← Back to Idea Match Studio
Data & Security
How Idea Match Studio stores, isolates and protects your candidate data.
Last updated: July 2026
1. Roles
Idea Match Studio processes candidate data on behalf of your organization. You are the data controller; IdeaTeam is the data processor. You decide what goes in; we keep it isolated, available and secure.
2. What we store
• Candidate profiles you add or import — name, contacts, location, skills, experience, CV content and files
• Your organization's settings, templates, reports and vacancies
• User accounts of your teammates (email + a hashed password)
• Your billing profile for invoicing
We only store what you or your integrations put in.
3. Tenant isolation
Every record belongs to exactly one organization. Access is scoped by row-level security at the database layer, so one client's data can never be read by another — even by mistake. Your candidates are yours alone.
4. Access control
Only the teammates you invite can access your organization's data, and each one gets the permissions you assign (view, edit, export, manage users, and so on). IdeaTeam staff do not browse your candidate data; access for support happens only at your request.
5. Encryption
• In transit: all traffic is encrypted over TLS/HTTPS.
• Passwords: hashed by our authentication provider — never stored in plain text.
• Integration credentials (your ATS API keys/tokens) are encrypted at rest with AES-256-GCM before they touch the database.
6. AI processing
To parse an uploaded CV or generate a tailored one, the relevant resume text or image is sent to our AI provider (Anthropic). It is processed to produce the result and is not used to train AI models. We send only what's needed for the task.
7. Sub-processors
We rely on a small set of vetted providers to run the service:
• Supabase — managed database & authentication
• Vercel — application hosting
• Anthropic — AI resume parsing & generation
• Monobank — payment processing
• Google Workspace — transactional email
• GitHub — a support request you send us is tracked there as a ticket, with the text you wrote
Each processes data only to deliver its part of the service.
8. Retention, export & deletion
You stay in control of your base at all times:
• Edit or delete any candidate whenever you want.
• Export your entire database (CSV / JSON) at any time.
• When you close your account, your organization's data is removed from active systems.
9. Your rights (GDPR)
We build in line with GDPR principles. Because you are the controller, data-subject requests (access, rectification, erasure, portability, restriction, objection) are handled by your organization, and we assist as your processor. Need a Data Processing Agreement (DPA) for your compliance file? Contact us and we'll provide one.
10. What we never do
• We never sell your data.
• We never share it with your competitors or other clients.
• We never use your candidate data for advertising.
11. Contact
Questions, a DPA request, or a security concern? Email sales@ideateam.dev.