The Pending Agency
Last Updated: 31 August 2026
1. Data Controller
The entity responsible for processing your personal data under Article 4(7) GDPR is:
The Pending GmbH
Nestroystraße 13, 81373 Munich, Germany
Amtsgericht München HRB 315656 | USt.-ID: DE360039760
Managing Directors: Tim Kriegler, Niklas Kornel
Email: info@thepending.app | service@thepending.app
2. Data Protection Contact
For all data protection enquiries, please contact us at privacy@thepending.app or at the postal address above. Please mark correspondence "Privacy / Data Protection".
The person responsible for data protection matters within The Pending GmbH is Niklas Kornel (CTO & CIO), reachable at niklas@thepending.app or via privacy@thepending.app. He is also the person in charge of the protection of personal information for the purposes of Canadian and Quebec privacy law.
Note: The Pending GmbH is not currently required to appoint a formal Data Protection Officer under Article 37 GDPR; the contact named above is our accountable privacy lead, not a statutory DPO. If this changes as the Platform scales, we will update this policy accordingly.
3. About The Pending Agency
The Pending Agency is a SaaS platform providing AI-powered management software to managers, bookers, and casting professionals, and career tools to artists and creatives. Users subscribe to software features — including talent search, project and job management, and AI assistants — and pay for that software access directly to The Pending GmbH, which is the seller and merchant of record for all purchases. Payments are processed on our behalf by Stripe (see Sections 5.7 and 7). The Platform is operated by The Pending GmbH and hosted on Amazon Web Services (AWS) infrastructure in the EU (eu-central-1, Frankfurt).
Alongside the main application, we operate public sub-sites on our own infrastructure: public artist portfolio pages, a public job board, a blog, and a partnerships site. Where a section below applies only to one of these, we say so.
4. Categories of Data Subjects
We process personal data about the following categories of individuals:
- Managers — Companies and individuals who use the Platform's software tools to create and manage projects, set job entities public to receive applications, and search for artists.
- Artists — Individuals with portfolios who use the Platform's software tools to apply to publicly accessible opportunities and manage their careers.
- Applicants (non-registered) — People who apply to publicly accessible job entities without a Platform account (e.g., by email). Their data is stored as submitted and processed on behalf of the manager who owns the job entity.
- Manual Profile Subjects and Submitted Artists — Third parties whose profiles are created by managers (e.g., scouted artists not yet registered), including via roster intake links, and artists submitted to a listing by an agent or by another user. The person creating or submitting the data is the Data Controller for it.
- Individuals Found Through Talent Search — Professionals whose publicly available information is surfaced by our Talent Finder from public web sources, and stored so that the searching manager can review the result. These individuals are not Platform users and have not provided us their data directly. See Section 5.6.
- Website Visitors — People browsing public pages, public portfolios, the public job board, the blog, or the public AI assistant preview.
- CRM Contacts and Business Leads — Business contacts added by artists via the Pocket CRM feature, and business leads managed in our internal sales tools.
- Partners — Companies that book or inquire about advertising placements under our Partnership Program, and the individuals acting on their behalf.
5. Personal Data We Collect and Why
5.1 Account and Identity Data
When you register, we collect your name and email address, and we record that you accepted these terms. Login and signup are protected by Cloudflare Turnstile and are rate-limited (see Section 7). Legal basis: Article 6(1)(b) GDPR (performance of a contract).
5.2 Artist Portfolio and Profile Data
Artists provide professional information including name, location, skills, bio, portfolio links, contact details, and profile pictures. This data powers the Platform's discovery and application features. Artists can publish a public portfolio page; data on a public page is visible to anyone on the internet. City/country location text you provide may be converted to geographic coordinates using the OpenCage geocoding service (Section 7). Legal basis: Article 6(1)(b) GDPR.
Artists may optionally provide special category data (e.g., gender identity, citizenship, physical characteristics, languages) via the personal details section of their profile. You are never required to provide this information to use the Platform, and each item can be hidden from view. The legal basis depends on your visibility settings: where you choose to make this data publicly visible on your profile, processing is based on Article 9(2)(e) GDPR (data manifestly made public by the data subject). Where you restrict visibility to registered users only, processing is based on your consent (Article 9(2)(a) GDPR), expressed through the act of knowingly entering and saving this data with restricted visibility. You may withdraw consent at any time by removing the data from your profile.
Where you have provided them, gender and similar attributes may be used to match you to opportunities that state a corresponding requirement, and are included in the AI analysis that generates search keywords for your profile (Section 6). You can prevent this by leaving those fields empty or hidden.
5.3 Application and Project Data
If you create job entities or projects that are set public to receive applications, or apply to a publicly accessible opportunity, we store the content of those entities and applications, including form responses, attachments, and correspondence. Managers may also import applications received elsewhere; imported application data is processed on the importing manager's behalf. Managers who set job entities or projects public are Data Controllers for the personal data of their applicants (see Section 13). Legal basis: Article 6(1)(b) GDPR.
5.4 Spotty and AI Interaction Data
When you interact with Spotty (via in-app chat or email), your inputs, the actions taken, and the AI responses are logged to provide the service and for quality and safety review. These logs may include excerpts of profile data or application content that Spotty references. Automated safeguards remove common personal identifiers (email addresses, phone numbers, payment identifiers) from internal tool logs before storage. Legal basis: Article 6(1)(b) GDPR.
A limited Spotty preview is available to website visitors without an account. Messages entered into the preview are sent to our AI infrastructure (AWS Bedrock, Section 6) to generate a reply and are truncated to a short length. Please do not enter personal data into the preview. Legal basis: Article 6(1)(f) GDPR (legitimate interest in demonstrating the Service).
We do not use your interactions — or any of your data — to train AI models.
5.5 Roster, Manual Profiles, and CRM Contacts
Managers may create manual profile entries for artists not registered on the Platform, including through roster intake links that can be completed by the artist or a third party without an account. Artists may add contacts to the Pocket CRM (including via file import or AI-assisted capture from images and websites). The person entering this data is the Data Controller for it. The Pending GmbH processes it as a Data Processor on their behalf. Legal basis for our processing: Article 6(1)(b) GDPR (performance of contract with the user entering the data); that user must separately ensure they have a lawful basis for holding the information.
5.6 Talent Discovery From Public Sources
Our Talent Finder helps managers discover professionals by searching publicly accessible web pages — for example personal websites, agency and company pages, and public professional directories. Where a page appears to describe an individual professional relevant to the manager's search, we extract and store a limited record so that the manager can review the result: the person's name, a short professional summary generated from the page, their professional website, the address of the source page, a publicly listed professional contact address where one is available, a location, a profession, and internal relevance scores. We do not collect photographs through this feature, and we do not build behavioural profiles, browsing histories, or vector representations of these individuals.
These records are used solely to answer the searching manager's query and to let that manager decide whether to contact the person. Where a manager saves a result, it becomes an entry in that manager's own roster and the manager becomes the Data Controller for it, as described in Sections 5.5 and 13.
Legal basis: Article 6(1)(f) GDPR (our legitimate interest, and the legitimate interest of our manager customers, in identifying professionals who publicly present themselves as available for professional engagement). We restrict this processing to information the individual has published in a professional context, and we do not collect special category data through this feature.
Your rights if you have been found this way. Because we obtain this data from public sources rather than from you, Article 14 GDPR applies. Providing individual notice to every person surfaced by a search would involve disproportionate effort in the sense of Article 14(5)(b), so we provide this notice publicly here instead. You have the right to object to this processing at any time under Article 21 GDPR, and to request access, correction, or erasure of what we hold. Write to privacy@thepending.app with the web address where you were found or the name under which you appear. We will act on your request without undue delay and in any event within one month, and we will not require you to create an account to exercise these rights.
5.7 Automatically Collected Technical Data
We automatically collect IP addresses, device and browser information, and access logs for security, performance, and troubleshooting. Successful logins and signups are recorded with IP address and browser information for fraud prevention and account security; these records are deleted after 90 days. Login, signup, and public forms are rate-limited by IP address.
We also operate privacy-preserving, cookieless first-party page statistics: page views are counted using a daily-rotating pseudonymous identifier together with coarse device class, referrer domain, and country. Country is derived on our own servers from a local geo-database — nothing leaves our infrastructure for this purpose — and no raw IP addresses are stored in these statistics. Public portfolio pages use the same cookieless approach to count views for the artist.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in platform security, stability, and aggregate usage measurement).
5.8 Billing and Financial Data
The Pending GmbH is the seller and merchant of record for all purchases on the Platform. Payment processing is handled by Stripe Payments Europe, Ltd. ("Stripe") as our payment processor. We store a Stripe customer reference, subscription references and status, billing period information, checkout and transaction references, and order records (product, price, credits) needed for accounting and to operate your subscription and credit balance. No payment card details are stored on our servers — card data is handled exclusively by Stripe (PCI-DSS compliant). To support fraud prevention and dispute resolution, the IP address used at checkout is transmitted to Stripe with the transaction. VAT is calculated at checkout via Stripe Tax. Invoices and payment history are available through the Stripe billing portal linked from your account settings. If you submit a cancellation request through our public cancellation form, we store the email address and details you provide, the time of receipt, and the outcome, as evidence that your cancellation was received and processed. Legal basis: Article 6(1)(b) GDPR; fraud prevention: Article 6(1)(f) GDPR; retention of billing records: Article 6(1)(c) GDPR (statutory accounting obligations).
5.9 Social Login Data
If you register or log in via Google, Apple, or Microsoft, we receive your name, email, and (where provided) profile picture from that provider. Legal basis: Article 6(1)(a) GDPR (consent, expressed via your choice of login method).
5.10 Partner Program Data
The Platform may display clearly labeled advertising from partner companies ("Partner" cards) under our Partnership Program. In connection with this program, we process:
- Partner accounts and inquiries — If you submit a partnership inquiry or request an offer, we store your company name, contact email address, and message to process your request and manage the partnership. Partner account holders additionally see their own company's booking and performance overview in the partner dashboard. Legal basis: Article 6(1)(b) GDPR (performance of a contract or pre-contractual measures).
- Advertising measurement — When a partner card is displayed to or clicked by you as a logged-in user, we record that event together with your account reference and a snapshot of your platform role, subscription plan, the interests you have chosen yourself, your language, device type, browser, and country. We do not store IP addresses, precise locations, or browsing profiles in these records, and this data is never used to decide which advertising you see: partner content is matched exclusively against interests you have explicitly selected in your profile, or shown untargeted to all users. Every partner card includes a "Why this?" explanation. Partners receive aggregate statistics only — your identity is never shared with them. These records are deleted after no more than 14 months. Legal basis: Article 6(1)(f) GDPR (legitimate interest in measuring and billing partner placements).
- Partner payments — Payments for partnership bookings are processed via Stripe (checkout or invoice). We store checkout and invoice references only. Legal basis: Article 6(1)(b) GDPR.
5.11 Messaging and User Content
We store the content and metadata of messages you send via the Platform's messaging and chat features (including group conversations, message requests, and file attachments), together with your blocking preferences, in order to deliver them and let you manage your conversations. Messages are private to their participants; we access their content only where necessary to investigate a report of unlawful or abusive use, to comply with a legal obligation, or to resolve a technical fault. If you report a message or a user, we store the report in order to review it. Legal basis: Article 6(1)(b) GDPR; moderation and abuse prevention: Article 6(1)(f) GDPR.
5.12 Submissions About Other People
Some features let one person submit information about another. Artists can submit themselves or a casting to an opportunity, and agents and representatives can submit the artists they represent to a listing. Where you submit information about someone else, you are responsible for having a lawful basis to do so and for informing that person; we process the submission on behalf of the listing owner, who is the Data Controller for it. An artist who is submitted by someone else can contact us at privacy@thepending.app to ask who submitted their data, to object, or to have the submission removed. Legal basis: Article 6(1)(b) GDPR (performance of the contract with the submitting and receiving users); our own interest in preventing abuse of these channels: Article 6(1)(f) GDPR.
5.13 Notifications and Emails
We send in-app notifications and emails about activity relevant to you (e.g., new applications, messages, matching opportunities, reminders, and digests). You can manage notification and email preferences in your settings, and every non-essential email contains a one-click unsubscribe link, which we also expose to your email provider so that its own unsubscribe button works. Purely transactional messages (e.g., password resets, purchase receipts, cancellation confirmations) do not carry an unsubscribe option because they are required to operate your account. Legal basis: Article 6(1)(b) GDPR for service communications; Article 6(1)(f) GDPR for digests and re-engagement communications, which you can object to at any time via the unsubscribe link or your settings.
5.14 Data Provided Without an Account
Some public features accept submissions from people without a Platform account: the public job posting form, roster intake links (including via QR code), the partnership inquiry form, the public cancellation form, and the Spotty preview. We process the data you submit to handle your submission; where the form belongs to a specific manager (e.g., roster intake), that manager is the Data Controller and we process on their behalf. Public submissions are protected by rate limiting and bot detection. Legal basis: Article 6(1)(b) GDPR (steps prior to or performance of a contract) or processing on behalf of the responsible user.
5.15 Public Sharing Links
Managers can generate links that make selected roster or profile information viewable outside the Platform, optionally protected by an access step. Where an access step is used, we set a short-lived, strictly necessary cookie on the visitor's device to remember that the link was unlocked. Pages reached through these links are marked so that search engines do not index them. If you are an artist whose profile is shared this way, the sharing manager is responsible for having a basis to do so.
5.16 Campaign and Referral Links
We use tracked short links in our own marketing and in materials shared by our representatives. Visits through such a link are counted using a daily-rotating pseudonymous identifier together with coarse device class, browser, country, and referrer domain — no raw IP addresses or user agents are stored in these records. If you create an account after following a tracked link, we record which link you arrived through, so that we can measure and account for our campaigns. You can object to this measurement at any time by contacting privacy@thepending.app. Legal basis: Article 6(1)(f) GDPR (legitimate interest in measuring our own marketing).
6. How We Use AI
The Platform uses AI extensively. AI features include:
- Spotty (Manager and Artist) — Conversational AI assistants, via in-app chat and email, that can perform actions on the Platform on your behalf. Actions that change data require your confirmation. A limited preview is available to visitors (Section 5.4).
- Talent Finder — AI-assisted talent discovery that processes your search queries and publicly available profile data to suggest artists, and which ranks and filters the results shown.
- Application Analysis — AI evaluation of incoming and imported applications, producing two scores (professionalism and project fit, each 0–10), an overall rating, a recommendation, and a written summary, to help managers review candidates. This analysis runs automatically for new applications unless the manager switches it off in their settings. Scores are decision-support only (see below).
- Profile Analysis and Embeddings — AI analysis of portfolio profiles and semantic vector representations of profile, job, and listing content to power search rankings and recommendations.
- Email Classification — Categorizes inbound emails (application, inquiry, spam) for inbox management. Messages classified as spam are not deleted: they are held in a separate "Filtered" area where the manager can review and restore them, and are deleted after 30 days if not restored.
- Job Finder and Job Matching — AI-assisted matching of publicly accessible job entities to artist profiles based on skills, location, and portfolio content, including scanning of websites you ask us to watch. Platform-initiated match suggestions are reviewed by a person before any artist is contacted.
- Application Assistant — Generates form responses and cover letters from your portfolio and the opportunity requirements, and can pre-fill external application forms at your request.
- Client Finder (Pocket CRM) — AI-assisted discovery of potential clients for artists, based on portfolio data and industry context.
- Content creation aids — AI drafting of emails, invitations, and outreach messages (which may include applicant or contact data you reference); AI-assisted creation of projects, jobs, profiles, and CRM contacts from text, images, or links you provide, including text extraction from uploaded documents and images; AI-generated application form structures; and personalized onboarding content.
- Job aggregation — AI classification of publicly available job listings collected from external public sources.
- Translation — AI translation of interface and dynamic content.
All AI model inference runs on AWS Bedrock using EU inference infrastructure (API endpoint in eu-central-1, Frankfurt; execution within EU AWS regions). The models used are Claude by Anthropic (Haiku, Sonnet, and Opus 4.5 generations, selected per feature) and Amazon Titan for text embeddings. AWS Bedrock does not use your data to train AI models, and we do not train AI models on your data.
Some AI features perform web research: search queries derived from your search briefs, profile, or instructions, and the addresses of pages to be read, are sent to our web search and page-reading provider, Jina AI (Section 7). We do not send your account identity to that service, but text you include in a search or brief is transmitted as part of the query.
AI interaction is disclosed. Wherever you interact directly with an AI assistant, this is marked in the interface, and AI-generated emails sent on your behalf are identified as such.
Human decision, not automated decision. Where AI features influence the visibility or ranking of artist profiles or applications, this constitutes automated processing that may affect you. No decision producing legal or similarly significant effects is taken by AI alone: the Platform does not automatically accept, reject, advance, or contact anyone on the basis of an AI score. Application scores and rankings are shown to the responsible manager as advisory input, ordering of applications by AI score is optional and off by default, and every screen presenting AI scores carries a notice that a person must make the final decision. We also measure, in anonymous form, how often the final human decision differs from the AI ranking, as an internal check that the tool is being used as decision support rather than relied on by default. You have the right to request human review of any AI-generated outcome that affects you, to express your point of view, and to contest the result. Contact privacy@thepending.app to exercise this right.
Partner advertising does not use AI-based or behavioral targeting of any kind (Section 5.10).
7. Third-Party Service Providers
We share personal data with the following third-party processors, each subject to a Data Processing Agreement:
- Infrastructure (AWS, Frankfurt) — Hosting, database, file storage, email sending and receiving (Amazon SES), AI model inference (AWS Bedrock, EU).
- Payment (Stripe Payments Europe, Ltd., Ireland) — Payment processing, subscription billing, VAT calculation, invoicing, and the billing portal for all purchases on the Platform, including Partnership Program bookings. Stripe is PCI-DSS compliant. Pages offering purchases load Stripe's checkout components in your browser.
- Web Search and Page Reading (Jina AI) — Web search and retrieval of public web page content for AI research features. Search queries derived from your search briefs, profile, or instructions are transmitted, as are the addresses of pages to be read. Your account identity is not transmitted, but text you include in a search or brief forms part of the query.
- Product Analytics (PostHog, EU hosting) — Where enabled, usage analytics and session replay, active only after you consent via the cookie banner (Section 9). We use a pseudonymous user reference; text you type is masked in session replays; IP addresses are discarded at ingestion.
- Social Login (Google, Apple, Microsoft) — Authentication data from third-party login providers, where you choose that login method. Transfers to the US rely on the EU-US Data Privacy Framework or Standard Contractual Clauses.
- Bot Protection (Cloudflare Turnstile) — Anti-bot verification on login, signup, and public forms. Your browser communicates with Cloudflare to solve the challenge and Cloudflare may set its own cookies; we transmit only the resulting token for verification.
- Geocoding (OpenCage, Germany) — Location text (city/country) converted to geographic coordinates for profile and search features.
Public portfolio pages can contain media embeds chosen by the artist (e.g., YouTube, Vimeo, Spotify, SoundCloud players, Instagram or TikTok embeds). When you view a page containing such an embed, your browser connects to that platform, which receives your IP address and browser information and may set its own cookies under its own privacy policy.
All JavaScript libraries, stylesheets, and fonts used by the Platform itself are hosted on our own infrastructure. Apart from the services named above, no third-party content delivery networks are loaded.
8. International Data Transfers
The Platform is hosted in AWS eu-central-1 (Frankfurt, Germany), and AI inference runs within EU AWS regions. Some of our processors are based in the United States or other countries outside the EU/EEA. For all such transfers we rely on the EU-US Data Privacy Framework where the recipient is certified, and otherwise on Standard Contractual Clauses (2021 version) approved by the European Commission, supplemented by Transfer Impact Assessments where required.
9. Cookies and Similar Technologies
We use the following cookies and browser storage:
- pending_sessionid — Keeps you logged in (7 days; strictly necessary, no consent required).
- csrftoken — Security token to prevent cross-site request forgery (strictly necessary).
- django_language — Stores your language preference (functional, no consent required).
- tp_cookie_consent — Records your cookie preferences (365 days; strictly necessary).
- Roster share unlock cookie — Set only when you unlock a shared roster link, to remember that this link was unlocked on your device (12 hours; strictly necessary for that feature).
- Product analytics (consent-only) — If, and only if, you accept analytics in the cookie banner, our analytics provider stores an analytics cookie and browser storage entries to recognize your session, and may record masked session replays (Section 7). Nothing is stored for analytics before you consent, and you can withdraw consent at any time.
Cloudflare Turnstile and Stripe may set their own cookies when their components load, for security and fraud prevention. Partner advertising measurement (Section 5.10) and our first-party page statistics (Section 5.7) are performed server-side without cookies or device storage.
You can change your cookie preferences at any time via the cookie settings link in the footer. Consent under § 25 TDDDG / Article 6(1)(a) GDPR can be withdrawn there with effect for the future.
10. Data Retention
- Account data: Retained for the duration of your account. When you delete your account in the Platform settings, your account and the personal data associated with it are deleted immediately, including the associated files in our file storage; residual copies in encrypted backups are overwritten within 30 days. Records we must keep by law (in particular billing records) are retained with the account reference removed.
- Application data, including AI evaluations: Applications — together with their attachments and any AI scores — are permanently deleted six months after the opportunity stops accepting applications. That period starts at whichever happens first: the listing is closed to applications, the project is archived or completed, the listing is deleted, or the manager deletes the application. Every application is kept for at least six months from the date it was submitted, so a late application is never deleted early. Where a listing is never formally closed, its application data is deleted after eighteen months without any activity on it — but never silently: we first notify the manager at least 30 days in advance, and the deletion only proceeds if that warning goes unanswered. The manager can confirm the process is still running, which restarts the period, or download an archive of the data beforehand. Deletion is automatic and runs daily.
- Listings and projects themselves: Not affected by the rule above. They remain until the managing user deletes them or closes their account — closing a listing is always the manager's own decision and is never done automatically.
- Anonymous statistics about applications: When application data is deleted, we may keep an anonymous statistical summary for the listing — a distribution of match scores and a measure of how often the final human decision differed from the AI ranking. These contain no personal data, are only produced where at least five applications were analysed, and are kept indefinitely.
- AI interaction data: Spotty conversations are retained until you delete them or your account. Internal AI processing logs are deleted after at most 12 months; AI usage accounting records (which contain no conversation content) after at most 13 months.
- Security records (successful login/signup with IP address): 90 days.
- Billing records: Retained for the period required by applicable tax law (typically 10 years in Germany).
- Manual profiles and CRM contacts: Retained until you delete them; deleted entries are permanently removed after a further 180 days, or immediately with your account.
- Talent search results about non-users (Section 5.6): Retained while they remain useful to the searching manager, and deleted when that manager deletes them or closes their account. If you object under Section 5.6, your record is removed.
- Partner advertising measurement records: Deleted after no more than 14 months.
- Messaging delivery logs: Deleted after no more than 120 days. Message content remains until you delete it or your account.
- Filtered (spam-classified) inbound email: 30 days, unless restored by the manager.
- Read in-app notifications: 180 days. Cookieless page statistics and campaign-link visits: no more than 13 months. Payment webhook records: 90 days.
- Data export archives: The archive generated for a data export request is deleted after 7 days; download links expire after 1 hour and can be re-sent.
11. Your Rights
Under GDPR, you have the following rights:
- Right of Access (Art. 15) — Obtain a copy of the personal data we hold about you.
- Right to Rectification (Art. 16) — Correct inaccurate or incomplete data.
- Right to Erasure (Art. 17) — Request deletion of your data where it is no longer necessary or processing is unlawful. Account deletion is available in the Platform settings and takes effect immediately.
- Right to Restriction (Art. 18) — Request that we limit processing in certain circumstances.
- Right to Data Portability (Art. 20) — You can request a machine-readable export of your data directly in your account settings; we email you a secure download link when it is ready. You can also contact privacy@thepending.app and we will provide a copy within 30 days. If you applied to an opportunity without a Platform account, contact us and we will provide your application data on verification of your identity.
- Right to Object (Art. 21) — Object to processing based on legitimate interest, including partner advertising measurement (Section 5.10) and digest or re-engagement communications (Section 5.13). Contact privacy@thepending.app.
- Automated decision-making (Art. 22) — We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Where AI scores or rankings support human decisions, you may request human review, express your point of view, and contest the result (Section 6).
- Right to Withdraw Consent — For processing based on consent (including special category data and analytics), you may withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact privacy@thepending.app. We will respond within 30 days. If you believe your rights have been violated, you may lodge a complaint with the competent Bavarian data protection authority:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany | poststelle@lda.bayern.de
12. Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption in transit (HTTPS/TLS, WSS) and at rest (AWS RDS, S3, ElastiCache encryption), with additional application-layer encryption for particularly sensitive stored credentials.
- Role-based access control and object-level permission enforcement, including tiered administrator access.
- CSRF protection, Content Security Policy headers, and bot detection (Cloudflare Turnstile).
- Rate-limited login, signup, and public forms, with IP-based logging of successful authentications.
- Time-limited presigned URLs for file access (up to 1 hour).
- Secrets management via AWS Secrets Manager (no hardcoded credentials).
- Signature verification for all inbound webhook endpoints.
- Automated removal of common personal identifiers from internal AI tool logs.
13. Manager Responsibility for Applicant and Contact Data
When managers set job entities or projects public to receive applications, or import applications, personal data of applicants is collected and processed. Managers act as the Data Controller for this applicant data. The Pending GmbH processes it as a Data Processor on the manager's behalf, as described in the Data Processing Agreement embedded in the Terms of Use (Section 9).
Managers are responsible for:
- Informing applicants of the processing of their data (e.g., via a privacy notice linked within the publicly accessible job entity). We provide a template notice you can adapt, linked in the footer and in your account settings.
- Ensuring application forms do not collect unnecessary or disproportionate personal data, and in particular not requesting protected characteristics unless there is a genuine, lawful occupational requirement.
- Obtaining explicit consent before collecting special category data through custom form fields.
- Complying with all applicable data protection laws in their jurisdiction, including retention, deletion, and responding to data subject rights requests.
- Complying with local rules on the use of automated tools in recruitment — including candidate notice, audit, and record-keeping obligations that apply in certain jurisdictions — when using AI-assisted evaluation features.
The Pending GmbH does not independently notify applicants about data processing on behalf of managers. This is the manager's responsibility.
14. Jurisdiction-Specific Notices
- United Kingdom — For users in the UK, references to the GDPR include the UK GDPR and the Data Protection Act 2018. Complaints may be addressed to the Information Commissioner's Office (ico.org.uk). Where we are required to designate a UK representative under Article 27 UK GDPR, their details will be published here.
- Switzerland — For users in Switzerland, this policy also serves as information under the Swiss Federal Act on Data Protection (FADP). Data is disclosed to the countries and recipients listed in Sections 7 and 8; transfers to the US rely on the Swiss-US Data Privacy Framework or equivalent safeguards. The competent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC).
- Canada — We process personal information in accordance with PIPEDA. Enquiries and access requests can be addressed to privacy@thepending.app; the person accountable for our privacy compliance is named in Section 2. Where a recommendation or evaluation is generated by automated processing, you may request an explanation and human review (Section 6). For users in Quebec, the person in charge of the protection of personal information is Niklas Kornel (Section 2); where a decision concerning you is based exclusively on automated processing, we inform you of this, and you may submit observations to a member of our staff who is in a position to review the decision.
- United States — The Platform is offered from Germany. We do not sell or share personal information as those terms are defined by US state privacy laws, and we do not use sensitive personal information for purposes that would require a right to limit. Verified requests submitted to privacy@thepending.app are honored where state-specific rights apply.
- Australia — We handle personal information consistently with the Australian Privacy Principles to the extent they apply. The automated processing used in the Service is described in Section 6. Complaints may be raised with us first and with the OAIC.
- Brazil — For users in Brazil, we process personal data in accordance with the LGPD (Lei Geral de Proteção de Dados). The legal bases stated in this policy correspond to those of Article 7 LGPD, and the rights under Article 18 LGPD can be exercised through the channels in Section 11. The competent authority is the ANPD.
- Japan — For users in Japan, we handle personal information in accordance with the APPI. The purposes of use are those described in Section 5, and we do not provide personal data to third parties except as described in this policy or with your consent. Requests may be addressed to privacy@thepending.app.
- Singapore — For users in Singapore, we handle personal data consistently with the PDPA. Our data protection contact is set out in Section 2; unresolved concerns may be raised with the PDPC.
- New Zealand — For users in New Zealand, we handle personal information consistently with the Privacy Act 2020 and its Information Privacy Principles. Complaints may be raised with us first and with the Office of the Privacy Commissioner.
- India — For users in India, we process digital personal data consistently with the Digital Personal Data Protection Act, 2023, to the extent it applies. Our grievance channel is privacy@thepending.app; the rights described in Section 11 can be exercised through it.
- Thailand — For users in Thailand, we process personal data consistently with the PDPA. The rights described in Section 11 can be exercised via privacy@thepending.app; the competent authority is the PDPC.
15. Updates to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. The current version is always available on the Platform. We will notify registered users of material changes by email or in-platform notice.
Contact
The Pending GmbH · Nestroystraße 13, 81373 Munich, Germany · Email: service@thepending.app | privacy@thepending.app
© 2026 The Pending GmbH. All rights reserved.