Digital Talent Partner ATS ("DTP ATS") and the Pipeline Catcher Chrome extension. Effective 2026-08-03.
Digital Talent Partner ("DTP", "we") is an independent recruiting partner for US technology startups. This policy covers the DTP ATS, our internal applicant-tracking system at ats.digitaltalentpartner.com, and the Pipeline Catcher Chrome extension our recruiters use to add candidates to it.
These are private, internal tools. Only DTP staff and contracted recruiters can sign in. They are not a public product, and candidates do not have accounts. This policy explains what we hold about candidates, because candidates are the people whose data we mostly process — even though they are not the ones using the software.
About candidates:
About the recruiters who use the ATS: their name and work email, their permission level and role assignments, and — if they connect a mailbox to send outreach — their email address and an encrypted credential for that mailbox.
We do not ask for or store government identifiers, financial account details, date of birth, or any special-category data such as health, ethnicity or religion. There is no field for any of these.
When a candidate is already on file, the extension only fills in fields that are empty. It never overwrites information already on the record.
We use candidate data to do recruiting work: to assess whether you fit a role we are hiring for, to contact you about it, to prepare and send a submission to the client hiring for that role, to schedule interviews, and to keep track of where you are in that process.
When we submit you to a client, we share the details relevant to that application. We do that because it is the point of the introduction, and we tell you which company before we do it.
To notice when you have replied to us, our system reads the mailboxes our recruiters have connected and matches incoming messages to candidate records by sender address. It reads a recruiter's inbox, not yours. A human reviews each match and decides what to record.
We never sell candidate data, never share it for advertising, and never use it to build profiles for anyone other than the role you are being considered for.
Our lawful basis. Where you applied to us directly, we process your data to take steps at your request before entering a contract, and with your consent. Where we found you through a public professional profile, we rely on our legitimate interest in matching qualified people to roles we are hiring for — an interest we have weighed against your privacy rights. You can object to that at any time by replying to any message from us or emailing the address below, and we will stop.
We do not send candidate data to any AI or large language model service. No part of the DTP ATS transmits your information to an AI provider. The one assistant feature in the system answers questions about a role from stored role information using fixed rules, and makes no external call at all.
No decision about you is made automatically. The ratings and tiers in our system are entered by a recruiter and are used to help a person decide, never to decide on their own. A human chooses who to contact and who to submit.
Clients. When we submit you for a role, we share your details with that employer. We identify the employer to you first.
Service providers. The DTP ATS runs on these, and each one handles some candidate data on our behalf:
Our pages load a web font from Google Fonts, which means Google receives your IP address and browser type when a page is opened. We use no analytics, advertising or tracking services of any kind.
We may also disclose information where the law requires it. Otherwise, we do not share candidate data with anyone else.
Candidate records live in DTP's private Notion workspace. Access to the ATS requires Google sign-in, restricted to our own company domain or to an individual account an administrator has explicitly added.
Not everyone who signs in sees everything. Contracted recruiters can be scoped to specific roles, and by default see only the candidates they own. Each write action — moving a stage, editing a field, sending outreach — is separately permissioned, and the server re-checks the permission on every request rather than trusting the screen.
Client identity is treated as confidential. The system checks every outbound message against our client list and blocks the send if a client's name appears in it.
Mailbox credentials are encrypted with AES-256-GCM before being stored, and the key is held only in the server environment. Candidate records themselves are protected by Notion's own security and by the access controls above; we do not separately encrypt individual fields.
When an administrator removes someone's access in the ATS, it takes effect immediately. If the underlying record is edited directly in Notion instead, the change is picked up within about a minute.
We do not currently delete candidate records automatically. The system has no retention timer and no scheduled clean-up. A record stays in our Notion workspace until someone at DTP removes it by hand.
Marking a candidate "Do Not Contact" stops outreach and blocks further changes to that record, but it is a suppression flag, not a deletion — the record and its history remain. The same is true of the "Withdrawn" stage.
If you want your record deleted, ask us and we will delete it. See the next section.
You can ask us to:
Depending on where you live, you may also have rights under the GDPR, the UK GDPR or US state privacy laws, including the right to complain to your local data protection authority.
How to exercise them: email us at the address below. There is no self-service button — a person handles each request by hand, in Notion. We will acknowledge your request within 5 business days and complete it within 30 days; if it is complex we may extend by a further 60 days and will tell you why. We may ask you to confirm your identity first, so that we do not disclose someone's record to the wrong person.
The ATS sets exactly one cookie, and only for recruiters who sign in. It is a session cookie named dtp_session. It holds the signed-in user's email address, their name, and an expiry time, cryptographically signed so it cannot be altered. It lasts 30 days, is marked HttpOnly and Secure, and is restricted to same-site requests. Signing out clears it.
There are no advertising cookies, no analytics cookies, and no third-party trackers. Candidates who never sign in are never given a cookie by this application.
DTP is based in the United States and the services listed in section 6 are US-based providers. If you are outside the US — for example in the UK or the EU — your information will be transferred to and processed in the United States, which may not offer the same legal protections as your home country. If you would like details of the safeguards we rely on for those transfers, contact us.
If we change how we handle your data, we will update this page and change the effective date at the top. Material changes to what we collect or who we share it with will be described here rather than made quietly.
Questions about this policy, or a request about your data: hire@digitaltalentpartner.com