Skip to main content
HACKTALENTSBack to site

Privacy Policy

Last updated: 7 August 2026


1. An Overview of Data Protection

General Information

The following information provides an easy-to-navigate overview of what happens with your personal data when you visit and use HackTalents. Personal data is any data with which you can be personally identified. For detailed information, please refer to the full Privacy Policy below.

Data Collection on This Website

Who is responsible for data collection on this platform? Data processing on this platform is carried out by the operator. You can find their contact details in the section "Information about the Controller" in this Privacy Policy.

How do we collect your data? Some data is collected because you provide it to us directly — for example, when you register an account, perform a search, or contact us. Candidate profiles come from candidates themselves, who upload their CV and information when applying to a Hack-Nation Global AI Hackathon. Other data is collected automatically by our systems when you use the platform, primarily technical data such as your browser, operating system, and the time of access.

This policy addresses two groups: companies using the platform to hire, and candidates whose profiles appear in the index. Their data comes to us differently and is covered separately in section 4.

What do we use your data for? Data is used to provide and operate the platform, to process transactions and contracts, to prevent fraud, and to fulfil legal obligations. No behavioural advertising or tracking takes place.

What rights do you have regarding your data? You have the right to receive free information at any time about the origin, recipients, and purpose of your stored personal data. You also have the right to request rectification or deletion of your data, to restrict processing, and to object to processing. If you have given consent to data processing, you may revoke that consent at any time. You also have the right to lodge a complaint with the competent supervisory authority. Please contact us at any time if you have questions about data protection.


2. Hosting

Vercel

We host the content of this platform at the following provider:

Vercel Inc., 340 Pine Street, Suite 701, San Francisco, CA 94104, USA.

For details, please refer to Vercel's privacy policy: https://vercel.com/legal/privacy-policy

We use Vercel on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in the reliable and performant operation of our platform. As Vercel processes data in the United States, this transfer is based on Standard Contractual Clauses (SCCs) adopted by the European Commission.


3. General Information and Mandatory Disclosures

Data Protection

The operator of this platform takes the protection of your personal data seriously. We handle your personal data confidentially and in accordance with applicable data protection law and this Privacy Policy.

We note that data transmission over the internet (e.g. when communicating by email) may have security vulnerabilities. Complete protection of data from access by third parties is not possible.

Information about the Controller

The controller responsible for data processing on this platform is:

Hack-Nation UG (haftungsbeschränkt) Tal 44 80331 München Germany

Email: k-wiederhold@web.de Phone: +49 1590 4193929

Commercial Register: Amtsgericht München, HRB 304261 VAT ID: DE456131673

This service is operated under the brand HackTalents at hacktalents.ai.

Data Protection Contact

For all data protection matters, including requests to exercise your rights and reports of a security issue, contact:

Kai Nestor Wiederhold k-wiederhold@web.de

We are not required to appoint a Data Protection Officer under § 38 BDSG. Kai Nestor Wiederhold is our responsible contact for data protection and handles all enquiries and incidents.

Storage Duration

Unless a more specific storage period is stated in this Privacy Policy, your personal data will remain with us until the purpose for which it was collected no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for retaining it (e.g. tax or commercial law retention periods); in that case, deletion will take place once those reasons cease to apply.


4. Data Collection on the Platform

4.1 Recruiter Data (Art. 13 GDPR)

HackTalents is a B2B platform for recruitment professionals. When you register and use HackTalents as a recruiter, we process the following data:

  • Account data: company name, name of the registering person, business email address
  • Authentication data: encrypted password hash, session tokens
  • Transaction data: credit purchases, pricing tier, payment references
  • Usage data: searches performed, candidate profiles viewed, interest checks and introductions requested, hire-fee trigger events
  • Billing data: invoice address, VAT identification number, transaction history and a payment method reference. Card details are entered directly with our payment service provider and are never received or stored by us.
  • Communication data: support correspondence

Purposes and lawful bases:

PurposeLawful basis
Providing the contracted serviceArt. 6(1)(b) GDPR — performance of contract
Billing and credit managementArt. 6(1)(b) GDPR — performance of contract
Invoicing and tax complianceArt. 6(1)(c) GDPR — legal obligation
Payment processingArt. 6(1)(b) GDPR — performance of contract
Fraud prevention and platform securityArt. 6(1)(f) GDPR — legitimate interest
Establishing and enforcing our contractual claimsArt. 6(1)(f) GDPR — legitimate interest
Service communicationsArt. 6(1)(b) GDPR — performance of contract

Payment fraud screening. Our payment service provider applies automated fraud scoring to transactions and may decline a payment on that basis. This screening is carried out by the payment service provider on its own responsibility. Where a payment is declined, you may contact us and we will review the transaction manually.

Retention: Account data is retained for the duration of the contractual relationship and for ten years thereafter in accordance with statutory commercial and tax record-keeping obligations (§ 257 HGB, § 147 AO).

4.2 Candidate Data (Art. 13 GDPR)

HackTalents maintains a searchable index of professional candidate profiles. This data is provided to us by candidates themselves, when they apply to take part in a Hack-Nation Global AI Hackathon. Hack-Nation UG (haftungsbeschränkt) operates both the hackathon and HackTalents, and is the controller for both.

We do not build the index by scraping. A profile is only created where the candidate has applied to a hackathon and has consented to their CV and information being shared with companies.

Categories of data processed:

  • Identity and contact data: name, email address, telephone number, country and city
  • Education data: university or institution, field of study, degree, level of study, graduation year
  • Professional data: CV content as uploaded by the candidate, job titles, employer history, skills, seniority indicators
  • The candidate's own LinkedIn profile URL as supplied by them, and publicly available professional information from that profile
  • Stated job-seeking preferences (whether the candidate is looking for part-time or full-time work)
  • Normalised representations of the above, generated by automated processes for search and ranking

We do not process health data, biometric data, criminal records, or data relating to minors. Demographic information collected during hackathon registration is used solely for the hackathon's own diversity reporting and is not included in the candidate index, not visible to companies, and not available as a search or filter criterion.

Purposes and lawful bases:

PurposeLawful basis
Including a candidate profile in the index and making it searchable by companiesArt. 6(1)(a) GDPR — consent given at hackathon registration
Semantic ranking of profiles against a company's searchArt. 6(1)(a) GDPR — consent
Disclosing a candidate's identity and contact details to a companyArt. 6(1)(a) GDPR — consent
Enriching a profile from the candidate's own stated LinkedIn URLArt. 6(1)(f) GDPR — legitimate interest in an accurate and current profile
Establishing and enforcing our contractual claims against companiesArt. 6(1)(f) GDPR — legitimate interest (Recital 47)

Withdrawal of consent. Where our processing rests on consent, you may withdraw that consent at any time with effect for the future, by writing to k-wiederhold@web.de. Withdrawal is as easy as giving consent and has no consequences for your participation in any hackathon. On withdrawal we remove your profile from the index without undue delay. Withdrawal does not affect the lawfulness of processing carried out before it.

Candidates who did not consent to sharing are not included in the index. Where a candidate declined to share their CV and information with companies, their application data is used solely for the hackathon and is not made available to any company through HackTalents.

Retention: Candidate profile data is retained for 24 months from the date it was last confirmed or updated by the candidate, or until consent is withdrawn, whichever is earlier. We contact candidates before the end of that period to ask whether they wish to remain in the index.

Candidate rights: Candidates have the right to access, rectify, erase, restrict, and object to processing of their data, to data portability, and to withdraw consent, at any time. To exercise these rights, contact k-wiederhold@web.de. We will respond within one month.


5. How Companies Reach You

Companies using HackTalents see your profile without your name, email address, telephone number or LinkedIn profile. Those details are not available to them by browsing or by payment.

There are three stages, and you control the second one:

Profile view. A company can see your experience, skills, education and seniority, free of charge and without your identity. They cannot contact you at this stage.

Interest check. If a company thinks you may be a fit, they ask us to check. We contact you, tell you which company it is and what the role is, and ask whether you are interested. We report only your answer back to them — not your details. If you say no, or do not reply, nothing further happens and the company is refunded.

Introduction. Only if you say yes may the company request an introduction. We then put you and the company in contact with each other. We do not hand your email address, telephone number or LinkedIn profile over as a data set.

Controller responsibility. From the point at which a company learns your identity through an introduction, that company becomes an independent data controller for your data (Art. 4(7) GDPR) and is solely responsible for how it handles it from then on. We are not joint controllers with them. Companies are notified of this before each introduction is completed.


6. Cookies

This platform uses only technically necessary cookies:

CookiePurposeDurationParty
Supabase auth sessionMaintains login stateSessionFirst-party
__stripe_sidPayment session, fraud prevention30 minutesStripe
__stripe_midDevice identifier for payment fraud prevention1 yearStripe

The Stripe cookies are set only on our billing and checkout pages, and only when you initiate a payment. We do not load the Stripe script on any other part of the platform. They are therefore strictly necessary to carry out the payment you have expressly requested.

All cookies listed above are exempt from prior consent under § 25(2) No. 2 TDDDG because they are strictly necessary for the service to function. No consent banner is displayed as no non-essential cookies are set. No analytics, advertising, or third-party tracking technologies are used.

Cookie security configuration: Secure, HttpOnly, SameSite=Lax.


7. Sub-processors and Third-Country Transfers

We share personal data with the following sub-processors. Transfers to countries outside the European Economic Area (EEA) are based on Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented by a Transfer Impact Assessment.

RecipientServiceLocationTransfer basis
Supabase Inc.Database hostingUnited StatesStandard Contractual Clauses
Vercel Inc.Application hosting and CDNUnited StatesStandard Contractual Clauses
OpenAI OpCo, LLCLanguage model processingUnited StatesStandard Contractual Clauses
Voyage AIEmbedding and semantic searchUnited StatesStandard Contractual Clauses
Weaviate B.V.Vector database and search indexEuropean Union—
Apify Technologies s.r.o.Retrieval of the candidate's own stated LinkedIn profileEuropean Union—
Google Ireland LimitedHackathon application forms and file uploadIreland / United StatesEU–US Data Privacy Framework
StripePayment processingIreland / United StatesEU–US Data Privacy Framework

Stripe's role. For the processing of payments, the prevention of payment fraud and its own regulatory and anti-money-laundering obligations, Stripe acts as an independent controller rather than as our processor, because it determines those purposes itself. Stripe's own privacy policy governs that processing. Stripe is certified under the EU–US Data Privacy Framework, so transfers to the United States rest on an adequacy decision of the European Commission.


8. Data Subject Rights

You have the following rights under GDPR:

  • Right of access (Art. 15): obtain confirmation and a copy of data we hold about you
  • Right to rectification (Art. 16): correct inaccurate personal data
  • Right to erasure (Art. 17): request deletion of your personal data
  • Right to restriction (Art. 18): restrict processing in certain circumstances
  • Right to data portability (Art. 20): receive your data in a structured, machine-readable format
  • Right to object (Art. 21): object to processing based on legitimate interests

To exercise any of these rights, contact k-wiederhold@web.de.


9. Right to Lodge a Complaint

You have the right to lodge a complaint with the competent data protection supervisory authority:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 27 91522 Ansbach Germany www.lda.bayern.de


10. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, and destruction, including encryption in transit (TLS), encryption at rest, role-based access controls, and secure cookie flags. Payment card details are entered directly with our PCI-DSS certified payment service provider and never pass through our systems.

We note that data transmission over the internet may have inherent security vulnerabilities and complete protection from third-party access cannot be guaranteed.


Last updated: 7 August 2026

  • Imprint
  • Privacy
  • Cookies
  • Terms
  • DPA
© 2026 HackTalents