Privacy Policy
WhyBrilliant GmbH | Last updated: September 2026
This Privacy Policy (Datenschutzerklärung) explains how WhyBrilliant GmbH collects, uses, stores, and protects personal data in connection with the WhyBrilliant platform and website. It applies to all individuals who interact with us: job seekers and candidates ('Talents'), companies and employers ('Companies'), and website visitors. We process personal data in accordance with the EU General Data Protection Regulation (GDPR / DSGVO), the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG), and the German Telecommunications and Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz – TDDDG).
1. Who We Are (Data Controller)
The data controller (Verantwortlicher) pursuant to Art. 4(7) GDPR is:
WhyBrilliant GmbH
c/o AI Campus Berlin, Max-Urich-Straße 3, 13355 Berlin, Germany
General: hq@whybrilliant.com
Privacy: privacy@whybrilliant.com
Website: www.whybrilliant.com
Data Protection Officer (Datenschutzbeauftragter – DPO)
We have appointed an external Data Protection Officer pursuant to Art. 37 GDPR / § 38 BDSG:
Kertos GmbH
Brienner Str. 41
80333 Munich
Germany
Email: dataprivacy(at)kertos.io
2. What Data We Collect
2.1 Talent and Candidate Data
When you register and use WhyBrilliant as a job seeker or candidate, we process:
- Account and contact data: name, email address, phone number, communication preferences
- Career and profile data: CV/resume, work history, education, skills, certifications, links to professional profiles (e.g. LinkedIn, GitHub, portfolio), job preferences (roles, industries, location, availability, salary expectations)
- Conversation and transcription data: when you use voice or chat features, we transcribe your input in real time and store transcripts, structured extracts (e.g. career preferences, constraints), AI-generated summaries, and metadata (time, duration, channel). You actively initiate voice interactions via a 'Start Call' button; we do not use always-on listening.
- Usage and device data: IP address, browser and device information, log files, feature usage events, session data
- Communications: messages you send us, support exchanges, our communications to you
- Special category data (Art. 9 GDPR): we do not seek to collect special category data. If you voluntarily share sensitive information (e.g. health, disability, religion), we process this only with your explicit consent. Please see Section 2.4 for full details, including our approach to voice data.
2.2 Company and Employer Data
When a company registers and uses WhyBrilliant as an employer, we process:
- Account and contact data: company name, registered address, contact persons' names, job titles, work email addresses, phone numbers
- Billing and payment data: invoicing details, payment information, VAT identification numbers
- Hiring requirements: role descriptions, salary ranges, hiring criteria, and related information you provide
- Communication data: messages exchanged with us, meeting notes, feedback on candidates
- Usage data: login and activity data, feature usage events
- Talent-access records: when someone on your Company's account views a Talent's profile, downloads a Talent's CV, or opens a Talent's professional links on the Platform, we record that access — the acting user, the Talent concerned, the type of access, and the date
2.3 Website Visitor Data
When you visit www.whybrilliant.com without registering, we may collect:
- Technical data: IP address, browser type, device information, referring URL, pages visited, session duration
- Cookie and tracking data: see Section 8.2
2.4 Special Category Data and Voice Data
We do not actively seek to collect special category data (Art. 9 GDPR) such as health data, disability, ethnic or racial origin, religion, or sexual orientation.
Important regarding voice transcripts: voice recordings can incidentally contain or reveal special category information. Our AI systems are designed not to extract, profile, or act on special category attributes from voice transcripts. If you voluntarily share such information and it is transcribed, we process it only to the minimum extent necessary to deliver the service, on the basis of your explicit consent (Art. 9(2)(a) GDPR). You may withdraw consent at any time.
If we were ever to introduce processing of special category data for any other purpose, we would seek fresh explicit consent before doing so.
3. How and Why We Use Your Data
For each processing activity below, we identify the purpose and legal basis.
3.1 For Talents and Candidates
Purpose: Providing the WhyBrilliant service
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
- Creating and managing your profile and account
- Enabling voice and AI-driven career conversations
- Building your candidate profile and generating match signals
- Identifying potentially relevant roles and employers
Purpose: Making your profile and CV visible to matched employers
Legal basis: Art. 6(1)(b) GDPR (performance of contract — being presented to employers hiring for roles you match is the service you signed up for)
- Making your profile visible on the WhyBrilliant platform to an employer hiring for a role that matches it: your name, headline, location, skills, availability and salary expectations, together with our match score for that role and a short written assessment of your fit, which names both what fits and any gaps or risks we see
- Making the CV you uploaded, and the professional links on your profile, available to that employer on the platform. Your CV is your own file, so it may contain your email address and phone number
- This visibility begins when a match is made and does not require a separate opt-in. You can remove your CV, correct your profile, or close your account at any time (see Section 9)
Purpose: Employer introductions — only with your explicit opt-in
Legal basis: Art. 6(1)(a) GDPR (your explicit consent). Consent can be withdrawn at any time. § 26(2) BDSG applies where consent is given in the context of identifying employment.
- Introducing you to a specific employer — connecting you and that employer directly, in a shared email thread — only after you explicitly opt in for that employer
- You can withdraw any Employer Opt-In at any time going forward
Purpose: Service and account communications
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
- Sending you the communications necessary to operate your account and the service: security and account notices, responses to your support requests, and information about material changes to the service or to our policies
- These are transactional communications and carry no promotional content
Purpose: Job-recommendation emails
Legal basis: Art. 6(1)(a) GDPR (your consent). Consent is given separately from acceptance of our Terms of Service and from marketing consent, and can be withdrawn at any time — via the unsubscribe link in any such email or in your account settings — without affecting the lawfulness of processing before withdrawal.
- Emailing you new roles and recommendations matched to your profile, at a frequency reflecting your activity and preferences
- We keep a record of when and how you gave or withdrew this consent
Purpose: Marketing communications (separate and optional)
Legal basis: Art. 6(1)(a) GDPR (your consent — e.g. subscribing to our newsletter)
- Any marketing or promotional emails, such as our newsletter, are a separate and optional preference: they are never bundled with the service communications above and are sent only where you have separately opted in
- You can withdraw consent and unsubscribe from marketing at any time, independently of the job-recommendation emails above
Purpose: Product improvement, quality assurance, and AI quality improvement
Legal basis: Art. 6(1)(f) GDPR (legitimate interest — diagnosing failures and improving matching and conversation quality). You can object to this processing at any time — see the notice at the top of this policy.
- Reviewing conversations with our AI assistant, including the prompts sent to and the responses received from our AI providers, to diagnose quality and safety problems. These records carry your account identifier and are held by our AI observability provider (see Section 8)
- Analysing product usage and feature events, which carry your account identifier rather than your name or email address
- Producing internal reports on matching quality, fairness, and reliability, from which direct identifiers are removed
- We do not use your personal data to train AI models, and we do not permit our AI providers to train their models on it. If that were ever to change, we would ask for your explicit consent first
3.2 For Companies and Employers
Purpose: Providing the WhyBrilliant recruitment service
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
- Setting up and managing your company account
- Facilitating introductions to Talents who have opted in
- Processing fees and invoices
Purpose: Communication and billing
Legal basis: Art. 6(1)(b) GDPR (contract); Art. 6(1)(f) GDPR (legitimate interest)
- Sending candidate shortlists and match notifications
- Service updates, invoicing, and support
Purpose: Recording access to Talent data
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). You can object to this processing at any time — see the notice at the top of this policy.
- Recording which users of your Company viewed a Talent's profile, downloaded a Talent's CV, or opened a Talent's professional links, and when
- We use these records to answer Talents' data-protection requests — telling a Talent which employers have accessed their data (Art. 15 GDPR) and routing a deletion request to an employer that has become an independent controller for that data (see Section 5) — and to administer our agreement with your Company
- Retained for 36 months (see Section 7)
3.3 For Website Visitors
Purpose: Operating and improving the website
Legal basis: Art. 6(1)(f) GDPR (legitimate interest) for strictly necessary technical operation; Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TDDDG for all non-essential analytics, advertising, and tracking technologies
- Technical operation and security of the website
- Analytics, advertising, and remarketing to understand and promote use of the website. We use a number of third-party tools for this
4. Automated Decision-Making and Profiling (Art. 22 GDPR)
We use AI and automated systems to build your candidate profile from what you tell us and upload, to generate match signals, and to rank and filter candidates against each role. This section sets out what is automated, where a person decides, and what you can ask us to do about it.
What is automated. Ranking and filtering are automated. Our systems assess how well a profile fits a role and apply that role's requirements — for example its location, its seniority level, and the skills it calls for. Where a profile does not meet a role's requirements, it is not surfaced for that role, and that outcome is not individually reviewed by a person beforehand. The same applies to the job recommendations we send you. We never surface your profile to your current employer.
Where a person decides. Three points in the process are human decisions:
- Before your profile can be shown to any employer, a member of our team reviews and approves it. Until then, no employer can see or search it.
- Which candidates to pursue for a role is decided by the employer's own hiring team, from the profiles surfaced to them. WhyBrilliant does not make hiring decisions and is not a party to them.
- No employer introduction happens without your explicit Employer Opt-In (see Section 3.1).
Your rights. Because automated ranking and filtering affect which roles you are considered for, you have the right to:
- Request human review of any automated assessment of your profile
- Express your point of view and contest an automated assessment or the match reasons shown to you
- Obtain a meaningful explanation of the logic involved in our matching and its significance. Your dashboard shows the match strength and the main criteria behind it for each role you are matched to; you can ask us for more
- Have inaccurate profile data corrected (Art. 16 GDPR), which changes how you are matched going forward
To exercise these rights, contact privacy@whybrilliant.com. We will respond within one month.
5. Data Sharing
We do not sell your personal data. We share data only as follows:
- With employers / companies: an employer hiring for a role that matches your profile can view your profile, the CV you uploaded, and the professional links on your profile, on the WhyBrilliant platform. We introduce you to a specific employer — connecting you and that employer directly — only after your explicit Employer Opt-In, and we tell you the employer's identity and the categories of data shared before you opt in. Employers are bound by confidentiality and become independent controllers for any Talent data they take into their own systems. We keep a record of employer access to Talent profiles, CVs, and professional links — which employer accessed what, and when — so that we can tell you which employers have seen your data and route a deletion request to any employer holding it.
- With service providers and processors (Auftragsverarbeiter): we use third-party providers for hosting, database and authentication, AI processing, and communication tools, and AI services. All process data on our behalf under written data processing agreements (Art. 28 GDPR). The full sub-processor list is set out in Section 8.1.
- With tracking and analytics tool providers: we use third-party tools on our website for analytics, advertising, and remarketing. Unlike the service providers above, these operate on a consent basis (Art. 6(1)(a) GDPR, § 25(1) TDDDG) rather than as Art. 28 processors for contract performance. This category is set out in Section 8.2.
- For legal compliance: where required by applicable law, court order, or governmental authority, to the extent strictly necessary.
- Business transfers: in the event of a merger, acquisition, or sale of assets, data may transfer to a successor entity under equivalent data protection obligations. Affected individuals will be notified.
6. International Data Transfers
Personal data is primarily processed within the EU/EEA. Transfers to so-called "third countries" only occur in compliance with the requirements of the GDPR and where suitable safeguards are in place. Before data is transferred to a service provider in a third country, the level of data protection is assessed. A transfer only takes place if sufficient protection mechanisms exist. All service providers must enter into a data processing agreement. For providers outside the EEA, additional measures are required. Pursuant to Articles 44 et seq. GDPR, a transfer is only permitted if at least one of the following requirements is met:
- The European Commission has determined that an adequate level of data protection exists.
- Standard Contractual Clauses have been concluded with the recipient.
- Other appropriate safeguards pursuant to Article 46 GDPR are in place.
- In certain exceptional cases as set out in Article 49 GDPR.
7. Retention Periods
We retain personal data only as long as necessary for the relevant purpose or as required by law.
- Talent account and profile data: retained for the duration of your active account. If you stop using your account without deleting it, your data is retained for up to 48 months so you can reactivate it, and for security purposes. Some data may be retained longer where legally required or necessary for the establishment, exercise, or defence of legal claims.
- If you delete your account — from your account settings or by asking us — the deletion is permanent, not a closure. We remove your CV files, your account and profile records, and your login credentials, and we redact residual personal data in the same operation. What remains is only anonymized, aggregate statistics (for example, counts of deleted accounts per week by coarse experience level and region) that cannot identify you and contain no personal data.
- Conversation transcripts and AI-generated summaries: maximum 48 months from creation, on a rolling basis unless earlier deletion is requested.
- Company account and billing data: for the duration of the contractual relationship, plus 10 years pursuant to German commercial and tax law (§§ 238, 257 HGB; § 147 AO).
- Records of employer access to Talent data: 36 months from the access, then deleted. Deleting your Talent account also deletes the access records concerning you.
- Website visitor logs: maximum 30 days for security purposes.
- Cookies and tracking technologies: see the individual retention periods in Section 8.2.
- Data subject request records: 3 years from closure.
8. Third-Party Tools and Sub-Processors
We distinguish two categories of third parties that receive data in connection with the Platform and website. This distinction matters because they operate on different legal bases: service providers process data on our instructions to deliver the service you asked for, while tracking and analytics tools process data only where you have consented, or where the tool is strictly necessary for the website to function.
8.1 Service Providers (Processors, Art. 28 GDPR)
These providers process personal data strictly on our behalf, under written data processing agreements pursuant to Art. 28 GDPR, for the purposes described in Section 3. No separate consent is required for this processing; it is necessary to deliver the service you use (Art. 6(1)(b) GDPR) or to operate it securely (Art. 6(1)(f) GDPR).
| Service Provider | Category | Purpose | Transfer Safeguard |
|---|---|---|---|
| Vercel, Inc. | Hosting & Infrastructure | Next.js application hosting (EU region) | EU region; Vercel is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) |
| Supabase, Inc. | Database, Auth & Storage | PostgreSQL database, user authentication, file storage (EU region) | EU region; SCCs are concluded |
| Google LLC (Gemini API) | AI Processing | Generative AI / LLM processing for matching and conversations (EU region) | EU region; Google is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) |
| ElevenLabs, Inc. | AI Voice | Conversational voice AI and real-time transcription (EU region) | EU region; ElevenLabs is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) |
| Langfuse GmbH | AI Observability | LLM observability, tracing, and performance monitoring (EU region) | EU region; German entity |
| Crustdata, Inc. | Data Enrichment | LinkedIn profile import — retrieves the public profile behind a LinkedIn URL the candidate provides (candidate-initiated, one-off per import) | SCCs |
| PostHog, Inc. | In-product Analytics | Logged-in product usage analytics within the Platform | EU region; PostHog is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) |
| Functional Software, Inc. (Sentry) | Error Monitoring | Application error monitoring and session correlation, strictly necessary for security purposes (EU region) | EU region; Functional Software is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) |
| Mailgun Technologies, Inc. | Transactional Email | Transactional and notification emails (EU region) | EU region; Mailgun is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) |
| Twilio Inc. | Messaging | Delivery and receipt of WhatsApp messages between you and our AI assistant, including your phone number and message content | SCCs |
| LinkedIn Ireland Unlimited Company | OAuth / Integrations | LinkedIn OAuth authentication for profile import | EU entity (Ireland) |
We maintain a current processor list. If we engage new processors that materially affect your data, we will update this policy and notify registered users.
8.2 Tracking and Analytics Tools Used on Our Website
We use the following tools on our website for analytics, advertising, and consent management. Unlike the service providers above, the non-essential tools in this category are used only where you have given consent via our cookie banner (Art. 6(1)(a) GDPR, § 25(1) TDDDG); the cookie management tool itself is strictly necessary.
| Provider | Tool(s) | Purpose | Transfer Safeguard |
|---|---|---|---|
| Google Ireland Limited | Google Analytics, Google Tag Manager, Google Ads (incl. Conversion Tracking and Remarketing), Google reCAPTCHA | Website analytics, advertising and remarketing, tag deployment, bot protection | EU entity |
| Meta Platforms Ireland Ltd. | Meta Pixel | Programmatic advertising and conversion tracking for Facebook/Instagram campaigns | EU entity |
| Microsoft Ireland Operations Limited | Microsoft Advertising (Bing Ads) | Programmatic advertising and conversion tracking for Microsoft/Bing campaigns | EU entity |
| Usercentrics GmbH | Cookiebot | Consent management: recording and storing your cookie preferences. Strictly necessary; no consent required for the tool itself | EU (Germany) |
Some of these tools use the following cookies:
| Cookie Name | Provider | Purpose | Category | Storage Period |
|---|---|---|---|---|
| NID | Stores user preferences and personalizes search results | Preference & Convenience Cookies | 5 mo. 30 d. | |
| _ga | Google Analytics | Distinguishes users via a unique ID for usage analytics | Statistics Cookies | 1 yr. 1 mo. |
| ga[ID] | Google Analytics | Stores state and user interactions for analytic purposes | Statistics Cookies | 1 yr. 1 mo. |
| _gcl_au | Google Tag Manager | Measures ad conversion for website optimization | Marketing/Tracking Cookies | 2 mo. 29 d. |
| _fbp | Meta Pixel | Identifies visitors for targeted Facebook ads | Marketing/Tracking Cookies | 2 mo. 29 d. |
| MUID | Microsoft Advertising | Captures unique user IDs across devices for advertising | Marketing/Tracking Cookies | 1 yr. 25 d. |
| Priority | Microsoft Advertising | Controls the delivery of Microsoft ads | Marketing/Tracking Cookies | Session |
| _uetsid | Microsoft Advertising | Stores session ID to track conversions | Marketing/Tracking Cookies | 1 d. |
| _uetvid | Microsoft Advertising | Stores a unique user ID for ad retargeting | Marketing/Tracking Cookies | 1 yr. 25 d. |
| __cf_bm | Supabase | Differentiates human users from bots; protects against abuse | Strictly Necessary Cookies | 30 min. |
| CookieConsent | Cookiebot | Stores the user's consent status | Strictly Necessary Cookies | 11 mo. 31 d. |
| NEXT_LOCALE | whybrilliant.com | Stores the language selection made by the user | Preference & Convenience Cookies | 11 mo. 31 d. |
| ph_phc_[ID]_posthog | PostHog | Identifies users for analysis of site interaction | Statistics Cookies | 1 yr. |
| ph_phc_[ID]_posthog | PostHog | Tracks user navigation, interactions, and events | Statistics Cookies | Session |
| ph_phc_[ID]_primary_window_exists | PostHog | Checks if multiple windows/tabs of the same user are open | Statistics Cookies | Session |
| ph_phc_[ID]_window_id | PostHog | Stores a window ID for event tracking in analytics | Statistics Cookies | Session |
9. Your Rights Under GDPR
You have the following rights under Art. 15–22 GDPR at any time:
- Right of access (Art. 15 GDPR): request a copy of your data and information about how it is processed
- Right to rectification (Art. 16 GDPR): request correction of inaccurate or incomplete data
- Right to erasure (Art. 17 GDPR): delete your account yourself from your account settings, or ask us to delete it, subject to legal retention obligations. See Section 7 for what deletion removes
- Right to restriction (Art. 18 GDPR): request that we restrict processing in certain circumstances
- Right to data portability (Art. 20 GDPR): receive your data in a structured, machine-readable format
- Right to object (Art. 21 GDPR): object to processing based on legitimate interest or for direct marketing — see the prominent notice at the top of this policy
- Right to withdraw consent (Art. 7(3) GDPR): withdraw consent at any time without affecting prior processing
- Rights regarding automated decisions (Art. 22 GDPR): see Section 4
- Right to lodge a complaint (Art. 77 GDPR): you can complain to the data protection supervisory authority at any time. The authority competent for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Friedrichstraße 219, 10969 Berlin, Germany
Website: datenschutz-berlin.de
Contact privacy@whybrilliant.com to exercise any right. We will respond within one month (extendable by two months in complex cases, with notice). Requests are free of charge unless manifestly unfounded or excessive.
10. Data Security
We implement appropriate technical and organizational measures to ensure the security and confidentiality of your personal data. These measures are designed to protect against unauthorized access, manipulation, loss, or misuse. Our security measures are regularly reviewed and adapted to reflect technological advancements and current industry standards.
Please note that despite extensive protective measures, data transmission over the internet may involve security vulnerabilities. In particular, unencrypted communication (e.g., standard email) carries the risk that data may be accessed by third parties. We have no influence over the actions of external parties. We therefore recommend that you use encryption or other protective measures when transmitting sensitive information electronically to minimize potential risks.
11. Changes to This Privacy Policy
We may update this policy to reflect changes in our practices or legal requirements. Registered users will be notified of material changes by email or in-platform notice. The current version is always at www.whybrilliant.com/privacy.
Change log:
- September 2026: We retired our AI memory sub-processor (Mem0 AI, Inc.). The conversational memory it held is now stored solely within our own database, and all data previously held by that provider has been deleted. No new recipients and no new processing purposes: this change removes a recipient.
- September 2026: We incorporated the change proposals from our Data Protection Officer: a revision of the processing purposes (job-recommendation emails now rely on separate consent rather than on bundled service communications; product-improvement processing was narrowed to named, specific activities), an update of the sub-processor list and the international-transfer safeguards, and the disclosure that we record when a Company's users view a Talent's profile, download a Talent's CV, or open a Talent's professional links ("access records" — Sections 2.2, 3.2, 5, 7). We also document for the first time that a matched Company can view a Talent's profile and CV on the Platform before an introduction is made with the Talent's consent ('Employer Opt-In') (Sections 3.1, 4, 5). The corresponding contractual change is in the Talent Terms of Service, Section 7. Registered users are notified of this update by email or in-platform notice as described above.
- September 2026: The information for participants in our referral programme for companies ("Friends of WhyBrilliant") was moved out of this general policy into a dedicated Friends privacy notice, delivered as part of the Friends of WhyBrilliant programme terms. This was an editorial relocation for clarity — the way we process a Friend's data did not change, and nothing changed about how we process the data of Talents, Companies, or website visitors. No new processing was introduced.
Last updated: September 2026 | WhyBrilliant GmbH, Berlin