Last updated: May 13, 2026
Eligio is committed to compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") for all users in the European Union and European Economic Area. This page explains our obligations and your rights under GDPR.
Under GDPR, the distinction between controller and processor is important:
Enterprise customers may request a Data Processing Agreement (DPA) by emailing legal@eligio.ai.
We process personal data on the following legal bases:
Some of our infrastructure providers are based outside the EEA. Where we transfer data internationally, we rely on:
A list of sub-processors is available upon request.
As a data subject (EU/EEA), you have the following rights:
Request a copy of all personal data we hold about you.
Ask us to correct inaccurate or incomplete data.
Request deletion of your personal data where there is no overriding legal basis to retain it.
Ask us to restrict processing while a dispute is resolved.
Receive your data in a machine-readable format for transfer to another controller.
Object to processing based on legitimate interests, including profiling.
AI scores on our platform are decision-support tools; final hiring decisions always involve human review.
To exercise any of these rights, email privacy@eligio.ai. We will respond within 30 days.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
If you are not satisfied with our response to a data request, you have the right to lodge a complaint with your national data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu.
For GDPR-related matters, contact our Data Protection Officer at dpo@eligio.ai.