Privacy Policy for Talent Journey and Hector Platforms
Effective Date: January 20, 2026
Last Updated: January 20, 2026
Service Provider:
Talent Journey
Legal Entity Name: Talent Journey, LDA
NIPC: 518824799
Registered in: RUA DA BALDRUFA, 239 2º FRAÇÃO T, Ponte de Lima, Portugal
Email: privacy@talentjourney.tech
Website: talentjourney.tech
1. Introduction
Welcome to Talent Journey's Privacy Policy. We operate two platforms:
- Talent Journey Relocation Platform (app.talentjourney.tech) - Global mobility and relocation services
- Hector Platform (hectorheadhunter.com) - AI-powered job matching and headhunting services
We are committed to protecting your privacy and handling your personal data responsibly and in compliance with applicable data protection laws, including:
- The General Data Protection Regulation (EU) 2016/679 ("GDPR")
- Portuguese Law 58/2019 (implementing the GDPR)
- Other applicable Portuguese and EU data protection regulations
This Privacy Policy explains:
- What personal data we collect on each platform
- Why we collect it
- How we use it
- Who we share it with
- Your rights regarding your data
- How we protect your data
Important: This Privacy Policy applies to both platforms. Platform-specific information is clearly marked throughout this document.
Who This Applies To:
- Talent Journey Users: Talents (individuals using relocation services), Client Company Representatives, Family Members
- Hector Users: Talents (job seekers), Company Representatives (hiring companies)
By creating an account or using our services, you acknowledge that you have read, understood, and agree to this Privacy Policy.
2. Data Controller and Contact Information
2.1 Who Controls Your Data
Talent Journey is the data controller for the personal data we process through both platforms. This means we determine the purposes and means of processing your personal data.
Our Roles:
- Talent Journey Platform: We process your data to provide global mobility and relocation services
- Hector Platform: We process your data to provide AI-powered job matching and headhunting services
2.2 How to Contact Us
For General Privacy Questions:
Email: privacy@talentjourney.tech
For Exercising Your Data Rights:
Use the same contact information above.
2.3 Supervisory Authority
You have the right to lodge a complaint with the Portuguese Data Protection Authority (Comissão Nacional de Proteção de Dados - CNPD):
CNPD
Address: Av. D. Carlos I, 134, 1º, 1200-651 Lisboa, Portugal
Phone: +351 213 928 400
Email: geral@cnpd.pt
Website: www.cnpd.pt
3. What Personal Data We Collect
We collect different types of personal data depending on which platform you use and your role.
3.1 Data Collected on Talent Journey Platform
3.1.1 For Talents (Relocation Service Users)
Identity and Contact Information:
- Full name (including any previous names)
- Date and place of birth
- Nationality and citizenship(s)
- Gender
- Passport number and details
- National ID card details (if applicable)
- Email address
- Phone number(s)
- Current residential address
- Emergency contact information
Family and Marital Information:
- Marital status
- Spouse/partner details (name, date of birth, nationality)
- Children's details (names, dates of birth, nationalities)
- Family composition
- Dependents requiring relocation
Employment Information:
- Current employer name and address
- Job title and position
- Employment start date
- Employment contract details (when relevant)
- Salary and compensation information (when relevant)
- Previous employment history (when relevant)
- Employer contact information (when relevant)
Immigration and Travel History:
- Previous visas and residence permits
- Immigration history (countries lived in, duration)
- Previous visa applications and outcomes
- Travel history
- Previous addresses
- Any immigration violations or issues (if applicable)
Education and Qualifications:
- Educational qualifications and degrees
- Universities and institutions attended
- Diplomas and certificates
- Professional licenses and certifications
- Language proficiencies
Financial Information:
- Bank account details (for assistance with account opening guidance)
- Income verification documents (when relevant)
- Financial statements (for rental applications)
- Tax identification numbers (NIF)
- Social security numbers (NISS)
Health Information (Limited and Only When Necessary):
- Health insurance information
- Medical certificates (when required for visa applications)
- Vaccination records (when required)
- Disability or special needs information (only if you provide it for accommodation purposes)
Note: We collect health data only when strictly necessary and with your explicit consent. This data is subject to additional protections.
Documents:
- Passport copies
- Birth certificates
- Marriage certificates (if applicable)
- Divorce decrees (if applicable)
- Police clearance certificates
- Educational certificates and diplomas
- Employment contracts and offer letters
- Bank statements
- Proof of address documents
- Any other documents required for your relocation
Accommodation Preferences:
- Preferred neighborhoods and locations
- Budget range
- Housing requirements (bedrooms, amenities)
- Move-in date preferences
- Pet information (if applicable)
- Accessibility requirements
Platform Usage Data:
- Login credentials (username and hashed password)
- Login history and timestamps
- IP addresses
- Device information (browser type, operating system)
- Pages visited and features used
- Documents uploaded and downloaded
- Messages sent through the Platform
- Service requests and status updates
- Feedback and survey responses
3.1.2 For Client Company Representatives
- Name and job title
- Business email address
- Business phone number
- Company name and registration details
- Company fiscal ID (NIPC)
- Role and authorization level
- Login credentials and usage data
- Communication preferences
- Billing and payment information
3.1.3 For Family Members
When family members are included in relocation services, we collect similar categories of data as listed in Section 3.1.1, as applicable to their age and circumstances. For minor children, we collect data with parental consent.
3.2 Data Collected on Hector Platform
3.2.1 For Talents (Job Seekers)
Profile Information:
- Name, email, phone number
- Nationality and residence location
- Skills, experience, and qualifications
- Education, certifications, and training
- Language proficiencies
- Employment status and availability
- Job preferences and expectations
- Marital status (for international mobility assessment)
- Desired salary range
- Career goals and objectives
Conversation Data:
- Your conversations with Hector AI
- Messages, responses, and interactions
- Questions asked and answers provided
- Skills assessments and evaluations
- Follow-up interview responses
Usage Data:
- Login history and activity
- Matches presented and your responses (accept/decline)
- Platform usage patterns
- Job searches and preferences
- Device and browser information
- Interaction timestamps
Documents (if uploaded):
- CV/Resume
- Certifications and licenses
- Portfolio materials
- Work samples
Job Search History:
- Jobs you viewed
- Jobs you were matched with
- Jobs you accepted/declined
- Companies you interviewed with
- Interview outcomes
Payment and Billing Information (processed by Stripe):
- Subscription status and plan type
- Billing history and payment dates
- Payment method details (stored securely by Stripe, not by us)
3.2.2 For Company Representatives (Hiring Companies)
Company Information:
- Company name, address, registration details
- Contact person name, email, phone
- Company fiscal ID
- Industry and company size
- Employer branding materials
Job Postings:
- Job titles and descriptions
- Required skills and qualifications
- Location and work arrangement
- Salary ranges (if provided)
- Employment type and contract details
Headhunting Activity:
- Matches received and actions taken
- Candidates reviewed and hired
- Feedback on match quality
- Interview outcomes and hiring decisions
- Headhunting metrics
Usage Data:
- Login history and activity
- Platform usage patterns
- Communication with our team
- Analytics and reporting access
3.3 Special Categories of Personal Data
Under GDPR, certain data is classified as "special category data" requiring extra protection. We may process the following special category data only when necessary and with your explicit consent:
- Health data: Medical certificates, vaccination records, disability information (Talent Journey only)
- Criminal records data: Police clearance certificates (required by immigration authorities for Talent Journey)
- Racial or ethnic origin: May be inferred from nationality or country of birth (processed only as necessary for immigration purposes on Talent Journey)
We process special category data only when:
- Required by immigration laws and regulations
- You have given explicit consent
- Necessary for legal claims or legal obligations
3.4 Data We Do NOT Intentionally Collect
We do not intentionally collect:
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Genetic data
- Biometric data (beyond photographs required for visas on Talent Journey)
- Data about sexual life or orientation
If such data is inadvertently provided, we will delete it unless it's necessary for legal compliance.
3.5 Children's Data
Talent Journey: We process data of minor children as part of family relocation services, always with parental or guardian consent. Special protections apply.
Hector: We do not target services to individuals under 18. Our platform is for adults seeking employment only.
4. How We Collect Your Data
4.1 Information You Provide Directly
Talent Journey:
- Account registration
- Service requests from you or your employer
- Document uploads through the Platform
- Forms and questionnaires
- Messages to our team
- Feedback and surveys
- Documents you've obtained from third parties (visa decisions, police certificates, diplomas, etc.)
Hector:
- Account registration
- Conversations with Hector AI
- Profile creation and updates
- Job preference settings
- Document uploads (CV, certifications)
- Match responses (accept/decline)
4.2 Information We Receive from Third Parties
Talent Journey:
- Your employer (for company-sponsored relocations): Employment details, salary, contract information
- You directly: You provide us with documents and information you've obtained from various sources, including:
- Visa decisions, permit statuses, and official documents from government authorities
- Police clearance certificates you've obtained from background check providers
- Educational diplomas, transcripts, and certificates from institutions
- Medical certificates and vaccination records from healthcare providers (when required)
- Bank statements and financial documents from your bank
- Employment contracts and references from employers
- Translated documents you've arranged
- Apostilled or legalized documents you've obtained
Important: We receive these documents from you after you've obtained them yourself. We do not collect this information directly from these third parties, except in specific cases where you grant us Power of Attorney (such as for NIF applications).
- Real estate agents and housing providers: When we coordinate housing search on your behalf, we receive property availability information, viewing schedules, and rental market data from real estate agents and housing providers.
- Immigration lawyers (case-by-case with Power of Attorney): In rare cases where specialized legal representation is needed and you grant us Power of Attorney, we may work with immigration lawyers who provide legal advice and document preparation services.
Hector:
- Companies: Job postings (from client companies or sourced through our research)
- Verification services: Credential verification (only if you authorize)
- Talent Journey: If you're hired for an international role and need relocation, your Hector profile transfers to Talent Journey
4.3 Information We Collect Automatically
Both Platforms:
- Platform usage: Pages viewed, features used, time spent, click patterns
- Technical data: IP address, browser type, device type, operating system
- Login data: Login times, session duration, access patterns
- Cookies: See Section 12 for detailed information about cookies
4.4 Information We Generate
Talent Journey:
- Case notes about your relocation progress and our guidance
- Status updates and milestone tracking
- Communication records
- Assessment reports and checklists
Hector:
- AI conversation summaries
- Match compatibility scores
- Candidate assessments
- Headhunting analytics
5. Legal Basis for Processing Your Data
Under GDPR, we must have a legal basis to process your personal data. Here are the legal bases we rely on:
5.1 Contract Performance (Article 6(1)(b) GDPR)
Processing is necessary to provide the services you've contracted for:
Talent Journey:
- Preparing documents for visa and residence permit applications (which you submit)
- Finding accommodation and coordinating with real estate agents
- Assisting with administrative procedures (NIF with POA, NISS online processing, guidance for other procedures)
- Communicating about your case and providing guidance
- Providing Platform access and document management
Hector:
- Matching you with relevant job opportunities
- Facilitating introductions to companies
- Providing AI interview services
- Managing your profile and preferences
If you don't provide this data, we cannot perform our contractual obligations and cannot provide services.
5.2 Legal Obligation (Article 6(1)(c) GDPR)
Processing is necessary to comply with legal obligations:
Talent Journey:
- Processing NIF applications with your Power of Attorney (as authorized by you under Portuguese law)
- Processing NISS registrations online on your behalf
- Retaining financial records (Portuguese tax law - 10 years)
- Responding to lawful requests from authorities
Hector:
- Retaining employment records (if applicable)
- Tax compliance for invoicing companies
- Responding to lawful requests from authorities
5.3 Legitimate Interests (Article 6(1)(f) GDPR)
Processing is necessary for our legitimate business interests:
Both Platforms:
- Service improvement: Analyzing usage to improve features
- Customer support: Maintaining communication records
- Security: Monitoring for fraud and security threats
- Business operations: Managing relationships and operations
- Legal claims: Establishing, exercising, or defending legal claims
Hector Specifically:
- AI improvement: Using anonymized conversation data to improve Hector's matching algorithms
- Quality assurance: Reviewing matches to ensure quality
We balance our legitimate interests against your rights and freedoms. You have the right to object to processing based on legitimate interests.
5.4 Consent (Article 6(1)(a) GDPR)
For certain processing activities, we obtain your explicit consent:
Both Platforms:
- Marketing communications (if you opt in)
- Sharing success stories or testimonials
- Optional services beyond core offerings
- Cookies and tracking (where required)
Talent Journey:
- Processing special category data (health information, criminal records)
- Granting us Power of Attorney for NIF applications
- Authorizing us to process NISS registration on your behalf
Hector:
- Transfer of profile data to Talent Journey for relocation (if hired internationally)
You can withdraw consent at any time without affecting services based on other legal grounds. Withdrawal doesn't affect processing that occurred before withdrawal.
5.5 Special Category Data (Article 9 GDPR)
For special category data (health, criminal records on Talent Journey), we rely on:
- Explicit consent (Article 9(2)(a))
- Legal obligations in employment/social security law (Article 9(2)(b))
- Legal claims (Article 9(2)(f))
6. How We Use Your Personal Data
6.1 Talent Journey - Service Delivery
Immigration Services:
- Prepare visa application documents for you to submit to embassies/consulates
- Prepare residence permit application documents for you to submit to AIMA
- Guide you through work permit processes
- Prepare you for appointments with AIMA, embassies, and consulates
- Coordinate appointment scheduling and provide preparation guidance
- Help you track application status and next steps
- Provide checklists and guidance on required documents
Administrative Services:
- NIF (Tax ID): Process your NIF application with your Power of Attorney
- NISS (Social Security Number): Process your NISS registration online on your behalf
- Guide you through tax authority registration processes
- Support you with social security-related procedures
- Guide you through address registration with local authorities
- Prepare documentation for CRUE applications for EU citizens (which you submit)
Housing Services:
- Understand your housing requirements and preferences
- Coordinate with real estate agents on your behalf
- Share your requirements and budget with property agents
- Arrange property viewings and accompaniment
- Guide you through rental contract negotiations
- Provide advice on lease terms and tenant rights
Settle-In Services:
- Guide you through bank account opening procedures (you open the account yourself)
- Support you with health center enrollment (you enroll yourself with our guidance)
- Provide orientation about living in Portugal
- Connect you with local services and resources
Platform Services:
- Provide access to your account
- Display case status, checklists, and next steps
- Enable secure document upload and management
- Facilitate communication with our guidance team
- Send notifications about deadlines and required actions
6.2 Hector - Job Matching Services
AI Matching:
- Conduct conversational interviews to understand your profile
- Assess skills, experience, and career goals
- Match you with relevant job opportunities
- Provide compatibility scoring and recommendations
Introduction Services:
- Facilitate introductions to hiring companies
- Share your profile with matched companies (with your consent)
- Coordinate interview processes and feedback
Platform Services:
- Manage your job seeker profile
- Display match notifications and opportunities
- Enable communication with companies
- Provide job search tools and resources
AI Improvement:
- Analyze conversation patterns to improve Hector AI
- Refine matching algorithms based on outcomes
- Enhance question quality and candidate assessment
- Improve user experience and matching accuracy
6.3 Cross-Platform Integration
If you use both platforms:
- If hired through Hector for international role requiring relocation, your data transfers to Talent Journey (with your consent)
- Unified account management (future feature)
- Coordinated service delivery between headhunting and relocation
- Seamless transition from job placement to relocation support
6.4 Communication and Support
Both Platforms:
- Respond to inquiries and requests
- Provide customer support and guidance
- Send service updates and notifications
- Share important deadline reminders
- Send appointment confirmations
- Alert you to required actions and next steps
6.5 Legal and Compliance
Both Platforms:
- Comply with applicable laws
- Fulfill tax and accounting obligations
- Respond to lawful requests from authorities
- Maintain records for legal purposes
- Establish, exercise, or defend legal claims
6.6 Business Operations
Both Platforms:
- Manage client relationships
- Process payments and invoices
- Generate reports and statistics (anonymized)
- Improve services based on feedback
- Train our staff and service providers
- Manage service provider relationships
6.7 Security and Fraud Prevention
Both Platforms:
- Monitor for unauthorized access
- Protect against security threats
- Investigate suspicious activity
6.8 Marketing (Only With Your Consent)
Both Platforms:
- Send information about new services (if you opt in)
- Share relevant updates about immigration policies or job market trends
- Send newsletters (if you subscribe)
You can opt out of marketing at any time by clicking "unsubscribe" in emails.
6.9 Analytics and Improvement
Both Platforms:
- Analyze Platform usage to improve features
- Understand user behavior and preferences
- Identify technical issues and bugs
- Optimize our processes and workflows
- Measure service satisfaction
We use anonymized or pseudonymized data wherever possible for analytics.
7. Who We Share Your Data With
We share your personal data only when necessary to provide services or comply with legal obligations. We never sell your personal data.
7.1 Government Authorities
Talent Journey:
We share data with Portuguese authorities in limited circumstances:
Direct Data Sharing (With Your Authorization):
- Autoridade Tributária (Tax Authority): We submit NIF applications with your Power of Attorney
- Segurança Social: We process NISS registration online on your behalf through the official portal
You Submit Directly (We Prepare Documents and Provide Guidance):
- AIMA (Portuguese Immigration Agency): You submit visa and residence permit applications yourself; we prepare documents and guide you through the process
- Embassies and Consulates: You submit visa applications yourself; we prepare documents and guide you
- VFS Global and Visa Application Centers: You submit applications yourself; we provide preparation support
- City Halls and Local Authorities: You register your address and submit CRUE applications yourself; we guide you through the process
- SNS (National Health Service) / Health Centers: You enroll yourself; we provide guidance and location information
- Portuguese Police (PSP/GNR): You obtain police clearances yourself when required
Legal Basis:
- For NIF and NISS: Legal obligation (Article 6(1)(c) GDPR) and your Power of Attorney/authorization
- For guidance and document preparation: Contract performance (Article 6(1)(b) GDPR)
Hector:
- Tax authorities (for invoicing companies if applicable)
- Law enforcement (if legally required by court order or legal obligation)
7.2 Employers and Sponsoring Organizations
Talent Journey:
For Company-Sponsored (B2B) Services:
When your employer contracts with us to provide relocation services for you, we operate a shared transparency model:
What All Parties See (Company, You, and Talent Journey):
- Case status updates (milestone progress, stage of process)
- Service completion confirmations
- Timeline information and deadlines
- Required actions and next steps
- Document checklists and submission status
- Invoice-related information for services the company is paying for
- Service delivery progress and outcomes
Important: For services your company pays for, information is shared transparently between you, your company, and us through the Platform. This ensures everyone is aligned on progress, requirements, and timelines.
For Self-Paid (B2C) Services:
If you pay for additional services yourself that your company does NOT pay for (such as family relocation when company only covers you individually):
Complete Separation:
- These services are handled in a completely separate case/account
- Your company has NO visibility into self-paid services
- Only you and Talent Journey see this information
- Separate invoicing, separate dashboard, separate communications
- Example: If your company pays for your individual relocation but NOT for your family, family relocation is handled separately as a B2C service with complete privacy from your employer.
Hector:
If your profile is matched with a company:
What Companies See (Only When You Accept Match):
- Your name and contact information
- Skills, experience, and qualifications
- Education and certifications
- CV/Resume
- Language proficiencies
- Job preferences and availability
- High-level conversation summaries (not full transcripts)
What Companies DON'T See:
- Your current employer name (we protect your confidentiality)
- Full conversation transcripts with Hector AI
- Profiles of talents not matched to their specific jobs
- Talents cannot be searched or browsed by companies
7.3 Service Providers and Partners
We work with trusted third-party service providers who assist in delivering services:
Talent Journey Service Providers:
Immigration and Legal Services:
- Immigration lawyers and consultants (only when hired case-by-case with your Power of Attorney)
- Legal advisors specializing in Portuguese immigration law (when needed)
- Document preparation specialists (when additional support is required)
Housing and Accommodation:
- Real estate agents and agencies (we coordinate with them on your behalf)
- Landlords and property managers (through real estate agents typically)
- Property viewing coordinators
- Rental platforms and listing services
Technology Providers:
- Cloud hosting providers (servers and data storage within EU)
- Email service providers
- Communication platforms
- Data backup services
- Security and encryption services
Professional Services (You Arrange, We Guide):
- Translation services (you arrange translations; we provide guidance on requirements)
- Apostille and legalization services (you obtain apostilles; we guide you)
- Background check providers (you obtain police certificates; we guide you)
- Banks (you open accounts; we guide you through the process)
- Healthcare providers (you enroll with health centers; we provide guidance)
- Educational institutions (for credential verification you arrange)
- Couriers and shipping (for your document submissions)
- Insurance providers (if you choose to purchase insurance)
Hector Service Providers:
Technology Providers:
- Cloud hosting and AI infrastructure providers (within EU)
- Communication services
- Analytics tools and platforms
Payment Processing:
- Stripe (payment processing, subscription management, Customer Portal)
Verification Services:
- Credential verification providers (only with your authorization)
- Background check services (only with your authorization)
Data Processing Agreements: All service providers with whom we share data are bound by contracts that:
- Limit data use to our instructions only
- Implement appropriate security measures
- Comply with GDPR requirements
- Prohibit unauthorized data use
- Return or delete data when services end
Legal Basis: Contract performance and legitimate interests.
7.4 Cross-Platform Data Sharing
Hector to Talent Journey:
If you're hired through Hector for an international position requiring relocation:
- Your Hector profile data transfers to Talent Journey platform
- Transfer occurs only with your explicit consent
- Transfer is necessary to provide relocation services
- You must accept Talent Journey Terms & Conditions
- Same data protection standards apply across both platforms
Talent Journey to Hector:
- We do not transfer Talent Journey relocation data to Hector
- These are separate services with separate purposes and user bases
7.5 Business Transfers
If Talent Journey is involved in a merger, acquisition, sale of assets, or bankruptcy, your personal data may be transferred to the successor entity. We will:
- Notify you before the transfer
- Ensure the new entity provides equivalent privacy protections
- Give you the option to delete your data if you don't consent to the transfer
Legal Basis: Legitimate interests (business continuity).
7.6 Legal Requirements and Protection
We may disclose your data when required or permitted by law:
- Legal obligations: Court orders, subpoenas, regulatory requests
- Legal claims: To establish, exercise, or defend legal rights
- Protection of rights: To protect our rights, property, or safety and that of others
- Fraud prevention: To detect, prevent, or address fraud or security issues
- Emergency situations: To protect vital interests of individuals
Legal Basis: Legal obligation and legitimate interests.
7.7 With Your Consent
We may share data with others if you give specific consent:
- Testimonials or case studies (always anonymized or with your explicit permission)
- References for future employers or educational institutions
- Sharing information with family members or representatives you authorize
- Marketing partners (only if you opt in to such communications)
Legal Basis: Consent (which you can withdraw anytime).
7.8 We Do NOT Share Your Data With
- Social media platforms (except for general advertising without personal data)
- Data brokers or list providers
- Marketing companies (unless you opt in)
- Unrelated third parties
- Anyone for purposes unrelated to our services
- Competitors or other relocation/headhunting services
8. International Data Transfers
8.1 Where Your Data is Stored
Your data is primarily stored and processed within the European Union.
8.2 Transfers Outside the EU
In limited circumstances, we may transfer data outside the EU:
Talent Journey:
- To Embassies/Consulates in Your Home Country: When you're applying for a Portuguese visa from outside the EU, you submit your application (which we prepared) to Portuguese embassies or consulates in your home country. This submission is made by you, but the documents we prepared for you contain your personal data. This is required by Portuguese immigration law.
- To Your Home Country for Documents: When you need to obtain documents from your home country (police certificates, educational diplomas, apostilles), you handle these requests yourself, but may need to share information we prepared.
Hector:
- To Companies Outside EU: If you're matched with a company located outside the EU and you accept the match, your profile data is shared with that company in accordance with your consent.
Both Platforms:
- To Service Providers with Servers Outside EU: Some of our technology providers may have servers outside the EU. In such cases, we ensure:
- EU Standard Contractual Clauses (EU SCCs) are in place
- Adequacy decisions by the EU Commission are relied upon (for approved countries like UK, Switzerland)
- Additional safeguards as required by GDPR
8.3 Safeguards for International Transfers
When transferring data outside the EU, we ensure:
Legal Mechanisms:
- EU Standard Contractual Clauses (EU SCCs) with all non-EU processors
- EU adequacy decisions (for approved countries like UK, Switzerland, Canada)
- Binding Corporate Rules (where applicable with large providers)
- Explicit consent (when required for specific transfers)
Technical Safeguards:
- Encryption during transfer (TLS/SSL)
- Secure transmission protocols
- Access controls and authentication
- Data minimization (sending only what's necessary)
8.4 Your Rights Regarding Transfers
You have the right to:
- Be informed about international transfers before they occur
- Object to transfers (though this may limit services available to you)
- Request detailed information about safeguards in place
- Lodge a complaint with supervisory authorities (CNPD)
9. How Long We Keep Your Data
We retain your personal data only as long as necessary for the purposes outlined in this Privacy Policy, and in compliance with legal retention requirements.
9.1 Talent Journey - Retention Periods
| Data Type |
Retention Period |
Purpose |
| Active Cases |
Throughout service delivery |
To provide ongoing relocation services |
| Completed Cases |
2 years after completion |
Customer support, legal claims, quality assurance |
| Financial/Tax Records |
10 years |
Portuguese tax law compliance (mandatory) |
| Legal Claims |
Until resolved + statute of limitations |
Defense or pursuit of legal claims |
| Marketing Consent |
Until withdrawn or 2 years of inactivity |
Marketing communications |
| Anonymized Data |
Indefinitely |
Statistical analysis, service improvement |
9.2 Hector - Retention Periods
| Data Type |
Retention Period |
Purpose |
| Active Profiles |
While account is active |
To provide ongoing job matching services |
| Inactive Profiles |
Indefinitely (marked inactive) |
Allow reactivation when ready |
| After Account Deletion |
90 days grace period |
Allow recovery if accidental |
| Conversation Data |
180 days after last activity |
AI improvement, quality assurance |
| Matched Talent Data |
1 year after match |
Dispute resolution |
| Financial Records (Companies) |
10 years |
Portuguese tax law compliance |
9.3 Exceptions to Retention Periods
We may retain data longer than specified if:
- You request: You ask us to keep your data longer for specific purposes
- Legal requirement: Law requires longer retention (e.g., ongoing tax audit)
- Legal claim: Ongoing or anticipated litigation requires retention
- Regulatory investigation: Active investigation by authorities requires data preservation
9.4 Secure Deletion
When retention periods expire, we securely delete data using industry-standard methods:
- Digital files: Secure deletion and overwriting using industry-standard protocols
- Physical documents: Cross-cut shredding or secure destruction services
- Backups: Overwritten in regular backup rotation cycles
- Third-party systems: Deletion requests sent to all service providers
- Verification: Deletion completion verified through audit logs
10. How We Protect Your Data
We take data security seriously and implement comprehensive technical and organizational measures to protect your personal data.
10.1 Technical Security Measures
Infrastructure:
- We use Google Cloud Platform infrastructure with data centers located within the European Union
- All data is encrypted in transit (TLS/SSL) and at rest (AES-256 encryption)
- Role-Based Access Control (RBAC): Employees can only access data necessary for their specific role
- Multi-factor authentication (MFA) for all administrative access
- Automatic session timeout for inactive accounts
- Regular security updates and vulnerability assessments
Data Protection:
- Regular automated backups (encrypted and stored in geographically separate EU locations)
- Network firewalls and intrusion detection systems
- Real-time security monitoring and alerting
- Protection against common attacks (SQL injection, XSS, CSRF, etc.)
10.2 Organizational Security Measures
Staff and Access Management:
- Need-to-know principle strictly enforced
- Regular data protection training for all employees
- Confidentiality agreements (NDAs) with all staff and contractors
- Background checks for employees with data access
- Immediate access revocation upon termination
Vendor Management:
- Data processing agreements with all service providers
- Regular security assessments of vendors
- All vendors must comply with GDPR requirements
Incident Response:
- Comprehensive data breach response plan
- 72-hour breach notification procedures (GDPR compliant)
- Designated incident response team
10.3 Your Role in Security
You can help keep your data secure:
Account Security:
- Use strong, unique passwords
- Don't share your password with anyone
- Log out on shared devices
- Enable MFA if available
- Report suspicious activity immediately to privacy@talentjourney.tech
Document Security:
- Use our Platform's secure upload feature
- Don't email sensitive documents without encryption
- Verify recipients before sharing information
Phishing Awareness:
- Verify emails claiming to be from us
- Don't click suspicious links
- We will never ask for your password via email
10.4 Limitations
While we implement strong security measures:
- No system is 100% secure
- You share responsibility for your account security
- Internet transmission has inherent risks
Our Commitment: We will notify you promptly of any data breach that poses a risk to your rights and freedoms, as required by GDPR (within 72 hours of becoming aware).
11. Your Data Protection Rights
Under GDPR and Portuguese data protection law, you have comprehensive rights regarding your personal data.
11.1 Right to Be Informed
What it means: You have the right to know how we collect, use, and process your data in clear and transparent language.
How we comply: This Privacy Policy, our Terms & Conditions, and notifications we send you when collecting data.
11.2 Right of Access (Article 15 GDPR)
What it means: You can request a copy of all personal data we hold about you.
What you'll receive:
- Confirmation that we process your data
- Copy of your personal data in commonly used format
- Information about processing purposes and legal basis
- Categories of data processed
- Recipients or categories of recipients of your data
- Retention periods or criteria for determining retention
- Information about your other rights
How to exercise:
Email: privacy@talentjourney.tech with subject "Data Access Request"
Timeline: We respond within 30 days (may extend to 60 days for complex requests).
Cost: First request is free. Additional requests may incur reasonable administrative fees if manifestly unfounded, excessive, or repetitive.
11.3 Right to Rectification (Article 16 GDPR)
What it means: You can correct inaccurate or incomplete personal data.
Examples:
- Update your address or phone number
- Correct misspelled names or birthdates
- Add missing information about your qualifications
- Update changed circumstances (employment, marital status, etc.)
How to exercise:
- Platform: Edit your profile or documents directly through account settings
- Email: privacy@talentjourney.tech with corrections and supporting documentation
Timeline: Corrections made within 30 days of verification.
11.4 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)
What it means: You can request deletion of your personal data in certain circumstances.
When this applies:
- Data no longer necessary for the original purpose
- You withdraw consent (for consent-based processing) and there's no other legal ground
- You object to processing (Article 21) and there are no overriding legitimate grounds
- Data was unlawfully processed
- Legal obligation requires deletion
When we CAN'T delete (legal exceptions):
- Required by law (e.g., tax records must be kept 10 years under Portuguese law)
- Necessary for legal claims (establishment, exercise, or defense)
- Services are still being provided to you
- Public interest or official authority reasons
How to exercise:
Email: privacy@talentjourney.tech with deletion request
Timeline: Response within 30 days (coordination with employer may extend to 60 days).
11.5 Right to Restriction of Processing (Article 18 GDPR)
What it means: You can request that we limit how we use your data (but not delete it) in certain situations.
When this applies:
- You contest data accuracy (restriction until we verify)
- Processing is unlawful but you don't want deletion
- We no longer need the data but you need it for legal claims
- You've objected to processing (restriction until we verify our grounds)
How to exercise:
Email: privacy@talentjourney.tech with restriction request and reason
11.6 Right to Data Portability (Article 20 GDPR)
What it means: You can receive your data in a structured, machine-readable format and transmit it to another service provider.
What's included:
- Data you provided to us directly
- Data processed by automated means
- Data processed based on consent or contract performance
Format: Commonly used, machine-readable, interoperable format (e.g., JSON, CSV, XML).
How to exercise:
Email: privacy@talentjourney.tech specifying desired format
Timeline: Delivery within 30 days (may extend to 60 days for complex requests).
11.7 Right to Object (Article 21 GDPR)
What it means: You can object to certain types of data processing.
Types of Objection:
Processing Based on Legitimate Interests:
- You can object to any processing we perform based on our legitimate interests
- We must stop unless we demonstrate compelling grounds that override your interests
Direct Marketing (Absolute Right):
- You have an absolute right to object to direct marketing at any time
- We must stop ALL marketing upon your objection, no exceptions
- Easy opt-out: Click "unsubscribe" in any marketing email
Profiling:
- You can object to automated decision-making and profiling that produces legal or similarly significant effects
11.8 Rights Related to Automated Decision-Making (Article 22 GDPR)
Talent Journey: We do not use fully automated decision-making for any significant decisions. All important decisions involve human review and judgment.
Hector: Hector AI provides matching recommendations, but:
- All matches are reviewed by humans before introduction (during Beta and beyond)
- Companies make final hiring decisions independently
- You can always request human review of any match decision
- You can challenge match decisions and request explanation
11.9 Right to Withdraw Consent (Article 7(3) GDPR)
What it means: If processing is based on your consent, you can withdraw that consent at any time, easily and free of charge.
Effect of Withdrawal:
- Withdrawal doesn't affect processing that occurred before withdrawal
- Services based on other legal grounds can continue
- Marketing and optional services based solely on consent will stop immediately
How to exercise:
Email: privacy@talentjourney.tech stating which consent you're withdrawing
11.10 Right to Lodge a Complaint
What it means: You can complain to a data protection supervisory authority if you believe we're mishandling your data.
Portuguese Supervisory Authority (CNPD):
Address: Av. D. Carlos I, 134, 1º, 1200-651 Lisboa, Portugal
Phone: +351 213 928 400
Email: geral@cnpd.pt
Website: www.cnpd.pt
We encourage you to contact us first at privacy@talentjourney.tech - most issues can be resolved directly.
No Retaliation: Exercising your right to complain will never negatively affect our services to you.
11.11 How to Exercise Your Rights
Contact Us:
Email: privacy@talentjourney.tech (fastest method)
Include in Your Request:
- Your name and email
- Which platform (Talent Journey/Hector)
- Which right you're exercising
- Any relevant details
Timeline: We respond within 30 days (may extend to 60 days for complex requests).
Free of Charge: Exercising rights is free (unless request is manifestly unfounded or excessive).
12. Cookies Policy
[Note: This section would typically contain details about cookie usage, types of cookies, and cookie management. Refer to your cookie banner and consent tool for specific details.]
13. Children's Privacy
13.1 Age Requirements and Restrictions
Hector Platform:
- Not directed to children: Our service is not directed to, and we do not knowingly collect personal data from, individuals under 18 years of age.
- Adult job seekers only: Hector is designed exclusively for adults seeking employment opportunities.
Talent Journey Platform:
- Family relocation exception: We do process data about minor children only when they are part of family relocation services (parents relocating with children).
13.2 Family Relocation Services (Talent Journey)
When minor children are included in family relocation services:
Parental Consent Required:
- We process children's data only with explicit parental or legal guardian consent
- Parents/guardians must review and accept Terms & Conditions on behalf of minors
- Parents/guardians can exercise all data rights on behalf of children
Limited Data Collection:
- We collect only data necessary for relocation purposes:
- Name, date of birth, nationality
- Passport/ID details (for visa/residence permit applications)
- Educational information (for school enrollment support if applicable)
- Health information (only if required for visas/immigration)
- No marketing to children
- No behavioral profiling
13.3 If We Discover Underage Use
Hector:
If we discover we've collected data from an individual under 18:
- Immediate cessation: We immediately cease all processing
- Prompt deletion: We delete the data within 72 hours
- Account suspension: The account is suspended pending verification
13.4 Parental Rights
Parents and legal guardians have all data protection rights on behalf of their minor children under 18, including access, rectification, erasure, restriction, objection, and portability.
How to Exercise Parental Rights:
Email: privacy@talentjourney.tech
Subject: "Parental Rights Request - [Child's Name]"
14. Updates to This Privacy Policy
14.1 When We Update
We may update this Privacy Policy from time to time due to:
- Changes in our services, features, or business operations
- Changes in applicable data protection laws or regulations
- Improvements to our data practices or security measures
- Technology changes
We review this Privacy Policy at least annually.
14.2 How We Notify You
Material Changes (affecting your rights or how we use data):
- Updated Privacy Policy posted on Platform
- Email notification to active users
- Notice in your account dashboard
- At least 30 days advance notice before material changes take effect
Non-Material Changes (clarifications, formatting):
- Updated Privacy Policy posted on Platform
- "Last Updated" date updated at top
- Changes take effect when posted
15. Contact and Legal Information
Contact Us About Privacy:
Email: privacy@talentjourney.tech
Address: RUA DA BALDRUFA, 239 2º FRAÇÃO T, Ponte de Lima, Portugal
NIPC: 518824799
Lodge a Complaint:
Portuguese Data Protection Authority (CNPD) at geral@cnpd.pt or www.cnpd.pt
Governing Law: Portuguese law (Law 58/2019 and GDPR). This policy is in English; if translated, English version prevails.
Related Documents: See our Terms & Conditions for service details.
Thank you for trusting Talent Journey with your personal data. We are committed to protecting your privacy, respecting your rights, and handling your data responsibly and transparently.
Effective Date: January 20, 2026
Last Updated: January 20, 2026
Version: 2.0