Catena · April 2026 · v2.0
Privacy Policy
Applies to: catena.work
Your privacy matters to Catena Consultoria em Marketing LTDA (CNPJ 46.961.528/0001-28), referred to as "CATENA". This policy describes how we collect, use, share and protect your personal data, in compliance with the LGPD (Brazil), GDPR (EU/UK), and the EU AI Act.
1. Data Controller
CATENA is the data controller for personal data collected on this website and on app.catena.work. Data Protection Officer (DPO) contact: privacidade@catena.work.
2. Who This Policy Applies To
- Visitors of catena.work
- Candidates who apply for jobs through app.catena.work
- Client Representatives who interact with CATENA on behalf of hiring companies
3. Data We Collect
Candidates: full name, email, phone/WhatsApp, CV/résumé, LinkedIn profile, work history, skills, interview responses (text and optionally audio), salary expectations and other information voluntarily provided.
Client Representatives: name, email and phone number.
Visitors (automatic collection): IP address, browser type, OS, pages visited, timestamps, language preferences, and UTM/tracking parameters via cookies and similar technologies.
4. Legal Bases for Processing (LGPD / GDPR)
- Contract performance (LGPD Art. 7, V / GDPR Art. 6(1)(b)): processing CVs and applications to match you with job opportunities.
- Legitimate interests (LGPD Art. 7, IX / GDPR Art. 6(1)(f)): maintaining the Talent Pool, improving AI models and the platform.
- Consent (LGPD Art. 7, I / GDPR Art. 6(1)(a)): sending communications about open roles and application status.
- Legal obligation (LGPD Art. 7, II): compliance with applicable law.
EU AI Act — High-Risk AI System (Art. 13 & 50)
CATENA uses AI to conduct initial screening interviews and generate compatibility scores. Under EU AI Act Annex III (Section 4), AI systems used in recruitment are classified as high-risk. We disclose that: you are interacting with an AI system, not a human recruiter; the AI score influences but does not solely determine hiring decisions; human oversight is available — hiring companies review all AI assessments; you have the right to request human review of any AI-based decision; our AI is designed to avoid discriminatory outputs based on protected characteristics.
5. AI-Based Decision Making
We use AI to analyse CVs, generate personalised interview questions and produce compatibility scores. Scores are advisory only; the final hiring decision is always made by a human at the hiring company. You may contest any AI assessment and request human review at privacidade@catena.work. (LGPD Art. 20 / GDPR Art. 22 / EU AI Act Art. 13, 14 & 50.)
6. Talent Pool
By applying through CATENA's platform, your data becomes part of our Talent Pool and may be accessed by our Clients for future hiring processes. CATENA acts as controller or co-controller in these cases.
7. Data Sharing
- Hiring companies (Clients): CV, interview transcript and score for recruitment purposes
- OpenAI: responses and CV text processed via API (OpenAI does not use this data to train its models)
- Infrastructure: Heroku (hosting), AWS S3 (file storage), SendGrid (email), Google Workspace
- Other providers: LinkedIn, Manatal, Zapier, Jotform, Mailchimp, WhatsApp Business, Google Analytics
- Authorities: when required by law or court order
We never sell your data to third parties or use it for advertising.
8. Data Retention
- Active applications: while the job posting is open + 12 months
- Interview transcripts/recordings: 12 months from interview date
- CVs and profile data: 24 months from last activity
- Client Representative data: duration of contract + legal retention period
After retention periods, data is securely deleted or anonymised.
9. Security
We implement TLS encryption in transit, encrypted storage, access controls and regular security reviews. In the event of a data breach affecting your rights, we will notify you within 72 hours.
10. International Transfers
Your data may be transferred to the United States (OpenAI, Heroku, AWS). Such transfers are protected by Standard Contractual Clauses (GDPR) and equivalent safeguards under LGPD.
11. Your Rights (LGPD / GDPR)
- Access your personal data
- Correction of inaccurate or incomplete data
- Erasure ("right to be forgotten")
- Data portability in machine-readable format
- Withdraw consent at any time
- Object to automated processing
- Human review of any AI-based decision that significantly affects you (EU AI Act Art. 14)
To exercise any right: privacidade@catena.work. We respond within 15 business days.
12. Cookies
We use cookies and similar technologies to improve site experience, perform traffic analysis (Google Analytics) and personalise content. You may disable cookies in your browser settings.
13. Changes to This Policy
We may update this policy at any time. The new version takes effect immediately upon publication. Material changes will be communicated by email or prominent notice on the platform.
14. Contact & DPO
Data Protection Officer: privacidade@catena.work
General enquiries: hi@catena.work
Catena Consultoria em Marketing LTDA · Av. Angélica 2529, São Paulo – SP, Brazil
