AITACS Talent is built with privacy, security, and anti-discrimination at its core. Here's exactly how we protect Candidate data — including the one place where we don't hide identifying information, and why.
Age, gender, race, religion, and marital status are not fields in the Platform at all — for any of the three AI features.
The chat assistant and candidate-analysis features strip identifying data before any AI call.
Every AI screening call is logged with redacted fields, model used, and human-review status.
AITACS Talent uses AI in three distinct features, and they don't all handle identifying data the same way. We say this plainly here because a single blanket claim would be misleading for one of them.
Full data including name, contacts, résumé link, professional notes
Strips name, phone, email, résumé link. Scrubs contact-like patterns from free text.
Auto-generated pseudonym replaces the Candidate's identity.
Receives only pseudonym + job-relevant professional data
Bulk import of CVs or client lists uses AI to extract a candidate's or company's name and contact details from an uploaded document — that extraction is the feature's entire purpose, so this data is not stripped before the AI call. Protection here relies on the AI provider's zero/short data-retention terms, not on de-identification. See Privacy Policy §3.2 for the full explanation.
(Applies to the chat assistant and candidate-analysis features only — see the notice above for the document-import exception.)
All communications between your browser, our server, and the AI provider are encrypted using TLS 1.2 or higher. No data travels in plaintext.
An automatic server-side filter strips identifying fields before the chat assistant or candidate-analysis call reaches the AI provider — as described above, this does not apply to the document-import feature.
Firebase Authentication with unique Recruiter IDs. Your data is isolated — no other Recruiter can access it. Two-factor authentication (2FA) is supported and recommended.
Every AI candidate-analysis call is recorded in ai_screening_log with a timestamp, the
fields redacted, the model used, and a human_reviewed flag — supporting bias-audit
obligations such as NYC Local Law 144.
Regular encrypted database backups. Data export available in JSON format at any time.
Documented procedures for detecting, containing, and reporting security incidents. GDPR-compliant 72-hour breach notification. See Incident Response Policy.
Full compliance with GDPR Articles 5–49. Data Processing Agreement (Art. 28) available. Data subject rights (Art. 15–22) supported. International transfers protected by Standard Contractual Clauses. Read DPA →
The Provider is an Israeli-registered sole proprietor; the Israeli Protection of Privacy Law, 5741-1981, and the Protection of Privacy Regulations (Data Security), 5777-2017, apply directly to the Provider's own processing. Governing law of the Terms of Service is the State of Israel. Read Terms §9 →
For Recruiters and Candidates located in Ukraine, the Law of Ukraine "On Protection of Personal Data" applies to the processing of their personal data, in parallel with GDPR and Israeli law.
No specific state/provincial privacy-law provisions are yet built out for these markets — placeholders exist in the Terms of Service §9.2–9.4 and will be completed before the Platform is offered in those markets.
AITACS Talent uses OpenAI's API for all three AI features. Key facts about how OpenAI handles your data:
No model training: API data is not used to train or improve OpenAI's models. Retention: under OpenAI's zero-retention API policy, API inputs and outputs are not retained by OpenAI after the response is returned (0-day retention). What OpenAI receives depends on which feature is in use — pseudonym plus professional data for the chat assistant and candidate analysis; the uploaded document's actual content for document import. See the comparison above.
Security is a partnership between AITACS Talent and you as the Recruiter. We handle server security, de-identification (for the features where it applies), encryption, and incident response. You are responsible for device security, obtaining Candidate consent, not reintroducing protected characteristics into free-text fields, and following the User Security Requirements.
Terms of Service · Privacy Policy · Informed Consent Template · Cookie Policy · Data Processing Agreement (DPA) · Recruitment Data Sharing Agreement · Subprocessor List · Security Requirements · Incident Response Policy · Security Overview · Refund Policy · Copyright Policy · Contact Us