Compliance

GDPR and data processing

Last updated 29 June 2026

Lucuma is built for recruiters who take data protection seriously. This page explains how the product is designed to support your compliance with the UK GDPR and EU GDPR when you screen candidates.

Where your data is processed

Your account and your saved records are stored in the EU. Lucuma's database is hosted in Ireland. Nothing in your account leaves the EU.

The AI that reads each CV is operated by Anthropic, a US company. When you run a screening, the CV text is sent to Anthropic's API to be scored. We have pinned that processing to the United States, so it does not run in an unpredictable location. Under Anthropic's Data Processing Addendum, Anthropic acts as a processor, transfers are covered by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, inputs and outputs are deleted from Anthropic's systems within 30 days, and your data is not used to train their models.

What we keep, and what we do not

Lucuma does not keep candidate CVs. They are held in your browser for the length of your session and are not written to our servers.

There is one exception, and it only happens if you choose it. If you press Save compliance record on a screening, the candidate names, scores and reasoning for that run are stored in our EU database so that you have an audit trail. That is the only route by which candidate data is stored with us. You can ask us to delete any record at any time by emailing apps@marvanova.com.

A correction, made 7 September 2026

Until 7 September 2026 this page said that all processing took place within the EU. The storage half of that was true. The AI processing half was not, because our AI provider has no EU inference region. We corrected it on 7 September 2026. If EU hosted inference becomes available we will move to it and update this page then, not before.

No model training on candidate data

We never use candidate data to train AI models. Your candidates' information is used solely to give you your results.

Controller and processor

For the candidate data you upload, you (or your organisation) are the data controller and Lucuma acts as your processor. Agency and Enterprise plans include a full Data Processing Agreement that documents this relationship, the processing details, and the safeguards in place.

Explainable and human-in-the-loop by design

Lucuma is designed to help you meet the requirements around automated decision-making. Every score is explainable in plain English, low-data CVs are flagged for manual review rather than guessed, and Lucuma never makes a hiring decision or auto-rejects a candidate. It ranks and explains; a human always decides. This keeps a meaningful person in the loop, which matters under UK ICO guidance and EU rules on automated decisions in hiring.

Your candidates' rights

Because you remain the controller, you are best placed to respond to candidate rights requests. Lucuma supports this by keeping screening transparent and auditable, with a clear reason behind every score.

Our sub-processors

These are the companies that help us deliver Lucuma, what each one does, and where.

Sub-processorWhat they do WhereSafeguard
Anthropic, PBC Scores each CV against your criteriaUnited States, pinned by us EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Deleted within 30 days. Not used to train models. Their own sub-processor list is at anthropic.com/subprocessors.
Supabase Database, accounts, and any compliance records you choose to saveEU, Ireland Stays within the EU
Netlify Serves the website and the appGlobal content network No candidate data is sent to it
Stripe Payments and invoicesEU and United States No candidate data is sent to it
Resend Account and notification emailEU and United States No candidate data is sent to it

Security

We use a small number of trusted infrastructure and AI processing providers, each under contractual data protection terms, and apply appropriate technical and organisational security measures. A current list of sub-processors and our security overview are available on request.

Request a DPA or more information

To request a Data Processing Agreement, a sub-processor list, or our security documentation, email apps@marvanova.com. See also our Privacy Policy.