Privacy Policy

The Pending Agency · Version date: 2026-09-29 · English version — this is the authoritative text.

The Pending Agency
Last Updated: 29 September 2026


1. Data Controller


The entity responsible for processing your personal data under Article 4(7) GDPR is:

The Pending GmbH
Nestroystraße 13, 81373 Munich, Germany
Amtsgericht München HRB 315656 | USt.-ID: DE360039760
Managing Directors: Tim Kriegler, Niklas Kornel
Email: info@thepending.app | service@thepending.app


2. Data Protection Contact


For all data protection enquiries, please contact us at service@thepending.app or at the postal address above. Please mark correspondence "Privacy / Data Protection".

The person responsible for data protection matters within The Pending GmbH is Niklas Kornel (CTO & CIO), reachable at niklas@thepending.app or via service@thepending.app. He is also the person in charge of the protection of personal information for the purposes of Canadian and Quebec privacy law.

Note: The Pending GmbH is not currently required to appoint a formal Data Protection Officer under Article 37 GDPR; the contact named above is our accountable privacy lead, not a statutory DPO. If this changes as the Platform scales, we will update this policy accordingly.


3. About The Pending Agency


The Pending Agency is a SaaS platform providing AI-powered management software to managers, bookers, and casting professionals, and career tools to creatives (formerly called "artists" in the Platform; "Creatives"). Users subscribe to software features — including talent search, listing and project management, and AI assistants — and pay for that software access directly to The Pending GmbH, which is the seller and merchant of record for all purchases. Payments are processed on our behalf by Stripe (see Sections 5.8 and 7). The Platform is operated by The Pending GmbH and hosted on Amazon Web Services (AWS) infrastructure in the EU (eu-central-1, Frankfurt). Public website assets and public portfolio media are delivered through Amazon CloudFront, AWS's content delivery network, using edge locations in Europe and North America (Sections 7 and 8).

This policy applies to the Platform on all of our domains, including thepending.com, agency.thepending.com, thepending.app, portfolios.thepending.com, and partnerships.thepending.com. Alongside the main application, we operate public sub-sites on our own infrastructure: public creative portfolio pages (including the contact card, inquiry form, Booking Sheet, and share pages a creative chooses to enable), a public talent showcase that lists only portfolios whose owners have explicitly opted in, a public job board, a blog, and a partnerships site. Where a section below applies only to one of these, we say so.


4. Categories of Data Subjects


We process personal data about the following categories of individuals:


5. Personal Data We Collect and Why


5.1 Account and Identity Data


When you register, we collect your name and email address, and we record that you accepted these terms. Login and signup are protected by Cloudflare Turnstile and are rate-limited (see Section 7). Email verification and password resets use short one-time codes bound to your session, which expire after a few minutes. Legal basis: Article 6(1)(b) GDPR (performance of a contract).

Regional availability check. When you register, the IP address of your request is matched on our own servers against a locally stored geo-database to determine the country you are connecting from. Registrations from countries subject to comprehensive EU sanctions (currently Russia, Belarus, North Korea, Iran, Syria, and Cuba) are refused. Only the country code is kept in your session and, for a refused attempt, in a log entry recording the country and the signup channel — never the IP address or the email address you entered. Logins to existing accounts from those regions are recorded for review. Legal basis: Article 6(1)(c) GDPR (compliance with EU restrictive-measures regulations) and Article 6(1)(f) GDPR.

Country declaration. Every account holder is asked once to declare their country. We store the declared country, the time of the declaration, the country your connection resolved to at that moment, and whether the two matched. The declared country determines only whether paid plans are offered to you: purchases are currently available in the EU/EEA, the United Kingdom, Switzerland, Norway, the United States, Canada, Australia, New Zealand, Japan, Singapore, India, and Thailand. If your country is not yet supported, you may opt in to be emailed when purchases become available there; we record the time of that opt-in and your role and plan at the time, and you can withdraw it at any time. Legal basis: Article 6(1)(b) and (f) GDPR; the waitlist email: Article 6(1)(a) GDPR.

Linked accounts. If you hold two separately registered accounts (for example a manager account and a creative account), you can link them after proving you control both by entering the other account's password. We store the link, an optional label, and the verification times; each account can see the other's name and email address, both are notified by email when a link is created or removed, and switching between linked accounts is rate-limited and re-verified periodically. Legal basis: Article 6(1)(b) GDPR.


5.2 Creative Portfolio and Profile Data


Creatives provide professional information including name, location, skills, bio, portfolio links, contact details, and profile pictures, and may upload a CV from which the Platform extracts text to pre-fill the profile (Section 6). This data powers the Platform's discovery and application features. Creatives can publish a public portfolio page; data on a public page is visible to anyone on the internet, and the same applies to the optional public contact card, downloadable contact file, Booking Sheet, badge, and share pages you can enable for it. Public portfolio pages can be listed on our public talent showcase only where you have explicitly opted in. City/country location text you provide may be converted to geographic coordinates using the OpenCage geocoding service (Section 7). Metadata embedded in uploaded images (such as GPS position, capture time, and camera identifiers) is removed on upload. Legal basis: Article 6(1)(b) GDPR.

Studio Access (collaborators). You may grant another account — for example a manager or a photographer — permission to view or edit your portfolio Studio, or accept such a request from a manager. We store the grant, its permission level and status, and the time of the collaborator's last edit. You can revoke a grant at any time; consent settings and anything related to payment always remain yours alone. Legal basis: Article 6(1)(b) GDPR.

Creatives may optionally provide special category data (e.g., gender identity, citizenship, physical characteristics, languages) via the personal details section of their profile. You are never required to provide this information to use the Platform, and each item can be hidden from view. The legal basis depends on your visibility settings: where you choose to make this data publicly visible on your profile, processing is based on Article 9(2)(e) GDPR (data manifestly made public by the data subject). Where you restrict visibility to registered users only, processing is based on your consent (Article 9(2)(a) GDPR), expressed through the act of knowingly entering and saving this data with restricted visibility. You may withdraw consent at any time by removing the data from your profile.

Where you have provided them, gender and similar attributes may be used to match you to opportunities that state a corresponding requirement: where a listing explicitly states a required gender, the Job Finder and the Platform's own opportunity matching do not suggest that listing to creatives whose profile gender differs, and do not suggest those creatives to the listing's manager. If you have not entered a gender but the pronouns you entered unambiguously indicate one (for example "she/her"), we treat that as your gender for this purpose only; neutral, mixed, or absent values never exclude you from anything. Gender and similar attributes are also included in the AI analysis that generates search keywords for your profile (Section 6). You can prevent all of this by leaving those fields empty or hidden.


5.3 Application and Project Data


If you create Listings or Projects that are set public to receive applications, or apply to a publicly accessible opportunity, we store the content of those Listings and applications, including form responses, attachments, photos a manager attaches to an application, and correspondence. We also record how each application reached the Platform (listing form, guest form, inbound email, file import, document import, or agent submission) and, where the applicant arrived through a share link the manager distributed, the channel and link used (Section 5.16). Managers may also import applications received elsewhere; imported application data is processed on the importing manager's behalf. Public Listing pages may, at the manager's choice (enabled by default), be exposed to search engines as structured job-posting data and in our sitemap and RSS feed. Managers who set Listings or Projects public are Data Controllers for the personal data of their applicants (see Section 13); this includes applications they share with external reviewers through review links (Section 5.15). Legal basis: Article 6(1)(b) GDPR.


5.4 Spotty and AI Interaction Data


When you interact with Spotty (via in-app chat or email), your inputs, the actions taken, and the AI responses are logged to provide the service and for quality and safety review. These logs may include excerpts of profile data or application content that Spotty references. Automated safeguards remove common personal identifiers (email addresses, phone numbers, payment identifiers) from internal tool logs before storage. Excerpts of your earlier conversations with the same assistant may be retrieved into a new conversation so that it remembers relevant context; you can delete conversations at any time. If you hold both manager and creative access, the assistant of one role may consult the assistant of the other and read your data from that role to answer you. Results of web research performed for you are cached for you for up to 15 minutes. Legal basis: Article 6(1)(b) GDPR.

To improve the assistants and finders, we also record how you act on their results — for example approving or skipping a proposed action, opening a result, copying a reply, marking a found opportunity as planned or applied, or adding a result to your CRM or Talent Database — and any reason you give with a thumbs-down. Where your feedback demonstrably changes a later result, we may credit you a Pen. Legal basis: Article 6(1)(f) GDPR (legitimate interest in improving answer quality); you can object at any time via service@thepending.app.

A limited Spotty preview is available to website visitors without an account. Messages entered into the preview are sent to our AI infrastructure (AWS Bedrock, Section 6) to generate a reply and are truncated to a short length. Please do not enter personal data into the preview. Legal basis: Article 6(1)(f) GDPR (legitimate interest in demonstrating the Service).

We do not use your interactions — or any of your data — to train AI models.


5.5 Talent Database, Manual Profiles, and CRM Contacts


Managers may create manual profile entries in their Talent Database (formerly "Roster") for creatives not registered on the Platform, including through intake links that can be completed by the creative or a third party without an account. Creatives may add contacts to the Pocket CRM (including via file import or AI-assisted capture from images and websites). Creatives also receive inquiries through the public inquiry form on their portfolio and through "Inquire" messages that managers send from the Talent Finder; the sender's name, email address, and message are stored as a contact and activity in the creative's Pocket CRM (and, where the sender is a registered user, additionally delivered as a message), and the creative is notified. The person entering or receiving this data is the Data Controller for it. The Pending GmbH processes it as a Data Processor on their behalf. Legal basis for our processing: Article 6(1)(b) GDPR (performance of contract with the user entering the data); that user must separately ensure they have a lawful basis for holding the information.


5.6 Talent Discovery From Public Sources


Our Talent Finder helps managers discover professionals by searching publicly accessible web pages — for example personal websites, agency and company pages, public professional directories, and public professional-network pages. Where a page appears to describe an individual professional relevant to the manager's search, we extract and store a limited record so that the manager can review the result: the person's name, a short professional summary generated from the page, their professional website, the address of the source page, a publicly listed professional contact address where one is available, a location, a profession, and internal relevance scores. We do not collect photographs through this feature, and we do not build behavioural profiles, browsing histories, or vector representations of these individuals.

These records are used solely to answer the searching manager's query and to let that manager decide whether to contact the person. Where a manager saves a result, it becomes an entry in that manager's own Talent Database and the manager becomes the Data Controller for it, as described in Sections 5.5 and 13.

Legal basis: Article 6(1)(f) GDPR (our legitimate interest, and the legitimate interest of our manager customers, in identifying professionals who publicly present themselves as available for professional engagement). We restrict this processing to information the individual has published in a professional context, and we do not collect special category data through this feature.

Your rights if you have been found this way. Because we obtain this data from public sources rather than from you, Article 14 GDPR applies. Providing individual notice to every person surfaced by a search would involve disproportionate effort in the sense of Article 14(5)(b), so we provide this notice publicly here instead. You have the right to object to this processing at any time under Article 21 GDPR, and to request access, correction, or erasure of what we hold. Write to service@thepending.app with the web address where you were found or the name under which you appear. We will act on your request without undue delay and in any event within one month, and we will not require you to create an account to exercise these rights.


5.7 Automatically Collected Technical Data


We automatically collect IP addresses, device and browser information, and access logs for security, performance, and troubleshooting. Successful logins and signups are recorded with IP address and browser information for fraud prevention and account security; these records are deleted after 90 days. Login, signup, public forms, and password-protected public pages are rate-limited by IP address.

We also operate privacy-preserving, cookieless first-party page statistics: page views are counted using a daily-rotating pseudonymous identifier together with coarse device class, browser, referrer domain, and country (for visits to public Listing pages and to listing share links also region and city). Country and location are derived on our own servers from a local geo-database — nothing leaves our infrastructure for this purpose — and no raw IP addresses are stored in these statistics. Public portfolio pages use the same cookieless approach to count views for the creative. The same local geo-database, again without any data leaving our infrastructure, is used for the regional availability check at registration and the country declaration (Section 5.1), for the purchase-availability notice, and for country restrictions on partner content (Section 5.10).

Legal basis: Article 6(1)(f) GDPR (legitimate interest in platform security, stability, and aggregate usage measurement).


5.8 Billing and Financial Data


The Pending GmbH is the seller and merchant of record for all purchases on the Platform. Payment processing is handled by Stripe Payments Europe, Ltd. ("Stripe") as our payment processor. We store a Stripe customer reference, subscription references and status, billing period information, checkout and transaction references, and order records (product, price, credits) needed for accounting and to operate your subscription and credit balance. No payment card details are stored on our servers — card data is handled exclusively by Stripe (PCI-DSS compliant). To support fraud prevention and dispute resolution, the IP address used at checkout is transmitted to Stripe with the transaction. VAT on plan and Pen purchases is calculated at checkout via Stripe Tax. Some payment methods (for example SEPA Direct Debit) settle with a delay; your plan or Pens are activated once Stripe confirms the payment. Where we credit Pens to your balance without a payment (for example a goodwill credit, a referral credit, or a feedback credit), we record the credit in your usage ledger with a zero price. Invoices and payment history are available through the Stripe billing portal linked from your account settings. If you submit a cancellation request through our public cancellation form, we store the email address and details you provide, the time of receipt, and the outcome, as evidence that your cancellation was received and processed. Legal basis: Article 6(1)(b) GDPR; fraud prevention: Article 6(1)(f) GDPR; retention of billing records: Article 6(1)(c) GDPR (statutory accounting obligations).


5.9 Social Login Data


If you register or log in via Google, Apple, or Microsoft, we receive your name, email, and (where provided) profile picture from that provider. Legal basis: Article 6(1)(a) GDPR (consent, expressed via your choice of login method).


5.10 Partner Program Data


The Platform may display clearly labeled advertising from partner companies (cards and strips marked "Partner", "Sponsored", or "Presented by") under our Partnership Program, for example in the Listings list, on a public Listing, on the creative dashboard, and on the perks page. In connection with this program, we process:


5.11 Messaging and User Content


We store the content and metadata of messages you send via the Platform's messaging and chat features (including group conversations, message requests, quoted replies, @mentions, and file attachments), together with your blocking, muting, and archiving preferences, in order to deliver them and let you manage your conversations. Other participants in a conversation can see when you have read a message (read receipts); you can switch this off for each conversation, in which case you are neither shown nor counted in that conversation's read status. When you @mention a participant, they are notified. Messages you delete are removed from all participants' view. Messages are private to their participants; we access their content only where necessary to investigate a report of unlawful or abusive use, to comply with a legal obligation, or to resolve a technical fault. If you report a message or a user, we store the report in order to review it. Legal basis: Article 6(1)(b) GDPR; moderation and abuse prevention: Article 6(1)(f) GDPR.


5.12 Submissions About Other People


Some features let one person submit information about another. Creatives can submit themselves or a casting to an opportunity, and agents and representatives can submit the creatives they represent to a Listing. Where you submit information about someone else, you are responsible for having a lawful basis to do so and for informing that person; we process the submission on behalf of the listing owner, who is the Data Controller for it. A creative who is submitted by someone else can contact us at service@thepending.app to ask who submitted their data, to object, or to have the submission removed. Legal basis: Article 6(1)(b) GDPR (performance of the contract with the submitting and receiving users); our own interest in preventing abuse of these channels: Article 6(1)(f) GDPR.


5.13 Notifications and Emails


We send in-app notifications and emails about activity relevant to you (e.g., new applications, messages, matching opportunities, reminders, and digests). You can manage notification and email preferences in your settings, and every non-essential email contains a one-click unsubscribe link, which we also expose to your email provider so that its own unsubscribe button works. Purely transactional messages (e.g., password resets, purchase receipts, cancellation confirmations) do not carry an unsubscribe option because they are required to operate your account. Product news and announcements are sent only if you have opted in (at signup or in your settings), and we keep a record of that consent; for existing customers we may send news about similar products of ours under § 7(3) UWG, always with a reminder that you can object at any time. Legal basis: Article 6(1)(b) GDPR for service communications; Article 6(1)(a) GDPR for product news; Article 6(1)(f) GDPR for digests and re-engagement communications, which you can object to at any time via the unsubscribe link or your settings.


5.14 Data Provided Without an Account


Some public features accept submissions from people without a Platform account: the public job posting form, Talent Database intake links (including via QR code), the public inquiry form on a creative's portfolio (Section 5.5), the partnership inquiry form, the needs-evaluation form on our website (which asks for an email address to send you the result), the public cancellation form, and the Spotty preview. External reviewers who open an application review link (Section 5.15) do so without an account. We process the data you submit to handle your submission; where the form belongs to a specific manager or creative (e.g., Talent Database intake, portfolio inquiry), that user is the Data Controller and we process on their behalf. Public submissions are protected by rate limiting and bot detection. Legal basis: Article 6(1)(b) GDPR (steps prior to or performance of a contract) or processing on behalf of the responsible user.


5.15 Public Sharing Links


Talent Database share links. Managers can generate links that make selected Talent Database or profile information viewable outside the Platform, optionally protected by a password. For each link the manager chooses what is shown: name, profession, location, picture, and portfolio link, and — each only if the manager switches it on — the manager's own notes about the person, a rating, custom fields, and download links to attached files (for example CVs). Where a password is used, we set a short-lived, strictly necessary cookie on the visitor's device to remember that the link was unlocked. We count how often a link is opened and when it was last opened; we do not record who opened it. Pages reached through these links are marked so that search engines do not index them. If you are a creative whose profile is shared this way, the sharing manager is responsible for having a basis to do so; creatives with a Platform portfolio can exclude their profile from such links in their portfolio settings.

Application review links. Managers can give a person without a Platform account — for example a client or a colleague — read-only access to the applications received for one Listing, through a link that always requires a password and expires (after 30 days by default; the manager can extend or revoke it). A reviewer sees the applicants' names, photos, contact details, messages, form responses, attachments, portfolio links, discussion stage, AI fit score, and the team's notes and ratings, and can reply to the manager only. We record how often and when the link was opened, and we set a signed cookie valid for 12 hours, bound to a hashed form of the reviewer's IP address, so the password does not have to be re-entered. Pages reached through these links are not indexed or cached. The manager is the Data Controller for what is shared this way (Section 13).


5.16 Campaign, Share, and Referral Links


We use tracked short links in our own marketing and in materials shared by our representatives. Visits through such a link are counted using a daily-rotating pseudonymous identifier together with coarse device class, browser, country, and referrer domain — no raw IP addresses or user agents are stored in these records. If you create an account after following a tracked link, we record which link you arrived through, so that we can measure and account for our campaigns. You can object to this measurement at any time by contacting service@thepending.app. Legal basis: Article 6(1)(f) GDPR (legitimate interest in measuring our own marketing).

Listing share links. Managers can create share links for their public Listings tagged by channel (for example LinkedIn, Instagram, WhatsApp, email, or their own website). Visits through such a link are counted using the same pseudonymous method together with the channel, referrer domain, device class, browser, country, region, and city. If you apply after following such a link, your application records the channel and link you arrived through, so that the manager can see which channels bring applications. Legal basis: Article 6(1)(f) GDPR (the manager's and our legitimate interest in measuring the reach of a Listing).

Referral links. Members can share an invite link that contains their personal invite code. If you open such a link while signed out, we store the code in your session and in a 30-day cookie (tp_ref); if you then register, we record who invited you so that both of you can receive a Pen credit once the programme's conditions are met. The person who invited you learns only that their invitation was rewarded. Legal basis: Article 6(1)(b) and (f) GDPR.


6. How We Use AI


The Platform uses AI extensively. AI features include:


All AI model inference runs on AWS Bedrock using EU inference infrastructure (API endpoint in eu-central-1, Frankfurt; execution within EU AWS regions). The models used are Claude by Anthropic (Haiku, Sonnet, and Opus 4.5 generations, selected per feature) and Amazon Titan for text embeddings. To speed up responses, Bedrock may hold the beginning of a conversation in a short-lived cache for a few minutes. AWS Bedrock does not use your data to train AI models, and we do not train AI models on your data.

Some AI features perform web research: search queries derived from your search briefs, profile, or instructions, and the addresses of pages to be read, are sent to our web search and page-reading provider, Jina AI (Section 7). We do not send your account identity to that service, but text you include in a search or brief is transmitted as part of the query.

AI interaction is disclosed. Wherever you interact directly with an AI assistant, this is marked in the interface, and AI-generated emails sent on your behalf are identified as such.

Matching and ranking parameters. Search, matching, and application ranking are based on the correspondence between a profile or application and the requirements stated in the listing or search — skills, experience, location, portfolio content, and keywords — weighted by discipline: for location-independent disciplines such as performers, vocalists, and musicians, role fit is weighted more heavily than location so that touring professionals are not disadvantaged. Where a listing explicitly states a required gender, creatives whose profile gender differs (Section 5.2) are not matched to or suggested for that listing. Paid plans, partner status, and advertising never influence how profiles or applications are ranked.

Human decision, not automated decision. Where AI features influence the visibility or ranking of creative profiles or applications, this constitutes automated processing that may affect you. No decision producing legal or similarly significant effects is taken by AI alone: the Platform does not automatically accept, reject, advance, or contact anyone on the basis of an AI score. Application scores and rankings are shown to the responsible manager as advisory input, ordering of applications by AI score is optional and off by default, and every screen presenting AI scores carries a notice that a person must make the final decision. We also measure, in anonymous form, how often the final human decision differs from the AI ranking, as an internal check that the tool is being used as decision support rather than relied on by default. You have the right to request human review of any AI-generated outcome that affects you, to express your point of view, and to contest the result. Contact service@thepending.app to exercise this right.

Partner advertising does not use AI-based or behavioral targeting of any kind (Section 5.10).


7. Third-Party Service Providers


We share personal data with the following third-party processors, each subject to a Data Processing Agreement:


Public portfolio pages can contain media embeds chosen by the creative (e.g., YouTube, Vimeo, Spotify, SoundCloud players, Instagram or TikTok embeds). When you view a page containing such an embed, your browser connects to that platform, which receives your IP address and browser information and may set its own cookies under its own privacy policy.

All JavaScript libraries, stylesheets, and fonts used by the Platform itself are hosted on our own infrastructure. Apart from Amazon CloudFront and the services named above, no third-party content delivery networks are loaded.


8. International Data Transfers


The Platform is hosted in AWS eu-central-1 (Frankfurt, Germany), and AI inference runs within EU AWS regions. Public website assets and public portfolio media may be served from CloudFront edge locations in North America as well as Europe; at the edge, CloudFront processes the requesting IP address transiently and no access logs are kept. Some of our processors are based in the United States or other countries outside the EU/EEA. For all such transfers we rely on the EU-US Data Privacy Framework where the recipient is certified, and otherwise on Standard Contractual Clauses (2021 version) approved by the European Commission, supplemented by Transfer Impact Assessments where required.


9. Cookies and Similar Technologies


We use the following cookies and browser storage:


Cloudflare Turnstile and Stripe may set their own cookies when their components load, for security and fraud prevention. Partner advertising measurement (Section 5.10) and our first-party page statistics (Section 5.7) are performed server-side without cookies or device storage.

You can change your cookie preferences at any time via the cookie banner or the "Manage cookies" control on our Cookie Policy page. Consent under § 25 TDDDG / Article 6(1)(a) GDPR can be withdrawn there with effect for the future.


10. Data Retention



11. Your Rights


Under GDPR, you have the following rights:


To exercise any of these rights, contact service@thepending.app. We will respond within 30 days. If you believe your rights have been violated, you may lodge a complaint with the competent Bavarian data protection authority:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany | poststelle@lda.bayern.de


12. Security


We implement appropriate technical and organizational measures to protect your data, including:


13. Manager Responsibility for Applicant and Contact Data


When managers set Listings or Projects public to receive applications, import applications, or share applications with external reviewers through review links, personal data of applicants is collected and processed. Managers act as the Data Controller for this applicant data. The Pending GmbH processes it as a Data Processor on the manager's behalf, as described in the Data Processing Agreement embedded in the Terms of Use (Section 9).

Managers are responsible for:


The Pending GmbH does not independently notify applicants about data processing on behalf of managers. This is the manager's responsibility.


14. Jurisdiction-Specific Notices



15. Updates to This Privacy Policy


We may update this Privacy Policy to reflect changes in our practices or legal requirements. The current version is always available on the Platform. We will notify registered users of material changes by email or in-platform notice.

This policy is written in English. Where we offer it in other languages, those versions are machine translations provided for convenience and marked as such; in the event of any inconsistency, the English version prevails.




Contact
The Pending GmbH · Nestroystraße 13, 81373 Munich, Germany · Email: service@thepending.app
© 2026 The Pending GmbH. All rights reserved.