FINPLOY TECHNOLOGIES PTE. LTD.
Finploy Technologies Pte. Ltd. ("Finploy Technologies", "we", "us", or "our") is committed to protecting personal data in accordance with Singapore's Personal Data Protection Act 2012 (PDPA).
This PDPA Policy explains how we collect, use, disclose, process, retain, and protect personal data from users, recruitment teams, corporate employers, authorised account representatives, and visitors using TalentZora (talentzora.com) and its related software dashboards.
TalentZora is a self-service B2B SaaS software platform. It provides tools for CV upload, AI-assisted CV-JD matching, private candidate vault search, shortlist creation, and recruiter productivity workflows. All candidate and job data uploaded into TalentZora is stored in encrypted form and scoped exclusively to the subscribing organisation that uploaded it.
Definitions
For the purposes of this PDPA Policy, the following definitions apply:
- "Personal Data" — data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which we have or are likely to have access, as defined under Section 2 of the PDPA.
- "Organisation" (Data Controller) — an organisation that controls the collection, holding, processing, and use of personal data. For candidate data uploaded by subscribing organisations, that subscribing organisation is the data controller for those records.
- "Data Intermediary" (Data Processor) — an organisation that processes personal data on behalf of, and under the instructions of, another organisation. Finploy Technologies Pte. Ltd. acts as a data intermediary for candidate data processed on behalf of subscribing organisations using TalentZora.
- "DEK" (Data Encryption Key) — a unique, randomly generated AES-256 encryption key assigned to each subscribing organisation. All personal data fields in that organisation's workspace are encrypted using their DEK before storage in our database.
- "KEK" (Key Encryption Key) — a master encryption key held securely in our server environment. The KEK encrypts each organisation's DEK so that the DEK can be stored in the database safely without being readable in plaintext.
- "PDPA" — Singapore's Personal Data Protection Act 2012 (No. 26 of 2012), including all subsequent amendments, most recently the Personal Data Protection (Amendment) Act 2020 which came into effect on 1 February 2021.
- "PDPC" — the Personal Data Protection Commission of Singapore, established under Part IX of the PDPA.
- "Subscribing Organisation" — a company, agency, or HR team that has entered into a subscription agreement with Finploy Technologies Pte. Ltd. for use of the TalentZora platform.
- "Workspace" — the private, isolated data environment assigned to a subscribing organisation within TalentZora, in which all uploaded candidate CVs, job descriptions, match results, and search history are stored.
PDPA Obligations Framework
Singapore's PDPA sets out data protection obligations with which organisations that collect, use, or disclose personal data must comply. As amended by the Personal Data Protection (Amendment) Act 2020, these obligations also extend to data intermediaries for certain duties. Finploy Technologies Pte. Ltd. is committed to upholding these obligations. Below is a summary of how each obligation applies to TalentZora:
- Consent Obligation: We collect, use, and disclose personal data only with the consent of individuals, or where an exception under the PDPA applies. See Section 2 of this Policy.
- Purpose Limitation Obligation: We collect, use, and disclose personal data only for purposes that a reasonable person would consider appropriate in the circumstances and that we have notified individuals of. See Section 3 of this Policy.
- Notification Obligation: We inform individuals of the purposes for which we collect, use, and disclose their personal data, through this Policy and our Privacy Policy at talentzora.com/privacy.php, before or at the point of collection.
- Access and Correction Obligation: We allow individuals to request access to and correction of their personal data. See Sections 5 and 13 of this Policy.
- Accuracy Obligation: We make reasonable efforts to ensure that personal data we collect and use is accurate and complete. See Section 6 of this Policy.
- Protection Obligation: We implement reasonable security arrangements — including AES-256 encryption, envelope encryption architecture, access controls, and physical security via AWS — to protect personal data from unauthorised access, use, or disclosure. See Sections 6 and 7 of this Policy.
- Retention Limitation Obligation: We retain personal data only for as long as it is necessary for the fulfilment of the purposes for which it was collected, or as required by law. See Section 8 of this Policy.
- Transfer Limitation Obligation: We transfer personal data to overseas recipients only in compliance with the PDPA, requiring comparable protection standards. See Section 9 of this Policy.
- Data Breach Notification Obligation: We assess and respond to personal data incidents promptly and notify the PDPC and affected individuals where required under the PDPA. See Section 10 of this Policy.
- Data Portability Obligation (2021 Amendment): We enable eligible data subjects to request the porting of applicable personal data in a machine-readable format. See Section 13 of this Policy.
- Accountability Obligation: We have designated a Data Protection Officer and maintain this Policy and related internal practices to demonstrate compliance with our PDPA obligations. See Section 11 of this Policy.
1. Personal Data We Collect
"Personal Data" means data about an individual who can be identified from that data, or from that data together with other information we have or may access. Depending on your use of the platform, we may collect:
- Contact details: name, mobile number, email address, and mailing address.
- Professional and profile details: work history, education, resume or CV contents, skills, certifications, and details uploaded by recruitment teams.
- Account details: username, profile settings, dashboard preferences, and login-related information.
- Corporate account information: company name, Unique Entity Number (UEN), billing address, and contact details of authorised representatives.
- Technical and usage data: IP address, device details, browser type, cookies, analytics data, and platform activity.
- Payment-related data: billing details, payment status, transaction references, and fraud-prevention information. We do not store complete card details unless permitted through a compliant payment service provider.
All personal data fields listed above that are uploaded into candidate records or job descriptions (name, contact details, CV text, job content, match results, and search history) are encrypted at rest using AES-256-CBC encryption before being stored in our database. See Section 7 for full details of our encryption architecture.
NRIC and sensitive identifier handling
TalentZora's CV matching and search functions do not require the collection of NRIC (National Registration Identity Card) numbers, FIN (Foreign Identification Number) numbers, passport numbers, or similar national identity document identifiers. In accordance with the PDPC's Advisory Guidelines on the NRIC, subscribing organisations are advised to redact full NRIC or FIN numbers from uploaded CVs unless collection is legally required for the specific recruitment process. Where such identifiers are present in uploaded documents, they are stored in encrypted form within the subscribing organisation's private workspace, subject to the same AES-256 encryption and DEK-based access controls described in Section 7. Subscribing organisations, as data controllers for uploaded candidate data, bear responsibility for ensuring compliance with the PDPC's NRIC guidelines in their collection and uploading practices.
2. Consent and Notification
We collect, use, and disclose personal data with your consent, or where authorised or required by law.
- Subscribing Organisation Users (Recruiters and HR Teams): By registering a TalentZora account, accepting our Terms of Use and this Policy, uploading CV or JD content, running AI matching, or using platform features, account users consent to the collection and use of their personal data for the purposes described in this Policy and for platform administration, billing, and support.
- Individual Candidates: Candidates whose CVs are uploaded to TalentZora do not register on the platform directly — their data is uploaded by the subscribing organisation (the recruiter or HR team). The subscribing organisation, as the data controller for that candidate data, is responsible for obtaining any consent from the candidate that is required before uploading. TalentZora processes candidate data solely on the instructions of the subscribing organisation and in accordance with its role as a data intermediary under the PDPA.
- Withdrawal of Consent: Account users may withdraw consent by contacting support@talentzora.com. Withdrawal may affect our ability to provide certain platform features or maintain an active subscription. For candidate data, withdrawal requests should be directed to the subscribing organisation that uploaded the data.
3. Purposes of Collection, Use, and Disclosure
We collect, use, and disclose personal data to:
- Operate and maintain our self-service private AI candidate database, search vault, and software platform.
- Private vault storage and CV-JD matching features are self-service tools only; TalentZora does not guarantee candidate availability, hiring outcomes, or placement results.
- Manage accounts, matching credits, dashboards, and user support.
- Enable users to run searches, parse CVs, and generate shortlists based on their own platform settings.
- Process payments, invoices, refunds where applicable, fraud checks, and account billing.
- Improve platform performance, security, analytics, and service quality.
- Comply with Singapore laws, regulatory requirements, payment provider checks, and lawful requests.
TalentZora is a private productivity layer and self-service SaaS platform. We do not operate as an employment agency, recruitment agency, manpower agency, placement service, or hiring representative.
For candidate data uploaded into private workspaces, Finploy Technologies Pte. Ltd. (operating TalentZora) acts solely as a data intermediary (data processor) under the PDPA, processing that data only on behalf of and under the instructions of the subscribing organisation. The subscribing organisation is the data controller and is solely responsible for establishing a lawful basis and obtaining any candidate consent required before uploading.
4. Sharing and Disclosure of Personal Data
We do not sell personal data. We may share personal data with:
- Authorised users within your organisation's subscription workspace when a team member uploads or reviews candidate files.
- Workspace members receive data only within their organization's boundaries; TalentZora does not pool or share CVs between different employer subscriptions.
- Service providers such as hosting, analytics, payment gateways, customer support, and security providers.
- Professional advisers, auditors, regulators, banks, payment providers, or authorities where required or permitted by law.
- We do not sell, rent, or share personal data with third parties for their independent marketing purposes.
Because candidate data is encrypted with a per-organisation Data Encryption Key (DEK), even parties with access to our database infrastructure cannot read another organisation's candidate or job data without that organisation's specific DEK.
5. Access and Correction of Personal Data
You may request access to, or correction of, your personal data by contacting our DPO at support@talentzora.com.
We may verify your identity before processing the request and may charge a reasonable fee where permitted under the PDPA.
Where a data access or correction request relates to encrypted candidate records in your workspace, we can assist by providing an export of your decrypted records in Excel format, or by correcting specific fields within the platform. To access decrypted data for this purpose, we will obtain your explicit written acknowledgement before proceeding.
Routing for individual candidates: Where an individual candidate seeks access to or correction of personal data that a subscribing organisation has uploaded to TalentZora, Finploy Technologies Pte. Ltd. acts as a data intermediary for that data. Individual candidates should direct access or correction requests to the subscribing organisation (the data controller) that uploaded their data. Finploy Technologies will only process such requests on the instruction of the relevant subscribing organisation, or where we are independently required to do so by law. If a candidate is unable to identify or reach the subscribing organisation, they may contact us at support@talentzora.com and we will provide reasonable assistance in routing the request.
6. Accuracy and Security
You are responsible for ensuring that personal data submitted by you is accurate, complete, and updated.
We use reasonable administrative, technical, and organisational safeguards to protect personal data, including access controls, secure transmission, restricted system access, and vendor checks. However, no electronic transmission or storage system is completely secure.
Our primary technical safeguard is application-layer encryption of all candidate and job data at rest, combined with TLS encryption for all data in transit. This means that even in the event of an unauthorised database access, the encrypted personal data fields cannot be read without the correct per-organisation decryption key. For full details of our encryption architecture, see Section 7 below.
7. Data Encryption and Technical Security
TalentZora implements a layered encryption system to protect all personal data stored on our platform. This section explains how that system works.
Encryption standard
All sensitive personal data stored in our database is encrypted at rest using AES-256-CBC (Advanced Encryption Standard, 256-bit key, Cipher Block Chaining mode). This is an industry-standard symmetric encryption algorithm used widely across financial, healthcare, and government systems to protect sensitive data.
Envelope encryption architecture (KEK and DEK)
We use an envelope encryption model. Every subscribing organisation has its own unique encryption key, which means no two organisations share an encryption boundary:
- Key Encryption Key (KEK): A master key held securely in our server infrastructure and access-controlled configuration, outside the database and not stored within the database at any point. The KEK is used to encrypt each organisation's individual data key before it is stored. The KEK is never written to the database.
- Data Encryption Key (DEK): A unique, randomly generated 256-bit encryption key created for each subscribing organisation at the time of account setup. The DEK is stored in its encrypted (KEK-wrapped) form in our database. To decrypt your data, the platform: (a) retrieves your encrypted DEK from the database, (b) decrypts the DEK using the KEK from the server environment, and (c) uses the decrypted DEK to decrypt the requested data fields.
This architecture ensures that even if our database were accessed without authorisation, neither the KEK nor any organisation's raw DEK is directly exposed — the KEK lives outside the database entirely.
Scope of encrypted data
The following personal data categories are encrypted using your organisation's DEK before storage:
- Candidate records: name, email address, phone number, full CV text (all parsed content), current company, current designation, core skills, education details, past companies, total years of experience, and the stored CV filename (used as a filesystem path to the uploaded file).
- Job descriptions: job role, department, company name, location, salary details, experience requirements, product/domain context, role overview, key responsibilities, job requirements, education requirements, sub-department, specialisation, domain experience, contact person name, contact person designation, contact mobile, contact email, category, employer mobile, and the full JD text.
- Match results: match score, fit summary text, AI reasoning bullets, overall verdict, and comparison detail.
- Smart search history: search query text, AI-generated messages, AI insights, and candidate ID lists returned by the search.
Non-sensitive operational fields — including internal record IDs, foreign key references, timestamp columns, and status or enum flags — are not encrypted, as they contain no personal data and are required for database queries to function.
DEK deletion and irreversible data inaccessibility
If your organisation's DEK is deleted — for example, upon account closure, at your request, or as part of a data erasure instruction — all encrypted personal data in active storage associated with your organisation becomes permanently inaccessible. Without the DEK, the ciphertext stored in our database cannot be decrypted by anyone, including TalentZora staff. This property is a deliberate architectural guarantee: DEK deletion is the technical equivalent of secure data destruction.
Backups: Our production systems maintain automated encrypted backups for disaster recovery purposes. These backups are retained on a standard rotation cycle and are automatically purged when the retention period expires. We do not actively restore encrypted backup data for the purpose of recovering data following a DEK deletion request. Any residual encrypted data remaining in backup snapshots after DEK deletion will be unreadable without the DEK and will be permanently purged when the backup cycle completes.
Legal holds: Where specific records are subject to an active legal hold, regulatory investigation, or a competent authority instruction to preserve evidence, a deletion request affecting those records may be paused or partially deferred. We will notify the requesting organisation if a legal hold prevents full compliance. Deletion will be completed as soon as the legal or regulatory hold is lifted.
TalentZora's access policy
Finploy Technologies Pte. Ltd. (operating TalentZora) holds the KEK and the encrypted DEK for each subscribing organisation. This means we are technically capable of decrypting your organisation's data. We commit that we will not decrypt your data without your explicit permission.
The only circumstances under which TalentZora may access or temporarily decrypt specific encrypted data fields are:
- At your explicit request for support: If you report a specific platform issue — for example, a candidate's parsed name or CV text is displaying incorrectly, or a match result appears corrupted due to an encryption or parsing error — we may, with your explicit written acknowledgement, access that specific data field to diagnose and resolve the reported issue. We access only the minimum data necessary to resolve the issue and log all such access.
- Internal security incident investigation: If TalentZora has credible grounds to believe that a security incident, suspected unauthorised access, fraud, or material breach of our Terms of Use is actively affecting your workspace or our platform, we may access the minimum data necessary to investigate and contain the incident. This access is restricted to authorised security personnel, independently logged, and we will notify the affected subscribing organisation as soon as it is safe to do so without prejudicing the investigation.
- Legal or regulatory obligation: Where we are required by Singapore law, a court order, or a competent regulatory authority to disclose specific data, we will comply with the applicable legal obligation.
TalentZora staff do not have routine, operational access to your organisation's decrypted candidate or job data. All access to encrypted data outside the normal platform operation is documented internally.
8. Retention of Personal Data
We retain personal data only as long as necessary for platform services, legal compliance, payment records, security, dispute handling, and business purposes. When no longer required, we will delete, anonymise, or securely dispose of the data.
For encrypted personal data (candidate records, job descriptions, match results, and search history), the effective method of secure disposal is deletion of your organisation's DEK. Once the DEK is deleted, all associated encrypted data in active storage becomes permanently inaccessible. Encrypted backups are retained on our standard rotation cycle and are automatically purged when the cycle completes; we do not restore backup data following a DEK deletion request. Non-encrypted operational records, such as billing records and anonymised usage logs, are retained for the minimum periods required by applicable Singapore law.
9. Cross-Border Data Transfers
We may transfer personal data outside Singapore to cloud, hosting, payment, analytics, or service providers. Where required, we will take reasonable steps to ensure comparable protection under the PDPA.
TalentZora relies on the following categories of sub-processors to deliver the service: cloud hosting (Amazon Web Services, ap-south-1, Mumbai, India) and AI processing providers (including Google) used to parse CVs and generate matching outputs. As our production infrastructure is hosted outside Singapore, all personal data processed by TalentZora is subject to the PDPA's Transfer Limitation Obligation. We address this obligation by requiring all sub-processors to maintain data protection standards comparable to those required under the PDPA through applicable data processing terms. Subscribing organisations that require data to be hosted within Singapore may request a Singapore-region deployment on AWS ap-southeast-1 — please contact us to discuss availability.
Where CV or JD text is sent to AI processing services for parsing or matching, the data is transmitted using encrypted HTTPS connections. Encrypted personal data fields are decrypted only within our controlled server environment and only for the duration needed to complete the specific operation requested.
On-premise deployment option: For subscribing organisations that require complete data sovereignty — where all candidate and organisational data must remain exclusively within their own infrastructure — TalentZora offers an on-premise installation model available on request. In this model, TalentZora has no access to or custody of client data; all cross-border transfer obligations with respect to that data are borne entirely by the subscribing organisation as the data controller in their own environment. TalentZora provides ongoing platform maintenance and technical support under a subscription arrangement. Contact us to discuss requirements.
9.1 Why personal data is transferred outside Singapore
Singapore's Transfer Limitation Obligation (PDPA, Part 9, Section 26) applies because TalentZora's default production infrastructure is located outside Singapore. The specific reasons for this overseas processing are:
- Platform hosting and database storage: TalentZora's application servers, relational database, and file object storage operate on Amazon Web Services (AWS) in the ap-south-1 (Mumbai, India) region. All candidate records, job descriptions, AI match results, search history, folder structures, and account data reside on this infrastructure. The transfer of personal data to this infrastructure is inseparable from delivering the platform's core functionality — the data must reside on the servers that run and store it.
- AI-powered CV parsing and matching: When a CV or job description is uploaded, the document's text content is extracted and transmitted to Google AI APIs for automated field parsing and similarity matching. These API services operate on Google's global infrastructure, which includes processing outside Singapore. This transfer is technically necessary to deliver the AI screening and matching features.
- Payment processing: Billing contact data and payment card information are transmitted to Stripe for subscription management and payment processing. Stripe's infrastructure operates internationally, including outside Singapore, as part of its payment network.
- Transactional email delivery: Automated system emails (OTP codes, account confirmations, and notifications) are delivered through a third-party email service provider. Name and email address are transmitted to this provider's infrastructure to deliver these messages.
9.2 What safeguards are implemented for overseas transfers
TalentZora implements the following technical and organisational safeguards to ensure that personal data transferred outside Singapore is protected to a standard comparable to that required under the PDPA:
- AES-256-CBC encryption at rest: All personal data fields stored in TalentZora's database — including candidate names, contact details, NRIC/passport references, CV text, job description text, match scores, and search history — are encrypted using AES-256-CBC before being written to disk. AES-256 is the international benchmark for data encryption at rest and is mandated by financial regulators, national security agencies, and data protection authorities globally. No personal data is stored in plaintext on any overseas server.
- Per-organisation envelope encryption (DEK/KEK architecture): Each subscribing organisation's data is encrypted under its own unique 256-bit Data Encryption Key (DEK). The DEK itself is encrypted by a master Key Encryption Key (KEK) held in a separate, access-controlled server environment outside the database. This two-layer architecture means that access to database contents alone is insufficient to decrypt any personal data. The KEK and DEK must both be available, and access to the KEK is restricted to authorised server processes only. Cross-organisation decryption is architecturally impossible — each organisation's DEK is unique and cannot decrypt another's data.
- TLS encryption in transit: All data transmissions — between users and TalentZora's servers, between TalentZora and AWS services, between TalentZora and Google AI APIs, and between TalentZora and Stripe — are encrypted using Transport Layer Security (TLS). No personal data is transmitted over unencrypted connections at any point in the processing chain.
- AWS data centre physical security: AWS Mumbai (ap-south-1) data centres implement 24/7 security personnel, multi-layer perimeter fencing, biometric access controls, multi-factor authentication for facility entry, CCTV surveillance, and continuous environmental monitoring. AWS maintains ISO 27001, SOC 1 (Type II), and SOC 2 (Type II) certifications across its global infrastructure. These certifications are independently audited by accredited third parties on an annual basis.
- Data minimisation in sub-processor transmissions: Only the data strictly necessary for each processing operation is transmitted to each sub-processor. For AI parsing, only CV and JD text is transmitted — encrypted field values are never shared with AI providers. For Stripe, only billing contact and card data are transmitted — candidate data is never sent to payment processors. For email delivery, only name and email address are transmitted — no candidate or organisational data is included.
- Contractual data protection obligations on all sub-processors: All sub-processors are engaged under contractual terms that impose specific data protection obligations, including: (i) processing data only on TalentZora's written instructions and for no other purpose; (ii) maintaining confidentiality and ensuring that personnel with access to personal data are bound by appropriate confidentiality obligations; (iii) implementing and maintaining appropriate technical and organisational security measures; (iv) not sub-contracting to further processors without TalentZora's prior written approval; (v) cooperating with TalentZora in handling data subject rights requests; (vi) notifying TalentZora without undue delay upon becoming aware of a personal data breach; and (vii) returning or securely deleting personal data on termination of the engagement.
9.3 How your data is protected overseas — end-to-end protection chain
The protection applied to personal data overseas operates as an end-to-end chain across all stages:
- At the point of upload: Data is transmitted from the user's browser to TalentZora's servers over a TLS-encrypted connection. It is never transmitted in plaintext over the internet.
- At the point of processing: Data is temporarily held in memory in plaintext only for the minimum time necessary to complete the specific operation requested (e.g., encryption, parsing, matching). It is encrypted before being written to disk or transmitted to any sub-processor that stores it.
- At the point of storage: Data is stored on AWS infrastructure encrypted with AES-256-CBC under the organisation's unique DEK. AWS's own infrastructure-level encryption (disk encryption) provides an additional layer of protection beneath TalentZora's application-level encryption. The combination means data is protected by two independent encryption layers at rest.
- At the point of AI processing: CV and JD text sent to Google AI APIs is transmitted over TLS. Google processes this data under its API data processing terms, which include confidentiality obligations and restrictions on use of API data for training general AI models.
- At the point of deletion: When an organisation terminates its subscription or requests data deletion, TalentZora deletes the organisation's DEK. Deletion of the DEK renders all associated encrypted data permanently inaccessible — even if the encrypted bytes remain temporarily on physical media, they cannot be decrypted without the DEK. This is TalentZora's primary mechanism for secure, cryptographic data disposal.
9.4 Who can access your personal data overseas
Access to personal data held on overseas infrastructure is strictly limited and controlled:
- Finploy Technologies authorised technical personnel: A small number of engineers hold administrative access to TalentZora's AWS infrastructure for operations, deployments, and security management. All administrative access requires multi-factor authentication and is logged. Routine platform operation does not require any personnel to view decrypted personal data — decryption for maintenance purposes would require accessing the KEK from a separate controlled environment, which is itself access-logged. This access is used only in documented, justified circumstances and never for commercial or unauthorised purposes.
- AWS infrastructure operations staff (hypervisor level only): AWS's own operations personnel maintain the physical infrastructure, virtualisation layer, and data centre environment. AWS does not have access to customer data stored within its services — this separation is foundational to AWS's shared responsibility model, under which AWS is responsible for the security of the cloud (infrastructure) while the customer (TalentZora) is responsible for the security of everything in the cloud (application data and encryption). AWS does not inspect, copy, or process customer personal data.
- Google AI services (text content only, transmitted for specific operations): CV and JD text is transmitted to Google AI APIs only when a parsing or matching operation is triggered. Google processes this content under its API terms, which include data protection obligations and confidentiality requirements. Google does not receive access to encrypted database fields, account data, or contact information.
- Stripe (billing and payment data only): Payment card and billing contact information is transmitted to Stripe for payment processing. Stripe does not receive or have access to any candidate data, job descriptions, or matching data. Stripe is PCI DSS Level 1 certified — the highest tier of compliance under the global payment card security standard.
- No other parties: Personal data is not shared with, sold to, licensed to, or disclosed to any other overseas entity, except as required by applicable law or as expressly directed in writing by the subscribing organisation. Any government or law enforcement request for data is assessed for legality before any response is given, and subscribing organisations are notified to the extent permitted by law.
9.5 What contractual protections exist for overseas transfers
TalentZora does not transfer personal data to any overseas party without contractual protections in place. The specific contractual frameworks governing each sub-processor are:
- AWS — AWS Data Processing Addendum (DPA): TalentZora's use of AWS is governed by the AWS DPA, which binds AWS to: implement appropriate technical and organisational security measures; process personal data only in accordance with TalentZora's instructions; maintain confidentiality; not disclose personal data to third parties except as required by law; cooperate with TalentZora in responding to data subject requests and security incidents; and notify TalentZora of any data breach affecting TalentZora's data. AWS's global DPA is based on frameworks including the EU Standard Contractual Clauses (SCCs), which provide a recognised legal mechanism for cross-border data transfers under data protection laws internationally.
- Google AI services — Google API Terms and Cloud DPA: Google's API data processing terms include data protection obligations, confidentiality commitments, and restrictions on how API-transmitted data may be used. Where applicable, Google's Cloud Data Processing Addendum (with Standard Contractual Clauses) applies to processing of personal data through Google services.
- Stripe — Stripe Data Processing Agreement: Stripe's DPA includes GDPR-compliant Standard Contractual Clauses, security requirements, confidentiality obligations, and audit rights. Stripe's compliance framework meets or exceeds the standard of protection required under Singapore's PDPA.
- PDPA Transfer Limitation Obligation compliance: In engaging each sub-processor, TalentZora has assessed that the sub-processor's data protection obligations — as established by applicable contractual terms, certifications (ISO 27001, SOC 2, PCI DSS), and legal obligations in their operating jurisdiction — collectively provide a standard of protection comparable to that required under Singapore's PDPA. This assessment satisfies TalentZora's obligations under Part 9, Section 26 of the PDPA with respect to these transfers.
These contractual protections do not limit the rights available to subscribing organisations or to individuals under the PDPA. TalentZora remains the accountable organisation for all personal data it processes, regardless of where that processing takes place. If you have any questions or concerns about overseas transfers or the protections in place, contact our Data Protection Officer at support@talentzora.com (subject line: Attention: Data Protection Officer).
10. Data Breach Management
We will assess and respond to personal data incidents promptly. Under the PDPA, a data breach is notifiable to the PDPC where it is likely to cause significant harm to affected individuals, or is of significant scale (currently defined as affecting 500 or more individuals). Where a breach meets these thresholds, we will notify the PDPC within 3 calendar days of determining that the breach is notifiable, and notify affected individuals without undue delay.
Notification to subscribing organisations: In our capacity as a data intermediary, we will notify affected subscribing organisations without undue delay and in any event within 72 hours of confirming that a breach has occurred affecting their workspace data — regardless of whether the breach meets the statutory notifiability threshold for PDPC reporting. Our notification will include the nature of the incident, the categories of personal data affected, the approximate number of individuals and records involved, the likely consequences, and the containment and remediation steps we have taken or plan to take. We will provide reasonable assistance to subscribing organisations in assessing their own notification obligations under the PDPA.
TalentZora's encryption architecture significantly limits the impact of a potential database breach. Because all candidate and job personal data is encrypted with per-organisation DEKs, and the DEKs themselves are encrypted by a KEK held outside the database, an attacker who gains access only to database contents cannot read any personal data fields. This does not eliminate breach risk entirely, but it substantially limits data exposure in the event of an unauthorised database access.
11. Data Protection Officer (DPO)
If you have questions, feedback, complaints, or requests regarding this PDPA Policy or your personal data, please contact our Data Protection Officer:
Email: support@talentzora.com
Subject line: Attention: Data Protection Officer
12. Amendments
We may update this PDPA Policy from time to time to reflect changes in our services, technology, business operations, or Singapore legal requirements. For material changes — such as changes to how we collect or use personal data, new sub-processors, or revised retention periods — we will notify subscribing organisations by email to the registered account address at least 30 days before the change takes effect, and will post the updated Policy on this page with a revised effective date. Subscribing organisations that object to a material change may terminate their subscription in accordance with the Terms of Use before the change takes effect. Continued use of the platform after the effective date of a material change constitutes acceptance of the updated Policy.
13. Data Portability Obligation
Singapore's PDPA, as amended by the Personal Data Protection (Amendment) Act 2020, introduced a Data Portability framework. To the extent this framework is applicable and in force for the categories of data held by TalentZora, it gives eligible individuals the right to request that an organisation transmit their personal data to another organisation in a commonly used machine-readable format, subject to conditions and exclusions prescribed by the PDPC.
For TalentZora users, data portability requests are handled as follows:
- Account and workspace data: Subscribing organisations can request an export of their workspace data (including uploaded candidate records, job descriptions, and match results) in Excel format, which constitutes a structured, machine-readable format. This export can be generated directly from the platform's export feature or requested by emailing support@talentzora.com.
- Candidate data: For candidate data uploaded into a subscribing organisation's private workspace, the subscribing organisation (as the data controller) is responsible for handling any data portability requests from individual candidates. TalentZora provides the export tools necessary for the subscribing organisation to fulfil such requests in accordance with the PDPA.
- Scope and exclusions: The Data Portability Obligation applies to personal data processed by automated means. It does not apply to personal data that was not provided by the individual themselves (e.g., inferred data, internal assessments), or to data held for legal, audit, or compliance purposes. Certain categories of business contact information and account management data may be excluded from portability obligations under the PDPC's prescribed exceptions.
- Format: Exported data is provided in Excel (.xlsx) format, which is widely supported and machine-readable. Where another machine-readable format is required, please contact us at support@talentzora.com and we will assess whether we can accommodate the request.
To make a data portability request, contact us at support@talentzora.com. We will respond within 30 calendar days. We may verify your identity and the eligibility of your request before processing it, and may charge a reasonable administrative fee where permitted under the PDPA.
14. Data Protection by Design and Default
Finploy Technologies Pte. Ltd. applies the principle of Privacy by Design and Default in the architecture and ongoing operation of TalentZora. This means that data protection is embedded into the design of the platform from the outset, rather than treated as a compliance add-on.
Key examples of how this principle is implemented in TalentZora include:
- Encryption by default: All personal data fields in the database are encrypted using AES-256 before storage. Encryption is applied automatically to all data for all subscribing organisations — there is no opt-in and no unencrypted-data configuration.
- Tenant isolation by design: The platform architecture enforces data isolation between subscribing organisations at the encryption key level. Each organisation has a unique DEK. It is architecturally impossible for one organisation's DEK to decrypt another organisation's data.
- Least-privilege access: Platform features are designed so that each user role has access only to the data necessary for their function. Team members of one organisation cannot view the data of another organisation, and platform staff do not have routine access to any organisation's decrypted candidate data.
- Secure deletion by key destruction: Data deletion is implemented via DEK deletion, which renders all associated encrypted data permanently inaccessible — not merely flagged as deleted in the database. This provides a higher standard of erasure than typical soft-deletion approaches.
- Data minimisation: We collect only the personal data necessary for each specific purpose. For example, account registration requires only a name and work email address; additional details are requested only as operationally necessary for billing or support purposes.
- Private workspaces by default: All new workspaces are private and isolated. Candidate data cannot be made publicly accessible through any default platform configuration — sharing or export requires an explicit action by an authorised user of the subscribing organisation.
Privacy considerations in the AI matching feature
The privacy implications of TalentZora's AI-powered CV matching feature — including data minimisation in AI processing, discrimination risk, transparency of outputs, access restrictions, and security of AI-processed content — were assessed and documented as part of the platform design process. These documented considerations informed the privacy-by-design measures described in this section and throughout this Policy, including: the architectural decision to transmit only extracted CV and JD text (not encrypted database fields or contact details) to AI processing services; the restriction of AI matching outputs to decision-support tools requiring human review rather than automated hiring decisions; the implementation of non-discrimination guidelines aligned with TAFEP; and the encryption of all AI-generated match outputs under the same DEK-based architecture as the source candidate data. Records of these design considerations are maintained internally and are available to enterprise subscribers upon request under a non-disclosure agreement.
15. Staff Training and Data Protection Governance
Finploy Technologies Pte. Ltd. maintains internal data protection awareness and governance practices among staff members with access to platform systems or personal data. These include:
- Briefing all staff with system access on their obligations under the PDPA and on TalentZora's internal data handling policies and procedures.
- Restricting production system access to personnel with a documented, legitimate operational need.
- Requiring multi-factor authentication for all administrative access to production infrastructure.
- Maintaining access logs for production system access, so that any access to encrypted personal data fields (for example, for an authorised support investigation) is recorded and attributable.
- Reviewing access permissions whenever staff roles change or employment ends.
- Maintaining this PDPA Policy and associated internal data handling procedures as living documents, reviewed at least annually or whenever there is a material change to services, technology, or Singapore data protection law.
Staff members are not permitted to access, copy, or transmit decrypted personal data from subscribing organisations' workspaces except where explicitly authorised by the subscribing organisation for support purposes, or where required by law or regulatory authority.
16. Sub-processors and Third-Party Data Processors
Finploy Technologies Pte. Ltd. engages third-party sub-processors in the delivery of TalentZora. Each sub-processor is engaged under data processing terms that require them to maintain appropriate data protection standards comparable to those required under the PDPA. The following categories of sub-processors are currently engaged:
- Amazon Web Services (AWS) — Cloud infrastructure and data storage. Production infrastructure, databases, and file storage are hosted on AWS in the ap-south-1 region (Mumbai, India). All personal data fields are encrypted at the application level before storage, meaning customer content is not stored in plaintext form in our databases or object storage. Decryption occurs only within controlled application processes when necessary to perform a platform function requested by the subscribing organisation. Subscribing organisations that require Singapore-region data hosting may request a deployment on AWS ap-southeast-1 — please contact us to discuss availability.
- Google — AI processing services. CV and JD text content is transmitted to Google AI services for parsing, text extraction, and matching output generation. Some processing may occur on servers located outside Singapore. All transmissions are made over encrypted HTTPS connections. Google processes this data solely to generate the requested parsing or matching output on behalf of TalentZora.
- Stripe — Payment processing. Subscription billing, payment card processing, and transaction management are handled by Stripe. Stripe is PCI DSS Level 1 compliant. Full payment card details are processed and stored by Stripe; they are not transmitted to or stored on TalentZora's own servers.
- Email delivery provider — Transactional email. Used for sending OTP verification codes, account verification emails, subscription confirmations, and system notifications. Email content processed by this provider may include the recipient's name and email address.
We review our sub-processor arrangements periodically and will update this section if sub-processors are added or changed in a manner that materially affects how personal data is processed. Where practicable, subscribing organisations will be notified in advance of any material change to our sub-processor register.
17. How to Raise a Complaint with the PDPC
If you have a concern about how Finploy Technologies Pte. Ltd. has handled your personal data, we encourage you to contact our Data Protection Officer first at support@talentzora.com (subject line: Attention: Data Protection Officer) so that we may attempt to resolve the matter directly. We will acknowledge your complaint within 3 business days and provide a substantive response within 30 calendar days.
If you are not satisfied with our response, or if you believe that we have failed to comply with our obligations under the PDPA, you may refer the matter to the Personal Data Protection Commission (PDPC) of Singapore:
- Website: pdpc.gov.sg
- Helpline: 6377 3131
- Online complaint form: Available through the PDPC's website at pdpc.gov.sg
- Address: Personal Data Protection Commission, 10 Pasir Panjang Road, #03-01 Mapletree Business City, Singapore 117438
The PDPC has the statutory power to investigate complaints, issue directions for organisations to remedy non-compliance, and impose financial penalties where the PDPA has been contravened. Lodging a complaint with the PDPC does not affect any right you may have to pursue civil legal remedies through the courts.
18. Document Version Control
This PDPA Policy is a controlled document. It is reviewed and updated as needed to reflect changes in our services, technology, guidance issued by the PDPC, or amendments to Singapore data protection law. The effective date at the top of this page indicates when the current version was published.
- Version 1.0 — 24 June 2026: Initial published version. Covers all applicable PDPA obligations, full encryption architecture disclosure (AES-256, KEK/DEK envelope encryption), scope of encrypted data, DEK deletion and irreversible inaccessibility, sub-processor register, Data Portability Obligation (introduced by the PDPA 2020 amendment), Data Protection by Design section, staff governance practices, and PDPC complaint procedure.
- Version 1.1 — 8 July 2026: Material additions. Added: NRIC/FIN handling clause; detailed cross-border data transfers subsections (Sections 9.1–9.5) covering why data is transferred, safeguards, end-to-end protection chain, who can access data overseas, and contractual protections — with AWS hosting region corrected to ap-south-1 (Mumbai, India) as default; 72-hour breach notification commitment to subscribing organisations (Section 10); candidate data subject rights routing added to Section 5; backup and legal hold carve-outs added to DEK deletion section (Section 7); internal security investigation exception added to access policy (Section 7); Enterprise DPA cross-reference with published link added (Section 19); governing law clause added (Section 20); 30-day material amendment notice with termination right added (Section 12).
Material updates to this Policy will be communicated to subscribing organisations by email notification sent to the registered account email address, and will be published on this page with a revised effective date. Where required by law, we will provide advance notice of material changes. Previous versions of this Policy are available on request by emailing support@talentzora.com.
19. Enterprise Data Processing Agreement
This PDPA Policy sets out Finploy Technologies Pte. Ltd.'s data protection practices in the context of a public-facing compliance framework. For subscribing organisations that require a bilateral, signable agreement specifically governing the data intermediary relationship, we offer a separate Data Processing Agreement (DPA) that supplements this Policy with contractual provisions covering:
- Processing instructions and permitted purposes.
- Security and confidentiality obligations of the data intermediary.
- Sub-processor appointment and flow-down obligations.
- Breach notification and cooperation duties.
- Data return and deletion on contract termination.
- Audit rights and assistance with customer PDPA compliance obligations.
Our full DPA is published at talentzora.com/dpa. To request a countersigned hard-copy version or discuss custom data processing terms, contact us at support@talentzora.com with the subject line "Data Processing Agreement Request".
20. Governing Law
This PDPA Policy is governed by, and construed in accordance with, the laws of the Republic of Singapore. Any dispute arising out of or in connection with this Policy shall be subject to the non-exclusive jurisdiction of the Singapore courts.