Data & security

GDPR and EU AI Act compliant. Processed in the EU.

processing region
EU
legal basis
GDPR
automated matching, disclosed
EU AI Act
processor agreements
Art. 28
German controller
GmbH

How this is governed

Compliant, contracted, and checked from outside.

EU AI Act

Regulation we build to

The EU AI Act

Recruiting AI falls inside the Act's high-risk category, and we build to it rather than around it. Matching is automated and the reasoning is disclosed on every shortlist — why each person fits, and where they don't. No hiring decision is made automatically: the shortlist is a recommendation and a person decides who they speak to, every time. The Art. 22 GDPR position is set out in the privacy policy.

Kertos GmbH, our external Data Protection Officer

Oversight from outside

External Data Protection Officer

Data protection here is not self-assessed. An external Data Protection Officer is appointed under Art. 37 GDPR and § 38 BDSG — Kertos GmbH — and reviews how this platform handles personal data independently of the people who built it. Their full contact details are in the privacy policy, which is where a named person belongs.

Every sub-processor runs in an EU region under a written Art. 28 data-processing agreement, Standard Contractual Clauses cover any incidental access from outside the EEA, and the full sub-processor list is published in the privacy policy rather than sent on request. Your legal review gets the documents behind every claim on this page.

In detail

The questions a legal review asks.

Who is the controller?

WhyBrilliant GmbH, a German company with a real address in the imprint. You are contracting with an entity inside the EU, not with a reseller of a US platform.

Where is data processed?

Inside the European Economic Area. We do not routinely transfer personal data outside the EEA; every sub-processor is configured to its EU region. Incidental access from outside the EEA — vendor support staff, for instance — is covered by EU Standard Contractual Clauses with additional technical safeguards.

Who can see a candidate's CV?

Not you, until the candidate agrees to the introduction. Consent to that introduction is the moment a company may hold their contact details, and it is enforced in the service rather than only in the interface. The CV reaches your ATS only when you export it, and only from a post-introduction stage.

What do you do with our brief?

We use it to fill your role. Your role, your requirements and your feedback are not sold on, not published, and not offered to anyone else as a lead. Your company data is not used to train a third-party model.

Which sub-processors are involved?

Hosting and infrastructure, database and file storage, the generative-AI processing behind matching and conversations, the conversational voice AI, and transactional email. All five operate in their EU regions under written Art. 28 data-processing agreements. They are named individually, with their purpose and transfer safeguard, in the privacy policy.

How long is anything kept?

Account and profile data for as long as the account is active, and up to 48 months after closure or inactivity to allow reactivation, unless earlier deletion is requested. Conversation transcripts and AI summaries: 48 months maximum, on a rolling basis. After deletion we keep only anonymised aggregate statistics that cannot identify anyone.

Is there automated decision-making?

Matching is automated and the reasoning is shown to you rather than hidden — every shortlist arrives with why each person fits and where they don't. No hiring decision is made automatically: the shortlist is a recommendation and you decide who you speak to. The privacy policy sets out the Art. 22 position.

What rights do candidates have, and how fast?

The full Art. 15–22 set — access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Requests go to the privacy address in the privacy policy and are answered within one month, extendable by two in complex cases with notice, free of charge.

Talk to a person

Still have questions? Talk to Yannick.

Yannick Domke, our Founding GTM Lead, answers data and security questions directly — a data-processing agreement, a completed vendor questionnaire, the sub-processor list as a document, or a specific question from your works council. Book a call and go through it in person.

Home