Your information, explained plainly.
This notice explains how Gael Talent Bridge uses personal data when you use our website, request services, submit a CV, contact us or use the signed-in Candidate Workspace.
Last updated: 4 October 2026
Data-protection law requires us to provide information about who controls personal data, why it is used, the legal basis, recipients, retention and rights. These are among the matters set out in Articles 6, 9 and 13 of the GDPR. This notice is a service document and should be checked against the final operating model before launch.
The Irish Data Protection Commission’s own job-applicant processing information illustrates why recruitment data needs a clear purpose, notice and rights route. Its DPIA guidance is relevant where planned processing is likely to create high risk.
1. Who is responsible for your data
Gael Talent Bridge is the controller of personal data described in this notice, except where we act on documented instructions as a processor for an employer or other controller.
Business name: Gael Talent Bridge.
Business address: Limerick, Ireland.
Privacy contact: info@gaeltalentbridge.ie.
2. Data we collect
Candidate and prospective-candidate data
We may collect contact and account details; professional profile information; CVs, cover letters, work history, education, certifications, portfolio links and work preferences; application and interview records; communications; programme/service records; consent choices; and technical/security records. We ask for only what is needed for the requested service.
Employer and prospective-employer data
We may collect business contact details, organisation and role-brief information, hiring requirements, communications, meeting notes, service and payment records, and feedback relevant to a hiring engagement.
Website and enquiry data
We may collect the information you enter in a form, email or phone enquiry, plus basic technical information necessary to deliver and secure the website. This static build states that it currently uses essential technology only; see the cookie notice.
3. Why we use data and our lawful bases
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Respond to an enquiry and discuss services | Contact details and message | Steps requested before entering a contract, and/or legitimate interests in responding to business enquiries |
| Deliver candidate or employer services | Professional profile, documents, strategy, role brief and communications | Performance of a contract; where appropriate, legitimate interests in operating and improving the service |
| Manage accounts, support and security | Account, access, audit and technical records | Contract, legal obligation where applicable, and legitimate interests in protecting systems |
| Send marketing | Contact details and preferences | Consent, where required; marketing is optional and separate from service communications |
| Meet legal, accounting or dispute-handling duties | Relevant service, payment and communications records | Legal obligation and/or legitimate interests in establishing, exercising or defending legal claims |
We do not rely on consent where another lawful basis is more appropriate for delivering a requested service. You may withdraw optional consent at any time; withdrawal does not affect processing already carried out lawfully.
4. CVs, documents and sensitive data
We use CVs and supporting documents to provide the service you request, for example career strategy, CV feedback, application preparation or agreed talent-search activity. Do not send passwords, PPSN details, passport copies, health information, ethnicity, religion, political opinions, sexual-orientation information or other special-category data through a general form.
Information revealing special categories of personal data has additional conditions under GDPR Article 9. If a documented and necessary service need arises, we will explain the appropriate basis and safeguards before asking for or using it. We do not use special-category data to profile, rank or reject candidates.
5. Application emails you forward to us
Your workspace can give you a private forwarding address. If you choose to use it, you can forward emails you receive about your own job applications, such as an acknowledgement, an interview invitation or a rejection, and the application appears in your job tracker without you typing it in again. Using this is entirely optional and the service works without it.
We do not have access to your mailbox. We never ask for your email password, and we do not connect to your email account or read anything in it. We receive only the individual messages you deliberately forward.
What we keep. From each forwarded message we record the employer name, the role title, the stage the application has reached, the date, and which job board or careers site it came from. Where we could not read a detail with confidence, the row is marked for you to confirm and the subject line of that email is held alongside it purely so you can recognise which application it refers to. That subject line is deleted as soon as you confirm the row. We also keep a one-way hash of the message identifier so the same email forwarded twice does not appear twice.
What we do not keep. The body of the forwarded email is read in memory to extract the details above and is then discarded. It is not written to our database, not stored as a file and not retained in our logs. Attachments are ignored.
What it is used for. Your own progress tracking, and your assigned consultant's ability to support you on your programme. It is not used for advertising, it is not sold, it is not shared with employers, and it is not used to build any product or dataset. Our lawful basis is performance of your service contract, together with your own act of forwarding the message.
How to stop. Stop forwarding, and nothing further is recorded. You can also replace your forwarding address at any time from your job tracker, after which anything sent to the old address is discarded without being read. Captured rows are yours to edit or delete like any other entry in your workspace.
6. Who receives data
Access is limited to authorised people who need it for the service: assigned consultants, authorised operations/support staff and, where applicable, an employer only after the candidate has agreed to the specific sharing. We may use carefully selected processors for hosting, email, database, file storage, analytics if introduced, security and AI features. They process data under appropriate contractual and security controls. We do not sell personal data.
Owner to confirm: the final processor list, hosting region, data-processing agreements and any employer-sharing workflow before collection begins.
Optional Gmail connection for application sending through ORLA
You may separately connect your own Gmail account to ORLA to send application emails from that account. Google's official consent screen requests permission to send email and to identify the Google account you connected. This send-only connection does not grant permission to read your inbox, modify existing messages or delete messages. We never request your Google password. Job Tracker's optional read-only connection is separate; connecting ORLA does not enable inbox scanning.
Before sending, you review the recipient, prepared message and approved attachments and confirm the send in the workspace. The server checks candidate access, profile and document approval, duplicate-send protection and the applicable daily allowance. Assigned staff may send for you only when you have enabled the separate staff-sending permission. You can turn that staff permission off in your ORLA settings.
Where MIRA outreach is enabled, it uses the same send-only Gmail connection and ORLA sending service. MIRA requires separate candidate-enabled consent, approved documents and confirmation of the selected recipients before sending. It does not obtain inbox-reading permission through this connection.
To deliver an approved email, the server sends the recipient address, message and selected attachments to Gmail. The recipients receive that content and those attachments. We store the connected sender address, encrypted authorisation tokens, prepared email content and send records, including recipient, subject, selected document references, status, Gmail message identifier and the candidate or authorised staff actor. These records support delivery, application history, access auditing, daily allowances and duplicate prevention.
You can disconnect ORLA's Gmail connection to remove its locally stored authorisation tokens. You can also remove the app's access in your Google Account settings. Disconnecting does not recall delivered messages or automatically erase application documents or send-history records. You may request deletion of those records using the privacy contact above, subject to applicable legal retention requirements. Retention of service records is described in the retention section below.
Optional Google connection for job-tracker updates
The mailbox-access statements in the forwarding section above apply to forwarding only. If the Google connection is enabled and you separately choose to connect your own Google account, you authorise read-only mailbox access through Google's official consent screen. We never request your Google password. Google does not provide a job-email-only permission: its read-only scope can access your mailbox, while our application limits searches and processing to recruitment updates.
The initial check covers up to 90 days of application confirmations, screening and interview updates, outcomes and offers. Full message bodies are processed in memory, not retained; attachments are not downloaded. We retain the candidate-linked message identifier, company, role, proposed stage, received date and narrowly extracted offer facts such as salary or start date, where present. These suggestions require your review before changing the job tracker. Tokens are encrypted, and the data is used only for this job-tracking feature, not for advertising, sale or model training.
You can disconnect in your Job Tracker. This removes locally stored Google tokens and email suggestions and attempts to revoke provider access; if revocation is unavailable, remove access in your Google Account settings. Previously approved tracker entries remain available for you to edit or delete. Connecting Google is optional and separate from ORLA sending, spreadsheet imports and email forwarding. Availability depends on completion of the owner's Google application setup and required verification.
Google API data use
Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google account information obtained through these optional connections is used to provide the sending or job-tracking feature you authorise. It is not used for advertising, sold to data brokers or used to train general-purpose AI models. Human access is limited to your expressly authorised service workflow or an applicable security or legal exception under that policy.
7. International transfers
We aim to keep processing within the European Economic Area where practical. If a supplier or recipient processes data outside the EEA, we will use an available lawful transfer mechanism, such as an adequacy decision or appropriate safeguards, and provide further information on request. The precise position depends on the providers selected.
8. Retention
We keep data only as long as needed for the purpose, service relationship, legal obligations and reasonable claim-management needs. The intended baseline is: general CV submissions for 12 months from last meaningful contact, unless you ask for earlier deletion or a longer period is justified; enquiry records for 12 months after closure; and candidate programme records for the programme term plus 24 months, so the candidate can receive agreed follow-up support and request an export. We may keep limited records for longer where required by law or reasonably necessary to establish, exercise or defend legal claims.
Owner to confirm: the candidate-programme retention period, employer-service retention period, accounting retention schedule and deletion process against the final business model before launch.
9. Your rights and how to use them
Depending on the circumstances, you may request access, correction, deletion, restriction, objection, data portability, withdrawal of consent and information about automated decision-making. The GDPR explains these rights in its rights provisions, including Articles 15-22. We do not make decisions producing legal or similarly significant effects solely by automated means about candidates.
Email info@gaeltalentbridge.ie with “Data request” in the subject line. Tell us what you need and which email address you used. We may need to verify identity before acting, and we will respond in line with applicable legal time limits.
10. Complaints
You may raise a concern with us first. You also have the right to complain to Ireland’s supervisory authority, the Data Protection Commission.
11. Security and updates
We use proportionate technical and organisational measures, including access controls, secure service configuration and restricted handling of documents. No system is risk-free. We will review this notice when services, suppliers or legal requirements change and will post the updated date here.
Optional CARA voice practice
Where the owner has enabled voice practice for a candidate, without requiring payment or a subscription, CARA asks interview questions aloud and allows spoken answers in the signed-in Interview Studio. Your browser asks for microphone permission and may use its own speech-recognition service to turn speech into text. CARA does not save the raw audio. It keeps the editable answer transcript, approximate answer duration, interview report and coaching notes in its service so you can review the practice. The existing configured AI provider processes the relevant career materials, job description and answers for interview analysis and coaching. Voice delivery suggestions are not a stress, anxiety or medical assessment. Your confidence choice on the results screen is not saved.
Voice practice is optional, limited to three sessions per Dublin day and can be replaced by written practice. You can delete a voice session’s active CARA record in the results screen; operational backups may remain temporarily under the applicable backup-retention controls. CARA does not automatically email a portal voice assessment to the office or share it with an employer. Ask us for provider, transfer and retention details before opting into this feature.