Legal & Compliance

Privacy Policy

This policy explains how i-TalentAI collects, uses, stores, and protects your personal data in compliance with the Saudi Personal Data Protection Law (PDPL) and the EU General Data Protection Regulation (GDPR).

Last updated: April 12, 2026

PDPL Compliant
GDPR Compliant
Data Encrypted
Your Rights Protected

1. Data Controller

i-TalentAI (“we”, “us”, or “our”) is the data controller responsible for your personal data. We are incorporated and operating in the Kingdom of Saudi Arabia.

i-TalentAI — Privacy Team
Riyadh, Kingdom of Saudi Arabia
[email protected]

2. Scope of This Policy

This Privacy Policy applies to all users of the i-TalentAI platform, including candidates, recruiters, and visitors to our website at i-talentai.com. It covers personal data collected through our website, mobile interface, API integrations, and any associated services.

This policy is designed to satisfy the requirements of both the Saudi Personal Data Protection Law (PDPL) (Royal Decree No. M/19 of 1443H, as amended) and the EU General Data Protection Regulation (GDPR) (Regulation 2016/679) for users located in the European Economic Area.

3. Personal Data We Collect

We collect the following categories of personal data:

CategoryExamplesPurpose
Identity DataFull name, profile photo, nationalityAccount creation, identity verification
Contact DataEmail address, phone numberCommunication, notifications
Professional DataCV/résumé, work experience, education, skillsInterview preparation, job matching
Interview DataVoice recordings, video recordings, AI-generated transcripts and scoresAI interview assessment, feedback generation
Biometric IndicatorsFacial presence detection (camera feed during interview)Interview integrity verification (anti-cheat)
Technical DataIP address, browser type, device identifiers, cookiesPlatform security, analytics, fraud prevention
Payment DataBilling name, payment method type (processed by Stripe; card numbers are never stored by us)Subscription and plan management
Usage DataPages visited, features used, session durationPlatform improvement, personalised experience

We do not collect sensitive personal data (e.g., health, religion, political opinions) unless you voluntarily provide it in your CV or interview responses. If such data is provided, it is processed solely to fulfil the interview service.

4. Legal Basis for Processing

We process your personal data on the following legal bases:

Legal BasisWhen We Rely on It
Contract PerformanceProcessing necessary to provide the interview platform service you have signed up for
Legitimate InterestsPlatform security, fraud prevention, AI model improvement (aggregated/anonymised), service analytics
ConsentMarketing communications, optional cookies, biometric processing for interview integrity
Legal ObligationCompliance with Saudi PDPL, ZATCA tax requirements, NCA cybersecurity regulations, and applicable court orders

Under the PDPL, we rely on contractual necessity and legitimate interest as primary bases. For GDPR purposes, we additionally rely on explicit consent for biometric indicators and optional analytics cookies.

5. How We Use Your Data

  • To create and manage your account and authenticate your identity.
  • To conduct AI-powered voice and video interviews and generate performance scores and feedback.
  • To rewrite and optimise your CV using AI, tailored to the job description you provide.
  • To verify interview integrity through camera-based face detection (anti-cheat gate).
  • To match candidates with relevant job opportunities and present ranked candidate reports to recruiters.
  • To process payments and manage your subscription or credit balance.
  • To send transactional emails (account confirmations, interview results, payment receipts).
  • To improve our AI models using aggregated, anonymised performance patterns (no individual re-identification).
  • To comply with applicable laws and respond to lawful requests from authorities.

6. Data Retention

Data TypeRetention Period
Account data (name, email, role)Duration of account + 3 years after deletion request
Interview recordings (audio/video)90 days from interview date, then permanently deleted
Interview transcripts and AI scores2 years from interview date
CV filesDuration of account + 1 year after deletion request
Payment records7 years (ZATCA / Saudi tax law requirement)
Server and access logs90 days
Cookie consent records3 years

You may request earlier deletion of your data at any time (see Section 9 — Your Rights). Certain data may be retained longer where required by law or for the establishment, exercise, or defence of legal claims.

7. Data Sharing and Third Parties

We share personal data only with trusted third parties who are contractually bound to protect it:

RecipientPurposeLocation
OpenAIAI interview question generation, voice transcription (Whisper), TTS, CV rewritingUSA (Standard Contractual Clauses applied)
StripePayment processingUSA (Standard Contractual Clauses applied)
Amazon Web Services (S3)Secure file and media storageConfigurable region; data stored in compliant regions
Manus PlatformHosting infrastructure, OAuth authenticationSingapore
ResendTransactional email deliveryUSA (Standard Contractual Clauses applied)

We do not sell, rent, or trade your personal data to any third party for marketing purposes. Recruiters who access candidate interview reports do so only for candidates who have applied to their job postings.

Cross-border data transfers to countries outside Saudi Arabia and the EEA are governed by appropriate safeguards including Standard Contractual Clauses (SCCs) and adequacy decisions where applicable, in accordance with PDPL Article 29 and GDPR Chapter V.

8. Cookies and Tracking Technologies

We use cookies and similar technologies to operate the platform and improve your experience. You can manage your cookie preferences at any time via the cookie consent banner.

Cookie TypePurposeConsent Required
Essential / FunctionalSession authentication, security tokens, language preferenceNo (necessary for service)
AnalyticsAggregated usage statistics to improve the platform (no personal profiling)Yes
PreferenceRemembering your settings (e.g., dark mode, language)Yes

We do not use advertising or cross-site tracking cookies. You may withdraw cookie consent at any time by clearing your browser cookies or contacting us.

9. Your Rights

Under the PDPL and GDPR, you have the following rights regarding your personal data:

RightDescription
Right of AccessRequest a copy of all personal data we hold about you.
Right to RectificationRequest correction of inaccurate or incomplete data.
Right to ErasureRequest deletion of your personal data ('right to be forgotten'), subject to legal retention obligations.
Right to RestrictionRequest that we limit processing of your data in certain circumstances.
Right to Data PortabilityReceive your data in a structured, machine-readable format (GDPR users).
Right to ObjectObject to processing based on legitimate interests, including profiling.
Right to Withdraw ConsentWithdraw consent at any time where processing is consent-based (e.g., marketing emails, analytics cookies).
Right to Lodge a ComplaintFile a complaint with the Saudi National Data Management Office (NDMO) or, for EEA users, your local Data Protection Authority (DPA).

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days (PDPL) or one month (GDPR). Identity verification may be required before we process your request.

10. Data Security

We implement technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • 🔒TLS/HTTPS encryption for all data in transit.
  • 🔒AES-256 encryption for sensitive data at rest in our storage systems.
  • 🔒Role-based access controls — only authorised personnel can access personal data.
  • 🔒Interview recordings are stored in private S3 buckets with pre-signed URL access only.
  • 🔒Regular security reviews and vulnerability assessments.
  • 🔒Compliance with NCA (National Cybersecurity Authority) Essential Cybersecurity Controls (ECC).

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by PDPL and GDPR.

11. Children's Privacy

The i-TalentAI platform is intended for users aged 18 years and older. We do not knowingly collect personal data from individuals under 18. If you believe a minor has provided us with personal data, please contact us immediately at [email protected] and we will delete the data promptly.

12. Saudi PDPL — Specific Provisions

For users in the Kingdom of Saudi Arabia, the following additional provisions apply under the Personal Data Protection Law (PDPL):

  • We process personal data only for the purposes stated in this policy and do not use it for undisclosed purposes.
  • We obtain explicit consent before processing sensitive personal data categories (e.g., biometric indicators for interview integrity).
  • Cross-border data transfers comply with PDPL Article 29 requirements, including contractual safeguards with international processors.
  • You have the right to file a complaint with the National Data Management Office (NDMO) at ndmo.gov.sa.
  • We maintain a data processing register as required by the PDPL implementing regulations.
  • Automated decision-making (AI scoring) is disclosed to users and you may request human review of any AI-generated assessment.

13. GDPR — Specific Provisions (EEA Users)

For users located in the European Economic Area (EEA), the following additional provisions apply under the General Data Protection Regulation (GDPR):

  • Our lawful bases for processing are set out in Section 4 above. Where we rely on legitimate interests, you may object to such processing.
  • We appoint a Data Protection Representative in the EU where required.
  • Data transfers to third countries (e.g., USA) are governed by Standard Contractual Clauses (SCCs) approved by the European Commission.
  • You have the right to data portability: receive your data in JSON or CSV format on request.
  • You may lodge a complaint with your national Data Protection Authority (DPA). A list of EEA DPAs is available at edpb.europa.eu.
  • Automated profiling (AI interview scoring) is disclosed. You have the right not to be subject to solely automated decisions with significant effects, and may request human review.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email (if you have an account) and update the “Last updated” date at the top of this page. Continued use of the platform after the effective date of any changes constitutes acceptance of the updated policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Privacy team:

i-TalentAI — Privacy Team
Riyadh, Kingdom of Saudi Arabia
[email protected]

For PDPL complaints, you may also contact the National Data Management Office (NDMO) at ndmo.gov.sa.

For GDPR complaints (EEA users), you may contact your local Data Protection Authority. A directory is available at edpb.europa.eu.