Skip to main content

Legal

Global Recruitment Privacy Notice

How TaaSFlow collects, uses, and protects personal data under GDPR, CCPA/CPRA, UAE PDPL, and other global privacy laws.

Global Recruitment Privacy Notice

Last updated: May 12, 2026

This Global Recruitment Privacy Notice explains how TaaSFlow ("TaaSFlow", "we", "us", or "our") collects, uses, shares, and protects personal data relating to individuals who apply for roles, are sourced, or otherwise interact with us in connection with our recruitment and talent‑sourcing activities (collectively, "Candidates").

This Notice applies to Candidates located in the European Union (EU), United States (US), United Arab Emirates (UAE), and other jurisdictions where we operate or provide services.

1. Who We Are

Data Controller: TaaSFlow Website: https://taasflow.com Email: privacy@taasflow.com

TaaSFlow acts as a data controller for personal data processed in connection with recruitment and sourcing activities. In some client‑engaged searches, we may act as an independent controller or, in limited cases, as a processor on behalf of a client.

2. Personal Data We Collect

We may collect and process the following categories of personal data:

Identification & Contact Information

  • Full name
  • Email address
  • Phone number
  • Location (city, country)

Professional Information

  • CVs, résumés, cover letters
  • Employment history, education, qualifications
  • Skills, certifications, languages
  • Salary expectations (where voluntarily provided)

Recruitment Process Information

  • Interview notes and assessments
  • References and reference feedback
  • Communications with us (emails, messages, calls)

Publicly Available Information

  • Professional profiles (e.g., LinkedIn or similar platforms), where permitted by law

Sensitive / Special Category Data (Limited)

We do not intentionally collect sensitive personal data unless:

  • Required by law (e.g., right‑to‑work checks), or
  • Voluntarily disclosed by the Candidate

Where required, such data is handled with enhanced safeguards.

3. How We Collect Personal Data

We collect personal data:

  • Directly from Candidates
  • From public professional sources
  • From referrals
  • From clients during mandated recruitment processes
  • Through recruitment technology platforms and assessments

4. Purposes of Processing

We process Candidate data for the following purposes:

  • Talent sourcing and recruitment activities
  • Assessing suitability for current or future roles
  • Communicating with Candidates
  • Presenting candidate profiles to clients (with appropriate safeguards)
  • Managing recruitment pipelines and talent pools
  • Legal, compliance, and audit purposes
  • Improving our recruitment services and operations

Depending on location, we rely on one or more of the following legal bases:

European Union (GDPR)

  • Legitimate interests — recruitment and talent matching
  • Pre‑contractual steps — requested by the Candidate
  • Consent — where required
  • Legal obligations — where applicable

United States

Notice and purpose‑limited processing under applicable state privacy laws (e.g., CCPA/CPRA).

United Arab Emirates (PDPL)

Consent, legitimate interests, contractual necessity, or legal obligation, as applicable.

Brazil (LGPD)

We process data of Brazilian residents in compliance with Lei Geral de Proteção de Dados (LGPD), relying on pre‑contractual steps, legitimate interest, or consent.

6. Sharing of Personal Data & Sub‑processors

We may share personal data with clients and prospected employers (limited to relevant role‑related data). We also use third‑party service providers ("Sub‑processors") to support our platform and operations.

Sub-processor Purpose Jurisdiction Safeguards Supabase, Inc. Backend, Database & Auth (via Lovable Cloud) USA SCCs AWS (Amazon Web Services) Infrastructure, Storage & Edge Computing USA / Global SCCs Cloudflare, Inc. CDN, Security, WAF & Turnstile (Captcha) USA / Global SCCs Google LLC Analytics (GA4), Tag Manager & Web Fonts USA SCCs / DPF Apollo.io (ZenLeads Inc.) Sourcing, Data Enrichment & B2B Marketing USA SCCs Microsoft Corporation Microsoft 365, Productivity & Communications USA / Global SCCs Netlify, Inc. Application Hosting & Deployment USA SCCs Locize / Weglot i18n Management & Localization Services Switzerland / France Adequacy / SCCs Resend / SendGrid Transactional Email & Communications USA SCCs

All sub‑processors are vetted for data security compliance and are prohibited from using your personal data for any purpose other than providing services to us.

7. International Data Transfers & Safeguards

As a global recruitment firm, we transfer personal data to jurisdictions outside your own, primarily to the United States where our core infrastructure (Supabase, AWS, Cloudflare) is hosted.

To ensure your data remains protected, we implement the following safeguards for all international transfers:

  • Standard Contractual Clauses (SCCs): We use the latest European Commission-approved SCCs for transfers to non-adequate countries.
  • Data Privacy Framework (DPF): For US-based providers certified under the EU-U.S. DPF and the UK Extension.
  • Technical Measures: Including end-to-end encryption in transit (TLS 1.3), encryption at rest (AES-256), and pseudonymization of analytics data.

An internal Transfer Impact Assessment (TIA) is maintained to document these safeguards and monitor the legal climate of recipient jurisdictions.

8. Data Retention & Cross‑Position Matching

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Our typical retention periods include:

  • Candidate Profiles: 2 years of inactivity, after which data is deleted or anonymized unless consent is renewed.
  • CVs & Artifacts: Purged 90 days after the recruitment process concludes or after last use.
  • Job Submissions: Anonymized for statistical purposes 2 years after a position is filled or closed.
  • Audit & Security Logs: 12 months for security and compliance monitoring.
  • Marketing & Client Data: Duration of the business relationship or until consent is withdrawn.

Cross‑Position Matching

By submitting your CV or creating a candidate account, you consent to TaaSFlow retaining your personal data (including your CV, professional history, skills, and contact information) for up to 12 months . During this period, your profile may be considered for other relevant positions that become available within our system, not only the specific role you originally applied for. This allows us to proactively match you with suitable opportunities and maximize your chances of finding the right role.

You may withdraw your consent or request deletion of your data at any time by contacting privacy@taasflow.com or through the data deletion option in your candidate profile settings.

After the retention period expires, your data will be anonymised or securely deleted unless you have given renewed consent or an active recruitment process is underway. Candidates may request deletion at any time by contacting privacy@taasflow.com .

9. Your Rights

Depending on your location, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion ("right to be forgotten")
  • Restrict or object to processing
  • Data portability (EU/EEA) — receive your data in a structured, machine-readable format
  • Withdraw consent (where applicable)
  • Opt‑out of certain data disclosures (US residents)

Requests can be made by contacting privacy@taasflow.com . We will respond within 30 days.

Candidates with an account on our platform can export their personal data and request account deletion directly from their profile settings.

10. AI‑Assisted Sourcing & Scoring

We use AI‑powered technology to assist in candidate sourcing, CV parsing, and role‑fit scoring. These tools analyze candidate data (e.g., skills, experience, qualifications) against role requirements to provide ranked shortlists to our recruiters.

Important: TaaSFlow does not make final recruitment decisions based solely on automated processing.

All AI‑generated scores and rankings are subject to human review by our professional recruitment team. You have the right to request a human explanation of any automated assessment or to contest the result.

11. Data Security

We implement appropriate technical and organizational measures to protect personal data, including:

  • Role-based access controls and progressive data disclosure
  • Encryption in transit (TLS) and at rest
  • Private storage buckets with time-limited signed URLs for sensitive documents
  • Message redaction to prevent unauthorized contact sharing
  • Comprehensive audit logging of data access
  • Vendor risk management and incident response procedures

12. Data Breaches

In the event of a personal data breach, we will notify relevant supervisory authorities within 72 hours (as required by GDPR) and affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

13. Cookies & Tracking Technologies

We use cookies and similar technologies to ensure essential functionality, analyze platform usage, and support our marketing activities.

Category of Cookies

  • Essential: Required for core platform functionality (auth, security, sessions). Cannot be disabled.
  • Analytics: Google Analytics (anonymized) to understand user behavior and improve performance.
  • Marketing: Apollo.io, Retention.com, and Weglot to support sourcing, personalization, and translations.

Consent: We do not load non-essential cookies or third-party trackers (Analytics, Marketing) until you provide explicit consent through our cookie settings banner. You can change your preferences or withdraw consent at any time using the "Cookie Preferences" link in the footer.

14. Children's Privacy

Our services are not directed at individuals under 16. We do not knowingly collect data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately.

15. Updates to This Notice

We may update this Privacy Notice periodically. Material changes will be communicated via email or a notice on our website. The latest version will always be available on this page.

16. Data Protection Officer (DPO) & Contact

We have appointed a Data Protection Officer to oversee our privacy strategy and ensure compliance with global data protection laws (GDPR, LGPD, etc.).

TaaSFlow Privacy & Data Protection Team Attn: Data Protection Officer Email: privacy@taasflow.com Address: [Legal Entity Address, if available]

If you are located in the EEA, UK, or Brazil and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority:

  • EU/EEA: Your local Data Protection Authority (DPA)
  • UK: Information Commissioner's Office (ICO)
  • Brazil: Autoridade Nacional de Proteção de Dados (ANPD)

See also our Terms of Service for the terms governing your use of our platform.

Internal Review Note: This privacy policy has been updated to reflect the actual sub‑processors and data processing activities identified during the May 2026 security audit. Final wording should be reviewed and approved by legal counsel to ensure alignment with current jurisdiction-specific requirements.