New: AI Recruiter v2.0 with multi-channel outreach is live  Read what's new →
Trust & Security

Security and data protection at LeadForce

LeadForce Talent is built for recruiting and talent teams that handle candidate data under GDPR and equivalent regimes. This page explains where your data lives, how we contact candidates lawfully, and how we operate as your data processor.

GDPR aligned EU data residency DPA available on request Consent-based outreach Patent-pending engine

Last updated: June 2026

How we operate

What every buyer's security team needs to know

A short, honest summary your procurement, legal and security reviewers can act on. Full documentation is available on request under NDA.

Where your data lives

  • Application and candidate data are hosted on Microsoft Azure in an EU region. Your data stays in the EU.
  • LeadForce Talent is a US Delaware C-Corporation. Our EU GDPR Article 27 representative is based in Poland.
  • Access is role-based and limited to the staff who operate your account.

How we contact candidates

Outreach is sent from LeadForce's own verified LinkedIn and email identities — never from your domain or accounts.

  • Each first contact is a single, individually personalized message based on a public professional profile, under a documented legitimate-interest basis.
  • Candidates can opt out at any time, and only candidates who reply and confirm interest are passed to you.
  • So you receive consented, interview-ready contacts — and we carry the first-contact data-handling risk.

Your data, your control

  • You can export your candidate data at any time.
  • After cancellation, data is retained for 90 days and then permanently deleted. You own your data, always.
  • Exclusion lists you provide — blacklists or no-poach partner lists — are honored and filtered out before any outreach.

Subprocessors

We work with a small set of vetted subprocessors to deliver the service:

  • Microsoft Azure — hosting (EU).
  • LLM providers — model inference for sourcing and messaging.
  • Contact-enrichment and email/LinkedIn delivery infrastructure.

The current, itemized subprocessor list is available on request.

Compliance status

Standards and documentation

We keep this current. Where a standard is in progress rather than complete, we say so.

Item
Status
GDPR (EU/EEA)
Aligned  Processor obligations, legal basis and data-subject rights documented.
EU AI Act
Position & roadmap  Risk classification and roadmap documented for our AI engine.
CCPA / CPRA (US)
Applicability assessed  Statement available for US buyers.
Data Processing Agreement (DPA)
Available on request
SOC 2
Planned  On our roadmap; this page will be updated when status changes.
Intellectual property
Patent-pending  USPTO Provisional No. 63/942,801 (behavioral sourcing engine).

Reviewing LeadForce as a vendor?

Request our compliance pack — GDPR statement, EU AI Act position, CCPA statement and a DPA — or book a 20-minute call with the team to walk through your security questionnaire.

Prefer email? Write to [email protected].