Version talent-privacy-2026-08-11-v5

Angular Space Talent Privacy Notice

1. Controller and contact

The controller for the Angular Space Talent registry is Decodely Daniel Glejzner, a sole proprietorship registered in Poland, ul. Sudecka 89 lok. 56, 58-500 Jelenia Góra, Poland, NIP 6112795976, REGON 380577564 ("Angular Space", "we", "us"). Privacy questions and data-rights requests may be sent to angularspacecontact@gmail.com.

This notice applies to members, prospective members who purchase or begin onboarding, approved or invited hiring-partner representatives, administrators, assessment applicants and people who contact support. Paddle provides its own privacy notice for payment processing for which it acts as a separate controller.

2. Information we process

Member and assessment data

Account email and authentication identifiers; name, telephone number, country and LinkedIn URL; profile photo; CV and professional history; skills, seniority, languages, availability, work preferences and compensation expectations; onboarding and correction responses; assessment application details, assessor notes, results, certificate identifiers and validity dates; introduction decisions and communications; and support or deactivation requests.

Hiring-partner data

Representative name, work email and account identifiers; company name, website, type, country and description; invitation and approval status; saved opportunities and explicit matching criteria; anonymous profiles viewed; introduction requests, decisions and communications; and support or deactivation requests.

If membership intake is closed, we also process the email address, consent timestamp and notification status of people who explicitly request a one-time intake-opening notification. That address is not added to a general marketing list.

Payment, contract and technical data

Paddle customer, transaction, price, product, subscription and adjustment identifiers; amounts, currency and billing status; the exact version and text of purchase acknowledgements; server timestamps; account and target identifiers; request identifiers; IP address; browser user-agent; authentication and rate-limit events; notifications; and limited metadata describing meaningful service actions. We do not receive or store complete payment-card details, passwords or authentication tokens in activity evidence.

3. Where the information comes from

Most information comes directly from the member or hiring partner. We also receive payment and subscription status from Paddle, authentication and storage events from Supabase, administrative review and assessment information from authorised Angular Space reviewers, and interaction records generated when the account uses the service. After a mutually approved introduction, each side receives the contact information deliberately released for that connection.

4. Purposes and legal bases

We process information where necessary to take requested pre-contract steps and perform the membership, assessment, partner-access and introduction services; to administer accounts and support; and to deliver the private contact package after mutual approval (GDPR Article 6(1)(b)).

We use necessary records to comply with tax, accounting, consumer-protection and lawful authority requirements (Article 6(1)(c)). Security monitoring, abuse and fraud prevention, service audit, matching assistance, dispute handling, legal-claim evidence and proportionate service improvement rely on our legitimate interests and those of users in operating a secure, accountable private network (Article 6(1)(f)). Where a future optional use genuinely requires consent, it will be requested separately and can be withdrawn without affecting earlier lawful processing.

5. Private profiles and disclosure controls

A member profile is not publicly searchable. Approved hiring partners initially receive an anonymous professional summary. Name, email, telephone number, LinkedIn URL and full CV are released only for a specific introduction after the member accepts and the hiring partner gives final approval. Declined, withdrawn or expired requests do not disclose the private contact package.

Hiring-partner accounts, saved opportunities and searches are also private. We do not publish partner names as public social proof without a separate lawful basis and appropriate authorisation.

6. Matching logic and automated decisions

When a hiring partner asks for matches, the system compares explicit profile facts with that partner's saved criteria. Relevant factors may include skills, seniority, work model, allowed country, availability and assessment status. For hybrid and on-site opportunities, a candidate outside the partner's stated allowed countries is excluded. Remaining profiles may be grouped into transparent tiers that show aligned factors and trade-offs.

The system does not infer personality, use secret CV scoring, or make a decision that produces legal or similarly significant effects. It is decision support only. Hiring partners decide whom to approach, members decide whether to accept, and employers retain responsibility for recruitment decisions. Angular Space does not use solely automated decision-making within Article 22 GDPR.

7. Recipients and service providers

Information is disclosed only as needed to: authorised Angular Space administrators, assessors and technical personnel; the specific member or approved hiring partner involved in a mutually approved introduction; Supabase for authentication, database and private file storage; Netlify for production application hosting and delivery; Cloudflare for the isolated staging deployment and related network/security services; Resend for transactional authentication email; and Paddle for checkout, tax, subscription administration, buyer support, refunds, fraud prevention and chargebacks.

Professional advisers, accountants, insurers, courts, regulators, banks or law-enforcement authorities may receive limited information where necessary for professional duties, a legal obligation or the establishment, exercise or defence of claims. We do not sell personal data or provide member identity data to data brokers.

8. Paddle and payment information

Paddle is the merchant of record and an independent controller for buyer, checkout, payment, tax, invoice, fraud, refund and chargeback processing. Paddle sends us identifiers and status information needed to provision and administer the product. Paddle's processing is described in its Privacy Notice. Relevant service-delivery and acknowledgement evidence may be supplied to Paddle when it handles a refund or payment dispute.

9. International transfers

Some providers or their subprocessors may process information outside Poland or the European Economic Area. Where GDPR transfer restrictions apply, we rely on an applicable European Commission adequacy decision, the EU Standard Contractual Clauses with appropriate supplementary measures, or another lawful transfer mechanism. Information about the safeguards relevant to a request is available from angularspacecontact@gmail.com.

10. Retention

  • Active account, profile, partner, opportunity and introduction information is kept while needed to provide the service. After deactivation or a valid erasure request, it is deleted or anonymised unless a narrower record must be retained for an unresolved introduction, payment, complaint, security matter or legal obligation.
  • Ordinary server-side activity evidence is scheduled for deletion after 180 days. Evidence linked to an open chargeback, refund, complaint or legal claim is held until the matter and applicable limitation period end.
  • Assessment applications, assessor notes, results and certificates are normally retained for the certificate's 12-month validity period and a further period reasonably needed to authenticate it, answer a complaint or defend a claim.
  • Expired partner invitations and short-lived authentication or rate-limit records are retained only for the security and audit period configured for those systems.
  • Payment, legal-acceptance, refund and accounting records are kept for the period required by Polish accounting and tax law and applicable legal limitation periods. Paddle independently retains its buyer records under its own policies.

Backups and provider logs may persist for a limited rolling period before deletion. We review retention when a purpose ends and restrict records that must be preserved rather than keeping them available for ordinary product use.

11. Is providing information required?

Account, payment and core onboarding fields are necessary to enter and perform the relevant service. Without them we cannot create, review or activate a profile, approve a partner account, fulfil an assessment or release a mutually approved introduction. Fields clearly marked optional may be omitted, although doing so can reduce the information available for matching.

Please do not include special-category information, criminal-offence information or third-party confidential information in a CV, message or free-text field unless it is strictly necessary and you have a lawful basis to provide it.

12. Security

Measures include encrypted transport, password-based authentication, server-side role and account-status checks, row-level database access controls, private file-storage buckets, short-lived authorised download links, separation of anonymous professional data from identity data, signed and idempotent Paddle webhooks, server-created checkout transactions, rate limits, restricted administrative access and versioned activity evidence. No internet service can promise absolute security; suspected unauthorised access should be reported promptly.

13. Cookies and local storage

The registry uses cookies and comparable browser storage that are strictly necessary for authentication, security, session continuity and user-interface state. Paddle may use its own checkout storage for payment, fraud-prevention and buyer-session purposes under its notice. We do not currently use advertising cookies or sell browsing behaviour. If non-essential analytics or advertising technology is introduced, the notice and consent controls will be updated before it is enabled where required.

14. Your rights

Subject to the conditions in applicable law, you may request access, rectification, erasure, restriction, data portability or object to processing based on legitimate interests. Where processing is based on consent, it may be withdrawn at any time without affecting earlier lawful processing. We may need to verify identity before acting on a request and normally respond within one month.

You may complain to a supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland, uodo.gov.pl. Some erasure or access requests may be limited where information must be retained by law, is necessary for legal claims, or would disclose another person's protected information.

15. Changes to this notice

We may update this notice when the service, providers or legal requirements change. The current version and effective date will remain published here. A material change affecting an active account will be communicated through the service or account email where appropriate.