Privacy Policy

Effective date: 5 September 2022

This Privacy Policy informs you of our policies and procedures regarding the collection, use and disclosure of personal information we receive from visitors and registered users of TalentHR.io (this "Site"). This Privacy Policy applies only to information that you provide to us through this Site and explains in plain language what we do with that information, how we share it, and how we handle the content you place. It also explains your rights and the choices available to you regarding our use of your personal information and how you can access and update this information.

Our Privacy Policy may be updated from time to time, and we will notify you of any material changes by posting the new Privacy Policy on the Site at Privacy Policy and revising the “Effective starting” date at the top of this policy. We encourage you to review our Privacy Policy whenever you use this “Site” to stay informed about our information practices and the ways you can help protect your privacy. If you disagree with any changes to this Privacy Policy, you will need to stop using this “Site” and deactivate your account(s), as outlined below.

This Privacy Policy applies to the information that we obtain through your use of "Site" via a "Device" or when you otherwise interact with TalentHR. A "Device" is any computer used to access the “Site”, including without limitation a desktop, laptop, mobile phone, tablet, or other consumer electronic device. “Site” includes the TalentHR web site and SaaS service.

By accessing and using this Site, you confirm that you have read and fully understood this Privacy Policy, that you agree to the collection and the usage of your own and others’ personal information in accordance with the Privacy Policy and that you have the authority to provide us with all information submitted by you via the Site, including but not limited to personal information of third parties, including your employees. By registering for or using TalentHR Services and accepting the Terms of Service you consent to the collection, transfer, processing, storage, disclosure and other uses described in this Privacy Policy

1. Who We Are

Epignosis: The Epignosis Group of companies (“Epignosis”) provide accessible and affordable HR management services (the “Services”) via TalentHR, to any single company or organization worldwide. “Epignosis LLC”, located in the United States of America (315 Montgomery Street (9th Floor) San Francisco, California CA 94104 USA tel. (+1) 646 797 2799) and “Epignosis UK LtD”, having as seat of establishment the United Kingdom (1 Buckwell Road, Kingsbridge, South Hams, United Kingdom, TQ7 1NQ, tel. (+44) 20 7193 1614) promote and provide HR management services, while the Greek Branch (Lykourgou Str. 1, Athens, 10551, (+30) 211 800 6449) of Epignosis UK Ltd is responsible for the management, maintenance and operation of the Services. The Epignosis Group complies with Data Protection Laws, including the European regulation for data protection 2016/679/EU (General Data Protection Regulation - GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA). Epignosis will not knowingly do anything or permit anything to be done which might lead to a breach of the Data Protection Laws.

TalentHR: TalentHR is a cloud subscription-based HR management service. By accessing TalentHR through a set of subscription packages, our customers (“Customers”) can manage HR records and HR payroll. Customers access the TalentHR service by means of a unique combination of a user identifier and secure password. By gaining access to the service through this combination, the Customers are allocated a specific domain that is owned and managed exclusively by them. The Customer specifies, customizes and provides access to the service to the authorized users (“Users”) of his domain, consisting of its employees, either supervisors or HR managers.

2. Collection: The Personally Identifiable Information We Collect

Visitors and Users: In the course of using this Site, you may provide us with personally identifiable information. This refers to information about you that can be used to contact or identify you, and information on your use of and activities at our Site that may be connected with you ("Personal Information"). Personal Information that we collect may include, but is not limited to, your name and email address. When you visit the Site, our servers automatically record information that your browser sends whenever you visit a website. This information may include, but is not limited to, your Internet Protocol address, browser type, the web page you were visiting before you came to our Site and information you search for on our Site. Like many websites, we may also use "cookies" to collect information. A cookie is a small data file stored by your browser at your Device's hard disk for record-keeping purposes. We use "session ID cookies" in order to support login and main service functionality. We may also use cookies of third-party providers, like Google Analytics to collect demographic data. In particular, Google stores a Google Analytics cookie in order to be able to differentiate between users and be able to show us how many times people visit the website on average (not individually) and information on what pages they've seen, how long the duration was, and so on. You can instruct your browser, by changing its options, to stop accepting cookies or to prompt you before accepting a cookie from the websites you visit. If you do not accept cookies, however, you may not be able to use all portions of the Site or all functionality of our services.

In some cases, another User (such as an administrator) may create an account on your behalf and may provide your information, including Personal Information (most commonly when your company requests that you use our service). We collect Information under the direction of our Customers and often have no direct relationship with the individuals whose Personal Information we process. If you are an employee of one of our Customers and would no longer like us to process your information, please contact your employer.

Customers: In addition to the data we collect about all Users, we also collect data that are required for your contract with us, such as your company affiliation, invoicing data and also service usage data that prove that the service is used in accordance to your subscription terms. We may also collect service usage data in aggregate form (i.e. demographics) to improve our service. We may also acquire additional data through our Customers’ support requests to the extent this is required for us to resolve a technical issue or respond to a request or complaint. If you are a Customer, you may also receive our Newsletter. However, if you wish to receive such emails you can remove yourself from the recipients list at any time by selecting the "unsubscribe" link provided within the e-mail footer.

Third-party intergrations in TalentHR: You may access Google Calendar via TalentHR. This third-party integration enables access to calendar functionalities.

By accepting the Terms of Service, you agree that Google Calendar may process Personal Information you provide them by using their services.

Credit Cards: We do not store your credit card information in our systems. All credit card transactions are processed using secure encryption - the same level of encryption used by leading banks. Card information is transmitted, stored, and processed securely at gateways on a PCI-compliant network.

Content: We collect and store Content that you or your Authorized Users create, input, submit, post, upload, transmit, store or display in the process of using our “Site”. Such Content includes any Personal Information or other sensitive information that you choose to include ("incidentally-collected Personal Information"). Although Epignosis owns the code, databases, and all rights to the TalentHR service, Customers retain ownership, control and all rights to their records and data which are their property.

3. How We Use, Process and Retain Personal Information

Personal Information is or may be used for the following purposes:

  • to provide and improve our Site, services, features and content,
  • to administer your use of our Site,
  • to enable you to enjoy and easily navigate the Site,
  • to better understand your needs and interests,
  • to fulfil requests you may make,
  • to personalize your experience,
  • to provide or offer software updates and product announcements, and
  • to provide you with further information and offers from us that we believe you may find useful or interesting, including newsletters, marketing or promotional.

We use information we obtain by technical means (such as the logging performed by our servers or through the use of cookies) for the above purposes and in order to monitor and analyze use of the Site and our services, for the Site's technical administration, to increase our Site's functionality and user-friendliness, and to better tailor it to your needs.

We collect and process personal data in a transparent manner, to the extent necessary for specified, explicit and legitimate purposes, and do not process it further in a manner incompatible with those purposes. We take care that the data we collect are accurate and, when necessary, updated. We take all reasonable steps to immediately delete or rectify personal data, if inaccurate. We process data in a way that guarantees their security, including their protection against unauthorized or unlawful processing and accidental loss, destruction or degradation, using appropriate technical or organizational measures. We are ready to prove at any moment how we adhere to the above principles. We take the appropriate technical and organizational measures for the security, confidentiality, integrity and availability of the data. We expressly declare that these measures ensure that, by definition, personal data are not made accessible without the intervention of the natural person to an indeterminate number of natural persons.

Each domain’s data are retained for as long as the Customer's paid subscription to the service or free plan lasts. If Customer elects not to renew a Subscription, Customer's account is downgraded to the free version of the Services. If Customer has a free version account and does not log into an account for more than 365 days, that account is permanently deleted. We will provide reminder notifications before deleting Customer’s account.

4. Information Sharing and Disclosure

Users: You should be aware that the administrator, as well as specially designated support personnel in order to provide support for technical issues you may face, may be able to: access information in and about your account; access communications history, including file attachments, for your account; disclose, restrict, or access information that you have provided or that is made available to you when using your account, including your Content; and control how your account may be accessed or deleted.

Third Parties: We do not sell your Personal Information or Content and will not share or disclose any of your Personal Information or Content with third parties except as described in this policy. We do not share Personal Information about you with third parties for their marketing purposes (including direct marketing purposes).

Service Providers, Business Partners and Others: For security, service operation and management purposes, TalentHR also uses third-party services that provide the same level of protection as Epignosis (e.g. Amazon AWS and Google Calendar). Third-party vendors and providers supply the necessary hardware, software, networking and storage to run the Talent HR service; a detailed listing of them is included in the Terms of Service in the Data Processing Addendum (DPA). These third parties have access to your Personal Information only for purposes of performing these tasks on our behalf.

Compliance with Laws and Law Enforcement: TalentHR cooperates with government and law enforcement officials to enforce and comply with the law. We will disclose any information about you to government or law enforcement officials, if requested by legally binding order (including but not limited to subpoenas). We will inform you of this disclosure, unless it is forbidden for reasons of public interest.

Children: Our services are not directed to children. We do not knowingly collect Personal Information from children. If we become aware that a child has provided us with Personal Information, we will take steps to delete such information. If you become aware that a child has provided us with Personal Information, please contact us at the contact information below.

Business Transfers: We may share or transfer your Information (including your Personal Information) in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company. You will be notified on any change in ownership or uses of your Personal Information, as well as any choices you may have regarding your Personal Information.

5. Your Rights

Epignosis respects your rights as a data subject. When Epignosis processes personal data on behalf of and as instructed by its Customers, our Customers are responsible towards the data subjects and you should contact the respective Customer to which the content of your service belongs for exercising your rights. In this case, Epignosis does not respond directly to your requests for the exercise of your rights that come to our knowledge, but we inform the Customer without delay and provide all reasonable assistance to satisfy your requests in accordance with instructions of the Customer. The service has all the necessary features to enable our Customers to protect the rights of the data subjects on their behalf.

A synopsis of your rights as a data subject is provided below.

Transparency, information and answers to requests: Epignosis adheres to the principle of transparency in processing. For any question regarding this policy you may contact us at privacy at talenthr dot io We will respond without delay and in any case within one month upon receipt of the request.

Access: You have the right to receive from Epignosis confirmation on whether your personal data are processed and in case this happens all required information thereof (processing means, goal, records etc.).

Rectification: You have the right to require the rectification of inaccurate data relating to you without undue delay, as well as to fill in incomplete data if necessary for processing. If you have an account on our Site you can update your account data through your profile.

Erasure: You have the right to ask for the erasure of personal data concerning you without undue delay. Epignosis by means of its designated personnel will erase the data where one of the following grounds applies: a) the personal data are no longer necessary in relation to the purposes of processing; or b) the person requesting the erasure withdraws consent on which the processing is based and there is no other legal ground for the processing; or c) the data subject objects to the processing and there are no overriding legitimate grounds for the processing or the data subject objects to processing for direct marketing; or d) the personal data have to be erased for compliance with a legal obligation. Epignosis will not proceed to the erasure of the personal data if the data must be maintained for compliance with a legal obligation or in cases where the processing is required for the establishment, exercise or defence of legal claims. If you receive marketing emails, you can remove yourself from the recipients list by selecting the "unsubscribe" link within the e-mail.

Restriction of processing: You have the right to request restriction of processing if the accuracy of personal data is disputed, for that period of time that allows Epignosis to verify the accuracy of personal data or based on any other legitimate reason specified in applicable Data Protection Laws.

Data Portability: You have the right to receive your personal data in a structured, commonly used and machine-readable format as well as the right to request the direct transmission of personal data by Epignosis to another, if this is technically feasible.

Right to Object: You may oppose the processing of personal data which takes place without your consent. In this case, Epignosis no longer submits the personal data unless it demonstrates imperative and legitimate reasons for the processing that outweigh the interests, rights and freedoms of you as a data subject or for the foundation, exercise or support of legal claims. If you receive promotional emails, you can remove yourself from the recipients list by selecting the "unsubscribe" link within the e-mail content. You may also oppose processing at any time by contacting us at the email provided at the end of this Policy.

Complaint to Supervisory Authority: You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of your personal data infringes Data Privacy Laws.

Right to opt out and right to Non-Discrimination: If you are a California resident, you should be specifically aware that you have the right to direct a business that sells (or may in the future sell) your Personal Information to stop selling your Personal Information and to refrain from doing so in the future. We do not sell your Personal Information to any other party.

If you are a California resident, you should be specifically aware that we will not discriminate against California residents or against any person, if they exercise any of the rights provided in the CCPA, or any applicable privacy law provision. In particular, we will not deny goods or services; charge different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties; provide a different level or quality of goods or services; or suggest that anybody (including California residents) will receive a different price or rate for goods or services or a different level or quality of goods or services.

6. Security

TalentHR is very concerned with safeguarding your information. We employ reasonable measures designed to protect your information from unauthorized access.

7. Data Ownership

Although Epignosis owns the code, databases, and all rights to the TalentHR service, Customers retain ownership, control and all rights to their records and data which are their property.

8. Data Transfers from the EU and the UK to the United States

The transfers are subject to the latest versions of the appropriate form of the Standard Contractual Clauses.

9. Cooperation With Supervisory Authority

Epignosis commits to cooperate with the panel established by the EU data protection authorities (DPAs) and the ICO in the UK and comply with the advice given with regard to data transferred from the EU and the UK. The EU representative of Epignosis LLC is the Greek Branch of Epignosis UK Ltd. The UK Representative of Epignosis LLC is Epignosis UK Ltd.

10. Contacting Us

If you have any questions about this Privacy Policy, please contact us at: privacy at talenthr dot io.