Contents
1. Who we are
2. Information we collect
3. Recruiter-uploaded candidate data
4. How data is used
5. Private workspace principle
6. Data security and encryption
7. Cookies and browser data
8. Data retention
9. Deletion and export
10. Your rights
11. Contact
12. Automated decision-making
13. Lawful basis for processing
14. Marketing communications
15. Third-party websites
16. Children and minors
17. Sub-processors
18. How to exercise your rights
19. Complaints
20. Policy version history
21. Governing law
Definitions
The following key terms are used throughout this Privacy Policy:
- Personal Data — data about an individual who can be identified from that data, or from that data together with other information we have or may have access to, as defined under Singapore's PDPA.
- Data Controller — the organisation that determines the purposes and means of processing personal data. For personal data relating to user accounts and platform administration, Finploy Technologies Pte. Ltd. is the data controller. For candidate CVs and related data uploaded by a subscribing organisation, that organisation is the data controller.
- Data Processor / Data Intermediary — an organisation that processes personal data solely on behalf of, and under the instructions of, a data controller. Finploy Technologies Pte. Ltd. (operating TalentZora) acts as data intermediary for candidate data uploaded by subscribing organisations.
- Subscribing Organisation — a company, recruitment agency, HR team, or individual business entity that has registered a TalentZora account and subscribed to a plan.
- Workspace — the private, isolated data environment assigned to a subscribing organisation, within which all uploaded CVs, job descriptions, match results, and search history are stored and accessed.
- DEK (Data Encryption Key) — a unique, randomly generated encryption key assigned to each subscribing organisation. All personal data fields in your workspace are encrypted using your DEK before being stored in our database.
- KEK (Key Encryption Key) — a master key held in our server environment. The KEK encrypts each organisation's DEK so the DEK can be stored safely. The KEK is never stored in the database.
- Sub-processor — a third-party service provider engaged by Finploy Technologies Pte. Ltd. to process personal data on its behalf as part of delivering the TalentZora service.
- PDPA — Singapore's Personal Data Protection Act 2012, as amended, including the Personal Data Protection (Amendment) Act 2020.
- PDPC — the Personal Data Protection Commission of Singapore, the statutory authority responsible for administering and enforcing the PDPA.
1. Who we are
TalentZora is a self-service technology platform that provides private AI-powered CV matching, candidate database search, shortlist creation and recruiter productivity workflows. TalentZora is a product operated by Finploy Technologies Pte. Ltd. (UEN 202548778H).
We are committed to protecting the personal data that your organisation entrusts to us and to being transparent about how that data is stored, processed, and secured. This policy describes what we collect, how we use it, and the technical measures — including encryption — that we apply to protect it.
2. Information we collect
We collect different categories of information depending on how your organisation uses TalentZora:
- Account information: name, work email address, company or agency name, and login credentials for the subscribing organisation and its team members.
- Candidate CV data: uploaded PDF, DOC, or DOCX resume files; text extracted from those files including candidate name, contact details, work history, education, skills, certifications, and the stored CV filename.
- Job description (JD) data: job role, department, company name, location, salary range, experience requirements, key responsibilities, role overview, and any other details entered or uploaded when creating a matching job description.
- AI matching outputs: match scores, fit summaries, AI reasoning, strengths and gap analysis, shortlist rankings, and detailed AI report content generated from CV-JD comparisons.
- Search and activity data: smart search queries, AI-generated search insights, candidate shortlist and search history, and platform activity logs.
- Technical data: IP addresses, browser type, device information, session data, and cookies required to operate the platform securely.
- Payment and billing data: billing contact details, payment status, transaction references, and invoice records. Full card numbers are handled by our payment provider and are not stored on our servers.
- Communication data: enquiry messages, support requests, and any correspondence submitted through the contact form or by email.
3. Recruiter-uploaded candidate data
Users must only upload CVs and candidate information where they have the right, permission, consent or other lawful basis to upload, store and process that information for recruitment-related purposes.
For candidate data uploaded into private workspaces, Finploy Technologies Pte. Ltd. (operating TalentZora) acts solely as a data intermediary (data processor) under the PDPA, processing that data only on behalf of and under the instructions of the subscribing organisation. The subscribing organisation is the data controller and is solely responsible for establishing a lawful basis and obtaining any candidate consent required before uploading.
Candidate data uploaded by one organisation is never shared with, visible to, or accessible by any other subscribing organisation. Each organisation's candidate vault is technically isolated at the database level through per-organisation encryption keys.
NRIC and sensitive identifier handling
TalentZora's CV matching and search functions do not require the collection of NRIC (National Registration Identity Card) numbers, FIN (Foreign Identification Number) numbers, passport numbers, or similar national identity identifiers. In accordance with the PDPC's Advisory Guidelines on the NRIC, subscribing organisations are advised to redact full NRIC or FIN numbers from uploaded CVs unless collection is legally required for the specific recruitment process in question (for example, where a role requires government security clearance or where statutory background checks require identity verification). Where such identifiers are present in uploaded CVs, they are stored in encrypted form in the subscribing organisation's private workspace, subject to the same AES-256 encryption and DEK-based access controls as all other candidate personal data.
Enterprise Data Processing Agreement
Subscribing organisations may request execution of a Data Processing Agreement (DPA) that supplements this Privacy Policy with contractual provisions covering processing instructions, security commitments, audit rights, sub-processor obligations, breach cooperation duties, and data return and deletion terms. Our full DPA is available at talentzora.com/dpa. To request a countersigned copy or discuss custom terms, contact us at support@talentzora.com with the subject line "Data Processing Agreement".
4. How data is used
Uploaded CVs and JDs are used to parse information, generate matching outputs, support searchable vault features, create exports and maintain user account functionality.
To provide parsing and matching, uploaded CVs and job descriptions are processed using third-party infrastructure and AI service providers. This includes cloud infrastructure hosted on Amazon Web Services (AWS) in the ap-south-1 region (Mumbai, India) and AI processing services (Google) used to parse CVs and generate matching outputs. Some AI processing may also take place on servers located outside India, including in the United States. As our infrastructure is located outside Singapore, all personal data processed by TalentZora is subject to the PDPA's Transfer Limitation Obligation. We address this obligation by requiring all sub-processors — including cloud hosting and AI processing providers — to maintain data protection standards comparable to those required under the PDPA through applicable data processing terms, and by ensuring all data transmissions occur exclusively over encrypted HTTPS connections.
We do not use uploaded candidate data to train general AI models, build shared candidate databases, or serve advertising. Data processed for one organisation's matching requests is not used for any other organisation's benefit. We require our AI service providers, by contract, not to use customer CV or JD content to train or fine-tune their own general AI models, except where expressly instructed or separately agreed in writing.
Deployment models
TalentZora is available under two deployment models:
- SaaS (hosted): TalentZora hosts the platform and all data on its own AWS infrastructure (ap-south-1, Mumbai, India). Subscribing organisations that require data to be hosted within Singapore may request a Singapore-region deployment on AWS ap-southeast-1 — please contact us to discuss availability.
- On-premise installation (available on request): For subscribing organisations that require complete data sovereignty, TalentZora can be deployed within the client's own cloud account or server environment. In this model, all candidate and organisational data remains exclusively within the client's own infrastructure — TalentZora has no access to or custody of client data. TalentZora provides ongoing platform maintenance and technical support under a subscription arrangement. This deployment model is built on demand — contact us to discuss your requirements.
Overseas processing and cross-border data transfers
Where your data is processed and stored: All personal data uploaded to TalentZora — including candidate CVs, job descriptions, match results, and account information — is processed and stored on Amazon Web Services (AWS) infrastructure located in the Asia Pacific (Mumbai) region, India (AWS ap-south-1). This is TalentZora's default production hosting region for all standard subscriptions. Because this infrastructure is located outside Singapore, all personal data processed through TalentZora is transferred outside Singapore and is therefore subject to the Transfer Limitation Obligation under Part 9 of Singapore's Personal Data Protection Act 2012 (PDPA). TalentZora complies with this obligation through the contractual, technical, and organisational safeguards described in this section.
Subscribing organisations with specific data residency requirements may request a Singapore-hosted deployment on AWS ap-southeast-1. Please contact us at support@talentzora.com to discuss availability and applicable terms.
Why personal data is transferred outside Singapore
Personal data is transferred to AWS infrastructure in Mumbai for the following operational reasons:
- Platform hosting and storage: TalentZora's web application, database servers, and object file storage systems operate on AWS ap-south-1 infrastructure. All candidate records, job descriptions, AI match results, search history, and account data are stored on this infrastructure to deliver the platform's core functionality. Without this transfer, the platform cannot operate.
- AI parsing and matching: CV and job description text content is transmitted to Google AI services (located outside Singapore, including in the United States) for automated text extraction, field parsing, and matching output generation. This transfer is necessary to provide the platform's AI-powered screening and matching features.
- Payment processing: Subscription billing and payment card data is transmitted to Stripe for payment processing and transaction management. Stripe operates internationally and processes transaction data outside Singapore as part of its payment infrastructure.
- Email delivery: Transactional emails (including OTP codes, account notifications, and system alerts) are delivered via a third-party email provider. These transmissions may involve processing of name and email address outside Singapore.
What technical and organisational safeguards are implemented
TalentZora implements the following safeguards for all personal data processed overseas, ensuring that the standard of protection is comparable to that required under the PDPA:
- Encryption at rest — AES-256-CBC: All personal data fields stored in TalentZora's database are encrypted using AES-256-CBC (Advanced Encryption Standard, 256-bit key length, Cipher Block Chaining mode) before storage. This includes candidate names, contact details, CV text, job description content, AI match results, and search history. No personal data is stored in plaintext on any AWS infrastructure. AES-256 is the same encryption standard mandated by many national security agencies and financial regulators worldwide.
- Per-organisation envelope encryption: Each subscribing organisation's data is encrypted under a unique, randomly generated 256-bit Data Encryption Key (DEK) created exclusively for that organisation. The DEK is itself encrypted by a master Key Encryption Key (KEK) stored outside the database in a controlled server environment. This two-layer architecture means that access to the database alone is insufficient to read any personal data — the KEK must also be obtained from a separate, access-controlled environment. Different organisations' data cannot be cross-decrypted under any circumstance.
- Encryption in transit — TLS: All data in motion between users and TalentZora's servers, and between TalentZora's servers and all sub-processors (AWS, Google, Stripe, email provider), is encrypted using Transport Layer Security (TLS). No personal data is transmitted over unencrypted HTTP connections at any point in the processing chain.
- Physical data centre security (AWS): AWS data centres in the ap-south-1 (Mumbai) region operate under industry-leading physical security controls, including 24/7 on-site security personnel, multi-layer perimeter security, biometric access controls, multi-factor authentication required for facility entry, CCTV surveillance, and environmental monitoring. AWS maintains ISO 27001, SOC 1 (Type II), and SOC 2 (Type II) certifications across its global infrastructure, including in India.
- Access controls — principle of least privilege: Access to TalentZora's production AWS infrastructure is restricted to a small number of authorised technical personnel at Finploy Technologies Pte. Ltd. All administrative access requires multi-factor authentication and is logged. Personnel roles are scoped to the minimum access necessary for their function. No team member has routine, open access to decrypted personal data.
- Data minimisation in overseas transmission: Only the data strictly necessary for each specific processing operation is transmitted to each sub-processor. For AI parsing, CV text is transmitted; encrypted data fields are never further disclosed to AI providers. For payment processing, only billing contact and payment card details are transmitted to Stripe; candidate data is never shared with payment processors.
- Contractual data protection obligations on all sub-processors: All sub-processors are engaged under contractual terms that impose data protection obligations on them. These obligations include: (i) processing data only for the specific purpose for which it was shared; (ii) maintaining confidentiality; (iii) implementing appropriate technical and organisational security measures; (iv) not further disclosing personal data to third parties without prior authorisation; (v) cooperating with TalentZora in responding to data subject rights requests and breach notifications; and (vi) complying with applicable data protection laws.
Who can access your personal data overseas
Access to personal data held on overseas infrastructure is strictly limited to the following:
- Finploy Technologies Pte. Ltd. authorised technical personnel: A small number of engineers with administrative access to TalentZora's AWS infrastructure for operations, maintenance, and security purposes. All access requires multi-factor authentication, is logged, and is restricted to the minimum necessary for the operational task. These personnel do not have routine access to decrypted personal data, as decryption requires the KEK held in a separate controlled environment.
- AWS infrastructure personnel (hypervisor level only): AWS's own operations personnel maintain the physical infrastructure, hypervisor, and data centre layer. AWS personnel do not have access to customer data stored within AWS services — this is a fundamental principle of AWS's shared responsibility model, under which AWS is responsible for the security of the cloud infrastructure, while TalentZora is responsible for the security of the data within it. AWS does not inspect, copy, or use customer data stored in its services.
- Google AI services (CV and JD text only, for parsing): CV and JD text content is transmitted to Google's AI APIs for parsing and matching. Google processes this content under its API service terms, which include confidentiality obligations, restrictions on use for training general AI models (except where separately agreed), and data protection commitments applicable to API data.
- Stripe (billing data only): Payment card and billing contact data is transmitted to Stripe for payment processing. Stripe does not receive or process any candidate data. Stripe is PCI DSS Level 1 certified, the highest level of payment security compliance.
- No other parties: Personal data is not shared with, sold to, disclosed to, or accessed by any other overseas parties, except as required by applicable law or expressly instructed in writing by the subscribing organisation.
How we comply with PDPA's Transfer Limitation Obligation
Singapore's Transfer Limitation Obligation (PDPA, Part 9, Section 26) requires that before transferring personal data to a country or territory outside Singapore, an organisation must ensure that the recipient of the personal data is bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPA. TalentZora addresses this obligation as follows:
- AWS (Mumbai, India): AWS operates under comprehensive data processing terms — the AWS Data Processing Addendum — which bind AWS to implement appropriate security measures, maintain confidentiality, process data only as instructed, and comply with applicable data protection laws. AWS India's data processing practices are governed by AWS's global privacy and security framework, which provides protections comparable to those required under the PDPA.
- Google AI services: Google processes API data under its Cloud Data Processing Addendum and applicable API terms, which include data protection obligations, confidentiality requirements, and security standards comparable to those required under the PDPA.
- Stripe: Stripe operates under its Data Processing Agreement, which includes GDPR-compliant standard contractual clauses and security measures that provide protection comparable to or exceeding the PDPA standard.
- Technical safeguards as additional layer: In addition to contractual protections, TalentZora's AES-256 encryption architecture provides an independent technical safeguard. Because personal data is encrypted before leaving TalentZora's controlled application environment, sub-processors receive data in a form that provides meaningful protection even in the event of a sub-processor's own security incident.
Notwithstanding overseas processing, TalentZora remains fully accountable to subscribing organisations and to the PDPC under Singapore's PDPA. All your rights under the PDPA — including access, correction, withdrawal of consent, and data portability — apply equally to data held on overseas infrastructure. Data breach notification obligations apply regardless of where a breach occurs. To exercise any right or raise any concern about overseas processing, contact our Data Protection Officer at support@talentzora.com (subject line: Attention: Data Protection Officer).
5. Private workspace principle
TalentZora is designed around private account workspaces. Recruiter-owned candidate data is not displayed publicly or shared into a common marketplace. Every subscription operates as an isolated vault — only users authorised by the subscribing organisation can access that organisation's candidates, job descriptions, and match results.
TalentZora is a software tool. We are not a recruitment marketplace, a staffing platform, or a public candidate directory. Your data exists within TalentZora solely to serve your organisation's own screening and matching workflows.
6. Data security and encryption
TalentZora uses a layered approach to data security that includes access controls, tenant isolation, secure file storage, audit logs, signed download links, and administrator controls. At the core of this is an encryption system that protects all candidate and job data stored on our servers.
Encryption at rest
All sensitive personal data stored in our database — including candidate names, contact details, CV text, job description content, AI match results, and search history — is encrypted at rest using AES-256-CBC, an industry-standard symmetric encryption algorithm widely used to protect sensitive data.
Envelope encryption: how your encryption key works
We use an envelope encryption architecture to maximise data isolation between subscribing organisations. Two layers of keys are involved:
- Key Encryption Key (KEK): A master key held securely in our server environment, outside the database. The KEK is used to wrap (encrypt) each organisation's unique data key so it can be stored safely.
- Data Encryption Key (DEK): A unique, randomly generated encryption key that is created for your organisation when your account is set up. The DEK is stored in encrypted form (wrapped by the KEK). The DEK is what actually encrypts and decrypts all of your organisation's candidate and job data.
This means that even if our database were accessed without authorisation, the encrypted data fields cannot be read without the correct DEK — and the DEK itself can only be unwrapped using the KEK, which is stored separately outside the database.
What data is encrypted
The following personal data fields are encrypted using your organisation's DEK before being stored in our database:
- Candidate data: name, email address, phone number, full CV text (parsed content), current company, current designation, core skills, education details, past companies, total years of experience, and the stored CV filename.
- Job descriptions: job role, department, company name, location, salary, experience requirements, role overview, key responsibilities, job requirements, education requirements, contact person name, contact designation, contact phone, contact email, and the full JD text.
- AI match results: match scores, fit summaries, AI reasoning, bullet-point analysis, and verdicts generated for each candidate-JD comparison.
- Smart search history: search queries entered, AI-generated messages and insights, and candidate lists returned.
Non-sensitive identifiers such as internal record IDs, foreign keys, timestamps, and status flags are not encrypted, as they are required for database operations and do not contain personal data.
DEK deletion and data inaccessibility
If your organisation's DEK is deleted — for example, upon account closure or a data erasure request — all encrypted data in active storage associated with your organisation becomes permanently inaccessible. Without the DEK, the encrypted data stored in our database cannot be decrypted by anyone, including TalentZora staff. This is a deliberate design choice that gives subscribing organisations a strong, technically enforced data erasure guarantee.
Backups: Our production systems maintain automated encrypted backups for disaster recovery purposes. These backups are retained on a standard rotation cycle and are automatically purged when the backup retention period expires. We do not actively restore encrypted backup data for the purpose of recovering data following a DEK deletion request. Any residual encrypted data remaining in backup snapshots after DEK deletion will be unreadable without the DEK and will be permanently purged when the backup rotation cycle completes.
Legal holds: Where data is subject to an active legal hold, pending litigation, regulatory investigation, or a competent authority instruction to preserve specific records, a deletion request affecting those records may be paused or partially deferred. We will notify the requesting organisation if a legal hold prevents full compliance with a deletion request. Deletion will be completed as soon as the legal or regulatory hold is lifted.
TalentZora's commitment on data access
TalentZora operates in a position where it could technically retrieve your organisation's DEK and decrypt your data, since the KEK and the encrypted DEK are both within our infrastructure. We commit clearly that we will not decrypt your organisation's data without your explicit permission.
The only circumstances in which we may access or temporarily decrypt specific data are:
- At your explicit request: If you raise a support issue that requires us to inspect a specific data record — for example, a candidate's parsed CV text appears garbled or a match result is displaying incorrectly due to an encryption or parsing issue — we may, with your explicit acknowledgement, access that specific field to diagnose and resolve the problem. We will only look at the minimum data necessary to resolve your reported issue.
- Internal security incident investigation: If TalentZora has credible grounds to believe that a security incident, suspected unauthorised access, fraud, or material breach of our Terms of Use is actively affecting your workspace or our platform, we may access the minimum data necessary to investigate and contain the incident. This access is restricted to authorised security personnel, independently logged, and we will notify the affected subscribing organisation as soon as it is safe to do so without prejudicing the investigation.
- Legal obligation: Where we are required by law, a court order, or a regulatory authority to disclose specific data.
We do not routinely access, read, or review the content of your uploaded CVs, job descriptions, or AI match results for any purpose other than delivering the platform's technical functions.
Encryption in transit
All data transmitted between your browser or application and TalentZora's servers is encrypted in transit using Transport Layer Security (TLS). This applies to CV uploads, JD submissions, login sessions, API calls, and all other communications with the platform. We do not serve the platform over unencrypted HTTP connections.
When uploaded CV and JD content is sent to third-party AI processing services for parsing and matching, it is transmitted over encrypted HTTPS connections. Data is not sent to any AI provider in plaintext over unencrypted channels.
Physical and infrastructure security
TalentZora's production infrastructure is hosted on Amazon Web Services (AWS) in the ap-south-1 region (Mumbai, India). AWS data centres are protected by multi-layered physical security controls including 24/7 manned security, biometric access controls, video surveillance, and environmental controls. TalentZora does not operate its own physical data centres — all infrastructure is provisioned on AWS's enterprise-grade cloud platform.
Database servers are not directly accessible from the public internet. Application-level access controls ensure that only authenticated, authorised requests can retrieve data, and all data is stored on encrypted storage volumes at the infrastructure level, in addition to the application-level AES-256 encryption applied to personal data fields.
Access controls and authentication
Access to TalentZora's production systems is restricted to authorised personnel only. Team members of Finploy Technologies Pte. Ltd. do not have open access to customer data. Administrative access to production infrastructure requires multi-factor authentication and is logged. Access permissions follow the principle of least privilege — personnel are granted only the access needed to perform their specific role.
All subscribing organisation users are authenticated via email-verified login before accessing their workspace. Sessions are protected with CSRF tokens and automatically expire after a period of inactivity.
7. Cookies and browser data
TalentZora uses essential session cookies to maintain login state and to protect form submissions against cross-site request forgery (CSRF). These cookies are required for the platform to function and are removed when you close your browser or log out.
We may collect basic usage data — such as which pages are visited and which platform features are used — to understand how the platform performs and to improve it. This data is aggregated, does not identify individual users, and does not contain personal data from uploaded CVs or job descriptions.
Types of cookies we use
- Strictly necessary cookies: These cookies are required for the platform to function. They include session authentication tokens, CSRF protection tokens, and login state cookies. Without these cookies, you cannot log in or use the platform. These cookies do not track you across websites and cannot be disabled without disabling the platform itself.
- Functional cookies: These cookies remember preferences and settings within your session, such as your selected plan filter or interface preferences. They improve your experience but are not essential to core functionality.
- Analytics cookies: We may use privacy-respecting analytics tools to collect aggregated, anonymised data about how users navigate the platform — for example, which features are used most frequently or where users encounter friction. This data does not identify individuals and is not linked to uploaded candidate data.
Managing your cookie preferences
You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. If you block strictly necessary cookies, the platform will not function correctly and you will not be able to log in. Deleting cookies will log you out of your current session. For more information on managing cookies, refer to your browser's help documentation.
8. Data retention
We retain account information, uploaded candidate data, job descriptions, and match results for as long as your subscription is active and for a reasonable period thereafter to handle support requests, billing queries, or legal obligations.
When your organisation's account is closed or a data deletion request is processed, your DEK is deleted. Once the DEK is deleted, all encrypted personal data associated with your organisation becomes permanently inaccessible — this is the technical equivalent of secure erasure. Non-encrypted operational records (such as billing records and anonymised usage logs) may be retained for the periods required by applicable law.
Retention schedule
The following guidelines describe how long we generally retain different categories of data:
- Active subscription data (candidate CVs, JDs, match results, search history): retained for the full duration of your active subscription.
- Account information (name, email, company details): retained for the duration of your subscription and for up to 90 days after account closure to facilitate any final billing queries or reactivation requests.
- Billing and payment records: retained for a minimum of 5 years from the date of the transaction, as required for financial record-keeping and tax compliance under Singapore law.
- Support and communication records: retained for up to 2 years from the date of the last communication, to allow us to handle follow-up requests or disputes.
- Anonymised usage analytics: retained indefinitely in aggregate form, as they contain no personal data.
- Legal hold data: where data is subject to a legal hold, regulatory request, or active dispute, the relevant data may be retained beyond the above periods for as long as required.
- General enquiries and contact form submissions (non-subscribing visitors): retained for up to 12 months from the date of submission or last contact, then deleted or anonymised. If you subsequently subscribe, your contact record is merged with your account record and subject to the subscriber retention periods above.
9. Deletion and export
Users can request export or deletion of their workspace data, subject to operational, legal and contractual limitations.
You may export your shortlisted candidates and match results in Excel format directly from the platform's export feature. For a full account data erasure, contact us at support@talentzora.com and we will process the deletion of your DEK and all associated encrypted data. Once the DEK is deleted, all encrypted personal data in active storage becomes permanently inaccessible. Encrypted backups are retained on our standard backup rotation cycle and are automatically purged when the cycle completes — we do not restore backup data following a DEK deletion request. Note that exports you have already downloaded to your own systems remain your responsibility to delete.
10. Your rights
Rights of subscribing organisations
As a subscribing organisation, you have the following rights in relation to personal data that Finploy Technologies Pte. Ltd. holds about you in your capacity as an account holder — including account contact information, billing records, and platform usage data:
- Request access to personal data we hold about your account, organisation, or subscription.
- Request correction of inaccurate personal data in your account records.
- Withdraw consent for data processing (subject to the contractual obligations under your active subscription agreement and applicable law).
- Request erasure of your workspace data, which we implement via DEK deletion — permanently rendering all encrypted candidate and job data in your workspace inaccessible and unrecoverable.
- Lodge a complaint with the PDPC if you believe your data rights have not been respected.
To exercise any of these rights as a subscribing organisation, contact us directly at support@talentzora.com.
Rights of individual candidates
For personal data that has been uploaded into TalentZora by a subscribing organisation (for example, a candidate's CV uploaded by a recruitment agency or HR team), Finploy Technologies Pte. Ltd. acts as a data intermediary — processing that data solely on behalf of, and under the instructions of, the subscribing organisation, which is the data controller for that data.
If you are an individual candidate whose CV or personal data has been uploaded to TalentZora by a recruiting organisation, your primary point of contact for exercising your PDPA rights — including access, correction, withdrawal, deletion, or portability — is the organisation that uploaded your data, not TalentZora directly. We will only process data requests relating to candidate data on the written instruction of the relevant subscribing organisation, or where we have an independent legal basis to do so.
If you are unable to identify or contact the subscribing organisation that holds your data, contact us at support@talentzora.com and we will provide reasonable assistance in routing your request to the correct data controller.
Security incident notification
If TalentZora confirms that a security incident has occurred that affects your organisation's workspace data, we will notify the affected subscribing organisation without undue delay and in any event within 72 hours of confirming the breach. Our notification will include the nature of the incident, the personal data categories and approximate volume of records affected, the likely consequences, and the remediation steps we have taken or intend to take. We will provide reasonable assistance to help the subscribing organisation assess its own notification obligations under the PDPA.
11. Contact
For privacy requests, contact support@talentzora.com.
12. Automated decision-making and AI-generated outputs
TalentZora uses artificial intelligence to parse uploaded CVs, extract structured data from unstructured documents, and generate match scores, fit summaries, and detailed reports comparing candidates against job descriptions. These outputs are decision-support tools, not final decisions.
No employment, hiring, or recruitment decision is automated solely by TalentZora. The platform provides ranked shortlists, match scores, identified skills gaps, and AI reasoning — but all final decisions on candidate selection, interview, or offer remain with your organisation's HR team or recruiters.
AI-generated match scores, fit summaries, and report outputs should be reviewed critically by human decision-makers. TalentZora does not guarantee the accuracy, completeness, or fitness-for-purpose of AI outputs for any specific hiring context. We recommend that users apply professional judgement alongside any platform output before making candidate-related decisions.
Where AI outputs relate to an identifiable individual (for example, a named candidate's parsed CV and match result), those outputs are subject to the same data protection obligations as the underlying personal data, and are encrypted and stored in the same way as all other personal data on the platform.
Non-discrimination: TalentZora's AI matching system is designed to assess candidate-role fit based on skills, experience, qualifications, and competency signals extracted from CVs and job descriptions. The platform is not designed to use, and we do not instruct our AI service providers to use, protected characteristics — such as age, race, nationality, religion, gender, marital status, or disability — as positive or negative scoring inputs. Subscribing organisations are responsible for ensuring that their use of TalentZora's outputs complies with Singapore's Tripartite Guidelines on Fair Employment Practices (TAFEP) and applicable employment law. All significant candidate selection decisions should involve human review and professional judgement.
Privacy considerations in AI matching design
The privacy implications of TalentZora's AI-powered CV and JD matching feature — including data minimisation in AI processing, discrimination risk, transparency of AI outputs, access restrictions on AI-processed content, and the security of content transmitted to AI providers — were assessed and documented during the platform's design and development phase. These documented considerations informed the privacy-by-design choices described throughout this policy, including: the decision to transmit only CV and JD text content (not full encrypted records or candidate contact details) to AI processing services; the restriction of AI match outputs to decision-support tools requiring human review and professional judgement rather than automated hiring decisions; the implementation of non-discrimination guidelines aligned with Singapore's TAFEP guidelines; and the encryption of all AI-generated match results, scores, and reasoning outputs under the same per-organisation DEK-based architecture as the underlying candidate data. Documentation of these design-phase privacy considerations is maintained internally and is available to enterprise and institutional subscribers upon request under a non-disclosure agreement.
13. Lawful basis for processing
Under Singapore's PDPA, we collect, use, and disclose personal data only with the consent of the individual or where an applicable exception under the PDPA applies. Our processing is based on the following:
- Consent: When you or your team members register for a TalentZora account, accept our Terms of Use, or submit an enquiry through our contact form, you provide consent for us to collect and use your personal data for the purposes described in this policy. You may withdraw consent at any time by contacting us, though withdrawal may affect our ability to provide certain features or maintain an active subscription.
- Contractual performance: Certain processing — including operating your subscription account, processing payments, delivering platform services, and providing customer support — is necessary to fulfil our contractual obligations to you under the Terms of Use and falls within the purposes you would reasonably expect as a condition of service.
- Legitimate interests exception (Third Schedule, PDPA): We may process certain operational and technical data — such as security logs, fraud detection, and platform performance analytics — under the legitimate interests exception where we have assessed that our interests do not override the rights and interests of the individuals concerned. An internal assessment has been conducted in relation to such processing and is available on request.
- Deemed consent by notification: Where we introduce a new use of personal data we already hold and provide individuals with reasonable prior notice and an opportunity to opt out before the new use begins, processing may proceed under the deemed consent by notification pathway introduced by the PDPA 2020 amendments.
- Legal obligation: Where we are required by Singapore law, a court order, or a competent regulatory authority to process or disclose personal data, we do so to comply with that legal obligation.
For candidate data uploaded by subscribing organisations, processing takes place solely on the instructions of the subscribing organisation (the data controller), and Finploy Technologies Pte. Ltd. acts as a data intermediary. The subscribing organisation is responsible for establishing and maintaining its own lawful basis for collecting and uploading candidate data to the platform.
14. Marketing communications
If you have subscribed to TalentZora or submitted an enquiry through our contact form, we may send you service-related communications such as account notifications, platform updates, billing information, policy changes, and security alerts. These communications are necessary for the operation of your account and cannot be opted out of while your subscription is active.
Where we send non-essential marketing or promotional communications (such as product announcements, new features, or event invitations), we will do so only where you have provided consent or where we have a legitimate interest in contacting you as an existing customer. You may opt out of marketing communications at any time by emailing support@talentzora.com with the subject "Unsubscribe" or by following the unsubscribe link in any marketing email. Opting out of marketing communications does not affect service-related communications.
15. Third-party websites and links
The TalentZora platform and our website may contain links to third-party websites, tools, or resources. These external sites are not operated by us and are not covered by this Privacy Policy. We have no control over the content, privacy practices, or data handling of third-party websites and are not responsible for their practices.
We recommend that you review the privacy policy of any third-party website you visit through a link from our platform. The inclusion of a link does not imply endorsement of that website or its privacy practices.
16. Children and minors
TalentZora is a B2B SaaS platform designed exclusively for use by businesses, recruitment agencies, and HR professionals. As a matter of policy, Finploy Technologies Pte. Ltd. restricts platform registration and use to individuals aged 18 and above. This is a self-imposed policy threshold of Finploy Technologies Pte. Ltd. — Singapore's PDPA does not prescribe a statutory minimum age of consent for personal data collection. Subscribing organisations are responsible for ensuring that all account users they authorise are aged 18 or above.
If you believe that a minor has provided personal data through our platform without appropriate parental or guardian consent, please contact us immediately at support@talentzora.com and we will take steps to delete that data as soon as reasonably practicable.
17. Sub-processors and service providers
To deliver the TalentZora service, we engage third-party service providers ("sub-processors") who process personal data on our behalf. We require all sub-processors to maintain appropriate data protection standards and enter into data processing agreements where required. The following sub-processors are currently engaged:
- Amazon Web Services (AWS), ap-south-1 (Mumbai, India): Cloud infrastructure, database hosting, and file storage. All personal data fields are encrypted at the application level before storage — see Section 6 for the full encryption architecture. Subscribing organisations that require Singapore-region data hosting may request a deployment on AWS ap-southeast-1 — please contact us to discuss availability.
- Google (AI processing services): Used for CV parsing and AI-assisted CV-JD matching outputs. CV and JD text content is transmitted to Google's AI services over encrypted HTTPS connections for the purpose of generating parsing and matching outputs. Google's data processing is governed by their applicable enterprise data processing terms.
- Stripe (Payment processor): Payment card processing, subscription billing, and transaction management. Stripe is PCI DSS Level 1 compliant. Full card details are processed and stored by Stripe and are not accessible to TalentZora's systems.
- Email service provider: Used for transactional emails including OTP delivery, account notifications, and support correspondence.
We review our sub-processor list periodically and will update this policy if we add or change sub-processors in a way that materially affects how your personal data is processed. We will notify subscribing organisations of material changes to our sub-processor list by email or in-platform notification.
Security assurance
Finploy Technologies Pte. Ltd. applies application-layer security controls to the TalentZora platform, including the encryption architecture described in Section 6, multi-factor authentication for production infrastructure access, access logging, principle of least privilege for system access, and periodic application security testing. Security documentation — including sub-processor details, data flow information, and information on our security controls — is available to enterprise and institutional subscribers under a non-disclosure agreement for the purpose of vendor security due diligence. To request this documentation, email support@talentzora.com.
18. How to exercise your rights
To exercise any of your rights under this Privacy Policy or Singapore's PDPA, you may contact us at support@talentzora.com. Please include the following information to help us process your request efficiently:
- Your full name and the email address associated with your TalentZora account.
- The name of your subscribing organisation.
- The specific right you wish to exercise (e.g., access, correction, erasure).
- Any relevant context that will help us locate the specific data you are requesting.
We will acknowledge receipt of your request within 3 business days and aim to respond in full within 30 calendar days. Where a request is complex or we receive multiple requests from the same party, we may extend the response period and will inform you if this is the case. We may verify your identity before processing any request.
There is no charge for submitting a data request. However, where requests are manifestly unfounded, excessive, or repetitive, we reserve the right to charge a reasonable administrative fee or decline to act on the request, consistent with what is permitted under applicable law.
19. Complaints
If you have a concern about how we have handled your personal data, we encourage you to contact us first so that we can try to resolve the matter directly:
- Email us at support@talentzora.com with the subject line "Privacy Complaint".
- Describe the nature of your concern and the specific data handling you believe was incorrect or unlawful.
- We will acknowledge your complaint within 3 business days and aim to provide a substantive response within 30 calendar days.
If you are not satisfied with our response, or if you believe we have failed to comply with Singapore's PDPA, you have the right to lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore. The PDPC can be contacted through their website at pdpc.gov.sg or by calling their helpline at 6377 3131. The PDPC is Singapore's statutory authority for personal data protection and has the power to investigate complaints and enforce compliance with the PDPA.
20. Policy version history
This policy is reviewed and updated periodically to reflect changes in our services, technology, and applicable law. The version currently in effect is the version displayed at the top of this page with the "Last updated" date. Previous versions of this policy are available on request.
- 24 June 2026: Initial published version. Covers full encryption architecture disclosure (AES-256, KEK/DEK envelope encryption), sub-processor register, automated decision-making disclosure, lawful basis for processing, data subject rights, and PDPA complaint procedure.
- 8 July 2026: Material additions. Added: NRIC/FIN handling clause; Enterprise DPA cross-reference with link to published DPA; deployment models section (SaaS and on-premise); detailed overseas processing and cross-border transfers section (why data is transferred, safeguards, who can access, PDPA Transfer Limitation Obligation compliance); 72-hour breach notification commitment to subscribing organisations; data subject rights split (subscribing organisations vs individual candidates); backup and legal hold carve-outs for DEK deletion; internal security investigation exception; TAFEP non-discrimination clause for AI matching; legitimate interests assessment and deemed consent by notification basis; governing law clause; retention schedule; 30-day material amendment notice with termination right.
If we make material changes to this policy — for example, adding a new sub-processor, changing how we use your data, or introducing new data retention periods — we will notify subscribing organisations by email to the registered account address at least 30 days before the change takes effect, and will post the updated policy on this page with a revised "Last updated" date. If a subscribing organisation objects to a material change, it may notify us before the effective date to discuss the matter, or may terminate its subscription in accordance with the Terms of Use before the change takes effect. Continued use of the platform after the effective date of a material change constitutes acceptance of the updated policy.
21. Governing law
This Privacy Policy is governed by, and construed in accordance with, the laws of the Republic of Singapore. Any dispute arising out of or in connection with this Privacy Policy — including any question regarding its existence, validity, or termination — shall be subject to the non-exclusive jurisdiction of the Singapore courts, without prejudice to any right to seek injunctive or other equitable relief in any competent court.