1. Data Controller

Talnflo Inc. ("Talnflo," "we," "us," or "our") is the data controller responsible for your personal data processed through our platform. For questions about how we handle your data, contact us at [email protected].

For Enterprise customers subject to a Data Processing Agreement (DPA), Talnflo acts as a data processor with respect to candidate data submitted through your ATS integration. Your organization remains the controller for that data.


2. Information We Collect

a) Information You Provide: Candidates

  • Account data: Name, email address, phone number
  • Profile data: Headline, desired role, location, work history, job titles, employers, dates of employment, job descriptions, education, degrees, certifications
  • Skills & qualifications: Skills, proficiency levels, professional certifications, languages
  • Compensation preferences: Desired salary range, preferred compensation type
  • Work preferences: Remote/hybrid/on-site preference, availability, employment type preferences
  • Security clearance: Self-reported clearance level
  • Identity verification: We use Socure, a third-party identity verification provider, to verify your identity. This requires a photo of a government-issued ID and a brief selfie. Talnflo does not store your ID image, selfie, or any facial biometric template. Socure processes and holds this data under their own privacy terms. We store only our derived verification outcome (verified/not verified, verification tier, and a reference token). See Section 3 for biometric consent details.
  • Video introductions: A recorded video you choose to upload as part of your candidate profile. Stored and served via Talnflo's infrastructure.
  • Resume: An uploaded PDF resume, if provided.
  • Communications: Messages sent through the platform to recruiters or our support team.

b) Information You Provide: Recruiters & Employers

  • Account data: Name, email address, job title, company
  • Company data: Company name, website, industry, size, description, logo
  • Job postings: Job titles, descriptions, requirements, compensation ranges, location, work arrangement
  • Application and pipeline data: Stage movements, notes, decisions, interview scheduling

With your consent via our cookie banner:

  • Analytics (Google Analytics 4): Pages visited, time on page, scroll depth, click events, session duration, device type, browser, screen resolution, language, referral source, UTM parameters
  • Marketing (LinkedIn Insight Tag): Conversion events linked to LinkedIn advertising campaigns
  • Support (Crisp): Chat conversations with our support team; linked to your account if you are logged in

We also collect:

  • Approximate IP address: Used for fraud prevention and security. Truncated after 90 days and never used for precise geolocation.
  • Session identifiers: Randomly generated tokens for session management. Not linked to your identity beyond the current session.
  • Application events: Which jobs you applied to, pipeline stage changes, interview events.
  • Product usage signals: Feature interactions used in aggregate to improve the platform.

3. Biometric Data and Identity Verification

This section applies to candidates who complete identity verification.

Talnflo partners with Socure to verify candidate identities. When you choose to verify:

  • You will be asked to photograph a government-issued ID and take a short selfie.
  • This data is transmitted directly to Socure and processed on their infrastructure.
  • Talnflo does not receive, store, or have access to your ID image, selfie, or facial biometric template. Socure holds this data under their own terms and privacy policy.
  • Talnflo receives and stores only our derived outcome: verified or not verified, the verification tier, and reference identifiers needed to link the outcome to your account.

Consent is required. We will present a clear disclosure and ask for your explicit written consent before any verification check runs. You may decline without affecting your ability to use Talnflo, though some roles may require verification as a condition of applying.

Retention. Socure retains biometric data (ID images, selfie images, and facial templates) for up to 3 years from the date of collection, or for the duration of our vendor relationship with Socure, whichever is shorter, after which it is permanently destroyed per Socure's biometric retention and destruction schedule. This schedule is available upon request by contacting [email protected]. Talnflo's derived verification outcome is retained for the life of your account and deleted upon account deletion.

Your biometric consent records (scope, timestamp, policy version, IP address) are retained for 3 years as required by applicable law.


Under the EU General Data Protection Regulation (GDPR), we process your data based on:

  • Consent (Art. 6(1)(a)): Analytics and marketing cookies, product improvement based on usage data, and video intro storage.
  • Explicit consent for sensitive data (Art. 9(2)(a)): Identity verification and any processing of biometric data signals. Consent is obtained separately before verification runs.
  • Contract Performance (Art. 6(1)(b)): Processing your account data, profile data, job applications, and communications to deliver the platform services you signed up for.
  • Legitimate Interest (Art. 6(1)(f)): Security, fraud prevention, and strictly necessary session management. We have conducted a legitimate interest assessment for these purposes.
  • Legal Obligation (Art. 6(1)(c)): Where required by applicable law.

5. How We Use Your Information

  • Provide and operate the platform: Account management, job matching, application tracking, messaging, interview scheduling
  • Identity verification: Confirming your identity to issue a verified badge and enable trust features
  • Scout Match Score: We use an automated scoring system to calculate a match score between candidate profiles and job postings. This score is based on skills, role alignment, experience, location, compensation range, security clearance, and certifications. It is a decision-support tool; recruiters make all final hiring decisions.
  • Video introductions: Storing, serving, and displaying your video intro to recruiters viewing your profile or application
  • Platform improvement: Analyzing aggregate, anonymized usage data to improve features, performance, and matching accuracy
  • AI and model training: We may use anonymized and aggregated platform data (application outcomes, match signals) to improve our scoring algorithms. We will never use your identifiable personal data to train third-party AI models.
  • Communications: Sending verification results, application updates, recruiter messages, and platform notifications
  • Marketing (with consent): Measuring the effectiveness of our advertising campaigns
  • Security and fraud prevention: Detecting abuse, protecting accounts, and meeting our obligations to third-party vendors including Socure
  • Legal compliance: Meeting regulatory obligations and responding to lawful requests
  • Business transfers: See Section 7.

6. Data Sharing and Disclosure

We do not sell your personal information. We may share data in the following circumstances:

  • Recruiters and employers: Your candidate profile, application materials, verification status, Scout Match Score, and video intro are shared with recruiters at companies whose jobs you apply to or whose Scout pool you appear in.
  • Identity verification (Socure): When you initiate verification, your ID and selfie are transmitted to Socure for processing. Talnflo does not receive raw biometric data. Socure's privacy policy governs their handling of this data.
  • Analytics providers (Google, LinkedIn): Aggregate analytics and advertising measurement data, subject to your cookie consent. These providers operate under their own data processing terms.
  • Support (Crisp): Chat conversations when you use our in-product support widget, subject to your cookie consent.
  • Enterprise ATS integrations: If your employer uses Talnflo's ATS integration (e.g., Workday, Bullhorn, iCIMS), application data may be shared with or received from that system under a Data Processing Agreement between Talnflo and the employer. The employer is the data controller for this data.
  • Legal requirements: When required by law, court order, regulatory authority, or to protect Talnflo's legal rights.
  • Service providers: Other infrastructure and technology providers (hosting, email delivery, monitoring) who process data on our behalf under data processing agreements.
  • Business transfers: See Section 7.

7. Business Transfers

If Talnflo is involved in a merger, acquisition, financing, reorganization, or sale of assets, your personal data may be transferred to the acquiring entity or its advisors as part of that transaction. We will notify you via the email address associated with your account or a prominent notice on our website before your data becomes subject to a materially different privacy policy. Your continued use of the platform after such a transfer constitutes acceptance of the successor entity's privacy policy.

We disclose this in accordance with our privacy policy's stated purposes, which include this type of data transfer as a business use.


Categories of Cookies

Category Services Purpose Retention Consent Required
Strictly Necessary Talnflo session, consent record Session management, security, storing your cookie preference Session / Persistent No
Analytics Google Analytics 4, LinkedIn Insight Tag Page views, session data, device/browser info, advertising measurement 12 months (GA4), 6 months (LinkedIn) Yes
Support Crisp In-product support chat, account linking Session / Persistent Yes

Managing Your Preferences

  • A cookie banner is shown on your first visit. You can accept all or reject non-essential cookies.
  • To change your preference after the initial choice, clear your browser cookies or contact us at [email protected].
  • We honor the Global Privacy Control (GPC) browser signal. If your browser sends a GPC signal, we automatically treat it as a rejection of non-essential cookies without displaying the banner.

We do not load any analytics or support scripts until you have made an active choice via the cookie banner. If you reject or if GPC is detected, only strictly necessary cookies are set.


9. Data Security

We implement industry-standard security measures including:

  • Encryption in transit (TLS 1.2+)
  • Encrypted storage for sensitive data fields
  • Role-based access controls with least-privilege principles
  • Access logging for sensitive personal information
  • Regular security assessments

We comply with the information security requirements in our agreement with Socure. No electronic storage method is 100% secure. If we become aware of a security breach affecting your personal data, we will notify you as required by applicable law.


10. Data Retention

Data Type Retention Period
Account and profile data Life of account; deleted within 30 days of account deletion request
Job applications and pipeline data Life of account
Video introductions Life of account; deleted within 30 days of deletion request
Identity verification outcome (our derived signal) Life of account
Biometric data (ID images, selfies) Not retained by Talnflo. Held by Socure per their retention schedule
Biometric and cookie consent records 3 years from the date of consent (regulatory requirement)
Analytics data (GA4) 12 months, per Google Analytics data retention settings
Support chat logs (Crisp) 24 months
Security and fraud prevention logs 90 days (raw IP), then truncated/anonymized

11. Sensitive Personal Information (CPRA)

Under the California Privacy Rights Act (CPRA), the following categories of sensitive personal information we collect are used only for the purposes disclosed in this policy and are not used to infer characteristics about you beyond what is necessary to operate the platform:

  • Government ID data: Processed by Socure for identity verification only. Not retained by Talnflo.
  • Biometric data: Processed by Socure. Not retained by Talnflo.
  • Security clearance level: Self-reported; used for job matching (Scout Score) only.
  • Compensation expectations: Used for job matching only.

You have the right to limit our use and disclosure of your sensitive personal information. To exercise this right, contact [email protected].


12. Your Rights Under GDPR (EU/EEA/UK)

If you are located in the EU, EEA, or UK, you have the following rights:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time (does not affect prior lawful processing)
  • Rights related to automated decision-making: Request human review of any automated decision that significantly affects you

To exercise any of these rights, contact [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority.


13. Your Rights Under CCPA/CPRA (California)

If you are a California resident, you have the following rights:

  • Right to Know: What personal information we collect, use, disclose, and sell (we do not sell)
  • Right to Delete: Request deletion of your personal information
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale or Sharing: We do not sell or share personal information as defined under CCPA/CPRA
  • Right to Limit Use of Sensitive PI: Limit our use of your sensitive personal information (see Section 11)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights

To exercise these rights, contact [email protected]. We will verify your identity and respond within 45 days.


14. Other US State Privacy Laws

We comply with applicable state privacy laws including:

  • Illinois (BIPA): Written consent obtained before biometric processing; biometric data held by Socure, not Talnflo; retention aligned with BIPA schedules
  • Texas (CUBI): Biometric identifier disclosure and consent
  • Washington (My Health MY Data / biometric laws): Consent before collection
  • Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA): Applicable consumer privacy rights including access, correction, deletion, and opt-out of profiling

We honor the Global Privacy Control (GPC) universal opt-out signal.


15. International Data Transfers

Your data may be processed in the United States and other countries. When we transfer data from the EU, EEA, or UK to countries without an adequacy decision, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission. To request a copy of applicable transfer mechanisms, contact [email protected].


16. Children's Privacy

Our services are directed at individuals 18 years of age or older. We do not knowingly collect personal information from individuals under 18. If we learn we have collected data from a minor, we will delete it promptly. To report a concern, contact [email protected].


17. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via a prominent notice on our website or by email. The updated effective date appears at the top of this page. Continued use of our services after changes constitutes acceptance of the revised policy.


18. Contact Us

Privacy inquiries and rights requests: Email: [email protected] Talnflo Inc.

We aim to respond to all requests within 30 days (or 45 days for CCPA requests).