Data & security

Where the data sits, and who can see it.

The short version, for the person who has to sign this off. The privacy policy is the binding text and every claim here points back to it.

processing region
EU
legal basis
GDPR
processor agreements
Art. 28
German controller
GmbH

In detail

The questions a legal review asks.

Who is the controller?

WhyBrilliant GmbH, a German company with a real address in the imprint. You are contracting with an entity inside the EU, not with a reseller of a US platform.

Where is data processed?

Inside the European Economic Area. We do not routinely transfer personal data outside the EEA; every sub-processor is configured to its EU region. Incidental access from outside the EEA — vendor support staff, for instance — is covered by EU Standard Contractual Clauses with additional technical safeguards.

Who can see a candidate's CV?

Not you, until the candidate agrees to the introduction. Consent to that introduction is the moment a company may hold their contact details, and it is enforced in the service rather than only in the interface. The CV reaches your ATS only when you export it, and only from a post-introduction stage.

What do you do with our brief?

We use it to fill your role. Your role, your requirements and your feedback are not sold on, not published, and not offered to anyone else as a lead. Your company data is not used to train a third-party model.

Which sub-processors are involved?

Hosting and infrastructure, database and file storage, the generative-AI processing behind matching and conversations, the conversational voice AI, and transactional email. All five operate in their EU regions under written Art. 28 data-processing agreements. They are named individually, with their purpose and transfer safeguard, in the privacy policy.

How long is anything kept?

Account and profile data for as long as the account is active, and up to 48 months after closure or inactivity to allow reactivation, unless earlier deletion is requested. Conversation transcripts and AI summaries: 48 months maximum, on a rolling basis. After deletion we keep only anonymised aggregate statistics that cannot identify anyone.

Is there automated decision-making?

Matching is automated and the reasoning is shown to you rather than hidden — every shortlist arrives with why each person fits and where they don't. No hiring decision is made automatically: the shortlist is a recommendation and you decide who you speak to. The policy sets out the Art. 22 position.

What rights do candidates have, and how fast?

The full Art. 15–22 set — access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Requests go to the privacy address in the policy and are answered within one month, extendable by two in complex cases with notice, free of charge.

What we do not claim

No certification we haven't got.

We do not hold ISO 27001, SOC 2 or TISAX. Some vendors imply a certification through careful wording on a page like this one; we would rather you knew. What we can give you is the sub-processor list, the data-processing agreement, the EEA position and a direct answer from a person on our team on anything your legal review raises.

Still need something

Ask, and a person on our team answers.

A data-processing agreement, a completed vendor questionnaire, the sub-processor list as a document, or a specific question from your works council — say what you need and you will get it from a person on our team.

Ask, and a person on our team answers.

A data-processing agreement, a completed vendor questionnaire, the sub-processor list as a document, or a specific question from your works council — say what you need and you will get it from a person on our team.

Home