Home›Privacy policy
Privacy policy

Your data, explained clearly.

We collect as little as possible, store it securely, and give you full control over it.

Contents
  • 1. Who we are
  • 2. What we collect
  • 3. How we use it
  • 4. Storage & security
  • 5. Your rights
  • 6. Retention
  • 7. Third parties
  • 8. Cookies
  • 9. Changes

1. Who we are

Norva Talent is a recruitment service operating in Finland. We connect international professionals with English-speaking companies through a structured, question-based assessment process.

DetailInformation
Company nameNorva Talent (Toiminimi)
Data controllerMike Verwoerd, Founder
Privacy contactprivacy@norvatalent.com
Websitenorvatalent.com
LocationEspoo, Finland
Supervisory authorityFinnish Data Protection Ombudsman (tietosuoja.fi)

2. What data we collect and why

We collect only the minimum data necessary to provide our recruitment service. Version 1.1, effective from company registration.

Data typePurposeLegal basisRetention
Email addressContact and authenticationConsent (Art. 6.1a GDPR)Until deletion request or 24 months inactivity
Questionnaire answersCandidate assessment and matchingConsent (Art. 6.1a GDPR)12 months active, deleted at 24 months
Spectrum scoresRole matching and talent poolConsent (Art. 6.1a GDPR)Same as questionnaire answers
Role application detailsProcessing specific job applicationsConsent + Legitimate interest6 months after application closes
Anonymous salary rangeMarket intelligence, never linked to an individualLegitimate interest (Art. 6.1f)Anonymised permanently
Consent timestampProof of consent givenLegal obligation (Art. 7 GDPR)5 years

What we do not collect: CVs are not stored on our systems. No names, phone numbers, addresses, demographic data, or photos are stored beyond what candidates explicitly provide in questionnaire answers.

3. How we use your data

Candidates

  • To assess your fit for specific roles using structured questionnaire answers
  • To maintain your profile in our talent pool if you have opted in
  • To contact you about future roles that match your profile (maximum once per month)
  • To provide honest feedback on your application regardless of outcome
  • To send you a magic-link login when you request access to your profile

Companies

  • To present shortlisted candidate profiles (anonymised until both parties agree to proceed)
  • To communicate about active recruitment engagements
  • To send service-related communications

We do not sell your data. We do not share your data with third parties outside of the active recruitment process. We do not use your data for advertising.

4. How we store and protect your data

All candidate data is stored in encrypted cloud infrastructure. We use Microsoft 365 (Outlook and OneDrive for Business) for email and document storage, which operates under Microsoft's GDPR-compliant data processing agreement applicable to all European customers.

  • All data is encrypted at rest and in transit using Microsoft enterprise-grade encryption
  • Access is restricted to authorised Norva Talent personnel only
  • Two-factor authentication is required on all systems holding personal data
  • Passwords are never stored. Authentication uses magic-link email only.
  • OneDrive for Business provides version history and deletion audit trails

5. Your rights under GDPR

To exercise any of these rights, contact us at privacy@norvatalent.com. We will respond within 30 days.

RightWhat it means
AccessRequest a copy of all data we hold about you
RectificationAsk us to correct inaccurate or incomplete data
ErasureAsk us to delete all your data. We confirm deletion within 30 days.
PortabilityReceive your data in a structured, machine-readable format (JSON or CSV)
RestrictionAsk us to stop processing your data while a dispute is resolved
ObjectObject to processing based on legitimate interest
Withdraw consentWithdraw consent at any time. Does not affect prior processing.

If you believe we have handled your data incorrectly, you have the right to lodge a complaint with the Finnish Data Protection Ombudsman: tietosuoja.fi

6. Data retention

Data typeRetention periodWhat happens after
Active application data6 months after application closesPermanently deleted
Talent pool profile (opted in)24 months from last activityProfile deleted, email removed
Consent records5 yearsArchived then deleted
Anonymous salary range dataIndefinite (fully anonymised)No individual deletion applicable
Email correspondence2 yearsPermanently deleted

Candidates in the talent pool receive a re-confirmation request at 18 months. If no response, the profile is archived. At 24 months of inactivity all personal data is permanently deleted.

7. Third-party services

ServicePurposeData processed
Microsoft 365Email, document and data storageEmail addresses, documents, questionnaire data (under Microsoft DPA)
SupabaseAssessment response databaseQuestionnaire answers, scores, timestamps (EU data residency)
Domainhotelli.fiWebsite hostingWebsite access logs only

8. Cookies and website

norvatalent.com uses minimal cookies necessary for basic website function, specifically a single cookie to remember your light/dark theme preference. No advertising cookies, tracking pixels, or third-party analytics scripts are used. If this changes, this policy will be updated and visitors will be informed.

9. Changes to this policy

When we make significant changes, we will notify affected individuals by email at least 14 days before the changes take effect. The latest version is always available at norvatalent.com/privacy.html.

Version 1.1 · Last updated: May 2026 · Questions: privacy@norvatalent.com