Legal
Privacy Notice
Effective date: [Insert date]
1. Purpose
This Privacy Notice explains how Talkfolio collects, uses, stores, and protects personal data.
Talkfolio is a platform that helps candidates present their professional experience through structured profiles and AI-supported recruiter interaction. Because the platform processes personal data, we aim to make those practices clear, understandable, and controlled.
This notice applies to candidates, recruiters, and other users who interact with the Talkfolio product and website.
2. Who We Are
Talkfolio is the controller of the personal data described in this notice, unless stated otherwise.
- Controller:
- [Insert legal entity name]
- Address:
- [Insert business address]
- Contact:
- [Insert contact email]
If required by law, Talkfolio will also provide details of its data protection contact or representative.
3. What Data We Process
The personal data we process depends on how you use Talkfolio.
3.1 Candidate data
If you create or manage a candidate profile, we may process:
- name, email address, phone number, location
- LinkedIn or other professional profile links
- profile photo
- CV or resume content, work history, achievements
- recommendations and supporting evidence or attachments
- written story inputs and curated answers
- profile variants, visibility settings, publication status
- optional voice or transcript inputs
3.2 Recruiter data
If you access candidate profiles as a recruiter or hiring contact, we may process:
- name, work email, company name, role or hiring context
- session activity and questions asked within the profile
- shortlist or save actions
- private recruiter notes
- contact or interaction events
3.3 Product and technical data
We may also process:
- account identifiers and authentication data
- IP address, browser and device information
- cookies or similar technical identifiers
- usage logs and security logs
- AI prompt and response records where retained
- analytics events related to product use
4. How We Collect Data
We collect personal data:
- directly from you when you create an account or fill in profile information
- when you upload files or other materials
- when you interact with Talkfolio features
- when recruiters ask questions or interact with a profile
- from cookies and technical logs during product use
- from third-party providers that support authentication, hosting, payments, analytics, or AI functionality
- from public professional links that you choose to include in your profile
Talkfolio does not aim to collect more data than is needed to operate the service.
5. Why We Use Personal Data
We use personal data to operate, protect, and improve Talkfolio. This includes:
- creating and managing user accounts
- hosting and displaying candidate profiles
- enabling recruiter interaction with those profiles
- generating AI-supported answers based on candidate-provided material
- managing profile publication and visibility settings
- processing payments where relevant
- responding to support requests
- protecting the platform from misuse, abuse, or unauthorized access
- maintaining system security, reliability, and diagnostics
- measuring product performance and improving the service
- complying with legal obligations
- communicating important service messages
We do not treat candidate data as a free general-purpose content pool. Candidate data exists primarily to support the candidate's profile and the service they chose to use.
6. Legal Bases for Processing
Depending on the context, Talkfolio processes personal data on one or more of the following legal bases:
Contract
We process data where needed to provide the Talkfolio service, such as account creation, profile hosting, recruiter Q&A, payments, and core service operation.
Legitimate interests
We may process data where necessary for legitimate interests such as platform security, fraud and abuse prevention, service diagnostics, limited product analytics, and service improvement. Where we rely on legitimate interests, we aim to do so in a balanced and proportionate way.
Consent
We rely on consent where required, especially for optional activities such as marketing communication, optional public discoverability settings, and optional data uses beyond core service delivery. Where consent is used, it can be withdrawn.
Legal obligation
We may process data where required to comply with legal, regulatory, tax, accounting, or enforcement obligations.
7. Publication and Visibility
Talkfolio is built around controlled visibility. Candidate data is not all treated the same way. Some data may be public within the candidate's profile, some may be visible only to recruiters, and some remains private or internal.
7.1 Candidate-controlled profile data
Candidates can control whether the profile is published or limited by direct access, whether contact details are visible, and what profile version is active.
7.2 Recruiter-private data
Recruiter-private notes, shortlist decisions, and similar recruiter-side tools are not shown to the candidate unless explicitly designed otherwise.
7.3 Internal-only data
Some data is used only for internal service operation, security, diagnostics, or compliance. Talkfolio aims to make these visibility boundaries clear in the product interface, not only in legal documents.
8. AI Features
Talkfolio may use AI to generate answers to recruiter questions based on candidate-provided profile material.
8.1 What this means
This may involve sending structured profile context, selected source material, or relevant facts to an AI provider in order to produce a response.
8.2 Data minimisation
We aim to send only the information needed for the response and to avoid unnecessary exposure of personal data in prompts.
8.3 No hidden assumption of broad reuse
Candidate data is not intended to silently become general model training material. If any use goes beyond direct service delivery, it must be clearly disclosed and governed under an appropriate legal basis.
8.4 Stored AI records
Where prompts or responses are stored for quality, diagnostics, or service improvement, they are governed by retention and access controls.
9. Cookies and Similar Technologies
Talkfolio may use cookies and similar technologies for authentication, session management, security, performance, analytics, and remembering settings or preferences.
Where required by law, Talkfolio will request consent before using non-essential cookies or similar technologies. More details are provided in a separate Cookie Notice.
10. Who We Share Data With
We may share personal data with service providers and processors that help us operate Talkfolio, including providers for hosting and infrastructure, database and storage, authentication, payments, email delivery, analytics, AI processing, and customer support. We share only what is necessary for the relevant service.
We may also disclose data:
- where required by law
- to enforce our legal rights
- to protect users, the platform, or the public
- in connection with a corporate transaction where legally permitted
11. International Transfers
Some service providers may process personal data outside the country where the user is located, including outside the EEA or UK where applicable. Where international transfers occur, Talkfolio aims to use appropriate transfer mechanisms and safeguards required by applicable law.
12. How Long We Keep Data
We retain personal data only for as long as necessary for the purposes described in this notice, unless a longer period is required by law or justified by a legitimate operational need.
When data is no longer needed, we aim to delete it, anonymise it, or retain only aggregated non-personal forms where appropriate.
13. Your Rights
Depending on your location and applicable law, you may have rights such as:
- the right to access your data
- the right to correct inaccurate data
- the right to delete data
- the right to restrict certain processing
- the right to object to certain processing
- the right to data portability
- the right to withdraw consent where consent is the basis
- the right to lodge a complaint with a supervisory authority
Talkfolio aims to provide practical ways to exercise these rights, including through settings, product controls, or a support/contact path.
14. Security
Talkfolio uses technical and organisational measures intended to protect personal data against unauthorized access, misuse, loss, alteration, or disclosure. These measures may include HTTPS/TLS in transit, encryption at rest where appropriate, access controls, authentication safeguards, role-based permissions, audit logging for sensitive actions, limited internal access, vendor review, and backup and recovery controls.
No system can promise absolute security, but Talkfolio aims to apply safeguards appropriate to the risk of the data it handles.
15. Children
Talkfolio is not intended for children, and we do not knowingly design the service for use by minors without a lawful basis and appropriate safeguards. If we learn that personal data has been collected from a child in a way that is not permitted, we will take appropriate steps to delete it.
16. Changes to This Notice
We may update this Privacy Notice from time to time. If changes are material, we will take appropriate steps to communicate them, such as updating the effective date, showing a product notice, or asking for renewed acknowledgment where needed. The latest version is always available at this page.
17. Contact
For privacy questions, requests, or concerns, contact:
- Email:
- [Insert privacy/contact email]
- Company:
- [Insert legal entity name]
- Address:
- [Insert business address]
If applicable, users may also have the right to contact their local supervisory authority.
Final principle
Talkfolio is built on two forms of trust: trust that the profile is truthful, and trust that the data is handled safely and lawfully. This notice supports the second.