a) GDPR)

For candidate applications, we process data based on explicit consent provided when submitting an application. Consent records, including method and date, are stored for compliance purposes.

Contract Performance (Article 6(1)(b) GDPR)

We process your account data to provide our services and fulfill our contractual obligations.

Legitimate Interest (Article 6(1)(f) GDPR)

We process usage data and analytics to improve our services, ensure security, and prevent fraud.

Third-Party Data Processors

We use the following third-party services that process personal data:

  • Supabase (database, authentication, file storage) - EU-based infrastructure
  • Vercel (hosting and CDN) - Global infrastructure with EU data centers
  • Resend (transactional emails) - Sends email notifications on behalf of the platform
  • OpenAI (AI content generation) - Processes content for AI features (US-based, see International Transfers)
  • Upstash (rate limiting) - Processes IP addresses for security purposes
  • CV Online (job board integration) - Job postings and application data shared when integration is enabled by the company
International Data Transfers

Some of our third-party processors (notably OpenAI and Vercel) may process data outside the European Economic Area (EEA). Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, to protect your personal data.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy. Companies can configure candidate data retention periods in their settings. By default, candidate application data is retained for up to 2 years after the application date, after which it is automatically deleted. Account data is retained until you delete your account.

Automated Decision-Making

Our AI features may assist recruiters with content generation and candidate data analysis. These features are tools to support human decision-making - no hiring decisions are made solely by automated processing. Recruiters always retain full control over candidate evaluation and status changes.

Your Rights

Under GDPR, you have the following rights:

  • Right of access - Request a copy of your personal data (available via Settings > Data Export)
  • Right to rectification - Correct inaccurate data
  • Right to erasure - Request deletion of your data (available via Settings > Account)
  • Right to restriction - Limit how we process your data
  • Right to data portability - Receive your data in JSON, XLSX, or TXT format
  • Right to object - Object to certain types of processing
  • Right to withdraw consent - Withdraw consent at any time
Data Security

We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit and at rest, role-based access controls, audit logging of sensitive actions, rate limiting, input sanitization, and security headers (CSP, HSTS).

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority (the State Data Protection Inspectorate of Lithuania) within 72 hours and inform affected individuals without undue delay.

Contact Us

For any questions about this Privacy Policy or to exercise your rights, please contact us at info@talentika.lt