1. Who is responsible for the data
Trend Career Center S.R.L. operates the TrendCareer platform and acts as controller for its accounts, security, audit, consent, billing and candidate-facing screening flows that it provides directly.
The employer that publishes a job is an independent controller for its recruitment process, job content, job criteria and final hiring decision. TrendCareer may also act as processor for certain data handled on the employer's instructions, under the signed agreement or DPA.
- Legal name: Trend Career Center S.R.L.
- Registered office: Bucharest, Sector 6, Iuliu Maniu Boulevard No. 7, Building U, 5th Floor, Romania.
- Tax identification number / CUI: 41186483, dated 28.05.2019.
- Trade Register number: J2019007003400.
- European Unique Identifier (EUID): ROONRC.J2019007003400.
- Certificate reference: ONRC ascertaining certificate issued on 20.03.2026, based on affidavit no. 1039069 dated 09.03.2026.
- NACE/CAEN codes authorised in the supplied certificate: 4740, 4763, 4764, 6392, 7020, 7810, 7820, 8220, 8559.
- Data protection contact: contact@trendcareer.ro.
- DPO: TrendCareer has not currently appointed a DPO; if one is formally appointed, the information will be published here and notified to the competent authority where legally required.
2. What TrendCareer does
TrendCareer is a B2B recruitment platform: an employer publishes a job, a candidate calls or messages a +40 number linked to that job, an AI assistant runs the screening in Romanian, and the employer receives a shortlist and structured recruitment information.
Screening may happen by voice call, WhatsApp, SMS, email or web, depending on the candidate's channel and the employer configuration.
3. Data we process
We process data needed for recruitment, platform operation, security, compliance and billing. The examples below reflect the current product and technical schema.
- Candidate data: phone number, name if provided, email if provided, location, availability, experience, certifications, salary expectations and concrete answers to job questions.
- Screening data: audio recordings, transcripts, structured conversation messages, Q&A answers, screening status, duration, channel used and technical safety events.
- Recruitment-derived data: scores, match percentage, confidence, AI explanations, pipeline stages and flags relevant to the employer.
- Documents and profile: CV or files uploaded by the candidate, parsed CV data, profile completion percentage and marketplace visibility, if those features are used.
- Communications: WhatsApp messages, SMS, transactional emails, reminders, unsubscribe links, contact opt-outs and STOP responses.
- Employer and account data: company name, CUI if provided, company contacts, members, roles, invitations, job settings, plans, subscriptions and billing data.
- Technical and audit data: account identifiers, security logs, provider events, GDPR consent, DSAR requests, rate-limit events, technical errors and metadata needed to investigate incidents.
4. Purposes and legal bases
- Candidate screening: the candidate's consent for recording and processing answers for evaluation against a job.
- Providing the service to employers: contract performance or pre-contract steps, including accounts, jobs, shortlists, notifications and support.
- Operational communications: contract performance, consent where required and legitimate interests for reminders strictly related to an application.
- Security, abuse prevention, audit and troubleshooting: legitimate interests and legal obligations, with minimised logs where possible.
- Billing and payments: contract performance and legal tax/accounting obligations.
- GDPR compliance and rights requests: legal obligation and legitimate interests for limited audit evidence.
- Marketing or commercial communications, where present: consent or legitimate interests under applicable law; the user can unsubscribe.
5. Consent in calls and screening
The canonical Romanian voice disclosure is version gdpr-voice-ro-v2-ai-disclosure: "Vorbiți cu un asistent vocal AI prin platforma TrendCareer. Acest apel este înregistrat pentru evaluarea aplicării; răspunsurile pot fi transcrise, structurate și evaluate pentru job. Prin continuarea conversației vă dați acordul pentru procesarea datelor conform GDPR. Puteți întrerupe apelul în orice moment. Pentru mai multe detalii vizitați trendcareer.ro. Putem continua?"
If a candidate does not want to continue, they can end the call, refuse during the conversation or later ask to withdraw consent. Withdrawal does not affect processing that was lawful before the withdrawal.
TrendCareer does not store sensitive data beyond concrete answers to the fixed job-question list, and it does not use emotion inference or sentiment analysis to evaluate candidates.
6. Recipients and subprocessors
Data relevant to an application is visible to the employer that published the job and to authorised members of that company. We do not sell candidate data to third parties.
To provide the service we may use the following providers, only where the relevant flow is active: Supabase for database and storage, Vercel for hosting, Telnyx for voice/WhatsApp, ElevenLabs for voice, Deepgram for speech-to-text, Google Vertex AI / Gemini EU for AI processing, Twilio for SMS/WhatsApp, Meta WhatsApp for messaging, Resend for email and Stripe for payments.
Production data is designed for EU/EEA residency, including Supabase eu-central-1 Frankfurt and AI endpoints configured in the EU. For providers outside the EEA or with global support/access, we use mechanisms permitted by GDPR Chapter V, such as adequacy decisions, Standard Contractual Clauses or another permitted mechanism, together with supplementary measures where needed.
7. How long we keep data
The current technical policy uses company-configurable retention with the platform defaults below, except where a contract, legal obligation, security investigation or legal hold requires a different period.
- Transcripts and audio recordings: default 90 days, with company override if configured.
- Structured answers in conversation_messages: default until withdrawal or until a configured retention policy soft-purges them; soft-purged rows are hidden from the application and hard-deleted after the applicable grace period.
- Screenings linked to closed jobs: operational cleanup archives by default 30 days after the job closes and deletes/anonymises by default 60 days after archive, unless routing_rules set different values.
- Candidate account deletion: authenticated DELETE /api/candidates/account anonymises the account and calculates final hard-delete after 7 days.
- Employer/user account deletion: authenticated DELETE /api/account anonymises the account and applies a 30-day window before final hard-delete.
- Contact opt-outs may be retained as suppression lists so we can honour the choice not to receive further communications.
- Legal obligations, disputes, security investigations or legal holds may require limited evidence to be retained for longer.
8. Candidate and user rights
Depending on your role and situation, you may request access, export/portability, rectification, deletion, restriction, objection, consent withdrawal, data correction and human intervention for automated results. Some flows are self-service only for authenticated accounts; candidates without an account can use the data protection contact after identity verification and will receive a response within GDPR timelines.
- Candidate export: the authenticated candidate profile uses GET /api/candidates/{candidate_id}/export and is limited to one export every 24 hours.
- Candidate deletion: the authenticated candidate profile uses DELETE /api/candidates/account for anonymisation and later hard-delete.
- Employer/user export: authenticated accounts can use GET /api/account/export before deletion or for portability.
- Employer/user deletion: authenticated accounts can use DELETE /api/account with the product's required confirmation phrase.
- Consent withdrawal and opt-out: screening consent is recorded in gdpr_consents, and withdrawals/declines are retained with withdrawn_at; SMS communications can be stopped with STOP, and outreach emails include an unsubscribe link.
- Contest a score or shortlist: contact the employer and TrendCareer for human review, data correction and contextual reassessment.
- Public data deletion request: use /en/legal/data-deletion or the data protection contact email.
9. AI scores, ranking and human decisions
TrendCareer compares candidate answers, transcripts, the provided profile or CV and job information with the questions and criteria configured by the employer. The platform may generate an overall score, match percentage, confidence level, AI explanation and suggested pipeline stage.
These outputs may influence shortlist order, follow-up priority and the context shown to a recruiter, but they are decision-support for recruitment, not a final automated decision. The final decision to contact, interview, reject or hire a candidate must be made by the employer through human review.
Candidates may request human review, contest a score or shortlist result, provide additional context and ask for inaccurate data to be corrected.
TrendCareer does not infer emotions, sensitive personality traits, health, ethnic origin, religion, sexual orientation or other special categories from the candidate's voice.
10. Security and confidentiality
We apply company-scoped access controls, database RLS policies, GDPR operation audit, rate limits on sensitive routes, log minimisation and internal PII masking rules. Candidate data is accessible only to the authorised company, the authenticated candidate where an account exists and authorised technical personnel for support or security.
12. Questions and complaints
For personal-data requests, use contact@trendcareer.ro. We will respond within GDPR timelines, generally within 30 days, with extensions where the law permits.
You have the right to complain to the Romanian data protection authority, Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP).