Skip to main content

Legal

Global Recruitment Privacy Notice

How TaaSFlow collects, uses, and protects personal data under GDPR, CCPA/CPRA, UAE PDPL, and other global privacy laws.

This notice is under counsel review and may be amended. For the current controller of record or a signed copy, contact the TaaSFlow team.

Processing environment

RoleProviderPurpose
Application hostingCloudflare WorkersServerless edge runtime for the TaaSFlow web application.
Backend, database, auth, storage, server functionsSupabase (managed Postgres platform)Postgres database, authentication, private storage buckets, realtime, and server-side functions.
CV parsing and evidence scoringGoogle (Gemini models, via TaaSFlow's managed AI gateway)Structured extraction of CV data and role-specific scoring signals used inside the workspace.
Transactional and system emailTaaSFlow transactional email infrastructureAuth flows and application lifecycle notifications.
Personal data collected through the intake, application, and workspace flows is stored in a managed Postgres database, with the application served from an edge hosting network. CV files are held in private object storage with row-level access policies. The named providers behind this infrastructure are listed in the sub-processor register in section 6 below.

Last updated: May 12, 2026

This Global Recruitment Privacy Notice explains how TaaSFlow ("TaaSFlow", "we", "us", or "our") collects, uses, shares, and protects personal data relating to individuals who apply for roles, are sourced, or otherwise interact with us in connection with our recruitment and talent‑sourcing activities (collectively, "Candidates").

This Notice applies to Candidates located in the European Union (EU), United States (US), United Arab Emirates (UAE), and other jurisdictions where we operate or provide services.

1. Who We Are

Data Controller: TaaSFlow Website: https://taasflow.com Email: privacy@taasflow.com

TaaSFlow acts as a data controller for personal data processed in connection with recruitment and sourcing activities. In some client‑engaged searches, we may act as an independent controller or, in limited cases, as a processor on behalf of a client.

2. Personal Data We Collect

We may collect and process the following categories of personal data:

Identification & Contact Information

  • Full name
  • Email address
  • Phone number
  • Location (city, country)

Professional Information

  • CVs, résumés, cover letters
  • Employment history, education, qualifications
  • Skills, certifications, languages
  • Salary expectations (where voluntarily provided)

Recruitment Process Information

  • Interview notes and assessments
  • References and reference feedback
  • Communications with us (emails, messages, calls)

Publicly Available Information

  • Professional profiles (e.g., LinkedIn or similar platforms), where permitted by law

Sensitive / Special Category Data (Limited)

We do not intentionally collect sensitive personal data unless:

  • Required by law (e.g., right‑to‑work checks), or
  • Voluntarily disclosed by the Candidate

Where required, such data is handled with enhanced safeguards.

3. How We Collect Personal Data

We collect personal data:

  • Directly from Candidates
  • From public professional sources
  • From referrals
  • From clients during mandated recruitment processes
  • Through recruitment technology platforms and assessments

4. Purposes of Processing

We process Candidate data for the following purposes:

  • Talent sourcing and recruitment activities
  • Assessing suitability for current or future roles
  • Communicating with Candidates
  • Presenting candidate profiles to clients (with appropriate safeguards)
  • Managing recruitment pipelines and talent pools
  • Legal, compliance, and audit purposes
  • Improving our recruitment services and operations

Depending on location, we rely on one or more of the following legal bases:

European Union (GDPR)

  • Legitimate interests — recruitment and talent matching
  • Pre‑contractual steps — requested by the Candidate
  • Consent — where required
  • Legal obligations — where applicable

United States

Notice and purpose‑limited processing under applicable state privacy laws (e.g., CCPA/CPRA).

United Arab Emirates (PDPL)

Consent, legitimate interests, contractual necessity, or legal obligation, as applicable.

Brazil (LGPD)

We process data of Brazilian residents in compliance with Lei Geral de Proteção de Dados (LGPD), relying on pre‑contractual steps, legitimate interest, or consent.

6. Sharing of Personal Data & Sub‑processors

We may share personal data with clients and prospective employers (limited to relevant role‑related data). We also use third‑party service providers ("Sub‑processors") to operate the platform. The register below reflects the infrastructure and vendors actually in use.

Sub-processorPurposeJurisdictionSafeguards
Supabase, Inc.Managed Postgres database, authentication, file storage, realtimeEU / USASCCs
Cloudflare, Inc.Application hosting (edge compute), CDN, WAF, DNSUSA / GlobalSCCs
Google LLCAnalytics (GA4), Tag Manager, and the AI models used for CV parsing and role-fit scoringEU / USASCCs / DPF
Resend (Plus Five Five, Inc.)Transactional and notification email deliveryUSASCCs
Apollo.io (ZenLeads Inc.)Sourcing, contact enrichment, B2B outreachUSASCCs
RB2B, Inc.Business-visitor identification on all public pages (always on; legitimate interest)USASCCs
Calendly LLCMeeting scheduling for client discovery callsUSASCCs / DPF
Attio Ltd.Customer relationship management for client and lead recordsUK / EUAdequacy
Microsoft CorporationMicrosoft 365 productivity, mail, and Teams communicationsUSA / GlobalSCCs / DPF

All sub‑processors are vetted for data security compliance and are contractually prohibited from using your personal data for any purpose other than providing services to us. We publish material changes to this register before a new sub‑processor begins processing candidate data.

This sub‑processor disclosure and the transfer wording in section 7 are pending review by TaaSFlow's legal counsel. Questions or corrections: privacy@taasflow.com.

7. International Data Transfers & Safeguards

As a global recruitment business, we transfer personal data to jurisdictions outside your own. Our core infrastructure is a managed Postgres database and file storage operated by Supabase, with application hosting, CDN and WAF services provided by Cloudflare's global edge network; processing may therefore take place in the European Union and the United States.

To ensure your data remains protected, we implement the following safeguards for all international transfers:

  • Standard Contractual Clauses (SCCs): We use the latest European Commission-approved SCCs for transfers to non-adequate countries.
  • Data Privacy Framework (DPF): For US-based providers certified under the EU-U.S. DPF and the UK Extension.
  • Technical Measures: Including encryption in transit (TLS 1.3), encryption at rest (AES-256), private storage buckets with time-limited signed URLs, and pseudonymisation of analytics data.

An internal Transfer Impact Assessment (TIA) is maintained to document these safeguards and monitor the legal climate of recipient jurisdictions.

8. Data Retention & Cross‑Position Matching

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Our typical retention periods include:

  • Candidate Profiles: 2 years of inactivity, after which data is deleted or anonymized unless consent is renewed.
  • CVs & Artifacts: Purged 90 days after the recruitment process concludes or after last use.
  • Job Submissions: Anonymized for statistical purposes 2 years after a position is filled or closed.
  • Audit & Security Logs: 12 months for security and compliance monitoring.
  • Marketing & Client Data: Duration of the business relationship or until consent is withdrawn.

Cross‑Position Matching

By submitting your CV or creating a candidate account, you consent to TaaSFlow retaining your personal data (including your CV, professional history, skills, and contact information) for up to 12 months . During this period, your profile may be considered for other relevant positions that become available within our system, not only the specific role you originally applied for. This allows us to proactively match you with suitable opportunities and maximize your chances of finding the right role.

You may withdraw your consent or request deletion of your data at any time by contacting privacy@taasflow.com or through the data deletion option in your candidate profile settings.

After the retention period expires, your data will be anonymised or securely deleted unless you have given renewed consent or an active recruitment process is underway. Candidates may request deletion at any time by contacting privacy@taasflow.com .

9. Your Rights

Depending on your location, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion ("right to be forgotten")
  • Restrict or object to processing
  • Data portability (EU/EEA) — receive your data in a structured, machine-readable format
  • Withdraw consent (where applicable)
  • Opt‑out of certain data disclosures (US residents)

Requests can be made by contacting privacy@taasflow.com . We will respond within 30 days.

Candidates with an account on our platform can export their personal data and request account deletion directly from their profile settings.

10. AI‑Assisted Sourcing & Scoring

We use AI‑powered technology to assist in candidate sourcing, CV parsing, and role‑fit scoring. These tools analyze candidate data (e.g., skills, experience, qualifications) against role requirements to provide ranked shortlists to the reviewers who oversee your account.

Important: TaaSFlow does not make final recruitment decisions based solely on automated processing.

All AI‑generated scores and rankings are subject to human review by the platform experts who oversee your account. You have the right to request a human explanation of any automated assessment or to contest the result.

11. Data Security

We implement appropriate technical and organizational measures to protect personal data, including:

  • Role-based access controls and progressive data disclosure
  • Encryption in transit (TLS) and at rest
  • Private storage buckets with time-limited signed URLs for sensitive documents
  • Message redaction to prevent unauthorized contact sharing
  • Comprehensive audit logging of data access
  • Vendor risk management and incident response procedures

12. Data Breaches

In the event of a personal data breach, we will notify relevant supervisory authorities within 72 hours (as required by GDPR) and affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

13. Cookies & Tracking Technologies

We use cookies and similar technologies for essential functionality, to measure how the site is used, and to support our business development activities.

Category of Cookies

  • Essential: required for core platform functionality (authentication, security, sessions, and storing your tracking choice). Cannot be disabled.
  • Strictly necessary measurement and business tools: Google Analytics in cookieless mode (no identifiers stored on your device, aggregate traffic counts only), the Apollo website tracker, and RB2B company-level visitor identification. These identify organisations, not individuals, and run on the basis of our legitimate interest in operating and developing the business.
  • Analytics (consent required): full Google Analytics measurement with device identifiers, and session quality tools such as Microsoft Clarity and Hotjar.
  • Marketing (consent required): advertising measurement and retargeting on Meta and LinkedIn.

Consent and regional behaviour: if you are in the EU, EEA, UK or Switzerland, nothing in the Analytics or Marketing categories loads until you give explicit consent through our banner; until then Google Analytics operates cookieless. Elsewhere, those categories are enabled by default and you can switch them off at any time. Your choice is stored on your device and applies to every page and future visits.

You can change your preferences or withdraw consent at any time using the "Cookie Preferences" link in the footer. Withdrawal takes effect immediately for tags that have not yet loaded, and no further data is sent to the affected tools.

14. Children's Privacy

Our services are not directed at individuals under 16. We do not knowingly collect data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately.

15. Updates to This Notice

We may update this Privacy Notice periodically. Material changes will be communicated via email or a notice on our website. The latest version will always be available on this page.

16. Data Protection Officer (DPO) & Contact

We have appointed a Data Protection Officer to oversee our privacy strategy and ensure compliance with global data protection laws (GDPR, LGPD, etc.).

TaaSFlow Privacy & Data Protection Team Attn: Data Protection Officer Email: privacy@taasflow.com Address: [Legal Entity Address, if available]

If you are located in the EEA, UK, or Brazil and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority:

  • EU/EEA: Your local Data Protection Authority (DPA)
  • UK: Information Commissioner's Office (ICO)
  • Brazil: Autoridade Nacional de Proteção de Dados (ANPD)

See also our Terms of Service for the terms governing your use of our platform.

Internal Review Note: This privacy policy has been updated to reflect the actual sub‑processors and data processing activities identified during the May 2026 security audit. Final wording should be reviewed and approved by legal counsel to ensure alignment with current jurisdiction-specific requirements.