Trust & compliance · EU regulatory readiness

Built for EU trust: privacy by default,explainable by design, compliant by architecture.

We treat privacy and compliance as load-bearing architecture, not a checkbox. Every claim on this page maps to a shipped, tested feature — not a marketing promise.

What this means for you, in plain language

  • Your profile is anonymous by default — employers see skills and experience, never your name or contacts, until you decide to share them.
  • Nothing is disclosed without your action: applying to a role or granting a reveal request. You can revoke access afterward.
  • We never sell your data. We make money from employer subscriptions, not from your information.
  • Every AI match comes with a plain-language reason — no unexplained rejections, no black box.

GDPR & data protection

Your data is yours. We hold it under EU rules and handle it with structural safeguards — not policies alone.

  • Anonymous by default

    Candidate profiles are anonymous from the moment of creation. Your name, contacts, and identity are never visible to employers until you explicitly grant a reveal. Anonymity is the system default — not an opt-in.

  • Reveal only by your consent

    PII is disclosed only when a candidate actively chooses to respond or grant a reveal request. The consent action is explicit, one-way, and revocable. No employer can bypass this gate.

  • We never sell your data to brokers

    We do not resell, share for advertising, or transfer your personal data to third-party data brokers — ever. Your information is used solely to operate the matching service.

  • Right to erasure (GDPR Art. 17) — hard cascade

    Deleting your account triggers a hard cascade: matches, contests, flags and your personal data are permanently removed, while analytics-only records such as the AI-cost ledger and matching feedback are irreversibly anonymized (the link to your identity is severed). One step, irreversible, immediate.

  • Automated data retention purge

    A single-runner retention-purge job prunes stale data on a schedule — it runs once per window across the entire cluster, preventing both data accumulation and duplicate execution.

Consent mechanic

You control who sees your identity — not us, not the employer

The consent-reveal system is structural: identity disclosure is gated by your explicit action. Employers cannot bypass it.

  • Reveal once to one employer — not broadcast
  • Revoke access at any time from your dashboard
  • Anonymous profile visible to all; identity to none until you act
Anonymous candidateSenior Nurse · 6 yrs
92%
Critical careACLSTeam lead
Consent required
Anonymous by default

Who sees what, at each step

Your data flow through MatchPRO is gated, not gradual leakage. Here is exactly what is visible to whom at every stage of the funnel.

Data visibility to the employer, the candidate, and MatchPRO across four funnel stages
StageWhat the employer seesWhat the candidate seesWhat MatchPRO stores
Anonymous browseAn anonymized handle, skills, experience level, salary band, and location preference — no name, no contacts, no CV file.Vacancy details, salary range, and company name (if the employer chose to disclose it) — full visibility, no gating.The full resume and identity, held server-side, never rendered to the employer at this stage.
Application / consentNothing new yet — the reveal grant happens at the moment of application, immediately after this step.A plain consent notice before applying: applying shares the full CV and contacts with this employer, revocable anytime from Reveals.The application event and the resulting consent grant, timestamped and auditable.
RevealFull name, contact details, and the complete CV — granted either by the candidate's application or by an explicit reveal request the candidate approved.A record of exactly which employer now holds their identity, with a one-click revoke.The reveal grant (who, when, origin) — a durable, queryable audit trail.
ChatMessages exchanged directly with the now-identified candidate through the in-app conversation.Messages from the employer who holds their reveal — no other employer can message them.Message content and metadata, stored to deliver and audit the conversation — never sent to the AI provider.

Your profile, before vs. after reveal

One concrete illustration of what a reveal actually exposes — nothing more, nothing less.

Name
Candidate #A17F — hidden
Contact
Hidden until reveal
CV file
Not accessible
Role
Senior Nurse · 6 yrs
Name
Elena Marchetti
Contact
Email and phone number, both visible
CV file
Full CV, downloadable
Role
Senior Nurse · 6 yrs

Illustrative example — names and contacts shown here are placeholders, not real candidate data.

We earn when employers hire — not when we sell your data. Our business model is structurally aligned with your privacy.

MatchPRO business model — privacy as product, not as policy

EU AI Act readiness (high-risk hiring)

Matching and AI screening in hiring is high-risk AI under EU AI Act Annex III. High-risk obligations apply from 2026-08-02. MatchPRO is engineered to meet these obligations — the features below are shipped and tested. We do not claim formal conformity-assessment or registration; those are deployment-time actions we are preparing.

High-risk obligations effective: 2026-08-02

  • Art. 13 / 86

    Explainability — right to explanation

    Every match exposes a deterministic factor breakdown: skills fit, experience fit, salary fit, and location fit — each with a score. A candidate can fetch exactly why they did or did not match a vacancy, even without a precomputed match record. No black box.

  • Art. 14

    Human oversight — contest & admin review

    Either match party — candidate or employer — can contest a match decision. An admin reviews the contest and records an outcome with a full audit trail. This is a live, end-to-end workflow, not a planned feature.

  • Art. 10 / 15

    Bias & fairness testing

    A repeatable diversity metric (industryDiversity) runs on the real corpus and reports the profession distribution of top results. A single-vertical bias is detectable before it harms candidates. The harness and threshold are in place to catch regression on every tuning round.

  • Art. 10

    Data governance — no PII to the AI provider

    No personally identifiable information is ever sent to the AI provider. The AI CV Q&A refuses identity-seeking questions and never echoes a contact field — even when a résumé contains a prompt-injection attempt. This is enforced at the system-prompt level, not by policy.

What is not yet in place: a formal conformity-assessment dossier (Art. 11) and registration in the EU high-risk database (Art. 49) are deployment-time actions we are preparing. The seeker-facing explainable-rejection UI has shipped — every vacancy page shows a candidate the deterministic factor breakdown behind their match, even without a precomputed match record.

Pay transparency

In line with EU Pay Transparency Directive 2023/970, a structured salary range is mandatory on every vacancy posted on MatchPRO. A vacancy without a salary range cannot be published — this is enforced by the API schema, not an optional field.

Salary range is required at the API level (OpenAPI schema validation rejects postings without it). Candidates always see what a role pays before any contact is made.

Security & data handling

We handle your data with structural safeguards. The points below reflect what is actually in place.

  • Sessions in PostgreSQL

    Authentication sessions are stored in PostgreSQL (Better Auth), not in volatile process memory. There are no sticky sessions; any server instance can validate any session.

  • No data-broker reselling

    We do not sell, rent, or share your data with advertising networks or data brokers. Data is used solely to provide the matching service.

  • EU-aligned data handling

    Data handling follows EU legal framework requirements. We do not claim third-party security auditing or attestation programmes we have not yet completed — we list only what is structurally true.

We do not currently hold any third-party security auditing attestations or conformity marks. We list only what is structurally in place.

Subprocessors — who else touches your data

We use a small, named set of subprocessors to run the service. Each one is scoped to a specific purpose and never receives more than it needs.

MatchPRO subprocessors with their purpose and processing region
SubprocessorPurposeRegion
OpenRouterAI inference for CV parsing, match explanations, and CV Q&A — never receives personally identifiable information.US-based routing to multiple model providers
StripePayment processing for subscriptions and one-time purchases (boosts, reveal top-ups).EU/US, PCI-DSS compliant
MeilisearchFull-text search and filtering over published resumes and vacancies — indexes only already-anonymized, publicly listed fields.Self-hosted alongside our infrastructure
Cloud hosting providerApplication, database, and file storage infrastructure.EU-region infrastructure
CentrifugoRealtime delivery for chat messages and live notifications — self-hosted, short-lived connection tokens only.Self-hosted alongside our infrastructure

Employer-controllers who need a signed Data Processing Agreement for their own compliance file can request one. Request a DPA

Read the full details

Our privacy policy covers data processing, retention, and your rights in full.