GDPR-compliant sourcing platform

Sourcing withoutthe data-protection headache.

Sourcing in DACH means using publicly visible profiles in a targeted way without violating GDPR. Talentwunder is built for exactly that as a Berlin-based GmbH, and treats data protection as a default, not an add-on.

Berlin GmbH · External DPO · Model DPA · Data protection by default

What is a GDPR-compliant sourcing platform?

A GDPR-compliant sourcing platform searches only publicly accessible sources, processes personal data on a clear legal basis, documents retention periods and a deletion concept, and provides a data processing agreement (DPA). Talentwunder meets these requirements as a German GmbH with an external data protection officer and treats GDPR as the precondition, not a marketing label.

Sourcing without compliance isn't sourcing. It's an open risk position.

How we cover this technically and contractually

The four building blocks our customers cite in their own compliance reviews.

  1. 01

    Public sources only

    We index publicly visible profiles only. No scraping of password-protected areas, no circumvention of platform policies.

  2. 02

    Clear legal basis

    Processing on the basis of legitimate interest (Art. 6 (1)(f) GDPR), documented in the record of processing and the privacy notice. The DPA covers the customer-specific usage layer.

  3. 03

    Actionable data subject rights

    Access, rectification, deletion, objection. Defined processes instead of ad-hoc promises. Escalation path via our DPO.

  4. 04

    DPA before contract

    A model DPA is ready and is signed before processing on behalf of the customer begins. It covers notes, ratings, status, projects and customer-initiated contact actions.

Hosting, encryption and the technical measures are set out on the Trust page. We do not currently claim SOC 2 Type II or ISO 27001.

Common questions for this page

The most relevant answers at a glance. The full catalogue lives in the FAQ.

  1. Yes. Talentwunder GmbH is based in Berlin, works with an external data protection officer (SECUWING GmbH & Co. KG) and is built to enable GDPR-compliant sourcing. Talentwunder plays two different roles depending on the stage of processing. We act as an independent controller when we build and maintain our database of publicly sourced candidate profiles. When a client selects a profile, adds notes or ratings, or initiates contact, the client acts as controller for that specific recruiting activity, and Talentwunder processes the resulting data on the client's instruction under a data processing agreement.
  2. The application and Keycloak run on AWS in Frankfurt. PostgreSQL, MongoDB and Elasticsearch run on dedicated Hetzner servers in Germany. Backups sit in Hetzner Object Storage in Germany, uploads in Amazon S3 Frankfurt. CloudFront may use edge locations in Europe and North America.
  3. Yes. We provide a template DPA before contract close and sign one by default with every customer. The DPA covers the customer-specific layer: notes, ratings, status, projects and customer-initiated contact actions. Talentwunder is the controller for building and maintaining the candidate-profile database.
  4. Talentwunder does not currently claim SOC 2 or ISO 27001 certification.

See all 18 questions

Two ways in. Both free.

Talk to a product expert or read yourself in first. Both work.

Live demo, 20 minutes

No sales deck. We walk you through the product against your use-cases.

Facts first

18 answers on category, product, pricing, and compliance. Structured catalogue.