Privacy Policy
Version 2026-06-19-v3-es. Last updated 19 June 2026.
This Privacy Policy explains how we collect, use, share and protect personal data when you use the T4G Impact Roster platform (the “Service”). It is issued in accordance with Articles 13 and 14 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), and, where it applies to UK-resident candidates, the UK GDPR and the Data Protection Act 2018.
1. Who we are
The controller of your personal data is NEMRAC Consulting S.L., a Spanish limited company (Sociedad Limitada), Spain Tax Identification Number B44624740, registered office at [registered office — to be confirmed], trading as T4G Impact. NEMRAC Consulting S.L. is the sole controller of the personal data processed through the Service. There is no joint-controllership arrangement.
Because we are established in Spain, our lead supervisory authority under Article 56 GDPR is the Agencia Española de Protección de Datos (AEPD) (www.aepd.es).
We have appointed a Data Protection Officer, who can be reached at dpo@t4glab.com. General privacy enquiries should be sent to privacy@t4glab.com. The DPO designation reflects our assessment under Art. 37(1)(b)–(c) GDPR and Art. 34 LOPDGDD: regular and systematic processing of candidate personal data on a non-negligible scale, including special-category data inside CVs (Art. 9 GDPR). The DPO operates independently and reports directly to senior management as required by Art. 38 GDPR.
The Service is targeted at candidates resident in the European Union and the European Economic Area. We do not market the Service to, or systematically monitor the behaviour of, individuals located in the United Kingdom; accordingly no UK Article 27 representative is appointed. UK-resident candidates who nonetheless choose to use the Service remain protected by the GDPR through this Spanish controller and may, in addition to complaining to the AEPD, raise concerns with the United Kingdom’s Information Commissioner’s Office (ICO) (ico.org.uk); the ICO is named here as a courtesy complaint route only, and is not a co-lead supervisory authority for the Service.
2. What data we collect
- Account data — name, email address, authentication metadata (including identifiers from Sign-in with Google where you choose that route), password hashes managed by Amazon Cognito.
- Profile data — information you voluntarily provide such as headline, location, availability, languages and links.
- CV file — the curriculum vitae document you upload. A CV very often contains data which is special-category data under Article 9 GDPR (for example health information, trade-union membership, religious or philosophical beliefs, ethnic origin, political opinions or data revealing sexual orientation). We therefore treat the CV with the safeguards that apply to Article 9 data.
- AI-extracted enrichment — structured fields extracted from your CV by our parser (described in section 8). This enrichment record is visible to platform administrators only and is tied to the source CV.
- Consent log — an immutable record of the consents you have given or withdrawn, with timestamp and policy version.
- Operational logs — IP address, user-agent, request paths and administrative-action audit logs, used for security and abuse prevention.
3. Why we process it and on what lawful basis
| Purpose | Categories of data | Lawful basis |
|---|---|---|
| Creating and operating your account | Account data | Performance of a contract — Art. 6(1)(b) GDPR |
| Letting you volunteer your profile to be shortlisted for opportunities | Profile data | Consent — Art. 6(1)(a) GDPR |
| Storing the CV you upload | CV file (may contain Art. 9 data) | Performance of a contract — Art. 6(1)(b); and, for any Art. 9 data inside the CV, your explicit consent — Art. 9(2)(a) GDPR |
| Automated parsing of the CV into structured fields for admin review | CV file and AI-extracted enrichment | Legitimate interests — Art. 6(1)(f) GDPR (building a usable candidate roster); and, where the CV contains Art. 9 data, your explicit consent — Art. 9(2)(a). A Legitimate Interests Assessment summary is below. |
| Marketing emails about opportunities | Account data, marketing opt-in | Consent — Art. 6(1)(a) GDPR, and Article 21 of the Spanish Law 34/2002 (LSSI) / the ePrivacy Directive (PECR in the UK) |
| Security, abuse detection, integrity of the Service | Operational logs | Legitimate interests — Art. 6(1)(f) GDPR |
| Complying with legal obligations | All of the above as required | Legal obligation — Art. 6(1)(c) GDPR |
Legitimate Interests Assessment (summary).Our interest is in operating a usable candidate roster for talent-for-good opportunities. The processing is necessary because manual administrative review of free-text CVs at scale is not feasible. We balance this interest against your rights by: (i) collecting Art. 9 data only under your explicit consent; (ii) restricting enrichment access to admins; (iii) keeping you in control via the in-product privacy panel; and (iv) providing a clear right to object under Art. 21. A candidate’s objection to AI parsing is honoured without detriment to their account. The full Legitimate Interests Assessment is maintained by the DPO and is available on request at dpo@t4glab.comin line with the AEPD’s guidance on Art. 6(1)(f).
4. Who we share data with
We do not sell personal data. We rely on a small set of carefully selected sub-processors:
- Amazon Web Services EMEA SARL — cloud hosting (Cognito, DynamoDB, S3). All personal data is processed in the Ireland (
eu-west-1) region, inside the European Economic Area. We will give 30 days’ notice via email and an on-screen banner before any change of region. - Anthropic PBC (United States) — provider of the Claude Sonnet 4.6 model used to parse CV content under our instructions.
- Google LLC — Sign-in with Google (OAuth), where you choose to authenticate with your Google account.
The current list, with addresses and transfer mechanisms, is published at /sub-processors. We may also disclose personal data where required by law, court order or to defend our legal rights.
5. International transfers
Our primary processing region is the European Union. Some sub-processors operate outside the EEA. Where this is the case we rely on the following transfer mechanisms:
- For transfers to Anthropic PBCin the United States: the EU–US Data Privacy Framework (DPF) where Anthropic is self-certified; otherwise the European Commission’s Standard Contractual Clauses (SCCs), supported by a Transfer Impact Assessment.
- For transfers of personal data originating from the United Kingdom: in addition to the SCCs we use the UK Information Commissioner’s International Data Transfer Addendum (IDTA), or the UK Addendum to the EU SCCs.
A copy of the applicable safeguards is available on request from dpo@t4glab.com.
6. Retention
Retention periods follow the AEPD’s guidance on candidate data and the principle of storage limitation (Art. 5(1)(e) GDPR). We distinguish three CV states because the AEPD expects unsuccessful applicants’ CVs to be retained for no longer than one year unless a fresh consent is obtained.
| Asset | Retention | Lawful basis to keep |
|---|---|---|
| CV file (S3) — candidate marked as available / active | Up to 12 months from upload; we ask you to re-confirm storage consent at the 11-month mark | Art. 6(1)(b); Art. 9(2)(a) for any special-category content |
| CV file (S3) — candidate not selected for an opportunity | Deleted within 12 months of the rejection decision unless you re-consent in writing to longer retention (per AEPD guidance on the principle of limitation of the period of conservation, Art. 5(1)(e) GDPR + Art. 32 LOPDGDD) | Same as above; conservation beyond 12 months requires fresh consent |
| CV file (S3) — candidate withdrawn / restricted | Deleted on next nightly job; never beyond 30 days from withdrawal | Art. 17 / Art. 18 GDPR |
| CandidateEnrichment row | Tied to the CV — deleted with the CV | Tied to the CV file’s basis |
| CandidateProfile (no CV) | 24 months from last sign-in, then delete or anonymise within 30 days | Art. 6(1)(b) |
| ConsentEvent log | 6 years from the event | Art. 17(3)(e) — retention necessary for the establishment, exercise or defence of legal claims and to evidence consent / withdrawal under Art. 7(1) GDPR. Survives erasure of the underlying profile. |
| CvAccessLog (admin review log) | 6 months minimum, in line with EU AI Act Art. 26(6) | Art. 6(1)(c); EU AI Act deployer obligation |
| Marketing opt-in | While you remain opted in; deleted within 30 days of withdrawal | Art. 6(1)(a) |
Deletion is executed by a nightly scheduled job that scans the relevant tables for objects past their retention horizon and removes them, with the operation itself recorded in an internal audit log. Where erasure under Art. 17 is requested, the operation is run immediately rather than at the next nightly window.
7. Your rights
Under Articles 15 to 22 GDPR (and the equivalent provisions of the UK GDPR for UK-resident candidates) you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- restrict our processing (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing carried out on the basis of legitimate interests, including the AI parsing of your CV (Art. 21); and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22) — see section 8.
You may also withdraw any consent at any time, without affecting the lawfulness of processing before withdrawal.
We will respond to a rights request within one month of receipt, as required by Art. 12(3) GDPR. The simplest way to exercise these rights is the in-product privacy panel at /account/privacy; you can also email privacy@t4glab.com.
Right to lodge a complaint. You have the right to complain to a supervisory authority. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD) (www.aepd.es). UK-resident candidates may, in addition or instead, complain to the UK Information Commissioner’s Office (ICO) (ico.org.uk).
8. Automated processing and profiling
When you upload a CV, we pass the text of that CV to a large language-model service operated by Anthropic PBC (model: Claude Sonnet 4.6). The model extracts structured fields such as job titles, employers, dates, skills, languages, education and a short free-text summary. The output (the enrichment record) is stored alongside the CV and is visible only to platform administrators.
The parser is a decision-support tool. It does not autonomously accept or reject candidates, does not score you, and is not used to make any solely-automated decision that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR. A human administrator reviews every shortlist and every outbound introduction to a partner organisation; that administrator’s actions are recorded in an audit log.
We consider this use case to fall within the high-risk category under Annex III, point 4 of Regulation (EU) 2024/1689 (the EU AI Act), because it is used in the context of recruitment-related activities. We comply with the corresponding deployer obligations — see our GDPR & AI Act Statement for details.
9. Consequences of refusing
Providing core account data is necessary to use the Service: if you do not provide it we cannot create an account for you. Uploading a CV is optional; you can maintain a profile without one, though admins will have less context when considering you for opportunities. You may refuse consent to the AI parsing of your CV and your account will continue to function normally — your CV will simply be stored without enrichment. If you refuse the specific Article 9 consent at upload, we will not store a CV that we have reason to believe contains special-category data.
10. Source of data
All personal data we hold about you is collected directly from you, either at sign-up, through the profile and CV-upload flows, or through your continued use of the Service.
11. Children
The Service is intended for adults aged 18 or over. We do not knowingly collect personal data from anyone under 18. If we become aware that we hold data relating to a person under 18 we will delete it. We rely on the age you declare at sign-up; we accept a reasonable-belief defence where a user has misrepresented their age.
12. Changes to this Policy
We may update this Policy from time to time. Where the change is material we will notify you by email and display an in-product banner before the change takes effect. The current version is 2026-06-19-v3-es.
13. Contact
Privacy enquiries: privacy@t4glab.com.
Data Protection Officer: dpo@t4glab.com.