Scope and Application
This Policy applies to all individuals who interact with Talent Solution outside Vietnam, including customers, end users, employees of business customers, job applicants, and website visitors.
By using our services, you acknowledge that you have read, understood, and agree to the terms of this Policy. If you are a resident of Vietnam, please refer to our Vietnamese Privacy Policy, which is governed by Vietnam's Personal Data Protection Law.
Definitions
"Personal Data" means any information relating to an identified or identifiable natural person.
"Sensitive Personal Data" (GDPR) / "Sensitive Personal Information" (CCPA) includes government identifiers, financial account details, precise geolocation, biometric data, health data, racial or ethnic origin, religious or political beliefs, sexual orientation, trade union membership, and employment-related data such as compensation and performance evaluations.
"Data Subject" / "Consumer" means the natural person to whom the Personal Data relates.
"Controller" determines the purposes and means of processing. "Processor" processes data on behalf of a Controller.
"Processing" means any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, erasure, or destruction.
Our Role: Controller and Processor
Talent Solution acts in two distinct capacities:
- As a Controller — when we process Personal Data of our own account holders, billing contacts, marketing recipients, and website visitors for our internal business purposes.
- As a Processor — when we process Personal Data of employees, contractors, or candidates that our business customers upload into the platform. In this case, our customer is the Controller and we process such data only on documented instructions, governed by a Data Processing Agreement (DPA).
Personal Data We Collect
Depending on how you interact with us, we may collect the following categories of Personal Data:
- Identifiers: name, email address, phone number, postal address, account credentials, IP address, device identifiers.
- Commercial information: subscription plan, billing details, payment history, transaction records.
- Professional or employment-related information: job title, employer, employment status, employment records uploaded by business customers (compensation, attendance, performance, contracts).
- Internet and network activity: browsing data, login activity, pages viewed, interaction with features, referral URLs.
- Geolocation data: approximate location derived from IP address; precise location only if you explicitly enable it.
- Inferences: usage patterns and preferences used to improve the service.
- Communications: support tickets, chat transcripts, emails you send us.
- Sensitive Personal Information (where applicable): government identifiers, financial account information, precise location, and employment data uploaded by business customers.
Sources of Personal Data
We collect Personal Data from the following sources:
- Directly from you when you register, configure your account, use the service, or contact us.
- From our business customers when they upload data about their employees, contractors, or applicants.
- Automatically through cookies, server logs, and analytics tools when you use our website or platform.
- From third-party integrations and identity providers (e.g., Google, Microsoft) when you authorize such connections.
Purposes of Processing
We process Personal Data for the following purposes:
- Providing, operating, securing, and maintaining the service.
- Account creation, authentication, and access management.
- Billing, payment processing, and tax compliance.
- Customer support, dispute resolution, and service communications.
- Product analytics, service improvement, and feature development.
- Marketing communications (only with consent or where permitted by law).
- Fraud prevention, abuse detection, and platform security.
- Compliance with legal obligations and enforcement of our Terms.
Legal Bases for Processing (GDPR)
Under the GDPR and UK GDPR, we rely on the following legal bases:
- Performance of a contract — to deliver the service you subscribed to.
- Consent — for optional processing such as marketing emails, non-essential cookies, and other use cases you specifically opt into. You may withdraw consent at any time.
- Legitimate interests — for service improvement, fraud prevention, network security, and internal analytics, where such interests are not overridden by your rights and freedoms.
- Legal obligation — to comply with tax, accounting, and other regulatory requirements.
- Vital interests — to protect the life or safety of an individual in rare emergency situations.
Disclosure and Sharing of Personal Data
We do not sell Personal Data in the traditional sense. We share Personal Data only in the following circumstances:
- With service providers (subprocessors) acting on our instructions to deliver the service — cloud hosting, email delivery, payment processing, analytics, customer support tools. Each is bound by a written DPA with confidentiality, security, and use-restriction obligations.
- With our business customers, when you are an end user whose data is managed by their account.
- With professional advisors (lawyers, auditors, accountants) under confidentiality obligations.
- With government authorities and law enforcement when required by valid legal process.
- In connection with a corporate transaction (merger, acquisition, restructuring), subject to continued protection of Personal Data.
Subprocessors
We engage a curated set of third-party service providers to operate the platform. A current list of subprocessors, including their location and the type of processing they perform, is available upon request to contact@talentsolution.app. We notify customers in advance of any material change to our subprocessor list and provide an opportunity to object.
International Data Transfers
Talent Solution operates globally and uses infrastructure and service providers located in jurisdictions including the United States, the European Union, Singapore, and Vietnam. When Personal Data is transferred from the EU/EEA, UK, or other regulated jurisdictions to countries that have not received an adequacy decision, we rely on appropriate safeguards, including:
- EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum.
- Transfer Impact Assessments (TIAs) following the Schrems II framework.
- Supplementary technical, contractual, and organizational measures where required.
You may contact contact@talentsolution.app to obtain a copy of the relevant safeguards.
Data Retention
We retain Personal Data only as long as necessary for the purposes stated in this Policy and as required by applicable law:
- Account data: for the duration of your subscription plus 12 months after account closure.
- Billing and transaction records: typically 7–10 years to meet accounting and tax obligations.
- Customer-uploaded employee data: retained per the business customer's instructions; we are the Processor.
- Support communications: 3 years after the last interaction.
- Cookies and technical logs: up to 12 months.
At the end of the retention period, data is securely deleted or irreversibly anonymized.
Security Measures
We implement technical and organizational measures appropriate to the risk, including:
- Encryption in transit (TLS 1.2+) and at rest.
- Role-based access control following the principle of least privilege.
- Continuous logging, monitoring, and anomaly detection.
- Regular backups and tested disaster-recovery procedures.
- Vendor security assessments and contractual security obligations.
- Employee training and confidentiality commitments.
No system can guarantee absolute security. You are responsible for protecting your credentials and notifying us promptly of any suspected unauthorized access.
Your Rights Under the GDPR / UK GDPR
If you are located in the EU, EEA, UK, or Switzerland, you have the following rights:
- Right of access — request a copy of your Personal Data.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten").
- Right to restrict processing.
- Right to data portability — receive your data in a machine-readable format.
- Right to object to processing based on legitimate interests or for direct marketing.
- Right not to be subject to solely automated decisions that produce legal or similarly significant effects.
- Right to withdraw consent at any time without affecting prior lawful processing.
To exercise any right, contact contact@talentsolution.app. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (e.g., the Irish DPC, the UK ICO, or the CNIL in France).
Your California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:
- Right to know — what categories and specific pieces of Personal Information we collect, the sources, the business purpose, and the third parties with whom we share.
- Right to delete Personal Information we have collected, subject to legal exceptions.
- Right to correct inaccurate Personal Information.
- Right to opt out of the sale or sharing of Personal Information.
- Right to limit the use and disclosure of Sensitive Personal Information.
- Right to data portability.
- Right to non-discrimination for exercising your privacy rights.
We do not sell Personal Information for monetary consideration. To the extent that the use of advertising cookies and analytics could be considered "sharing" under the CCPA, you may opt out at any time. We honor Global Privacy Control (GPC) signals.
To exercise your rights, email contact@talentsolution.app or use the "Your Privacy Choices" link in our footer. We will verify your identity using reasonable methods proportional to the sensitivity of your request.
Automated Decision-Making
Talent Solution does not currently make decisions about you that are based solely on automated processing and that produce legal or similarly significant effects. If we introduce such processing — for example, AI-assisted candidate ranking or performance scoring — we will provide prior notice, explain the logic and significance involved, offer the right to human review, and (for California residents) honor the right to opt out under CPRA's Automated Decision-Making Technology (ADMT) rules.
Cookies and Tracking Technologies
We use cookies and similar technologies for essential functionality (authentication, security, preferences) and, with your consent, for analytics and product improvement. You can manage cookie preferences through our cookie banner or your browser settings. We honor browser-level signals such as Global Privacy Control where applicable. Refusing non-essential cookies will not impair core functionality of the service.
Children's Privacy
Talent Solution is a business product not intended for use by individuals under the age of 18. We do not knowingly collect Personal Data from children under 16 (under the GDPR) or under 13 (under the COPPA / CCPA framework). If we learn that we have collected such data without verified parental consent, we will delete it promptly.
Data Breach Notification
If a Personal Data breach occurs that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Article 33).
- Notify affected individuals without undue delay when the breach is likely to result in a high risk.
- Comply with state-level breach notification laws applicable in the United States and other jurisdictions.
- Document the breach, its effects, and remedial actions taken.
Data Protection Contact
Talent Solution is in the process of formalizing a dedicated Data Protection Officer (DPO) function. In the meantime, all inquiries from data subjects and supervisory authorities relating to this Policy or to the processing of Personal Data should be directed to contact@talentsolution.app. We will respond within 30 days and will publish the DPO contact details once the appointment is finalized.
Complaints to Supervisory Authorities
We encourage you to contact us first so we can address your concerns directly. You also have the right to lodge a complaint with a competent supervisory authority, including:
- EU/EEA: your national data protection authority (find your authority at edpb.europa.eu).
- United Kingdom: the Information Commissioner's Office (ico.org.uk).
- California: the California Privacy Protection Agency (cppa.ca.gov) or the California Attorney General's office.
- Other jurisdictions: the data protection authority where you reside.
Changes to This Policy
We may update this Policy from time to time to reflect changes in our services, technology, legal requirements, or business practices. Material changes will be communicated through email or a prominent notice on our website at least 30 days before they take effect. Your continued use of the service after the effective date constitutes acceptance of the updated Policy.
Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your Personal Data, please contact:
- Legal entity: TALENT SOLUTION GLOBAL COMPANY LIMITED
- Address: 96 Cao Thang Street, Ban Co Ward, Ho Chi Minh City, Vietnam
- Email: contact@talentsolution.app
We aim to respond to all inquiries within 30 days.
