Legal

Data Processing & Security

Last updated: May 2026

This overview describes how TALNT handles your data and the safeguards we maintain. It is intended as a starting point for any required data processing agreement.

Draft — pending attorney review. This document is a working outline of TALNT's intended policy. It must be reviewed and finalized by licensed counsel before relying on it for any customer relationship.

1. Roles

Under most data-protection frameworks, you are the controller of your candidate and operational data; TALNT processes it on your instructions as a processor. A formal Data Processing Addendum is available on request via legal@gettalnt.com.

2. Categories of data processed

  • Account data (names, work emails, login activity)
  • Candidate profile data (name, contact details, employment history, certifications, address)
  • Communications data (outreach messages, replies, scheduling tokens)
  • Operational telemetry (audit logs, error traces, usage metrics)
  • Billing data (handled by Stripe; TALNT stores customer/subscription IDs only)

3. Security controls

  • Data encrypted at rest (Supabase Postgres) and in transit (HTTPS / TLS 1.2+).
  • Role-based access control with admin, recruiter, and hiring-manager scopes.
  • JWT-based session tokens with rotation on logout.
  • Rate limiting and audit logging on sensitive routes.
  • Secrets stored in Vercel encrypted environment variables; never in source.

4. Sub-processors

TALNT relies on the following sub-processors to operate the service:

  • Supabase — managed Postgres + storage
  • Vercel — application hosting + edge CDN
  • Stripe — billing and payment processing
  • Twilio — SMS delivery (when enabled)
  • Resend — transactional email delivery

See Third-Party Services for the full disclosure.

5. Data residency

TALNT's primary production database is hosted in the United States. Sub-processors may transfer data internationally consistent with their own published policies. Customers requiring regional data residency should contact us before signing.

6. Breach notification

If TALNT becomes aware of a security incident affecting your data, we will notify designated account admins without undue delay (and in any case consistent with applicable law) with the available facts and our remediation plan.

7. Data subject requests

Requests by individual candidates to access, correct, or delete their data should be initiated by you as the controller. TALNT provides export and deletion tools to facilitate these requests within your account.