Trust & Compliance

GDPR-compliant sourcing.Berlin GmbH, German data-protection framework.

Where Talentwunder stands legally, organisationally and technically. What we already publish, what we provide on request, and what is coming in the next compliance iteration.

Current as of: September 2026

Hosting, encryption and the technical measures are set out in the terms, the privacy notice and the DPA. We do not currently claim SOC 2 Type II or ISO 27001.

Talentwunder at a glance.

Legal entity
Talentwunder GmbH, Berlin
Data protection officer
SECUWING GmbH & Co. KG
Legal framework
GDPR as default
Supervisory authority
Berlin Commissioner for Data Protection

Data sources: public profiles only.

Profiles on Talentwunder come exclusively from publicly accessible sources such as search engines, social networks and business portals. No leaked data sets, no private APIs, no purchased lists. Affected persons can object to their data being shown on Talentwunder at any time.

  • 1

    Only publicly accessible profiles, no access to private areas or content.

  • 2

    The source list is documented transparently, currently 30 networks (full list in the FAQ).

  • 3

    Objection rights of the data subject: once we receive an objection, we delete the profile and block it from further collection.

Two roles, depending on the processing step.

Talentwunder plays two different roles depending on the stage of processing. We act as an independent controller when we build and maintain our database of publicly sourced candidate profiles. When a client selects a profile, adds notes or ratings, or initiates contact, the client acts as controller for that specific recruiting activity, and Talentwunder processes the resulting data on the client's instruction under a data processing agreement.

Processing bases.

We process personal data exclusively on a GDPR basis. The ones relevant to our product:

Performance of contract · Art. 6(1)(b)

Use of the Talentwunder platform, account management, search, pool and pipeline functions.

Legitimate interest · Art. 6(1)(f)

Providing sourcing features on publicly accessible profile data, product personalisation, security and abuse prevention.

Consent · Art. 6(1)(a)

Contact requests, newsletter, and optional marketing or analytics tags.

Legal obligation · Art. 6(1)(c)

Statutory retention periods (tax, commercial), official or court orders.

Data-subject rights.

Any person whose data is processed on Talentwunder has the following rights. Requests are handled by our external data protection officer.

Requests to the DPO
epost@datenschutz-agentur.de
  • Access to the data we hold about you (Art. 15)

  • Rectification of inaccurate data (Art. 16)

  • Erasure (Art. 17)

  • Restriction of processing (Art. 18)

  • Objection to processing (Art. 21), including marketing opt-out

  • Data portability (Art. 20)

  • Withdrawal of consent with effect for the future

  • Complaint to the competent supervisory authority

Sub-processors and data sharing.

Service providers receive only the data they need to deliver their specific service and are engaged contractually as processors. The platform sub-processors are listed in Annex 3 of the DPA.

  • Hetzner Online GmbH: databases, LLM component and backups in Germany.
  • Amazon Web Services EMEA SARL: application, Keycloak, S3, load balancing and secrets in Frankfurt. CloudFront edges in Europe and North America, under the AWS DPA.
  • Lusha Systems Ltd.: contact-data enrichment. Transfer to Israel under Art. 46 GDPR, as set in the Lusha DPA.
  • Talentwunder's own recruiting: Karriera. That covers our vacancies, not customer use of the platform.

International data transfers.

Production infrastructure for the platform runs in the EU: the application and Keycloak on AWS Frankfurt, the databases on Hetzner in Germany. CloudFront may use edge locations in Europe and North America, under the AWS DPA. Lusha processes contact data in Israel under Art. 46 GDPR.

Confidentiality of customer information.

Non-public information that customers enter into Talentwunder, such as project data, candidate lists, ratings, notes and communication content, is protected by a contractual confidentiality obligation. It is used solely to perform the contract and made available only to those employees and service providers who need it and who are themselves bound to confidentiality. For personal data, the confidentiality obligations of the data processing agreement apply in addition.

Technical and organisational measures.

  1. 01

    Staff commitment

    All employees are bound by confidentiality and trained on data protection on a regular basis.

  2. 02

    Access management

    Role- and right-based access within the platform, audit logs for administrative actions.

  3. 03

    Hosting

    Application and Keycloak on AWS in Frankfurt. PostgreSQL, MongoDB and Elasticsearch on dedicated Hetzner servers in Germany. Backups in Hetzner Object Storage in Germany, uploads in Amazon S3 Frankfurt.

  4. 04

    Logs

    Authentication and infrastructure logs in Keycloak and AWS CloudWatch are kept for 90 days and then deleted. They are used for security, support and accountability.

  5. 05

    Encryption in transit

    Public endpoints enforce TLS 1.2 or higher. Connections between AWS and the Hetzner databases also use TLS and are restricted by firewall.

  6. 06

    Encryption at rest

    Amazon S3 encrypts uploads in Frankfurt. Encryption at rest is enabled on all Hetzner hosts, including the database servers.

What we do not claim.

Two attestations we do not currently hold:

SOC 2 Type II

Talentwunder does not currently claim SOC 2 certification.

ISO 27001

Talentwunder does not currently claim ISO 27001 certification.

This page is maintained together with our external data protection officer and updated after every compliance iteration.

Further documents.

The full legal texts live in the Legal section.

Send a compliance request.

Security questionnaire, DPA template, hosting details or vendor assessment? Write to us. We usually reply within one business day.