GDPR & AI Act Statement
Version 2026-06-19-v3-es. Last updated 19 June 2026.
This statement sets out, in plain language, how T4G Impact Roster complies with the EU General Data Protection Regulation (GDPR), the Spanish Organic Law 3/2018 (LOPDGDD), the EU AI Act (Regulation (EU) 2024/1689) and the UK GDPR. The Service is operated by NEMRAC Consulting S.L., Spain Tax Identification Number B44624740, registered office at [registered office — to be confirmed], trading as T4G Impact, as sole controller. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD).
1. The lawful bases we rely on
For each activity we have identified a specific lawful basis:
- Running your account — performance of a contract (Art. 6(1)(b) GDPR).
- Letting you appear on the roster — your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
- Storing the CV you upload — performance of a contract for the file itself, plus your explicit consent under Art. 9(2)(a) GDPR for any special-category data the CV may contain.
- Parsing your CV with an AI model — our legitimate interest in operating a usable roster (Art. 6(1)(f) GDPR), plus your explicit Art. 9(2)(a) consent for any special-category data.
- Sending you marketing — your consent (Art. 6(1)(a) GDPR), with a one-click unsubscribe link in every message.
- Security and abuse prevention — our legitimate interest in keeping the Service safe (Art. 6(1)(f) GDPR).
- Meeting legal obligations — Art. 6(1)(c) GDPR.
2. Specific Art. 9 consent at upload
When you upload a CV we present a separate, granular, opt-in consent for the processing of any special-category data the CV may contain (Article 9 GDPR). This consent is:
- Granular — it is distinct from your account consent and from any marketing consent;
- Refusable — you may decline it without losing access to the Service; we will not store a CV that we have reason to believe contains special-category data if you have refused; and
- Withdrawable — you can withdraw it at any time from
/account/privacy, which triggers deletion of the CV and its associated enrichment record.
3. Right to object to AI parsing (Art. 21)
You have an unconditional right to object to the AI parsing of your CV, because that processing relies on legitimate interests under Art. 6(1)(f) GDPR. The in-product mechanism for this is the /account/privacypanel: toggling off “Allow AI parsing of my CV” immediately stops further parsing and triggers deletion of any existing enrichment record. Your CV itself remains stored, but unenriched, until you ask us to delete it. We do not penalise candidates who exercise this right.
4. Your rights and how to use them
- Access (Art. 15) — request a copy of your data via
/account/privacyor by emailing privacy@t4glab.com. - Rectification (Art. 16) — edit profile fields inline, or email us for fields that are not directly editable.
- Erasure (Art. 17)— “Delete my account” in
/account/privacyerases your profile, CV and enrichment record on the deletion schedule in our Privacy Policy. - Restriction (Art. 18) — email privacy@t4glab.com.
- Portability (Art. 20) —
/account/privacyoffers a machine-readable export. - Object (Art. 21) — see section 3 above.
- Withdraw consent — toggle in
/account/privacyor email us.
Complaint route. Your primary complaint route is the Agencia Española de Protección de Datos (AEPD) (www.aepd.es), our lead supervisory authority. If you are resident in the United Kingdom you may, additionally or alternatively, complain to the UK Information Commissioner’s Office (ICO) (ico.org.uk).
5. International transfers
Most processing happens inside the European Union. Where data has to leave the EEA we use lawful transfer mechanisms, in plain English:
- EU–US Data Privacy Framework (DPF) — a European Commission decision that recognises certain US companies as offering an adequate level of protection. We rely on it for transfers to Anthropic PBC where Anthropic is self-certified under the DPF.
- Standard Contractual Clauses (SCCs) — a set of contractual terms approved by the European Commission. We rely on them as a fallback whenever the DPF does not apply.
- UK International Data Transfer Addendum (IDTA) — the UK equivalent. We use it (or the UK Addendum to the EU SCCs) for personal data originating from the United Kingdom.
- Transfer Impact Assessment (TIA) — for each non-DPF transfer we review the laws and practice of the destination country and any additional safeguards we need to put in place.
6. Automated decision-making
We do not take decisions about you that are based solely on automated processing and that produce legal or similarly significant effects on you. The AI parser is a decision-support tool: a human administrator reviews every shortlist and every introduction to a partner organisation, and every administrative action is recorded in an audit log.
7. EU AI Act
We treat the parser as a high-risk AI system under Annex III, point 4 of Regulation (EU) 2024/1689 because it operates in the context of recruitment-related activities. As deployer we comply with the obligations that begin to apply from 2 August 2026, including:
- operating the parser strictly according to its instructions;
- monitoring its outputs and reporting serious incidents;
- retaining system logs for at least six months;
- telling you, in this statement and in the upload flow, that an AI system is being used; and
- conducting a Fundamental Rights Impact Assessment (FRIA) alongside our GDPR Data Protection Impact Assessment, and reviewing both at least annually.
8. Data Protection Impact Assessment (DPIA) and FRIA — published summary
We have completed a Data Protection Impact Assessment under Art. 35 GDPR and a Fundamental Rights Impact Assessment under Art. 27 of the EU AI Act. The AEPD’s position is that processing in the recruitment context with AI tooling is high-risk; we therefore publish a summary here rather than provide it only on request.
Triggers identified
- Systematic processing of CVs — documents that, in practice, frequently contain Art. 9 GDPR special-category data.
- Use of a large language model (Claude Sonnet 4.6) to extract structured fields from those CVs, classified as high-risk under Annex III, point 4 of the EU AI Act.
- Decision-support for admins selecting candidates for project opportunities — the human reviewer is informed by the AI extraction.
- International transfer of CV contents to a US sub-processor (Anthropic PBC).
Key mitigations in place
- Explicit Art. 9(2)(a) consent at the point of CV upload, granular and separate from account consents, and the right to refuse without losing access to the Service.
- No solely-automated decision-makingunder Art. 22 GDPR — every shortlist and every external introduction is reviewed by a named human administrator, whose action is recorded in
CvAccessLog. - System-prompt guardrails in the parser that instruct the model to omit race, religion, health, sexual orientation, union or political-opinion content from the extracted enrichment, even where present in the CV.
- Immutable ConsentEvent log proving Art. 7(1) consent and Art. 17(3)(e) retention.
- Art. 18 restriction is operationally enforced: restricted profiles are excluded from matching and from any enrichment reruns.
- Transfer Impact Assessmentcovering the Anthropic transfer, on top of the EU–US Data Privacy Framework / SCC basis.
- Right to object under Art. 21 honoured in real time via the in-product privacy panel; objection deletes any existing enrichment within seconds.
Residual risks
After mitigations the residual risk is assessed as low to moderate, principally from (i) a candidate unintentionally including Art. 9 data despite the upload-time prompt, and (ii) downstream misuse of extracted fields by an administrator. Both are mitigated by audit logging, admin training, and the right to object. The DPIA and FRIA are reviewed at least annually, and any time we add a new sub-processor or change a purpose. The full assessments are held by the DPO and available on request to dpo@t4glab.com.
A Register of Processing Activities (ROPA) under Art. 30 GDPR is published at /ropa and lists every category of data, purpose, lawful basis, retention period and recipient.
9. Security
- All traffic to and from the Service is protected with TLS.
- CVs and enrichment records are stored encrypted at rest with AWS KMS.
- Database access is owner-scoped at the row level: a candidate can only see their own data.
- Administrative functions are gated by an ADMIN Cognito group and protected by multi-factor authentication.
- Every administrative action is recorded in an admin-action audit log retained for at least six months.
10. Breach notification
If we suffer a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the AEPD as our lead supervisory authority within 72 hours of becoming aware of it, as required by Art. 33 GDPR. Where UK-resident data subjects are affected and notification is required under the UK GDPR, we will also notify the ICO. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly under Art. 34 GDPR.
11. Children
The Service is intended only for adults aged 18 or over. We do not knowingly process personal data of children. If we discover that we hold data relating to a child we will delete it.
12. Contact
Data Protection Officer: dpo@t4glab.com.
This statement was drafted with input from independent data-protection counsel. It will be reviewed at least annually.