Privacy policy
Last updated: October 3, 2026
Deelbert is a people and company workspace: employers keep employee files, contracts, time off, documents and attendance in it, and recruiting teams keep candidate pipelines in it, with AI features on top. That means we handle personal data: yours, your employees' and your candidates'. This page says plainly what we collect, why, where it goes (including outside the EU), how long we keep it and how to get it out or delete it.
Contents: 1. Who is responsible · 2. Account and company data · 3. Employee data · 4. Candidate data · 5. AI providers and transfers · 6. Subprocessors · 7. Security · 8. Retention · 9. Your rights · 10. Contact
1. Who is responsible for the data
Deelbert (operator of deelbert.com, "we") provides the service. Privacy contact: contact@deelbert.com. The company that operates Deelbert:
- Company: HARP SOFTWARE S.R.L.
- Registered office: Intrarea Guliver nr. 13, bl. C2, sc. 2, et. 7, ap. 500, Sector 6, București, România
- Trade Register number: J2021022546402
- Tax identification number (CUI): 41883863
- VAT ID: RO41883863
- Email: contact@deelbert.com
The use of the service is governed by our Terms and Conditions.
- Your account data (name, email, password, settings, billing): we are the data controller.
- Employee data and candidate data your organization puts in (employee files, contracts, time off, documents, candidate profiles, notes): your organization is the data controller and we are its data processor. We process that data only to run the service, on your organization's instructions, under a data processing agreement.
If you are an employee or a candidate of a company that uses Deelbert, that company decides why and how your data is processed. Section 9 explains how to exercise your rights with them and with us.
2. Account and company data
What we collect
- Name, email address and a password stored only as a salted hash.
- Your workspace (organization) memberships, roles, the modules your organization has turned on and the plan it is on.
- Company structure your organization sets up: units, teams, locations, positions, cost centers, holiday calendars, leave policies, document templates and company policies.
- Operational records: sign-in sessions and last login time, API tokens and extension pairing codes (stored hashed), AI usage counters (how many AI actions were used and how many tokens, never the content), rate-limit records keyed by IP address, and in-app feedback you send us.
- Billing, when a paid plan is active: subscription status and provider identifiers. Card details go directly to our payment provider and never reach our servers.
Why (legal basis)
- Running the service you signed up for (performance of contract).
- Transactional email: email verification, password reset and change notices, team and employee invitations, time off and request notifications (performance of contract).
- Security and abuse prevention: rate limiting, session management, audit logging (legitimate interest).
- We do not send marketing email you did not ask for, and we use no third-party analytics or advertising trackers on this site, in the app or in the extension. The only cookie we set is the session cookie that keeps you signed in; your theme preference is kept in your browser.
3. Employee data (processed for your employer)
When a company uses Deelbert as its people and company system, it stores information about its employees and contractors. The company is the controller; we are the processor. The categories below describe what the product can hold. Each company decides which of them it actually uses.
Categories
- Identity and contact: name, work email, phone, address, date of birth, job title, team, manager, location, employment type and status.
- National identification number (CNP or equivalent): stored only in encrypted form (see Security). On a deployment where the encryption key is not configured, the field cannot be saved at all.
- Employment contracts and addenda: start and end dates, probation, position, working time, salary and other contract terms. Salary is visible only to roles the company authorizes.
- Time off and absences: leave requests, balances, approvals and the notes on them. Medical leave (sick leave and medical certificates) is a special category of data under GDPR Article 9. In Deelbert the medical type of an absence and the certificate scan are visible only to the employee, HR, owners and roles the company designates; other users see a generic absence, and the audit log and exports mask the medical trace for anyone without that access.
- Attendance and time: attendance days, work schedules, and hours logged on projects.
- Documents and files: generated documents (contracts, certificates, decisions, policies), uploaded files such as signed scans, diplomas and ID copies, and click-to-sign records. Files are stored inside our database (up to 25 MB per file).
- Requests and workflows: employee requests, certificate requests, onboarding and offboarding checklists, policy acknowledgements.
- Audit trail: who changed what and when in an employee file, including the IP address of the person acting for signatures and policy acknowledgements.
Legal basis and responsibility
The employer processes this data to perform the employment contract, to meet its legal obligations (labour, tax and social security law) and, for special categories such as medical leave, under the employment-law exceptions in GDPR Article 9(2)(b). The employer is responsible for having a valid basis and for informing its employees. We process the data only on the employer's instructions and never for our own purposes.
Who can see it
Access is role-based and enforced by the server, not just hidden in the interface: an employee sees their own file, managers see their reports, HR and owners see the whole company, and finance-type roles see what the company grants them. Every organization's data is isolated from every other organization's.
4. Candidate data (recruiting module and browser extension)
- Profiles captured with the Deelbert Capture extension or pasted or typed in by hand: the visible text of the profile page you explicitly chose to save, its URL and the profile photo if one was on the page.
- CVs you upload, notes you write, pipeline stages, jobs, interviews, leads and contacts, and match scores.
- Structured fields the AI extracts from that text (skills, seniority, experience, languages). The AI is instructed not to invent data: anything it cannot find in your text stays empty. AI scores are decision support only; the product never auto-rejects or auto-advances a candidate based on a score.
The browser extension, specifically
- On your device the extension stores one thing: the access token that connects it to your Deelbert account (plus your name and workspace label for display). You connect through an authorization screen on deelbert.com; the extension never sees your password.
- When you click capture, the previewed profile text is sent over HTTPS to your own Deelbert workspace and nowhere else. The extension makes no requests to LinkedIn or any third party. Message and conversation capture was removed from the product.
- You can disconnect the extension at any time: open it and click "Disconnect". This revokes that device's access immediately.
5. AI providers and international transfers
AI features run only when you or your organization trigger them. For each feature, the text it works on is sent to an AI provider, which returns a structured result. We do not train models on your data. What each provider receives:
| Feature | What is sent | Provider today |
|---|---|---|
| Candidate extraction and translation | The captured profile text or the text of an uploaded CV | DeepSeek |
| Match scoring and outreach drafts | The candidate's extracted profile and the job description | DeepSeek |
| Job description analysis, job import from documents, LinkedIn search generator, weekly pipeline summary | The job text, the document you upload, your search criteria, or aggregate pipeline activity | DeepSeek |
| Employee ID pre-fill (people module) | The text layer of the identity document you upload: name, national ID number, date of birth, address, nationality. Image-only scans are not processed. The file itself is not stored; you review the fields before anything is saved. | DeepSeek |
| Semantic candidate search (only when enabled) | Candidate profile text, converted to numeric embeddings for similarity search | Voyage AI (United States) |
Anthropic (Claude API, United States) is the alternative provider our software supports. Production does not currently send data to Anthropic. If we enable it for some or all features, it will be listed in the table above and in Section 6 first.
AI outputs are always shown to a person for review. Deelbert does not make automated decisions with legal or similarly significant effects about employees or candidates.
6. Subprocessors
Deelbert runs on Fly.io in Frankfurt, Germany (EU). All service data, including uploaded files, lives in a PostgreSQL database there, encrypted in transit. We use a small number of subprocessors, only for what is listed:
| Subprocessor | What for | What they see | Location |
|---|---|---|---|
| Fly.io | Hosting and managed database | Infrastructure hosting all service data | Data in Frankfurt, Germany (EU); US company |
| DeepSeek | AI features (see Section 5) | The text a feature runs on, per request | China (outside the EU/EEA, no adequacy decision) |
| Voyage AI | Embeddings for semantic candidate search, only when enabled | Candidate profile text, per request | United States |
| Anthropic | Alternative AI provider, not active in production today | Nothing today; the same text as DeepSeek if enabled | United States |
| Resend | Transactional email delivery | Recipient email address and the message content | United States |
| Stripe | Payments and subscriptions, when a paid plan is active | Your name, email and payment details (card data never reaches us) | United States and EU entities |
| Cloudflare | DNS for deelbert.com | DNS lookups only; it does not proxy or read application traffic | United States |
We do not sell personal data. We do not share it with data brokers or advertisers. Nobody gets employee or candidate data except the organization that entered it, the subprocessors above for the listed purposes, and us, to the extent needed to operate the service.
7. Security
- HTTPS everywhere; the session cookie is marked secure and HTTP-only in production.
- Passwords are stored as salted hashes; API tokens and extension pairing codes are stored hashed.
- National ID numbers (CNP) are encrypted at the field level with AES-256-GCM using a key held outside the database, when that key is configured. They are never written in clear text and never appear in the audit log, not even masked.
- Server-side, role-based access control on every API route; tenant isolation between organizations; medical data restricted to designated roles (see Section 3).
- An audit log records changes to employee files, documents, absences and settings, with the acting user, time and IP address, so both the employer and we can show what happened. Sensitive values in the log are masked.
- Identity documents uploaded for pre-fill are processed in memory only and are not stored or logged.
- Rate limiting and session management to prevent abuse.
8. How long we keep it
- Candidate data: until your organization deletes it or the workspace is closed. Deleting a candidate is a real delete: the profile, its captured raw text, AI outputs, notes and history are hard-deleted from the live database, not flagged and kept.
- Employee data: for as long as your employer keeps it in the workspace. Labour and tax law requires employers to keep some employment records for long periods, so Deelbert does not auto-delete employee files; offboarding closes a file rather than erasing it. Employers decide their own retention periods and can delete individual records through us or close the workspace, which hard-deletes everything in it.
- Your account: kept while it is active. If you close it, account data is deleted on the same hard-delete basis.
- Audit records are kept for the life of the workspace so that the employer and we can demonstrate what happened. They reference events, not file contents, and are deleted with the workspace.
- Backups: our hosting provider keeps database backups for a limited rolling period; deleted records disappear from backups when those expire.
- Provider retention: AI providers receive data per request and are not asked to keep it. What they retain is governed by their own terms; see Section 5 for the DeepSeek caveat.
9. Your rights, and employees' and candidates' rights
Under the GDPR these apply whether you are a Deelbert user, an employee of a company that uses Deelbert, or a candidate whose profile a recruiter saved:
- Access and portability (Art. 15, 20): the product has a built-in per-person export: the complete employee file (profile, contract, absences, documents, requests and the audit trail about that person) and the complete candidate record, each in one file. Employers and recruiters can run it themselves; employees and candidates can request it.
- Rectification (Art. 16): every field is editable by the organization that owns the record; employees can keep their own contact details up to date from their account.
- Deletion (Art. 17): built in as a permanent hard delete for candidates and workspaces, subject to the employer's legal retention duties for employment records.
- Objection and complaints: you can object to processing, and you have the right to complain to your data protection authority. In Romania that is ANSPDCP (dataprotection.ro).
If you are an employee or a candidate: the company that entered your data is the controller, so the fastest route is asking them directly. But you can always write to us at contact@deelbert.com; we will pass the request to the right organization and make sure it is honored.
Changes to this policy
If we change what we collect, which providers process it or where it goes, we will update this page and the date at the top, and for changes that matter we will tell users in the app before they take effect. Switching the AI provider counts as a change that matters.
10. Contact
Questions, requests, or something here that is not clear: contact@deelbert.com.