Deciml ("we", "us", "our") operates the Deciml recruitment platform at deciml.io. This Privacy Policy explains how we collect, use, store and protect your personal data when you use our platform, in accordance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) where applicable, and the Data Protection Act 2018.
1. Data Controller
The data controller responsible for your personal data is Birch & James Associates Limited, registered in England and Wales (company no. 09549374), registered office: Office Gold Building 7, Floor 5, 566 Chiswick High Road, Chiswick Business Park, London W4 5YG, United Kingdom, trading as Deciml and, for our recruitment outreach, TechChain Talent. If you have questions about this policy or wish to exercise your rights, please contact us at privacy@deciml.io.
2. What personal data we collect
2.1 Candidate data
When you create a profile on our platform, we collect:
- Name, email address and password (hashed)
- Professional information: job title, location, bio, work experience, education
- Skills and proficiency levels
- Career preferences: desired role, work type (remote/hybrid/onsite), salary expectations, preferred location and company stage
- Availability status (actively looking, open to opportunities, not looking)
- Social and messaging handles: Telegram, Discord, GitHub, Twitter/X
- If you verify a GitHub or X handle (Run my match): the handle, when it was verified, and for X, the links to up to five public posts you chose to submit and their text
- Scores we calculate from your public GitHub activity, and topic labels for the X posts you submitted. The topic labels come from an AI model that sees only the text of each post, never your name or handle; they describe your public work and are not used to accept or reject you for any role
- CV/resume documents you upload
- Profile photograph
- Application history and cover notes
- Communication preferences (email and Telegram notification settings)
2.2 Data from CVs
When you upload a CV, we use AI-powered text extraction to parse your document and pre-populate your profile with information including your name, title, skills, work history and education. You can review and edit all extracted data before it is saved.
2.3 Technical and usage data
- IP address, browser type and version
- Pages visited, time spent on pages, referral source
- Device information (operating system, screen resolution)
- If you are a candidate: the days you said GM (checked in), to show your streak to you and to recruiters
Usage analytics are collected first-party and processed by PostHog on EU-hosted infrastructure acting as our processor. We do not use advertising pixels, cross-site trackers, or browser-extension telemetry, we do not run third-party ad networks on any page, and analytics data is never sold or shared with advertisers.
2.4 Data from third-party integrations
- Telegram chat ID (when you link your Telegram account for notifications)
- Job data synced from our CRM system (Manatal) for the roles listed on the platform
2.5 People we contact about hiring
Our recruitment business, trading as TechChain Talent, contacts founders, executives and hiring managers at companies that are likely to be hiring, usually after a funding round, to offer our recruitment services. If you received an email or message from us about hiring, this section explains what we hold about you and why.
- What we hold: your name, job title and seniority; your employer, its funding rounds and investors; your work email address and whether it has been verified; where available, your phone number, location, education, LinkedIn, X and Telegram profiles, your X follower count and an influence score we calculate from it; notes our team writes about you; the messages we draft or send to you, including passages drafted with the help of AI, and your replies; and labels we use to prioritise our outreach.
- Where it comes from: RootData (public funding data, including founders and team members and their public profiles), Apollo (a business-contact data provider), public web sources found by our AI-assisted research tool, lists our team imports or enters by hand, and anything you send us, such as an enquiry through our website. We aim to email work addresses only, and hold back any address at a known personal email provider.
- Why, and our legal basis: to offer recruitment services to your company. Our legal basis is legitimate interests: approaching people in their professional capacity about hiring for the company they work for.
- How we contact you: a person on our team decides to contact you, and nobody is added to our outreach without that decision. Messages on LinkedIn, Telegram or by phone are always sent by a person; after that decision, some emails in a sequence may be sent on a schedule. Parts of our emails are drafted with the help of an AI model, which sees your name, job title and facts about your company; your email address and contact handles are not shared with it.
- Who we share it with: Apollo (contact data), Google Workspace (the mailbox our emails are sent from and replies arrive in), OpenRouter/Anthropic (drafting and research), Slack (internal alerts to our team about new funding rounds, which can include your name and contact details), and the providers that run our platform: Supabase (database), Vercel (hosting), Inngest (background jobs) and Sentry (error monitoring). We never share it with other clients or candidates.
- How long we keep it: we delete your details once 24 months have passed without us contacting you or recording anything new about you, such as a new funding round at your company. If you reply to us or your company becomes a client, we keep them while we work together. If you opt out, we keep only what we need to make sure we never contact you again. If you ask us to erase your details and we hold no email address for you, we keep only your LinkedIn profile address, so that we never add or contact you again. Emails we exchanged also remain in our email mailbox.
- Opting out: use the unsubscribe link in any of our emails, reply asking us to stop, or write to privacy@deciml.io. We then stop all contact on every channel. Your other rights are set out in Section 8.
2.6 Card verification and scans
Card verification is off unless you switch it on. When it is on, the QR code on your Deciml card opens a page that shows your card name (never your real name), finish, rarity, role family, a broad region, your availability, the signals we verified (GitHub, wallet, on-chain score, X posts, dated experience) and your card stats. It never shows your contact details, handles, wallet address, employer or exact location. The page carries a signature so a viewer can check the numbers have not been altered.
When someone opens that page, we may record a scan: the date, the city and country our hosting provider derives from their connection, and whether they came from the QR code, a link or a banner. We never store their IP address. Only you see your scans; recruiters never do. If the visitor signs up within 30 days, we note that on the scan and, if your profile is public, credit you as their referrer.
A visitor can ask us for an introduction from that page by leaving their email address and, optionally, a company and a note. We pass the request to our team and tell you someone asked; we ask you before we share any of your details. We keep the visitor's request as a notification to our team.
2.7 Anonymised profiles shown to companies
Anonymised, non-identifying summaries of profiles may be shown to companies considering hiring through us. A summary carries only a role family, a broad region, a band of years of experience, five skills and one line of evidence (for example "GitHub verified"), and each summary is shown only when at least five candidates in our network share it, so it cannot single anyone out. It never includes a name, photo, employer, school, handle, wallet, exact location, salary, notice period or availability. Imported profiles and candidates who have blocked any company are never included, and neither are hidden or closed profiles or anyone not looking for work. Nobody is introduced to a company without our asking them first.
When a company pastes a job description into our analyser, we read the role's facts with an AI model (company facts only: no candidate data goes into that step) and keep a record of what was parsed, never the job description itself. If the company books a call, we keep the parsed summary with their enquiry.
3. How we use your data
We process your personal data for the following purposes:
- Account creation and authentication: to create and manage your account on the platform (legal basis: contract performance)
- Profile and job matching: to match your profile to relevant job opportunities using our automated matching engine, and to display your profile to our recruitment team (legal basis: contract performance and legitimate interests)
- Application processing: to process your job applications and manage your candidacy through the recruitment pipeline (legal basis: contract performance)
- Communications: to send you notifications about application status updates, new job matches, and weekly job digests via email and/or Telegram (legal basis: consent and legitimate interests)
- Platform improvement: to analyse usage patterns and improve our platform and matching algorithms (legal basis: legitimate interests)
- Security: to protect the platform against fraud, abuse and security incidents (legal basis: legitimate interests)
- Legal compliance: to comply with applicable laws and regulations (legal basis: legal obligation)
4. Automated decision-making
Our platform uses automated processing to match candidate profiles to job opportunities and to score the quality of matches. This processing uses a combination of rules-based classification (matching your skills, experience and preferences against job requirements) and AI-powered scoring (using large language models to assess match quality).
These automated matches are used to surface relevant opportunities to you and to assist our recruitment team in identifying suitable candidates. No automated decision produces legal effects or similarly significant effects on you without human review. All hiring decisions involve human assessment by our recruitment team and the hiring client.
You have the right to request human review of any automated matching decision, to express your point of view, and to contest the outcome. Contact us at the email address above to exercise this right.
For accountability, we keep an internal log of automated matching decisions that were surfaced or acted on (the job, the score, and the model and version that produced it). This log is included in your data export (Section 8), is pseudonymised if you delete your account, and is retained for 24 months.
5. Who we share your data with
- Hiring clients: When you apply for a role or we identify you as a potential match, we share relevant profile information (name, title, skills, experience, location, CV) with the hiring company for that specific role. We do not share your salary expectations or availability status with clients without your consent.
- Public profile (optional): If you switch on a public profile, the profile sections you choose to make public (such as your name, headline, skills, credentials and scores) are visible to anyone at your chosen deciml.io/u/ address. Public profiles are off by default, your availability, salary expectations and applications are never public regardless of your settings, and you can switch the public profile off at any time.
- Service providers: We use the following third-party processors to operate the platform:
- Supabase (database hosting and authentication, EU/US)
- Vercel (application hosting, global CDN)
- OpenRouter/Anthropic (AI-powered matching and CV parsing)
- Resend (transactional email delivery)
- Telegram (messaging notifications, where you have opted in)
- Upstash (rate limiting infrastructure)
- PostHog (first-party product analytics, EU-hosted)
- Cloudflare (Turnstile bot protection on public forms)
- Legal requirements: We may disclose your data where required by law, regulation or court order.
We do not sell your personal data to third parties. We do not share your data with advertisers.
6. International data transfers
Some of our service providers process data outside the UK and EEA (including in the United States). Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office or the European Commission, or reliance on an adequacy decision.
7. Data retention
We retain your personal data for as long as your account is active on the platform. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain certain records for legal, regulatory or legitimate business purposes (such as records of placements made).
We record the date of your last sign-in so long-inactive accounts can be identified. Where an account has seen no sign-in for 24 months, we may contact you to ask whether you wish to keep it; if we receive no response within 30 days, we may delete the account and its associated data.
Candidate records imported from our recruitment CRM that have never been used on this platform (no applications, shortlists or recruiter activity) are automatically deleted 24 months after import.
Job application records may be retained for up to 3 years after the application date for the purpose of responding to any disputes or claims related to the recruitment process.
8. Your rights
Under UK GDPR and EU GDPR (where applicable), you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data (subject to legal retention requirements).
- Right to restrict processing: Request that we limit how we use your data in certain circumstances.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests, including profiling for matching purposes.
- Right to withdraw consent: Where processing is based on consent (e.g. marketing communications), you may withdraw consent at any time via your profile notification settings.
- Right not to be subject to automated decision-making: Request human review of automated matching decisions (see Section 4).
To exercise any of these rights, contact us at privacy@deciml.io. We will respond within one month. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or, if you are in the EU, your local supervisory authority.
9. Data security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Passwords are hashed using bcrypt and never stored in plain text
- All data in transit is encrypted via HTTPS/TLS
- Database access is restricted to authorised services only
- API endpoints are protected by authentication and rate limiting
- Security headers (CSP, HSTS, X-Frame-Options) are enforced on all pages
- Access to candidate data by our recruitment team is limited to those who need it for their role
10. Children
Our platform is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email or via a notice on the platform. The date at the top of this policy indicates when it was last updated.