1. Our Data-Protection Roles
MetronTalent is a product of Prassix. Prassix acts as controller for account, billing, security, support and demo-request data that it collects for operating the service.
For candidate and recruitment data uploaded by a customer, the customer normally determines the purposes and lawful basis of the processing and Prassix processes that data on the customer’s documented instructions as a processor. The applicable Data Processing Agreement governs that processing.
Contact: info@metrontalent.com
2. What Data We Collect
We process the following categories of personal data:
- Account data — name, email address, company name, country
- CV / resume data — work experience, education, skills, certifications
- Billing data — company, tax and invoice information; card data is handled by Stripe
- Demo-request data — contact details, timezone and proposed meeting slots
- Usage and audit data — features used, operational events and security records
- Authentication data — encrypted session tokens (no passwords stored in plain text)
The matching engine is designed not to use special-category or protected characteristics as matching criteria. CVs can nevertheless contain information supplied by candidates; customers must avoid uploading unnecessary special-category data and must ensure that any processing is lawful.
3. Legal Basis for Processing
- Article 6(1)(b) GDPR — account and service processing necessary to perform the customer contract
- Article 6(1)(c) GDPR — records required for legal, accounting and tax obligations
- Article 6(1)(f) GDPR — proportionate security, fraud-prevention, support and service-operation interests
- Article 6(1)(a) GDPR — where Prassix specifically asks for consent
The customer, as controller, is responsible for selecting and documenting the lawful basis for candidate recruitment data. Uploading a CV to MetronTalent does not by itself establish consent.
4. How We Use Your Data
- To provide AI-assisted CV matching and candidate ranking
- To manage your account and subscription
- To send transactional emails (invoices, password resets)
- To improve the platform (aggregate, anonymised statistics only)
We do not sell personal data or disclose candidate data for third-party marketing. Data is processed on MetronTalent’s Microsoft Azure infrastructure and by disclosed subprocessors only for the contracted service.
5. AI-Assisted Processing
MetronTalent uses artificial intelligence to score and rank candidates against job requirements. In compliance with Article 22 GDPR, no hiring decision is made solely by automated means — a human recruiter reviews all AI-generated scores before any decision is taken.
Match results include available dimension-level evidence and, where enabled, an AI-generated explanatory summary. Human review remains required.
6. Cookies
This site uses only strictly necessary cookies required for authentication and security. No tracking, advertising, or analytics cookies are used.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
sessionid |
Maintains your login session | Session / 2 weeks | Strictly necessary |
csrftoken |
Protects against cross-site request forgery | 1 year | Strictly necessary |
Because we use only strictly necessary cookies, no consent banner is required under the ePrivacy Directive.
7. Data Retention
Retention is applied by data category and purpose:
- Active-service candidate data — up to 24 months from the last relevant activity, unless the customer requests earlier deletion or configures another lawful period
- Matching and AI audit records — up to 730 days where required for traceability, subject to the customer agreement and erasure obligations
- Expired organization data — a 7-day export and renewal window after the paid period ends, followed by deletion from the live service
- Recovery copies — 7-day soft-delete/recovery retention before expiry
- Invoices and statutory records — retained for the period required by tax and other applicable law
- Demo requests — retained only as long as needed to arrange and follow up the requested meeting, then deleted or minimized
These periods do not override a valid earlier erasure request unless continued retention is legally required.
8. Your Rights Under GDPR
As a data subject, you have the right to:
MetronTalent processes candidate personal data under Article 6(1)(f) GDPR — legitimate interest in recruitment. Where candidates submit their data directly (e.g., through CV upload), processing may also rely on Article 6(1)(a) — explicit consent.
AI-assisted scoring is used to assist hiring decisions, not to make them autonomously. In compliance with Article 22 GDPR, no candidate is subject to a decision based solely on automated processing.
Right of Access
Request a copy of all personal data we hold about you.
Right to Rectification
Correct inaccurate personal data or complete incomplete data.
Right to Erasure
Request deletion of your personal data ("right to be forgotten").
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Restriction
Limit how we process your data while a dispute is resolved.
Right to Object
Object to processing based on legitimate interest at any time.
Candidate data is retained for a maximum of 24 months after the last interaction, after which it is automatically purged from the system.
Data breach notifications are issued to the relevant supervisory authority within 72 hours as required by GDPR Article 33.
This platform uses artificial intelligence to score and rank candidates against job requirements. The AI evaluates skills, experience, and education — it does not process any protected characteristics (age, gender, ethnicity, religion, disability, or nationality).
All match scores include an explanation showing why a candidate received their score. A human recruiter always makes the final hiring decision.
In accordance with EU employment equality directives, the following attributes are not displayed in candidate profiles and are never used as matching criteria:
9. Data Security
Data is encrypted in transit and at rest using the controls of the Azure-hosted SaaS environment. MetronTalent uses Microsoft Azure services, including Azure OpenAI and configured Azure document-processing services, and Stripe for billing. Candidate data is not sent to Stripe. Processing locations, security controls and subprocessors are documented contractually and reviewed as the architecture changes.
Data breach notifications are issued to the relevant supervisory authority within 72 hours as required by GDPR Article 33.
10. Supervisory Authority
If you believe your data protection rights have been infringed, you may lodge a complaint with the Hellenic Data Protection Authority (HDPA):
- Website: www.dpa.gr
- Email: contact@dpa.gr
- Address: Kifisias 1-3, 115 23 Athens, Greece
11. Contact Us
For any data protection enquiries or to exercise your rights, contact: info@metrontalent.com