Your data deserves a clear answer.
TalentBraid builds and manages automation for recruitment agencies. This page explains how data moves through a scoped workflow, where it is processed, and what changes if AI is involved.
TalentBraid builds and manages automation for recruitment agencies. This page explains how data moves through a scoped workflow, where it is processed, and what changes if AI is involved.
For EU agency engagements, our workflow infrastructure is hosted in Paris, France using AWS France and Hostinger France. US and other non-EU engagements are served from a dedicated Northern Virginia environment. The region and any permitted exceptions are set out during scoping and in the agreement.
EU-only candidate content stays within the agreed EU workflow region. If a proposed integration, remote access arrangement, or AI feature cannot meet that requirement, we review it with you before enabling it.
TalentBraid is a managed automation layer. Candidate and client records pass through the workflows we build; we do not create a separate, permanent candidate database as the service model. Operational records needed for troubleshooting or investigation may be retained for up to 90 days, then deleted from our active systems. The exact categories and retention settings are recorded for your engagement.
You can request earlier deletion through our official contact channel, subject to legal obligations and the records needed to resolve an active incident. Third-party systems connected to your workflow have their own retention rules.
Candidate data is encrypted while traveling between systems and while stored on TalentBraid infrastructure. We scope access to the engineers and systems needed to build, operate, and support your agreed workflows. A confidential client-facing control-panel view can be provided when it is useful for the specific engagement.
AI is optional and only enabled for agreed use cases. Where feasible for the task, we replace direct identifiers such as names before sending a limited payload to an AI provider. Redaction reduces exposure; it does not guarantee that every record is anonymous. We document the selected provider, fields, model features, region, and retention terms before activation.
OpenAI and Anthropic API retention is feature- and contract-dependent. Standard API abuse-monitoring or input/output retention is commonly up to 30 days, with exceptions for certain endpoints, files, safety or legal needs, and separately configured terms. OpenAI’s Responses API can hold application state for at least 30 days by default. We do not describe either provider as universally “30-day maximum” or “zero retention.” See the provider details.
We define the workflow, access, regional requirements, and retention with your team before work begins. We can provide a data processing agreement for review and handle access or deletion requests through the agreed contact route. Read our DPA overview.