Data & security
GDPR and EU AI Act compliant. Processed in the EU.
- processing region
- EU
- legal basis
- GDPR
- automated matching, disclosed
- EU AI Act
- processor agreements
- Art. 28
- German controller
- GmbH
How this is governed
Compliant, contracted, and checked from outside.

Regulation we build to
The EU AI Act
Recruiting AI falls inside the Act's high-risk category, and we build to it rather than around it. Matching is automated and the reasoning is disclosed on every shortlist — why each person fits, and where they don't. No hiring decision is made automatically: the shortlist is a recommendation and a person decides who they speak to, every time. The Art. 22 GDPR position is set out in the privacy policy.

Oversight from outside
External Data Protection Officer
Data protection here is not self-assessed. An external Data Protection Officer is appointed under Art. 37 GDPR and § 38 BDSG — Kertos GmbH — and reviews how this platform handles personal data independently of the people who built it. Their full contact details are in the privacy policy, which is where a named person belongs.
Every sub-processor runs in an EU region under a written Art. 28 data-processing agreement, Standard Contractual Clauses cover any incidental access from outside the EEA, and the full sub-processor list is published in the privacy policy rather than sent on request. Your legal review gets the documents behind every claim on this page.
In detail
The questions a legal review asks.
Who is the controller?
WhyBrilliant GmbH, a German company with a real address in the imprint. You are contracting with an entity inside the EU, not with a reseller of a US platform.
Where is data processed?
Inside the European Economic Area. We do not routinely transfer personal data outside the EEA; every sub-processor is configured to its EU region. Incidental access from outside the EEA — vendor support staff, for instance — is covered by EU Standard Contractual Clauses with additional technical safeguards.
Who can see a candidate's CV?
Not you, until the candidate agrees to the introduction. Consent to that introduction is the moment a company may hold their contact details, and it is enforced in the service rather than only in the interface. The CV reaches your ATS only when you export it, and only from a post-introduction stage.
What do you do with our brief?
We use it to fill your role. Your role, your requirements and your feedback are not sold on, not published, and not offered to anyone else as a lead. Your company data is not used to train a third-party model.
Which sub-processors are involved?
Hosting and infrastructure, database and file storage, the generative-AI processing behind matching and conversations, the conversational voice AI, and transactional email. All five operate in their EU regions under written Art. 28 data-processing agreements. They are named individually, with their purpose and transfer safeguard, in the privacy policy.
How long is anything kept?
Account and profile data for as long as the account is active, and up to 48 months after closure or inactivity to allow reactivation, unless earlier deletion is requested. Conversation transcripts and AI summaries: 48 months maximum, on a rolling basis. After deletion we keep only anonymised aggregate statistics that cannot identify anyone.
Is there automated decision-making?
Matching is automated and the reasoning is shown to you rather than hidden — every shortlist arrives with why each person fits and where they don't. No hiring decision is made automatically: the shortlist is a recommendation and you decide who you speak to. The privacy policy sets out the Art. 22 position.
What rights do candidates have, and how fast?
The full Art. 15–22 set — access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Requests go to the privacy address in the privacy policy and are answered within one month, extendable by two in complex cases with notice, free of charge.
Talk to a person
Still have questions? Talk to Yannick.
Yannick Domke, our Founding GTM Lead, answers data and security questions directly — a data-processing agreement, a completed vendor questionnaire, the sub-processor list as a document, or a specific question from your works council. Book a call and go through it in person.