A clear DPA before data moves.
Recruitment agencies handle sensitive candidate and client information. We set out the processing instructions and safeguards in a written data processing agreement before a workflow handles that information.
Recruitment agencies handle sensitive candidate and client information. We set out the processing instructions and safeguards in a written data processing agreement before a workflow handles that information.
Your agency determines why and how candidate and client information is used. TalentBraid builds and manages the agreed automation layer on your instructions. The signed DPA describes the data categories, people affected, purposes, duration, and documented instructions for each engagement.
The agreement records encryption in transit and at rest, access limited to the service team and necessary systems, and the incident-notification and assistance process. We also document how support access and any optional client control-panel view are handled.
EU workflow infrastructure is in Paris, France; US and other non-EU workflows are served from Northern Virginia. AWS France and Hostinger France support EU infrastructure. OpenAI or Anthropic is used only if the engagement explicitly includes AI. The signed DPA lists the actual providers and any approved transfers or exceptions. Review the provider overview.
Our managed workflows do not create a permanent candidate database. Operational records can be held for up to 90 days for troubleshooting or investigation, then removed from active systems, unless an applicable obligation requires otherwise. The DPA defines deletion and return at the end of service, assistance with data-subject requests, and the handling of earlier deletion requests. Connected systems and optional AI providers have separate retention terms.
We will provide the formal DPA with the proposal or on request through our official contact channel. We will not begin processing your agency’s candidate data until the agreed terms and configurations are in place.