Last updated 29 June 2026
Lucuma is built for recruiters who take data protection seriously. This page explains how the product is designed to support your compliance with the UK GDPR and EU GDPR when you screen candidates.
Your account and your saved records are stored in the EU. Lucuma's database is hosted in Ireland. Nothing in your account leaves the EU.
The AI that reads each CV is operated by Anthropic, a US company. When you run a screening, the CV text is sent to Anthropic's API to be scored. We have pinned that processing to the United States, so it does not run in an unpredictable location. Under Anthropic's Data Processing Addendum, Anthropic acts as a processor, transfers are covered by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, inputs and outputs are deleted from Anthropic's systems within 30 days, and your data is not used to train their models.
Lucuma does not keep candidate CVs. They are held in your browser for the length of your session and are not written to our servers.
There is one exception, and it only happens if you choose it. If you press Save compliance record on a screening, the candidate names, scores and reasoning for that run are stored in our EU database so that you have an audit trail. That is the only route by which candidate data is stored with us. You can ask us to delete any record at any time by emailing apps@marvanova.com.
Until 7 September 2026 this page said that all processing took place within the EU. The storage half of that was true. The AI processing half was not, because our AI provider has no EU inference region. We corrected it on 7 September 2026. If EU hosted inference becomes available we will move to it and update this page then, not before.
We never use candidate data to train AI models. Your candidates' information is used solely to give you your results.
For the candidate data you upload, you (or your organisation) are the data controller and Lucuma acts as your processor. Agency and Enterprise plans include a full Data Processing Agreement that documents this relationship, the processing details, and the safeguards in place.
Lucuma is designed to help you meet the requirements around automated decision-making. Every score is explainable in plain English, low-data CVs are flagged for manual review rather than guessed, and Lucuma never makes a hiring decision or auto-rejects a candidate. It ranks and explains; a human always decides. This keeps a meaningful person in the loop, which matters under UK ICO guidance and EU rules on automated decisions in hiring.
Because you remain the controller, you are best placed to respond to candidate rights requests. Lucuma supports this by keeping screening transparent and auditable, with a clear reason behind every score.
These are the companies that help us deliver Lucuma, what each one does, and where.
| Sub-processor | What they do | Where | Safeguard |
|---|---|---|---|
| Anthropic, PBC | Scores each CV against your criteria | United States, pinned by us | EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Deleted within 30 days. Not used to train models. Their own sub-processor list is at anthropic.com/subprocessors. |
| Supabase | Database, accounts, and any compliance records you choose to save | EU, Ireland | Stays within the EU |
| Netlify | Serves the website and the app | Global content network | No candidate data is sent to it |
| Stripe | Payments and invoices | EU and United States | No candidate data is sent to it |
| Resend | Account and notification email | EU and United States | No candidate data is sent to it |
We use a small number of trusted infrastructure and AI processing providers, each under contractual data protection terms, and apply appropriate technical and organisational security measures. A current list of sub-processors and our security overview are available on request.
To request a Data Processing Agreement, a sub-processor list, or our security documentation, email apps@marvanova.com. See also our Privacy Policy.