Privacy notice

Last updated 24 July 2026

If you only want one thing from this page: if we hold your business contact details and you want them gone, the opt-out page does it. No account, no explanation, permanent, and it applies to every customer of ours who has already seen them.

1. Who we are

Taliro Global Talent, S.L., trading as Yellowdesk, registered office at Rambla de Badal 62, 3-3, 08014 Barcelona, Spain, tax number B26780288, is the controller for the personal data described in Part A, Part B and Part C of this notice.

Contact for any data protection matter: privacy@taliro.net, or by post at the address above.

We operate a sales intelligence service for recruitment agencies. It identifies companies that are likely to be buying recruitment services and lets a recruiter obtain the business contact details of the people who make that decision.

For the business contact data described in Part A we are a controller, not a processor. We decide which vendors supply it, which people are surfaced, what is retained and for how long. Our competitors' agreements tend to say the customer is the controller and the vendor a mere processor. A processor does not go out and source the data. We do, so we are not one. Saying otherwise would be more comfortable and less true, and it would leave the people in the database with nobody answerable to them.

2. Which part of this notice is about you

Three quite different groups of people end up on this page, and most of it concerns only one of them.

Read
You are in our business contact database. You are a decision maker at a company that hires. We hold your business contact details and we did not get them from you.Part A
You are a customer, or a user of a customer's account. You signed up, or a colleague invited you.Part B
You visited our website, booked a demo, or filled in a form.Part C

# Part A. If you are in our business contact database

A1. What we hold about you

Your name, your job title, your employer, your business e-mail address, your business telephone number and your professional profile URL. Alongside that, the company you work for, its size, its sector and the roles it has advertised.

We hold this about you in a professional capacity only. We do not hold, and do not want, anything about your private life. We do not hold special category data about you: nothing about your health, your beliefs, your politics, your trade union membership, your ethnicity or your sexual orientation. We do not build a behavioural profile of you, we do not track you across the internet, and we hold nothing about what you do outside your job.

A2. Where we got it

Not from you. We obtain business contact details from third-party business contact data vendors, who compile them from public professional sources. We obtain job advertisements and company information from job data vendors and from public sources.

Every record we store carries the name of the vendor it came from, the identifier it had there, and the date we retrieved it. If you ask us where a specific record about you came from, we tell you, by name. We describe our data vendors by category on the public sub-processor list rather than naming them there; that is a narrower disclosure than a public page, and it does not put the answer out of reach of the person it is about.

A3. What we do with it

We show a recruiter which companies appear to be buying recruitment services, and, where they choose to spend a credit, we show them your business contact details so they can approach your company about recruitment or staffing services.

We do not sell lists. A customer reveals one person at a time, deliberately, and pays for it.

We hold no standing database of contact details. The list of people at a company is fetched from the vendor when a customer looks at that company and is not stored. The only contact details we retain are the individual records a customer has explicitly paid to reveal. This is a design constraint we defend, not an accident: a competitor holding 160 million scraped contacts on a five year retention was fined EUR 240.000 by the French regulator, and that shape is the one we deliberately do not have.

A4. Our lawful basis

We process your business contact data on the basis of legitimate interests, Article 6(1)(f) GDPR. Our interest is operating a business-to-business service that connects recruitment suppliers with companies that need them; the corresponding interest of our customers is finding the right person to speak to; and yours, as a person whose job includes being contacted about that, is not overridden by it.

Spanish law is explicit on this point. Article 19 of Organic Law 3/2018 (LOPDGDD) presumes that processing the contact data of individuals who provide services within a legal entity is covered by Article 6(1)(f) GDPR, where the data relate only to that person's role in the entity and the purpose is to maintain a relationship of some kind with the entity. That is exactly what we hold and exactly why we hold it.

We have carried out and documented a Legitimate Interests Assessment. You can ask for a summary of it at privacy@taliro.net.

For the reveal of a mobile telephone number, and for any subsequent contact by telephone or e-mail, additional rules apply under the ePrivacy Directive and its national implementations. The obligation to comply with those rules when contacting you sits with the customer who contacts you, and our Terms of Service require them to screen numbers against the applicable national registers and to have their own lawful basis.

A5. Why we did not e-mail you to tell you

Article 14 GDPR would normally require us to contact you and tell you we hold your data. We rely on the exemption in Article 14(5)(b): doing so for every person in the database would involve disproportionate effort.

That exemption is not a way out, and we do not treat it as one. It obliges us to take appropriate measures instead, including making this information publicly available. Those measures are:

1. this notice, published without a login, linked from the footer of every public page; 2. the opt-out page, a working, no-login route to object and be erased; 3. the Data Opt-Out Policy, which explains exactly what happens when you use it; 4. a 180 day retention limit on revealed details, rather than an indefinite one; and 5. a public sub-processor list, kept current.

These are the whole of our Article 14 position, which is why they are on every public page and why we do not treat any of them as optional.

A6. How long we keep it

Contact details revealed to a customer180 days from the date we retrieved them. Then the e-mail address, the telephone number and the profile URL are redacted from every account holding them, including accounts that paid. The name, title and employer remain.
Contact details not revealed to anyoneNot retained at all. The list a customer browses is fetched live and discarded.
A suppression record, if you opt outKept indefinitely, as a one-way hash of your e-mail address or profile URL. See A8.
Job advertisements and company recordsFor as long as they are useful to the service. These are about companies, not about you, except where your name appears as the poster of an advertisement.

We do not retain revealed contact details indefinitely. A five year window is exactly what the French regulator fined a comparable company for.

A7. Your rights

You have the right of access, rectification, erasure, restriction, portability and objection, and the right not to be subject to a decision based solely on automated processing that produces legal effects.

In practice the right you want is objection, and one route delivers it: yellowdesk.ai/opt-out. The Data Opt-Out Policy explains how it works, why we verify a request before we action it, what an access request returns, and how long we take. We do not charge for any of it.

Automated decision making. The buying signal scores companies, not people. No decision producing a legal or similarly significant effect on you is made by automated means. A language model is used to work out which company an agency advertisement is recruiting for; where your name appears in an advertisement it may be processed for that purpose, and the output is about the company, not about you.

A8. What we keep after you opt out, and why

When you opt out, we purge your details. We keep one thing: a one way hash of the e-mail address or profile URL you asked us to suppress. We cannot read it back into your address, and we do not store the address itself.

We keep it because it is the only way to keep the promise. Without it, the next time a vendor supplies your record we would have no way of knowing you had already objected, and you would have to object again every few months. The hash is checked before any contact is shown or revealed. This is processing necessary to comply with our obligation to honour your objection, and it is a recognised exception to erasure.

# Part B. If you are a customer or a user of a customer's account

B1. What we hold

CategoryWhat
Identity and accountName, e-mail address, role, account membership, country, language, date and time format preferences, the hash of your password (never the password)
Authentication and securitySession records including the IP address and browser user agent at sign-in, sign-in timestamps, failed sign-in counts, verification and reset token hashes
BillingCompany name, billing address, VAT number, invoices, the credit ledger, and the brand, last four digits and expiry of your card. We never see or store a card number.
UsageWhich parts of the service you use, searches you save, contacts and companies you reveal, credits you spend, and product analytics events
Content you uploadCVs you submit to Candidate Match, and the search criteria derived from them
AdministrativeSupport correspondence, and an append-only audit log of administrative actions taken on your account

B2. Why, and on what basis

PurposeBasis
Providing the service, managing your account, supporting youPerformance of the contract
Taking payment, issuing invoices, chasing failed paymentsPerformance of the contract, and legal obligation for the accounting records
Keeping the service secure: rate limiting, session management, fraud prevention, error trackingLegitimate interests, in operating a service that is not trivially abused
Understanding how the product is used, so we can improve itLegitimate interests, in improving a product our customers pay for
Sending service e-mails: verification, password reset, invitations, billing, alerts you asked forPerformance of the contract
Sending marketing e-mail about the serviceLegitimate interests for an existing customer relationship, or consent. You can opt out in any message.
Complying with law, and defending claimsLegal obligation and legitimate interests

We do not sell your data, and customer data never enters the business contact database. Being a customer does not put you in the product.

B3. CVs and Candidate Match: we are your processor here

When you upload a CV you are handing us a third party's personal data, and the roles reverse: you are the controller, we act on your instruction as a processor. The terms are in the Data Processing Agreement.

The document is read in memory and converted to text, then sent to a language model hosted in the European Union which derives a set of search criteria from it. The document is never written to disk, never logged, and is gone when the request ends.

If you save the search, what persists is the derived criteria and a derived profile: titles, seniority, skills, years of experience and languages. No name, no employer, no dates, no free text from the document. It is a job specification derived from a person, not a record of the person, and it is what makes a saved search re-runnable without us keeping the CV. It is deleted when you delete the saved search.

B4. How long we keep it

Account and user recordsFor as long as the account is active
A suspended account90 days after the deletion warning, then anonymised: contact reveals purged, user records stripped of personal data, account closed
Sessions30 days, or until you sign out
Verification and reset tokens24 hours and 1 hour respectively, then void. Invitations, 7 days
Invoices, credit ledger and accounting recordsAt least 6 years, as required by Article 30 of the Spanish Commercial Code and applicable tax law
Audit log of administrative actionsRetained with the account and for the accounting period after it. It is append-only by design and entries are never edited or deleted
Product analytics eventsNot deleted on a schedule today. They record which features an account used and when, they are keyed to an account rather than to a browser, and they are not used to build a profile of an individual. We are setting a maximum period for them and it will be stated here once it is enforced
Error tracking dataHeld by our error tracking provider under its standard retention, currently 90 days
Support correspondence3 years from the last contact

B5. Your rights

You have the same rights listed in A7. Most of them you can exercise yourself in Settings: correct your details, change your e-mail address, delete a saved search, turn off alerts. For anything else, write to privacy@taliro.net.

Where you ask us to delete your account, we anonymise it as described above. We cannot delete the invoices and ledger entries, because we are required to keep them.

# Part C. If you visited our website

C1. Analytics

The website yellowdesk.ai uses Google Analytics 4, provided by Google Ireland Limited. It sets cookies and assigns your browser an identifier, so we ask you first and nothing is stored until you accept. Decline and it stays denied, with no part of the site withheld. Your answer is remembered in local storage under yd_consent; clear this site's storage and we will ask again.

The basis is your consent, which you may withdraw at any time. Where you have not given it, the tag runs in a mode that stores nothing on your device and records only that a page was viewed.

What we measure is deliberately narrow: which pages are read, which calls to action are pressed, which language the site is being read in, and how many people start a sign-up or book a demo. We do not use it for advertising, and advertising storage and personalisation are set to denied and never enabled.

Google is established in the United States and may transfer data there, relying on the European Commission's standard contractual clauses. Google acts as a controller for its own purposes under its own privacy policy. See the Cookie Policy for the individual cookies and their lifetimes.

C2. If you contacted us

If you book a demo, request a trial or fill in a form, we hold what you typed: your name, your e-mail address, your company, and anything you wrote. We use it to reply to you and to follow up about the service. The basis is your request, and our legitimate interest in responding to it.

Demo scheduling is handled by Zeeg, and form submissions reach us by e-mail through Resend. Both appear on the sub-processor list.

We keep enquiry records for 24 months from the last contact, unless you become a customer, in which case Part B applies.

# Common to all parts

3. Who else sees your data

Our sub-processors, listed publicly and kept current at yellowdesk.ai/subprocessors. Today they are: Vercel (application hosting), OVHcloud (database, cache, search index, object storage and language model inference), Stripe (payments), Resend (e-mail), PostHog (product analytics), Sentry (error tracking), Google Analytics and Zeeg (website), and our business contact data vendors.

Also:

  • Professional advisers (lawyers, accountants, auditors) where they need it.
  • Public authorities, where the law requires it. We will tell you unless we are prohibited from doing so.
  • A buyer of the business, if we are acquired or merged, subject to the same protections.

We do not sell personal data to anyone, and we do not share it for anyone else's marketing.

4. Where your data is processed

All primary storage is in the European Union. The database, the cache, the search index and the object storage run on OVHcloud in Germany and France, operated by a French company. The application runs on Vercel in Frankfurt. Language model inference runs on OVH AI Endpoints, in the EU.

Several of our providers are established in the United States even though they process in the EU, which means their staff can in principle be asked to access data in the course of support. Where that is the case we rely on the European Commission's standard contractual clauses, together with the provider's own data processing agreement and its technical measures, and we have carried out . We do not transfer contact records to a country without one of those safeguards in place.

5. What we never send to a language model

Contact details are never sent to a language model. Not an e-mail address, not a telephone number, not a profile URL. The pipeline that identifies which company an agency is recruiting for sends job advertisement text only.

The one exception is Candidate Match, where a CV you upload is sent to a model to derive search criteria, as described in B3. That model is hosted in the European Union, the document is never stored, and it is a substantive reason we chose an EU model host rather than a cheaper one elsewhere.

We do not use your data, or the contact database, to train any model.

6. Security

We describe the measures in the Data Processing Agreement, Annex III. In summary: everything travels over TLS, passwords are hashed with Argon2id, session tokens are stored only as hashes, access is limited to the people who need it, all primary data stays in the EU, and card numbers never reach us.

No system is perfectly secure. If a breach occurs that is likely to result in a high risk to you, we will tell you, and we will notify the AEPD within 72 hours where the law requires it.

7. Children

The service is for business use by adults. We do not knowingly collect data about anyone under 18. If you believe we have, tell us and we will remove it.

8. Changes to this notice

We update this notice when what we do changes. The date at the top is the date of the version you are reading. Where a change materially affects customers, we tell them by e-mail.

9. Complaining

Talk to us first if you are willing: privacy@taliro.net. We can usually fix it faster than anyone else can.

You do not have to. You can complain directly to the Spanish supervisory authority:

Agencia Española de Protección de Datos (AEPD) C/ Jorge Juan, 6, 28001 Madrid, Spain www.aepd.es

If you live in another EU or EEA country, you can complain to your own national supervisory authority instead.

Language

This document is published in English, German, French, Dutch and Spanish. The translations are provided for convenience. Where a translation and the English version differ, the English version governs.