← leadl.ai RU

Security and candidate data protection

We build a product that finds people who never applied to you. That only works if the people we find are treated properly, and if the recruiter using our output can answer a candidate who asks “where did you get my data?” This page explains how we handle that — in plain language, with the operative details taken from our Privacy Policy.

Who is responsible for what

Leadl processes personal data in more than one capacity, and the rules differ by capacity. This matters for your DPO more than any security badge does.

DataOur role
Candidate profiles we source and assemble from public sourcesController — we decide the purposes and means
Data you upload or instruct us to process (your ATS data, notes, CVs)Processor — we act on your documented instructions
Account, billing and usage dataController

When a sourced profile is made available to you, you become an independent controller of your copy. We are not joint controllers with our customers — each side answers for what it does with the data.

What we collect, and what we deliberately do not

What we hold about a candidate: professional and vocational information — name; role, skills, experience and education; links to public professional profiles and work outputs; city or region; and professional contact details where the person has made them public. Sources are publicly accessible ones: professional networking sites, developer and portfolio platforms, public professional directories, and licensed data vendors.

What we do not collect. We do not intend to collect or infer special category data under Art. 9 GDPR — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health, sex life or sexual orientation, genetic or biometric data. Sources and models are configured to exclude and filter such data at ingestion and to avoid producing inferences about protected characteristics. Anything of that kind received inadvertently is deleted.

The legal basis, stated plainly

Sourcing runs on legitimate interests, Art. 6(1)(f) GDPR: connecting qualified professionals with relevant opportunities and letting employers recruit efficiently. We keep collection limited to role-relevant professional information, and we provide candidates the Article 14 notice — the disclosure required when data was not obtained from the person directly. It is published in full inside our Privacy Policy and made available at first contact.

We are established in Spain and operate under the GDPR (Regulation (EU) 2016/679) and Spanish Organic Law 3/2018 (LOPDGDD). The supervisory authority is the Agencia Española de Protección de Datos (AEPD).

How long data lives here

Sourced candidate profiles with no engagement and no other legal basis are automatically deleted after 365 days. Processing we do on your instruction follows your retention settings and our agreement with you.

Opt-out and suppression

When a candidate objects or asks for erasure, we delete the active record and keep only a minimal hashed identifier on a suppression list — solely so that we do not re-source or re-contact that person later. Keeping a hash is what makes “do not contact me again” actually stick. We also recognise Global Privacy Control signals.

Candidate rights, and what we do with a request

Candidates have the rights of access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20) and objection (21), the right not to be subject to solely automated decisions (22), and the right to withdraw consent where processing rests on it. Requests go to hay@leadl.ai and we answer within one month (extendable by two for complex cases), free of charge in ordinary cases. Where we act as a processor, we forward the request to the customer-controller and assist them; the substantive answer is theirs to give.

AI: what it decides and what it does not

The platform uses automated processing, including profiling, to produce a suitability indication, possible red flags and suggested interview questions. These are decision-support outputs for a human recruiter. They are not a decision based solely on automated processing producing legal or similarly significant effects: final screening and hiring decisions are made by your personnel, who review the outputs and keep full authority to disregard them.

We provide meaningful information about the logic involved — the criteria influencing an output — without disclosing trade secrets. A candidate who believes an automated output significantly affected them may request human review, express their view and contest the output via hay@leadl.ai.

AI systems used in recruitment may qualify as high-risk under the EU AI Act (Reg. (EU) 2024/1689). We implement transparency, human-oversight, logging and monitoring measures accordingly.

AI providers cannot train on this data

Our AI and LLM sub-processors are contractually barred from using personal data to train their models. The current sub-processor list and the transfer mechanism applicable to each vendor are available on request at hay@leadl.ai.

Transfers outside the EEA

Where personal data leaves the EEA we rely on an adequacy decision (including the EU–US Data Privacy Framework for certified importers), the EU Standard Contractual Clauses, the UK IDTA/Addendum, and Swiss safeguards — supported by a transfer impact assessment where required. Copies of the safeguards are available at hay@leadl.ai.

Technical and organisational measures

We implement measures appropriate to the risk under Art. 32 GDPR: access control, encryption in transit, logging, backups, and an incident-response process. Where a personal-data breach requires it, we notify the supervisory authority and affected individuals under Arts. 33–34.

We would rather say what we have than imply what we do not: this page lists the measures we actually operate. We do not currently claim SOC 2 or ISO 27001 certification, and we will not display badges we have not earned. If your procurement process requires a specific certification or a completed security questionnaire, write to hay@leadl.ai and we will tell you honestly where we stand.

Reporting a vulnerability

If you believe you have found a security issue, email hay@leadl.ai with steps to reproduce. Please give us reasonable time to fix the issue before disclosing it publicly. We do not currently run a paid bounty programme, and we will not pursue researchers who report in good faith and avoid privacy violations, data destruction and service disruption.

Contact

AI LEADPLATFORM, S.L. — CIF B75627067, Calle Consell de Cent, 38, 08014 Barcelona, Spain.
Data protection contact: hay@leadl.ai

Full legal texts: Privacy Policy · Terms of Service · Cookie Policy · Data Processing Consent.