Skip to main content

Privacy

Migratalent privacy policy

Effective 28 July 2026. This policy explains how Migratalent handles personal data across migratalent.com, its authenticated account portal, and the Migratalent mobile application.

Who is responsible and what this policy covers

Migratalent is the service responsible for the personal data described here. Privacy questions and rights requests can be sent to support@migratalent.com. This policy covers the public website, Migratalent accounts and workspaces, and the Android app. A linked job source, government site, employer site, email provider, telephone network, Marketplace, or DigitalNomad service may have its own notice when it operates independently.

  • Privacy contact: support@migratalent.com
  • Public deletion-request page: https://migratalent.com/account-deletion
  • The app and service covered by this policy are named Migratalent
  • Last updated: 28 July 2026

Information you provide

The information collected depends on the feature you choose. We do not require every category from every user.

  • Account and access data, such as name, email address, one-way password hash, organization, role, website, and access-request message
  • Agency and employer workspace data, such as organization records, team membership, workers, employers, cases, notes, status history, and audit events
  • Worker and candidate data, such as contact and profile information, employment details, CV information, nationality, and migration-workflow details
  • Private files and extracted document fields, which may include identity-document, passport, date-of-birth, qualification, contract, or other case evidence
  • Correction, rating, support, consent, data-export, and account-deletion requests
  • Internal public-job CV intake is disabled in the current release; public job pages direct users to the source or contact route shown on each record

Technical data and information kept on your device

When you connect, the service necessarily receives network and request information used to deliver and secure the service, such as an IP address, request time, route, response status, and limited device or browser information. The current Migratalent app does not include advertising, third-party analytics, crash-reporting, or push-notification SDKs.

  • The mobile app stores its session credential in operating-system secure storage
  • The mobile app keeps locale and onboarding preferences in local app storage and uses the device locale to choose an initial language
  • Job-search text and selected country/contact filters are sent to the service when you run a search and may appear in limited operational request logs
  • The website stores theme and locale preferences in browser storage
  • The public access-request form does not persist names, email addresses, organization details, websites, roles, or messages in browser storage
  • The authenticated website uses a secure, HttpOnly session cookie; the browser cannot read it with page scripts
  • The current Android release does not request location, contacts, camera, microphone, broad storage, SMS, phone, or notification permission

Public jobs, agencies, translators, and provenance

Public job and directory pages use approved source records and are designed to publish job, organization, professional, contact, and provenance information that is appropriate for public discovery. Source referenced does not mean government approval, credential review, or a guaranteed outcome. Private accounts, case files, CVs, and identity documents are not public directory content.

  • Public job records can include employer, location, source, website, email, phone, and a named business contact
  • Agency and translator records can include public organization or professional contact information and source provenance
  • Corrections and ratings are reviewed before public status changes
  • Contact and source links may open a third-party email, telephone, website, or application service governed by that party

Why we use personal data

We use personal data only for identified service, safety, compliance, and communication purposes. The applicable legal basis depends on the relationship and feature.

  • To create and secure accounts, authenticate sessions, restore access, and provide requested workspace features
  • To prepare and manage worker, employer, agency, case, document, directory, and support workflows requested by users or organizations
  • To respond to access, correction, privacy, export, and deletion requests
  • To maintain service security, prevent abuse and fraud, troubleshoot failures, keep audit records, and protect users and the platform
  • To meet legal obligations and establish, exercise, or defend legal claims
  • Where processing is optional and based on consent, you may withdraw that consent without affecting earlier lawful processing

Legal bases

Depending on the context, processing may be necessary to perform a contract or take requested pre-contract steps, to comply with law, for Migratalent's or another party's legitimate interests in operating and securing a professional workflow, or on the basis of consent. We assess the purpose and data involved rather than assigning one basis to every feature.

Who can receive personal data

We do not sell or rent personal data. Access is limited by role and purpose. Data may be disclosed only as needed to operate a requested workflow or meet a lawful duty.

  • Authorized Migratalent personnel and authorized members of the relevant tenant or organization
  • Hosting, database, storage, security, email, and operational service providers acting under appropriate instructions
  • Employers, agencies, translators, providers, or advisers when you or the responsible organization directs or authorizes that workflow
  • Courts, regulators, law-enforcement bodies, or public authorities where disclosure is lawfully required
  • A successor responsible for the service after a legitimate corporate transaction, subject to applicable safeguards and notice duties

International processing

Some infrastructure or service providers may process data outside Romania or the European Economic Area. Where European data-protection law requires a transfer safeguard, we use an applicable mechanism such as an adequacy decision or approved contractual safeguards. You can ask support@migratalent.com for current information relevant to your data.

Retention and deletion

We retain data only while needed for the purpose collected and then delete or de-identify it, unless a longer period is required for law, accounting, fraud prevention, security, dispute resolution, or legal claims. Retention depends on account status, the active case or service relationship, document type, contractual duties, and applicable limitation periods; we do not claim one fixed period for every record.

  • Active account and workspace data is retained while the account or requested service is in use
  • Case files and documents are reviewed against the responsible organization's operational and legal retention needs
  • Security, audit, and transaction records may outlast an account where integrity, abuse prevention, or law requires them
  • A deletion request starts identity verification and review; it is not an instant automated deletion
  • Eligible account data is deleted or de-identified, and any retained data is restricted to the continuing lawful purpose
  • Local browser or app preferences remain on the device until the user clears app/browser data or uninstalls the app

Your data-protection rights

Subject to applicable conditions, you may request information and access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent where consent is the basis. You may also complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) or another competent supervisory authority. We may need to verify identity before disclosing or changing account data.

  • Use https://migratalent.com/account-deletion for an account-deletion request
  • Email support@migratalent.com for access, export, correction, restriction, objection, consent, or other privacy questions
  • Do not send passwords or identity documents in an ordinary support email
  • A request will not be refused merely because you used the public intake page; eligibility and lawful retention still require review

How we protect data

Migratalent uses HTTPS, secure session storage, role and tenant access controls, private file routes, minimized API responses, secret management, and security logging designed not to include sensitive document values. Access to CVs, identity records, and case documents is restricted. No internet service can promise absolute security; suspected security or privacy incidents should be reported to support@migratalent.com.

Children

Migratalent is an employment and professional migration-workflow service intended for adults and organizations, not children. We do not knowingly invite children to create accounts or submit case records. If you believe a child supplied data, contact support@migratalent.com so it can be reviewed and removed where required.

Policy changes and questions

We may update this policy when the product, providers, or legal requirements change. Material changes will be identified by a new effective date and, where required, an in-product notice. Questions, complaints, and privacy requests can be sent to support@migratalent.com.