Our commitment at a glance
"Trust is built on transparency. Here's exactly how we protect your data."
Recruitment involves sensitive data: CVs, evaluations, interview notes, candidate personal information. At Aurelia, security isn't optional, it's foundational. We apply the highest standards to protect both your data and that of candidates you recruit.
Summary of our security guarantees
| Aspect | Our guarantee |
|---|---|
| Hosting | 100% European Union (Germany and France) |
| Legal compliance | GDPR by design, AI Act ready |
| Encryption at rest | AES-256 for all stored data |
| Encryption in transit | TLS 1.3 for all communications |
| Authentication | 2FA available, timed sessions |
| Subprocessors | All GDPR compliant, DPA signed |
| AI training | Never used to train models |
Data location and infrastructure
Technical infrastructure
| Service | Location | Function | Certification |
|---|---|---|---|
| Supabase / PostgreSQL | AWS Frankfurt (eu-central-1) | Main database | GDPR, SOC 2 |
| Hostinger | France | Next.js application servers | GDPR |
| Cloudflare | Edge EU | CDN, DDoS protection, WAF | GDPR, BCR |
| Stripe | European Union | Secure payments | GDPR, PCI-DSS |
No data to the United States
GDPR compliance: the 6 respected principles
- 1
Lawfulness, fairness, transparency
Legal basis: subscription contract execution. Clear information in privacy policy. Consent requested for each specific processing.
- 2
Purpose limitation
Data collected only to provide Aurelia service, improve user experience and ensure security. We never sell your data.
- 3
Data minimisation
We collect only necessary data: recruiter identity, recruitment data (CVs, evaluations), technical security logs.
- 4
Accuracy
You can modify your data anytime. Candidates can request corrections. We fix reported errors within 30 days.
- 5
Storage limitation
Recruitment data retained maximum 24 months. Billing data: 10 years (legal obligation). Deletion on request anytime.
- 6
Integrity and confidentiality
AES-256 encryption at rest, TLS 1.3 in transit, restricted data access, regular audits, least privilege principle.
Data retention periods
Data retention register
| Data type | Retention period | Legal basis |
|---|---|---|
| Recruiter account | Subscription duration + 1 year | Contract execution |
| Recruitment data | 24 months after recruitment | Legitimate interest |
| Candidate CVs | 24 months or consent withdrawal | Candidate consent |
| Interview transcriptions | Recruitment duration + 6 months | Candidate consent |
| Security logs | 12 months | Legal obligation / security |
| Billing data | 10 years | Legal accounting obligation |
Your GDPR rights
Rights of recruiters and candidates
| Right | How to exercise it | Response deadline |
|---|---|---|
| Access your data | Export from your account or request to support | Within 30 days |
| Rectification | Direct modification in interface or request support | Immediate or within 30 days |
| Erasure | One-click account deletion or request support | Within 30 days |
| Portability | JSON/CSV export available in settings | Immediate |
| Objection | Contact our DPO at contact@aurelia.jobs | Within 30 days |
Where exactly is my data stored?
What happens if I cancel my subscription?
How is candidate data protected?
Are you ISO 27001 or SOC 2 certified?
Need our security documentation?
On request, we provide complete privacy policy, Data Processing Agreement (DPA), processing register and impact analysis (AIPD).
