Privacy Policy

Version 2026-08-15

Benchler is a talent marketplace. This policy explains what we collect from engineers and from companies, why we are allowed to, who else sees it, how long we keep it and what you can demand from us.

Who is responsible for your data

Registered address available on request.

iam@benchler.com

What we collect

From engineers: your email address and password hash (held by our authentication provider), your name, your public handle, and the profile you fill in — title, bio, location, timezone, years of experience, skills, experience entries, projects, salary expectations, availability and a GitHub link if you add one.

Also from engineers: the CV file you upload, the text extracted from it, your answers in the AI interview and the assessment produced from them, the outcome of any human technical review, and the messages you exchange with a company or an AI agent after you accept their request.

From companies: the account email, the name of the person using it, the company profile, the jobs you publish, the answers given during role validation, and the requests and messages you send.

From everyone: product events — that an interview was started, a request was answered, a profile was viewed. Each event carries an account identifier, a name and a small set of properties. We do not record what you typed, and we do not build advertising profiles.

Why we are allowed to process it

Performing our contract with you (Art. 6(1)(b) GDPR): running your account, building your profile, producing your assessment, matching you with roles, and delivering requests and messages. This is the basis for almost everything on the platform.

Your consent (Art. 6(1)(a)): shareable credential links, which are off until you switch them on; accepting a company's or an agent's interview request, which is what opens a private channel; and the recording of a human technical review, which only happens if you request one. Each of these can be withdrawn, and withdrawing does not affect what happened before.

Our legitimate interests (Art. 6(1)(f)): keeping the service secure, preventing abuse, understanding aggregate product usage, and defending legal claims.

Legal obligations (Art. 6(1)(c)): accounting and tax records where they apply.

Automated assessment and matching

Your CV is read by a large language model, your interview is conducted and scored by one, and matching between candidates and roles is computed by us. Every score we publish is labelled as an AI assessment. It is a description of what one model concluded from what you wrote — not an objective measure of you as an engineer.

Matching recommends; people decide. A company sees candidates the engine surfaced and chooses whom to contact. No hiring decision, and no removal from the marketplace, is made automatically about you in the sense of Art. 22 GDPR.

You can ask us how a score or a match was produced, contest it, and request a human technical review, which is conducted by a person and attached to your profile alongside the AI result.

Who else sees your data

Signed-in companies see the discovery profile of engineers: title, bio, location, timezone, experience, skills, salary expectations, availability, GitHub link and assessment results. They never see your CV file, your interview answers, your email address or your phone number. Contact happens through the platform, and only after you accept a request.

AI agents belong to a company and see the same public profile fields — never contacts, salary or CV paths.

Anonymous visitors see only what you have deliberately published: an opted-in profile page, and a credential page at /c/<code> if you turned shareable links on. A credential page states who issued the verification, to whom, what was checked and when. It carries no skills, scores, experience, availability or contacts.

Nobody buys this data from us. We do not sell personal data and we do not share it for advertising.

Processors we use

Supabase — database, authentication and file storage.

An AI provider — CV text, interview questions and answers, and role validation answers are sent for processing. We contract for processing only, and against the use of your content to train models.

Resend — transactional email, so the other side is notified about a request, an acceptance or a message.

Sentry — error reporting, so a broken page can be fixed.

PostHog (EU region) — product analytics. Configured without cookies: no identifier is stored on your device by the analytics tool.

Vercel or an equivalent host — serving the application. Each of these acts on our instructions under a data processing agreement. Where a provider is outside the EEA, the transfer relies on the European Commission's standard contractual clauses or an adequacy decision.

Cookies and similar technologies

We set two kinds of cookie, both strictly necessary and neither of which asks for consent under the ePrivacy Directive: the authentication cookies that keep you signed in, and a cookie that remembers your language choice.

We run no advertising, no tracking pixels and no third-party marketing scripts. Our product analytics is configured to keep no identifier on your device, which is why this site shows no cookie banner: there is nothing to ask you about.

How long we keep it

Your account data lives as long as your account does. Deleting your account removes your profile, skills, experience, projects, interviews and answers, assessments, verifications, requests and messages, and the CV file in storage — immediately and irreversibly.

Product events are kept for twelve months and then deleted. Abandoned interviews are deleted after ninety days. Withdrawn and declined requests, and the messages under them, are deleted after six months. Failed CV reviews are deleted after thirty days.

The CV file you upload is deleted seven days after its review finishes. The structured profile the review produced stays — the document does not: nothing in the service reads it again once it has been read.

A verification carries a validity window of one year from the day it was issued. Nothing is deleted when it passes: the verification, its date and the credential page stay exactly as they are. It simply stops counting as current evidence in matching, and you are invited to take the check again.

A recorded human technical review is kept for a few months for quality and dispute review, then deleted. You are told this before you request one, and the call only happens if you request it.

Backups are retained for a short rolling window and overwritten in turn.

Your rights

You may ask for a copy of your data, correct it, delete it, restrict or object to its processing, and receive it in a portable format. Two of these are self-service: Settings has a button that exports your data as JSON, and a button that deletes your account.

Withdrawing consent is equally direct: switch shareable links off, decline a request, or stop an assessment from being publicly quotable.

For anything else, write to us at the address above. We answer within one month. If you think we have handled your data badly you may complain to your national data protection authority — you do not need our permission to do so.

Security

Every table carries row-level security, so a browser holding our public key cannot read rows that do not belong to it. CV files sit in a private bucket. Private columns — the CV path, a reviewer's notes, an interview call link — are not granted to the browser-facing API at all. Ownership is re-checked on the server for every write.

No system is beyond compromise. If a breach affects your rights we will notify the supervisory authority within 72 hours and tell you directly where the law requires it.

Changes

The version and date at the top of this page change whenever the document does. For substantive changes we ask you to accept the new version the next time you sign in, and we keep a record of which version you accepted and when.

Terms of Service