GDPR & AI Act Statement

Version 2026-06-19-v3-es. Last updated 19 June 2026.

This statement sets out, in plain language, how T4G Lab Roster complies with the EU General Data Protection Regulation (GDPR), the Spanish Organic Law 3/2018 (LOPDGDD) and the EU AI Act (Regulation (EU) 2024/1689). The Service is operated by NEMRAC Consulting S.L., Spain Tax Identification Number B44624740, registered office at [registered office — to be confirmed], trading as T4G Lab, as sole controller. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD). The Service is offered exclusively to candidates resident in the European Union; it is not offered to UK-resident data subjects.

1. The lawful bases we rely on

For each activity we have identified a specific lawful basis:

  • Running your account — performance of a contract (Art. 6(1)(b) GDPR).
  • Letting you appear on the roster — your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
  • Storing the CV you upload — performance of a contract for the file itself, plus your explicit consent under Art. 9(2)(a) GDPR for any special-category data the CV may contain.
  • Parsing your CV with an AI model — our legitimate interest in operating a usable roster (Art. 6(1)(f) GDPR), plus your explicit Art. 9(2)(a) consent for any special-category data.
  • Sending you marketing — your consent (Art. 6(1)(a) GDPR), with a one-click unsubscribe link in every message.
  • Security and abuse prevention — our legitimate interest in keeping the Service safe (Art. 6(1)(f) GDPR).
  • Meeting legal obligations — Art. 6(1)(c) GDPR.

2. Specific Art. 9 consent at upload

When you upload a CV we present a separate, granular, opt-in consent for the processing of any special-category data the CV may contain (Article 9 GDPR). This consent is:

  • Granular — it is distinct from your account consent and from any marketing consent;
  • Refusable — you may decline it without losing access to the Service; we will not store a CV that we have reason to believe contains special-category data if you have refused; and
  • Withdrawable — you can withdraw it at any time from /account/privacy, which triggers deletion of the CV and its associated enrichment record.

3. Right to object to AI parsing (Art. 21)

You have an unconditional right to object to the AI parsing of your CV, because that processing relies on legitimate interests under Art. 6(1)(f) GDPR. The in-product mechanism for this is the /account/privacypanel: toggling off “Allow AI parsing of my CV” immediately stops further parsing and triggers deletion of any existing enrichment record. Your CV itself remains stored, but unenriched, until you ask us to delete it. We do not penalise candidates who exercise this right.

4. Your rights and how to use them

  • Access (Art. 15) — request a copy of your data via /account/privacy or by emailing privacy@t4glab.com.
  • Rectification (Art. 16) — edit profile fields inline, or email us for fields that are not directly editable.
  • Erasure (Art. 17)— “Delete my account” in /account/privacy erases your profile, CV and enrichment record on the deletion schedule in our Privacy Policy.
  • Restriction (Art. 18) — email privacy@t4glab.com.
  • Portability (Art. 20) /account/privacy offers a machine-readable export.
  • Object (Art. 21) — see section 3 above.
  • Withdraw consent — toggle in /account/privacy or email us.

Complaint route. Your primary complaint route is the Agencia Española de Protección de Datos (AEPD) (www.aepd.es), our lead supervisory authority. You may also complain to the supervisory authority of the EU Member State of your habitual residence (Art. 77 GDPR).

5. International transfers

Most processing happens inside the European Union. Where data has to leave the EEA we use lawful transfer mechanisms, in plain English:

  • EU–US Data Privacy Framework (DPF) — a European Commission decision that recognises certain US companies as offering an adequate level of protection. We rely on it for transfers to Anthropic PBC where Anthropic is self-certified under the DPF.
  • Standard Contractual Clauses (SCCs) — a set of contractual terms approved by the European Commission. We rely on them as a fallback whenever the DPF does not apply.
  • Transfer Impact Assessment (TIA) — for each non-DPF transfer we review the laws and practice of the destination country and any additional safeguards we need to put in place.

6. Automated decision-making

We do not take decisions about you that are based solely on automated processing and that produce legal or similarly significant effects on you. The AI parser is a decision-support tool: a human administrator reviews every shortlist and every introduction to a partner organisation, and every administrative action is recorded in an audit log.

7. EU AI Act

We treat the parser as a high-risk AI system under Annex III, point 4 of Regulation (EU) 2024/1689 because it operates in the context of recruitment-related activities. As deployer we comply with the obligations that begin to apply from 2 August 2026, including:

  • operating the parser strictly according to its instructions;
  • monitoring its outputs and reporting serious incidents;
  • retaining system logs for at least six months;
  • telling you, in this statement and in the upload flow, that an AI system is being used; and
  • conducting a Fundamental Rights Impact Assessment (FRIA) alongside our GDPR Data Protection Impact Assessment, and reviewing both at least annually.

8. Data Protection Impact Assessment (DPIA)

We have completed a DPIA covering the CV-upload, parsing and admin-review flows, and a FRIA covering the same flows. A summary is available on request to the Data Protection Officer at dpo@t4glab.com.

9. Security

  • All traffic to and from the Service is protected with TLS.
  • CVs and enrichment records are stored encrypted at rest with AWS KMS.
  • Database access is owner-scoped at the row level: a candidate can only see their own data.
  • Administrative functions are gated by an ADMIN Cognito group and protected by multi-factor authentication.
  • Every administrative action is recorded in an admin-action audit log retained for at least six months.

10. Breach notification

If we suffer a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the AEPD as our lead supervisory authority within 72 hours of becoming aware of it, as required by Art. 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly under Art. 34 GDPR.

11. Children

The Service is intended only for adults aged 18 or over. We do not knowingly process personal data of children. If we discover that we hold data relating to a child we will delete it.

12. Contact

Data Protection Officer: dpo@t4glab.com.


This statement was drafted with input from independent data-protection counsel. It will be reviewed at least annually.