Home/Compliance
Compliance

Compliance isn't a feature
we added later.

Recruitment is a high-risk area under the EU AI Act. We designed for that review from day one, not after it. This page is written for the people who run that review: legal, security, data protection, works councils.

Runs inside your ATS 70+ signals, human decides GDPR and EU AI Act by design
Compliance at a glance
EU AI Act classification
Built to meet the Annex III (employment) obligations. We do not rely on an exemption.
Automated decisions
None. Signals and a score for a human to review. No Article 22 decision-making.
GDPR roles
Customer is the controller. TalentShield is the processor under a DPA with a named sub-processor list.
Data location
Application and database in Frankfurt, reports in Nuremberg. AI processing in Microsoft's EU Data Zone, with stored data in Sweden.
Model training on customer data
No. Inputs and outputs are not retained by model providers.
Audit trail
Signal library version, detected signals, score, badge and timestamp for every verification.
Candidate rights
Exercised through the customer as controller; requests reaching us are forwarded within five business days.
Certifications
ISO 27001 and SOC 2 not held yet; compensating controls described in the Security & Architecture Overview.
Principles

Six things that are true
on every report.

Human in the loop

No automated decisions

TalentShield produces information for a recruiter to review. It does not reject, rank out or filter anyone on its own. Every recorded verdict is a person's.

Explainability

Every signal has a reason

Recruiters see which checks passed, which raised a flag and why. Candidates can get a meaningful explanation, as the AI Act requires.

Data residency

Hosted and processed in the EU

Application data is stored on EU infrastructure. AI processing runs on Azure OpenAI Service in Microsoft's EU Data Zone, with no retention and no training on your data.

GDPR

Processor, not controller

You stay the controller of candidate data. TalentShield acts as your processor under a Data Processing Agreement with a named sub-processor list.

Audit trail

We log what we did

Signal version, detected signals, score and timestamp for every verification. Ready for a DPIA, a candidate request or an auditor.

Minimisation

Only what the check needs

Deterministic checks run locally. Open questions go to the model with identifying data reduced to what the specific check needs. Configurable per customer.

EU AI Act

We don't pretend to be low-risk.

AI systems used to filter or evaluate job applications are listed in Annex III of the AI Act. Some vendors in this space describe themselves as "assistive" to stay out of that box. We do the opposite: we assume the classification applies and build for the obligations that come with it. That is a better place to be when your legal team asks, and it is the honest description of what the product does.

  • Human oversight by design. Outputs are information for a person. The system has no path to reject, rank out or filter a candidate on its own.
  • Transparency to the people affected. Every signal is written so it can be shown to a candidate: what we found, why it matters, how to check it.
  • Logging. For every verification we record the signal library version, detected signals, score, badge and timestamp. The recruiter's review (who, what, when) is recorded separately in the decision history, as the recruiter's own.
  • Documentation for the deployer. Instructions for use, the description of checks and their data flows, and the division of responsibilities between us and you are part of the customer documentation.

Obligations for Annex III systems apply from December 2027 after the 2026 amendment of the Act. We are not waiting for the date.

GDPR

You are the controller. We are the processor.

Candidate data lives in your ATS. TalentShield processes it on your documented instructions, under a Data Processing Agreement that lists every sub-processor by name, location and purpose. Public professional profile information is personal data too, and we treat it that way: it is processed under your legitimate interest, only for the checks you switch on, and never bought or enriched for other purposes.

  • No automated decision-making in the meaning of Article 22: the product informs a human decision, it does not make one.
  • Data minimisation per check: deterministic checks run locally; open checks send the model only what that check needs; enrichment sources are configurable per customer and off by default in pilots.
  • Candidate rights (access, rectification, erasure, objection, human intervention) are exercised through you as the controller; requests that reach us are forwarded to you within five business days.
  • DPIA support: we provide the description of processing, data flows and safeguards your assessment needs.
Infrastructure

Hosted in the EU. Processed in the EU.

The application and its database run in Frankfurt. Verification reports are stored in Nuremberg. AI processing runs on Azure OpenAI Service in Microsoft's EU Data Zone, with our resource and stored data in Sweden; inputs and outputs are not retained and are not used for training. Transactional email leaves through an EU region. Encryption in transit (TLS 1.2+) and at rest (AES-256), access controls with multi-factor authentication, and separate accounts per system are the baseline, not the premium tier.

We do not hold ISO 27001 or SOC 2 yet. We say so, and the Security & Architecture Overview describes the compensating controls in detail.

Sub-processors

Sub-processors for candidate data.

Every third party that can receive candidate data, by name. The full list with transfer mechanisms and dated prior versions is Annex 3 of the DPA.

ProviderPurposeLocation
Render Services, Inc.Application hosting, database, backupsFrankfurt, Germany
Hetzner Online GmbHStorage of verification reportsNuremberg, Germany
Microsoft Ireland Operations Ltd. (Azure OpenAI Service)Language model for document parsing and open-ended checks; no retention, no trainingEU Data Zone (resource and stored data in Sweden)
Sinch ABTelephone number type lookup; receives the number onlySweden
Mailgun Technologies (Sinch Email), EU regionTransactional email to your users; never candidate dataEU
Public profile retrieval provider (named in the DPA)Only for customers who enable profile checks; receives the profile URL onlyStated in the DPA

Last updated 5 October 2026.

Documents

What you get for your review.

  • Security & Architecture Overview
  • Data Processing Agreement with Annexes (processing description, technical and organisational measures, sub-processors)
  • AI Governance Statement
  • Terms of Service, Design Partner Agreement for pilots
  • Answers to standard security questionnaires, on request
  • Privacy Policy

The Privacy Policy is public. The DPA, Security & Architecture Overview and AI Governance Statement are sent on request, usually the same day. Ask for the pack in the demo form or write to privacy@talentshield.app.

FAQ

Questions from legal,
security and DPOs.

Systems used to filter or evaluate job applications fall under Annex III of the AI Act, and we treat TalentShield as such. We do not claim an exemption. The product is built for the obligations that follow: human oversight by design, explainability of every output, logging, and documentation for the deployer.

Our customer. TalentShield processes candidate data on the customer's instructions as a processor, under a Data Processing Agreement with a named sub-processor list. We do not use candidate data for our own purposes and we do not contact candidates.

Application data and reports are stored on EU infrastructure (Frankfurt and Nuremberg). AI processing runs on Azure OpenAI Service in Microsoft's EU Data Zone (EU and EFTA countries), with stored data in Sweden, without retention and without training on customer data.

No. It produces information for a recruiter to review: a score, a badge and the reasons. There is no automatic rejection, ranking out or filtering. Every recorded verdict in the system is a person's. No text shown to recruiters or candidates is generated by a language model; every signal explanation is a fixed template written by us.

A meaningful explanation of what was checked and what was found. Every signal in a report is written to be shown to the candidate: what we found, why it matters, how to verify it.

Security & Architecture Overview, Data Processing Agreement with sub-processor list, AI Governance Statement, Privacy Policy, and our answers to standard security questionnaires. Ask for the compliance pack in the demo form.

Security questions and vulnerability reports: security@talentshield.app (acknowledged within 2 business days). Data protection, DPA and candidate requests: privacy@talentshield.app. Page last updated 5 October 2026.

See it on your own pipeline.

Leave your email and the ATS you use. We come back within one business day to book a 30-minute demo, on your own applicants if you want. Just have questions? Talk to Mateusz, 30 minutes, no slides.

Book a demo