HuntingTalent.ai
Legal · GDPR

Privacy policy & GDPR rights

Last updated: 2026-05-11 · Effective immediately

01

Who we are

Talent AI Labs UAB ("Talent AI Hunting", "we", "us") is a private limited company incorporated in Lithuania under company code 307572423, registered office in Vilnius, Lithuania. We operate as an AI-native recruitment agency placing candidates across the EU, UK, US, Canada and remote-friendly Web3 ecosystems.

The full legal information about our entity is available on our Imprint page.

02

Data we collect

2.1. When you visit this website

  • Technical data: IP address, browser type, device type, pages visited, referrer URL, session duration
  • Functional data: language preference stored in your browser's local storage (no cookie)
  • No analytics or advertising cookies are loaded by default. If/when we add analytics, we will request your consent first via a cookie banner.

2.2. When you book an intake call

  • Identity: first and last name, professional email, company name, role
  • Hiring context: role you want to fill, target salary band, hiring timeline, location requirements
  • This data is processed via our scheduling tool (Calendly) and stored in our CRM.

2.3. When we run a recruitment search on your behalf

  • Client data: billing details, contract terms, role specifications, hiring manager contact
  • Candidate data: CVs, video validation footage, interview scores, references — processed under the specific consent obtained from each candidate
03

Why we process this data

We rely on the following legal bases under Article 6 GDPR:

  • Consent (Art. 6.1.a): for marketing emails, analytics cookies (if/when enabled), candidate video validation
  • Contract performance (Art. 6.1.b): to deliver recruitment services to our clients
  • Legitimate interest (Art. 6.1.f): for security logs, fraud prevention, technical operation of the site. You have the right to object — see §6.
  • Legal obligation (Art. 6.1.c): for accounting, tax records, and compliance reporting
04

EU AI Act compliance

Recruitment is classified as a high-risk use case under Annex III of the EU AI Act. Where AI is used in the candidate evaluation pipeline, we apply:

  • Article 13 — Transparency: candidates are informed when their evaluation involves AI scoring or AI video validation
  • Article 14 — Human oversight: no hire decision is taken on AI score alone; a human recruiter reviews and validates every shortlist
  • Article 15 — Accuracy & robustness: bias monitoring with full audit trail, retained for the legal retention period
05

How long we keep your data

  • Website analytics (when enabled): 13 months max
  • CRM contact data: as long as the commercial relationship is active, then 3 years for follow-up, deleted on request
  • Recruitment candidate files: 2 years after the last interaction unless the candidate consents to longer retention
  • Accounting records: 10 years (Lithuanian legal requirement)
06

Your rights under GDPR

You have the right to:

  • Access the data we hold about you (Art. 15)
  • Rectify inaccurate or incomplete data (Art. 16)
  • Erase your data ("right to be forgotten", Art. 17)
  • Restrict our processing (Art. 18)
  • Port your data to another provider (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Not be subject to a decision based solely on automated processing (Art. 22) — which is why we always have a human reviewer in the recruitment pipeline

To exercise any of these rights, contact us at contact@talentai.bid or via LinkedIn. We respond within 30 days.

07

International data transfers

Some of our infrastructure providers (e.g. AWS Bedrock for our LLM layer) may process data outside the EEA. In those cases we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and ensure equivalent protection.

08

Complaints

If you believe your rights are not being respected, you have the right to lodge a complaint with the supervisory authority. Our lead supervisory authority is:

State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija) — vdai.lrv.lt

EU residents may also complain to their national supervisory authority (e.g. CNIL in France, BfDI in Germany, ICO in the UK).

09

Changes to this policy

We update this policy when our practices evolve. The "last updated" date at the top of this page reflects the latest version. Material changes are announced via LinkedIn and email to clients on file.

For legal information about our entity, see the Imprint page.