Back to home

Legal

Privacy Policy

Last updated: 5 July 2026

1. Who we are and the scope of this policy

Talara is a recruiting-software product operated by TALARA DATA RESEARCH SRL, a company incorporated in Romania (Trade Register No. J2026042613000; sole registration code (CUI) 55106433). Romania is an EU member state subject to Regulation (EU) 2016/679 (the General Data Protection Regulation, GDPR) and Law No. 190/2018.

This policy covers both:

  • the Talara website (talara.app), including the demo-request form; and
  • the Talara application (the recruiting platform and its AI assistant, Tally).

Our roles depend on the data:

  • For website visitors and demo requests, Talara is the data controller.
  • For personal data processed inside the application on behalf of a customer (for example, candidate data entered by a hiring company), Talara is a data processor and the customer is the controller. That processing is governed by our Data Processing Agreement (DPA) with the customer.
  • For a customer user's own connected-account data (Google, Microsoft, Slack, and Zoom tokens and the actions taken with them), Talara acts on the user's behalf as described in Section 5.

2. Data we collect

Website and demo requests: first and last name, work email, and company name; and, with your consent, anonymised analytics (browser, device, and approximate location derived from IP address).

Application account data: name, work email, role, and authentication data for users of a customer's workspace.

Candidate and recruiting data (processed for customers): candidate names, contact details, CVs and resumes, application answers, interview notes, scorecards, messages, and pipeline activity, as entered or uploaded by the customer or captured through the product's features.

Connected-account data: OAuth tokens and the specific data described in Section 5 when a user connects Google, Microsoft 365, Slack, or Zoom.

We do not knowingly collect data from anyone under 18. The service is for professional use only.

3. Why we process it and our legal bases

  • Demo requests and product updates: your consent, given via the form.
  • Providing the application to customers: performance of the contract with the customer, and the customer's instructions and legitimate interest (as processor).
  • Product development and analytics: our legitimate interest.
  • Security, fraud prevention, and legal compliance: our legitimate interest and legal obligations.

You may withdraw consent at any time (Section 11).

4. Artificial intelligence (Tally) processing

Talara uses AI to power features such as job-description generation, candidate insights and summaries, interview-transcript analysis, and the Tally assistant. To do this, we send the relevant recruiting content to our AI subprocessors (see Section 6). Our AI providers process this data only to return results to Talara and do not use it to train their models. We do not use AI to make solely automated decisions that produce legal or similarly significant effects on candidates without human involvement.

5. Connected accounts (Google, Microsoft, Slack, Zoom)

Connecting an account is optional and initiated by the user. We request the minimum scopes needed and store OAuth tokens encrypted at rest. You can disconnect at any time in Talara (Settings, then Integrations) or revoke access from the provider; revoking deletes the stored tokens.

5.1 Google (Gmail and Google Calendar)

Scopes requested: gmail.send, calendar.events, calendar.freebusy, plus basic profile (openid, userinfo.email, userinfo.profile).

  • Gmail (send only): Talara sends recruiting emails from your connected mailbox on your behalf. Talara does not read, search, or store your inbox (we do not request read access).
  • Google Calendar: reads your availability (free/busy) and creates, updates, or cancels interview events you schedule through Talara.
  • Sharing: We do not sell Google user data, do not share it with third parties, do not use it for advertising, and do not use it to train generalized AI or ML models. It is not read by humans except for security, to comply with law, or with your consent.
  • Limited Use: Talara's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5.2 Microsoft 365 (Outlook and Teams)

Scopes requested: Mail.Send, Calendars.ReadWrite, OnlineMeetings.ReadWrite, User.Read, offline_access.

  • Outlook mail (send only): Talara does not read your mailbox.
  • Outlook calendar: read availability and create, update, or cancel interview events.
  • Microsoft Teams: create Teams meeting links for interviews you schedule.
  • Profile: your name and email to identify the connected account.

Talara's use of Microsoft data complies with the Microsoft APIs Terms of Use and Microsoft's data-handling requirements. Data is used only to provide the features above and is not sold or shared for advertising.

5.3 Slack

Scopes requested: chat:write, im:read, im:history, im:write, app_mentions:read, channels:read, team:read, users:read, users:read.email, commands.

Used to deliver notifications and to let you interact with the Tally assistant in Slack. Talara reads the direct messages you send to Tally and messages that @-mention Tally (to respond to them), and reads basic workspace and user identity (name, email, workspace). Talara does not read your general channel history and does not use Slack data for advertising.

5.4 Zoom

Scopes requested: meeting:write (and basic profile).

Used to create and manage Zoom meetings for interviews you schedule, on your behalf. Talara's use of Zoom data complies with Zoom's Marketplace and API terms; we do not sell Zoom data or use it for advertising. You can remove Talara from your Zoom account at any time via the Zoom App Marketplace.

6. Who we share data with (subprocessors)

We use vetted subprocessors under GDPR-compliant data processing agreements. Each is bound to appropriate confidentiality and security obligations and may only process data on our instructions. Our current subprocessors, their purpose, and location are listed at talara.app/subprocessors. We update this list as our vendors change and, per our DPA, notify customers of new subprocessors in advance so they may object. We do not sell personal data, and we do not share it with third parties for their own marketing.

7. International transfers

Some subprocessors process data in the United States. Transfers are covered by the EU-US Data Privacy Framework where the vendor is certified, and otherwise by Standard Contractual Clauses (GDPR Article 46) plus supplementary measures.

8. How long we keep data

  • Demo-request data: until you ask us to delete it or the purpose ends; deleted within 30 days of a request.
  • Customer and candidate data: for the duration of the customer's subscription and per the customer's configured retention policies and our DPA; deleted or returned on termination.
  • Connected-account tokens: until you disconnect or revoke access, then deleted.
  • Backups: purged on a rolling schedule.

9. Security

We protect data with encryption in transit (TLS) and at rest, including authenticated field-level encryption for personal data (email, phone, name) and encrypted storage of OAuth and secret tokens. Access is tenant-isolated at the database layer, role-restricted, and audited. We follow the principle of least privilege for scopes and internal access.

10. Cookies

We use cookies and similar technologies on this website. You can manage your cookie preferences through the cookie banner displayed on your first visit, or by adjusting your browser settings.

Strictly necessary cookies are set automatically and cannot be disabled. They are required for the website to function and do not store any personally identifiable information.

Optional cookies (used for analytics and CRM) are only set with your explicit consent. You may withdraw consent at any time by clearing your browser cookies and revisiting this website.

11. Your rights under GDPR

You have the rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Where Talara acts as a processor for a customer, we will refer your request to that customer (the controller) and assist them in responding.

To exercise your rights, email privacy@talara.app or use the contact form. We respond within 30 days.

12. Supervisory authority

You may lodge a complaint with the Romanian data protection supervisory authority:

Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucuresti 010336, Romania
www.dataprotection.ro

13. Contact

TALARA DATA RESEARCH SRL
Str. General Magheru nr. 3, bl. A+B, sc. D, ap. B12, Râmnicu Vâlcea, Vâlcea County, Romania
Trade Register No. J2026042613000, CUI 55106433
Email: privacy@talara.app

14. Changes to this policy

We may update this policy; we will change the date above and, for material changes, notify you by email where we hold your contact details.

© 2026 Talara Privacy Subprocessors Terms