Nobl.ai

Services Privacy Policy

This document summarizes how the EU General Data Protection Regulation (GDPR) applies to the data Nobl.ai services handle. It also describes how and under which conditions we collect, use, store and share personal information. This document applies exclusively to the SaaS services we offer, where we act as a data processor. You can find the privacy policy for our website, where we act as a data controller, here: Website Privacy Policy.

What GDPR is

The GDPR (Regulation EU 2016/679, in force since 25 May 2018) is the European law that protects people’s personal data. It gives individuals rights over their data and sets clear obligations for the organisations that handle it. Nobl.ai has been built around these rules from the start.

We take your privacy seriously

Nobl.ai (Nobl.ai BV, Ghent, Belgium) provides AI software (candidate–vacancy matching, ESCO occupation tagging, CV parsing, career guidance and related agents) as a service to HR customers such as job boards, staffing agencies and public employment services. Because we handle data like CVs and candidate profiles, we hold ourselves to the highest privacy and security standards and fully comply with the GDPR.

Our role: we are a data processor

The personal data we process (mainly candidate and employer/recruiter data) belongs to our customers, who are the data controllers and decide why and how it is used and are responsible for having a lawful basis, such as consent. Nobl.ai acts as a data processor: we only process that data on the customer’s documented instructions, never for our own purposes, and never for a third party.

What data we handle, and how we get it

  • Candidate data (provided by our customers, on their behalf): CV and profile information such as name, contact details, age, location (postcode-level), work experience, education and training, skills, languages, driver’s licence, interests, job preferences and applications; plus behavioural signals such as viewed jobs and searches.
  • Employer/Recruiter data: name, work address, phone and email needed to manage vacancies and applications.

We do not intentionally collect or use special categories of data (e.g. health, biometrics) or criminal-record data in our core services. If a CV happens to contain such information, it is not used as a matching input.

How we use the data

We use candidate and employer/recruiter data only to provide the agreed services on the customer’s behalf: matching candidates and jobs, classifying vacancies, parsing CVs and providing career guidance. We may use aggregated, non-identifying information to improve model quality where permitted.

Fairness. Because our systems may influence employment opportunities, they have been designed and built with fairness at their core. Our models are continuously monitored for bias (demographic parity, equal opportunity), and produce explanations so recommendations can be understood. We never use protected characteristics (gender, age, origin, etc.) as matching inputs. Protected characteristics are used only to monitor and correct for bias, never to rank or match candidates. Hiring decisions always remain with the human recruiters.

How long we keep it

We keep personal data only as long as necessary for the purpose and according to the customer’s instructions. Our engines store the minimum needed and, where possible, avoid keeping direct identifiers. Customers can update or delete a person’s data at any time via our APIs; deletion removes their data from our systems and from the datasets we use for future model training.

When we share it

We do not sell personal data. We share it only with sub-processors that help us run our services, under contracts requiring similar levels of protection. These sub-processors are:

  • AWS: cloud hosting and infrastructure (EU hosting by default; other regions when a customer requires local residency).
  • For AI features that use large language models (e.g. CV parsing, conversational agents), LLM providers (such as Anthropic or Google) under data-processing agreements that prevent training on customer data.

We do not transfer personal data outside an agreed region unless there is a lawful basis (adequacy decision, appropriate safeguards, or a GDPR derogation) and the controller’s prior written consent. We may disclose data if legally required, or in the context of a merger/acquisition, always with appropriate safeguards.

How we protect it

We apply strong technical and organisational measures such as encryption in transit and at rest, access controls, logging, backups and monitoring. See our Security Policy for more details. No system is ever 100% secure, but we work hard to keep data safe and to respond quickly to any incident.

Data Processing Agreement (DPA)

Before processing any personal data, we sign a Data Processing Agreement with the customer. This document sets out each party’s rights and obligations, the categories of data, the purpose and duration, where the data is hosted, our sub-processors, and our security commitments.

Data Protection Impact Assessments (DPIA)

When a new or higher-risk processing activity or technology is involved, we help the controller assess whether a DPIA is needed and support them in carrying it out.

Your rights

Individuals have the right to accesscorrectrestrictport and erase their personal data. Because our customers are the data controllers, candidates should usually contact them directly (the organisation whose platform they used). Where needed, we assist the controller to fulfil these requests, typically within 7 days. Complaints in this regard can be lodged with your national data protection authority.

Changes & contact

We may update this policy as our services or the law evolve; material changes will be made clear. Questions or requests should be directed to our Data Protection Officer, Alex Mara (dpo@nobl.ai).

Scroll to Top