Legal

GDPR & Data Protection

Last updated: 27 March 2025  ·  Contact: hello@marvanova.com

Recruitment involves processing sensitive personal data. This page explains how Lucuma supports your GDPR obligations as a recruiter, and what we do to protect candidate data.

Who is responsible for what

When you use Lucuma to screen CVs, there are two distinct roles under GDPR:

You

Data Controller

You decide why and how candidate personal data is processed. You are responsible for ensuring you have a lawful basis to process the CVs you upload (e.g. legitimate interest in assessing job applicants, or explicit consent from candidates). You are responsible for responding to candidate data subject requests.

Lucuma / Marvanova

Data Processor

We process candidate data only on your instruction, to generate screening results. We do not process that data for any other purpose. We retain no copies of uploaded CVs after your session.

Our GDPR commitments

Data Processing Agreement (DPA)

Agency and Enterprise plan subscribers receive a formal GDPR Data Processing Agreement which documents:

To request a DPA, contact hello@marvanova.com.

Your obligations as a recruiter

When using Lucuma you remain responsible for:

Candidate rights

Lucuma does not retain candidate data, so we cannot respond to candidate data subject access requests on your behalf. If a candidate contacts you about how their data was used in your screening process, that is your responsibility as data controller to address.

If a candidate contacts us directly, we will direct them to you as the data controller and confirm that we hold no copies of their data.

AI and automated decision-making (Article 22)

Lucuma's screening results constitute automated processing. Under Article 22 of UK GDPR, if automated processing produces legal or similarly significant effects on candidates, those candidates have the right not to be subject to solely automated decisions.

Lucuma is designed as a screening tool, it produces a ranked shortlist for human review, not a final decision. We recommend that you:

Data breach notification

In the event of a data breach affecting your account data, we will notify you within 72 hours of becoming aware of the breach, in accordance with UK GDPR Article 33. As we do not retain candidate CV data, a breach would not expose candidate CVs.

ICO registration

As a UK-based data processor, Marvanova is registered with the Information Commissioner's Office (ICO). If you have unresolved concerns about how we handle data, you may lodge a complaint with the ICO at ico.org.uk.

Contact our data team

For all GDPR-related enquiries, DPA requests, or data subject assistance:
hello@marvanova.com