1. Data controller
The controller for this platform is TalentPath, operating at talentpath.eu. TalentPath is an independent project; it is not affiliated with, endorsed by, or accredited by the European Commission or any EU institution. Contact for data enquiries: info@talentpath.eu Postal address available on request via email. Response time: within 2 business days for general enquiries; within 30 calendar days for formal GDPR access/erasure/portability requests, as required by law.
2. What we collect
We collect the following personal data: • Assessment participants: first name, last name, email address, and assessment responses (scores, domain results, timestamps). • B2B organisation users: organisation name, country, VAT number (optional), and admin email address. • Usage data: page visits, assessment start/completion events. We use Plausible Analytics, which is cookieless and GDPR-compliant by default. We do not collect payment card details directly — payments are processed by Stripe under their own privacy policy.
2a. The Talent Pool
Listing yourself in the Talent Pool is optional and separate from everything else here. This section describes it in full, because it processes more of your data than any other part of the platform. WHAT IS PUBLISHED. Your listing is shown under a handle such as TP-7K2M9X. It carries: your headline, the occupation you want, years of experience, country of residence, the EU countries you would move to, sectors, languages and self-assessed CEFR levels, availability, your right-to-work status, your written summary, your work history (job titles, kind of organisation, sector, country, years and the achievements you list), your self-declared skills, your qualifications (level and subject), driving licences, your contract, working-time and remote preferences, the date you last updated the listing, and whether you hold a TalentPath digital-skills credential. Your pay expectation is published ONLY if you tick the box to publish it. WHAT IS NEVER PUBLISHED. Your name, your e-mail address, your LinkedIn link, your portfolio link, your photograph, your date of birth, your nationality, the names of your employers and the names of your schools. Employer names and institution names are not published because we do not ask for them at all: a job title with an employer and a date identifies almost anyone. WHO CAN SEE IT. Anyone on the internet can browse the pseudonymous listings without an account. Individual candidate pages are marked "noindex" so search engines are asked not to index them, and they are not in our sitemap — but we cannot guarantee the behaviour of every crawler, and you should assume a listing is public. HOW YOUR IDENTITY IS RELEASED. An employer must hold an account with a confirmed e-mail address and send you a request describing the role. You see the request and decide. Only if you approve does the platform e-mail your name, e-mail address, LinkedIn link and portfolio link to that one employer. Declining shares nothing. We do not verify employers, and we tell you so at the moment you decide. LEGAL BASIS. Publishing your listing and releasing your identity rest on your consent (GDPR Art. 6(1)(a)), and on your explicit consent under Art. 9(2)(a) so far as the combination of details in a listing may reveal special-category data. You can withdraw consent at any time by unlisting or deleting your listing, which is as easy as giving it. Holding your account rests on performance of a contract (Art. 6(1)(b)). HOW LONG IT IS KEPT. Your listing stops appearing in the pool after 18 months without you using it, and is deleted with its contact history after 24 months. Signing in and saving your listing starts the clock again. This follows the reference period the French supervisory authority sets for holding candidate data in a recruitment pool. You can unlist or delete at any time; deleting removes the listing and its contact requests entirely. SPECIAL CATEGORIES. We do not ask for anything in Art. 9 — no health, religion, politics, trade-union membership, ethnic origin, sexual orientation or biometrics — and we do not scan your writing for them. Please do not volunteer them in your summary: the form warns you of this where you write it. TRANSFERS OUTSIDE THE EU. Employers who browse the pool, and employers whose requests you approve, may be located outside the EU or EEA. Where you approve a request from such an employer, your identity is transferred to them on the basis of your explicit consent to that specific transfer (Art. 49(1)(a)), and you should understand that a country outside the EEA may not offer equivalent protection. NO AUTOMATED DECISIONS. Candidates are not scored, ranked or matched by any algorithm. Searching and filtering compare exactly what candidates entered, and results are ordered by when a listing was last updated. There is no profiling within the meaning of Art. 22, and no AI system is used to evaluate candidates. CONTACT REQUESTS. When an employer contacts you we store their name, organisation, stated reply-to address, role title and message, together with the account that sent it. A request you answered is part of the record of your decision and is deleted with your listing. A request nobody ever answered is deleted after 6 months, because it holds the employer's personal data and keeping it longer serves no one. TAKING YOUR DATA WITH YOU. From your listing page you can download everything you gave us, and every contact request you received, as a JSON file (Article 20). Verification results we produced about you are observations rather than data you provided, so they are not in that export — ask us and we will send them under your right of access (Article 15). EVIDENCE OF CONSENT. When you list yourself we record the moment you did and which version of this notice was in force, so that we can show what you agreed to (Article 7(1)). Unlisting does not erase that record of the agreement it withdraws; deleting your listing does.
3. Why we collect it (legal basis)
• To deliver the assessment service and issue certificates: performance of a contract (GDPR Art. 6(1)(b)). • To send assessment result emails: performance of a contract. • To operate the B2B compliance dashboard: performance of a contract. • To maintain aggregate analytics for platform improvement: legitimate interest (GDPR Art. 6(1)(f)). We do not use your data for advertising, profiling, or automated decision-making with legal effects.
4. How long we keep your data
• Assessment results and certificates: 2 years from the date of issue, then deleted. • B2B organisation and staff records: 2 years after last activity, or on request. • Contact and support emails: 1 year. You can request deletion at any time (see Your Rights below).
5. Who we share data with
We share data only with processors required to run the platform: • Vercel — hosting and edge functions (EU region). • Neon / Supabase — database (EU region, encrypted at rest). • SMTP (nodemailer) — transactional email delivery. • Stripe — payment processing (B2B plans only). • Anthropic — AI-powered tools on /readiness, /market, /intelligence use the Claude API. Inputs are processed transiently; Anthropic's data use policy applies. We do not sell data to third parties.
6. Cookies
We use session cookies for authentication only (NextAuth.js). We do not use advertising or tracking cookies. Plausible Analytics is cookieless. You can disable session cookies in your browser but this will prevent B2B dashboard access.
7. Your rights under GDPR
You have the right to: • Access the personal data we hold about you. • Correct inaccurate data. • Request deletion ("right to be forgotten"). • Request data portability (receive your data in a machine-readable format). • Object to processing based on legitimate interest. • Withdraw consent at any time (where consent is the legal basis). To exercise any of these rights, email info@talentpath.eu. We will respond within 30 days. If you believe we are not handling your data correctly, you have the right to lodge a complaint with your national data protection authority.
8. International transfers
All data is stored on servers within the European Economic Area (EEA). Where sub-processors operate outside the EEA (e.g. Anthropic, Stripe), we rely on Standard Contractual Clauses (SCCs) and adequacy decisions to ensure equivalent protection.
9. Changes to this policy
We will notify B2B account holders of material changes by email. The date at the top of this page reflects the last update. Continued use of TalentPath after a change constitutes acceptance.