Hosting, encryption and the technical measures are set out in the terms, the privacy notice and the DPA. We do not currently claim SOC 2 Type II or ISO 27001.
Talentwunder at a glance.
Data sources: public profiles only.
Profiles on Talentwunder come exclusively from publicly accessible sources such as search engines, social networks and business portals. No leaked data sets, no private APIs, no purchased lists. Affected persons can object to their data being shown on Talentwunder at any time.
- 1
Only publicly accessible profiles, no access to private areas or content.
- 2
The source list is documented transparently, currently 30 networks (full list in the FAQ).
- 3
Objection rights of the data subject: once we receive an objection, we delete the profile and block it from further collection.
Two roles, depending on the processing step.
Talentwunder plays two different roles depending on the stage of processing. We act as an independent controller when we build and maintain our database of publicly sourced candidate profiles. When a client selects a profile, adds notes or ratings, or initiates contact, the client acts as controller for that specific recruiting activity, and Talentwunder processes the resulting data on the client's instruction under a data processing agreement.
Processing bases.
We process personal data exclusively on a GDPR basis. The ones relevant to our product:
Performance of contract · Art. 6(1)(b)
Use of the Talentwunder platform, account management, search, pool and pipeline functions.
Legitimate interest · Art. 6(1)(f)
Providing sourcing features on publicly accessible profile data, product personalisation, security and abuse prevention.
Consent · Art. 6(1)(a)
Contact requests, newsletter, and optional marketing or analytics tags.
Legal obligation · Art. 6(1)(c)
Statutory retention periods (tax, commercial), official or court orders.
Data-subject rights.
Any person whose data is processed on Talentwunder has the following rights. Requests are handled by our external data protection officer.
- ✓
Access to the data we hold about you (Art. 15)
- ✓
Rectification of inaccurate data (Art. 16)
- ✓
Erasure (Art. 17)
- ✓
Restriction of processing (Art. 18)
- ✓
Objection to processing (Art. 21), including marketing opt-out
- ✓
Data portability (Art. 20)
- ✓
Withdrawal of consent with effect for the future
- ✓
Complaint to the competent supervisory authority
Sub-processors and data sharing.
Service providers receive only the data they need to deliver their specific service and are engaged contractually as processors. The platform sub-processors are listed in Annex 3 of the DPA.
- Hetzner Online GmbH: databases, LLM component and backups in Germany.
- Amazon Web Services EMEA SARL: application, Keycloak, S3, load balancing and secrets in Frankfurt. CloudFront edges in Europe and North America, under the AWS DPA.
- Lusha Systems Ltd.: contact-data enrichment. Transfer to Israel under Art. 46 GDPR, as set in the Lusha DPA.
- Talentwunder's own recruiting: Karriera. That covers our vacancies, not customer use of the platform.
International data transfers.
Production infrastructure for the platform runs in the EU: the application and Keycloak on AWS Frankfurt, the databases on Hetzner in Germany. CloudFront may use edge locations in Europe and North America, under the AWS DPA. Lusha processes contact data in Israel under Art. 46 GDPR.
Confidentiality of customer information.
Non-public information that customers enter into Talentwunder, such as project data, candidate lists, ratings, notes and communication content, is protected by a contractual confidentiality obligation. It is used solely to perform the contract and made available only to those employees and service providers who need it and who are themselves bound to confidentiality. For personal data, the confidentiality obligations of the data processing agreement apply in addition.
Technical and organisational measures.
- 01
Staff commitment
All employees are bound by confidentiality and trained on data protection on a regular basis.
- 02
Access management
Role- and right-based access within the platform, audit logs for administrative actions.
- 03
Hosting
Application and Keycloak on AWS in Frankfurt. PostgreSQL, MongoDB and Elasticsearch on dedicated Hetzner servers in Germany. Backups in Hetzner Object Storage in Germany, uploads in Amazon S3 Frankfurt.
- 04
Logs
Authentication and infrastructure logs in Keycloak and AWS CloudWatch are kept for 90 days and then deleted. They are used for security, support and accountability.
- 05
Encryption in transit
Public endpoints enforce TLS 1.2 or higher. Connections between AWS and the Hetzner databases also use TLS and are restricted by firewall.
- 06
Encryption at rest
Amazon S3 encrypts uploads in Frankfurt. Encryption at rest is enabled on all Hetzner hosts, including the database servers.
What we do not claim.
Two attestations we do not currently hold:
SOC 2 Type II
Talentwunder does not currently claim SOC 2 certification.
ISO 27001
Talentwunder does not currently claim ISO 27001 certification.
This page is maintained together with our external data protection officer and updated after every compliance iteration.
Further documents.
The full legal texts live in the Legal section.