The Pending Agency

Privacy Policy

Download

The Pending Agency
Last Updated: 29 September 2026


1. Data Controller


The entity responsible for processing your personal data under Article 4(7) GDPR is:

The Pending GmbH
Nestroystraße 13, 81373 Munich, Germany
Amtsgericht München HRB 315656 | USt.-ID: DE360039760
Managing Directors: Tim Kriegler, Niklas Kornel
Email: info@thepending.app | service@thepending.app


2. Data Protection Contact


For all data protection enquiries, please contact us at service@thepending.app or at the postal address above. Please mark correspondence "Privacy / Data Protection".

The person responsible for data protection matters within The Pending GmbH is Niklas Kornel (CTO & CIO), reachable at niklas@thepending.app or via service@thepending.app. He is also the person in charge of the protection of personal information for the purposes of Canadian and Quebec privacy law.

Note: The Pending GmbH is not currently required to appoint a formal Data Protection Officer under Article 37 GDPR; the contact named above is our accountable privacy lead, not a statutory DPO. If this changes as the Platform scales, we will update this policy accordingly.


3. About The Pending Agency


The Pending Agency is a SaaS platform providing AI-powered management software to managers, bookers, and casting professionals, and career tools to creatives (formerly called "artists" in the Platform; "Creatives"). Users subscribe to software features — including talent search, listing and project management, and AI assistants — and pay for that software access directly to The Pending GmbH, which is the seller and merchant of record for all purchases. Payments are processed on our behalf by Stripe (see Sections 5.8 and 7). The Platform is operated by The Pending GmbH and hosted on Amazon Web Services (AWS) infrastructure in the EU (eu-central-1, Frankfurt). Public website assets and public portfolio media are delivered through Amazon CloudFront, AWS's content delivery network, using edge locations in Europe and North America (Sections 7 and 8).

This policy applies to the Platform on all of our domains, including thepending.com, agency.thepending.com, thepending.app, portfolios.thepending.com, and partnerships.thepending.com. Alongside the main application, we operate public sub-sites on our own infrastructure: public creative portfolio pages (including the contact card, inquiry form, Booking Sheet, and share pages a creative chooses to enable), a public talent showcase that lists only portfolios whose owners have explicitly opted in, a public job board, a blog, and a partnerships site. Where a section below applies only to one of these, we say so.


4. Categories of Data Subjects


We process personal data about the following categories of individuals:

  • Managers — Companies and individuals who use the Platform's software tools to create and manage projects, set Listings public to receive applications, and search for creatives.
  • Creatives — Individuals with portfolios who use the Platform's software tools to apply to publicly accessible opportunities and manage their careers.
  • Applicants (non-registered) — People who apply to publicly accessible Listings without a Platform account (e.g., by email). Their data is stored as submitted and processed on behalf of the manager who owns the Listing.
  • Manual Profile Subjects and Submitted Creatives — Third parties whose profiles are created by managers (e.g., scouted creatives not yet registered), including via Talent Database intake links, and creatives submitted to a Listing by an agent or by another user. The person creating or submitting the data is the Data Controller for it.
  • Individuals Found Through Talent Search — Professionals whose publicly available information is surfaced by our Talent Finder from public web sources, and stored so that the searching manager can review the result. These individuals are not Platform users and have not provided us their data directly. See Section 5.6.
  • Website Visitors and Link Recipients — People browsing public pages, public portfolios, the public job board, the blog, or the public AI assistant preview, and people who open a share link or review link that a manager or creative has sent them.
  • CRM Contacts and Business Leads — Business contacts added by Creatives via the Pocket CRM feature (including people who contact a creative through the public inquiry form on their portfolio), and business leads managed in our internal sales tools.
  • Partners — Companies that book or inquire about advertising placements under our Partnership Program, and the individuals acting on their behalf.

5. Personal Data We Collect and Why


5.1 Account and Identity Data


When you register, we collect your name and email address, and we record that you accepted these terms. Login and signup are protected by Cloudflare Turnstile and are rate-limited (see Section 7). Email verification and password resets use short one-time codes bound to your session, which expire after a few minutes. Legal basis: Article 6(1)(b) GDPR (performance of a contract).

Regional availability check. When you register, the IP address of your request is matched on our own servers against a locally stored geo-database to determine the country you are connecting from. Registrations from countries subject to comprehensive EU sanctions (currently Russia, Belarus, North Korea, Iran, Syria, and Cuba) are refused. Only the country code is kept in your session and, for a refused attempt, in a log entry recording the country and the signup channel — never the IP address or the email address you entered. Logins to existing accounts from those regions are recorded for review. Legal basis: Article 6(1)(c) GDPR (compliance with EU restrictive-measures regulations) and Article 6(1)(f) GDPR.

Country declaration. Every account holder is asked once to declare their country. We store the declared country, the time of the declaration, the country your connection resolved to at that moment, and whether the two matched. The declared country determines only whether paid plans are offered to you: purchases are currently available in the EU/EEA, the United Kingdom, Switzerland, Norway, the United States, Canada, Australia, New Zealand, Japan, Singapore, India, and Thailand. If your country is not yet supported, you may opt in to be emailed when purchases become available there; we record the time of that opt-in and your role and plan at the time, and you can withdraw it at any time. Legal basis: Article 6(1)(b) and (f) GDPR; the waitlist email: Article 6(1)(a) GDPR.

Linked accounts. If you hold two separately registered accounts (for example a manager account and a creative account), you can link them after proving you control both by entering the other account's password. We store the link, an optional label, and the verification times; each account can see the other's name and email address, both are notified by email when a link is created or removed, and switching between linked accounts is rate-limited and re-verified periodically. Legal basis: Article 6(1)(b) GDPR.


5.2 Creative Portfolio and Profile Data


Creatives provide professional information including name, location, skills, bio, portfolio links, contact details, and profile pictures, and may upload a CV from which the Platform extracts text to pre-fill the profile (Section 6). This data powers the Platform's discovery and application features. Creatives can publish a public portfolio page; data on a public page is visible to anyone on the internet, and the same applies to the optional public contact card, downloadable contact file, Booking Sheet, badge, and share pages you can enable for it. Public portfolio pages can be listed on our public talent showcase only where you have explicitly opted in. City/country location text you provide may be converted to geographic coordinates using the OpenCage geocoding service (Section 7). Metadata embedded in uploaded images (such as GPS position, capture time, and camera identifiers) is removed on upload. Legal basis: Article 6(1)(b) GDPR.

Studio Access (collaborators). You may grant another account — for example a manager or a photographer — permission to view or edit your portfolio Studio, or accept such a request from a manager. We store the grant, its permission level and status, and the time of the collaborator's last edit. You can revoke a grant at any time; consent settings and anything related to payment always remain yours alone. Legal basis: Article 6(1)(b) GDPR.

Creatives may optionally provide special category data (e.g., gender identity, citizenship, physical characteristics, languages) via the personal details section of their profile. You are never required to provide this information to use the Platform, and each item can be hidden from view. The legal basis depends on your visibility settings: where you choose to make this data publicly visible on your profile, processing is based on Article 9(2)(e) GDPR (data manifestly made public by the data subject). Where you restrict visibility to registered users only, processing is based on your consent (Article 9(2)(a) GDPR), expressed through the act of knowingly entering and saving this data with restricted visibility. You may withdraw consent at any time by removing the data from your profile.

Where you have provided them, gender and similar attributes may be used to match you to opportunities that state a corresponding requirement: where a listing explicitly states a required gender, the Job Finder and the Platform's own opportunity matching do not suggest that listing to creatives whose profile gender differs, and do not suggest those creatives to the listing's manager. If you have not entered a gender but the pronouns you entered unambiguously indicate one (for example "she/her"), we treat that as your gender for this purpose only; neutral, mixed, or absent values never exclude you from anything. Gender and similar attributes are also included in the AI analysis that generates search keywords for your profile (Section 6). You can prevent all of this by leaving those fields empty or hidden.


5.3 Application and Project Data


If you create Listings or Projects that are set public to receive applications, or apply to a publicly accessible opportunity, we store the content of those Listings and applications, including form responses, attachments, photos a manager attaches to an application, and correspondence. We also record how each application reached the Platform (listing form, guest form, inbound email, file import, document import, or agent submission) and, where the applicant arrived through a share link the manager distributed, the channel and link used (Section 5.16). Managers may also import applications received elsewhere; imported application data is processed on the importing manager's behalf. Public Listing pages may, at the manager's choice (enabled by default), be exposed to search engines as structured job-posting data and in our sitemap and RSS feed. Managers who set Listings or Projects public are Data Controllers for the personal data of their applicants (see Section 13); this includes applications they share with external reviewers through review links (Section 5.15). Legal basis: Article 6(1)(b) GDPR.


5.4 Spotty and AI Interaction Data


When you interact with Spotty (via in-app chat or email), your inputs, the actions taken, and the AI responses are logged to provide the service and for quality and safety review. These logs may include excerpts of profile data or application content that Spotty references. Automated safeguards remove common personal identifiers (email addresses, phone numbers, payment identifiers) from internal tool logs before storage. Excerpts of your earlier conversations with the same assistant may be retrieved into a new conversation so that it remembers relevant context; you can delete conversations at any time. If you hold both manager and creative access, the assistant of one role may consult the assistant of the other and read your data from that role to answer you. Results of web research performed for you are cached for you for up to 15 minutes. Legal basis: Article 6(1)(b) GDPR.

To improve the assistants and finders, we also record how you act on their results — for example approving or skipping a proposed action, opening a result, copying a reply, marking a found opportunity as planned or applied, or adding a result to your CRM or Talent Database — and any reason you give with a thumbs-down. Where your feedback demonstrably changes a later result, we may credit you a Pen. Legal basis: Article 6(1)(f) GDPR (legitimate interest in improving answer quality); you can object at any time via service@thepending.app.

A limited Spotty preview is available to website visitors without an account. Messages entered into the preview are sent to our AI infrastructure (AWS Bedrock, Section 6) to generate a reply and are truncated to a short length. Please do not enter personal data into the preview. Legal basis: Article 6(1)(f) GDPR (legitimate interest in demonstrating the Service).

We do not use your interactions — or any of your data — to train AI models.


5.5 Talent Database, Manual Profiles, and CRM Contacts


Managers may create manual profile entries in their Talent Database (formerly "Roster") for creatives not registered on the Platform, including through intake links that can be completed by the creative or a third party without an account. Creatives may add contacts to the Pocket CRM (including via file import or AI-assisted capture from images and websites). Creatives also receive inquiries through the public inquiry form on their portfolio and through "Inquire" messages that managers send from the Talent Finder; the sender's name, email address, and message are stored as a contact and activity in the creative's Pocket CRM (and, where the sender is a registered user, additionally delivered as a message), and the creative is notified. The person entering or receiving this data is the Data Controller for it. The Pending GmbH processes it as a Data Processor on their behalf. Legal basis for our processing: Article 6(1)(b) GDPR (performance of contract with the user entering the data); that user must separately ensure they have a lawful basis for holding the information.


5.6 Talent Discovery From Public Sources


Our Talent Finder helps managers discover professionals by searching publicly accessible web pages — for example personal websites, agency and company pages, public professional directories, and public professional-network pages. Where a page appears to describe an individual professional relevant to the manager's search, we extract and store a limited record so that the manager can review the result: the person's name, a short professional summary generated from the page, their professional website, the address of the source page, a publicly listed professional contact address where one is available, a location, a profession, and internal relevance scores. We do not collect photographs through this feature, and we do not build behavioural profiles, browsing histories, or vector representations of these individuals.

These records are used solely to answer the searching manager's query and to let that manager decide whether to contact the person. Where a manager saves a result, it becomes an entry in that manager's own Talent Database and the manager becomes the Data Controller for it, as described in Sections 5.5 and 13.

Legal basis: Article 6(1)(f) GDPR (our legitimate interest, and the legitimate interest of our manager customers, in identifying professionals who publicly present themselves as available for professional engagement). We restrict this processing to information the individual has published in a professional context, and we do not collect special category data through this feature.

Your rights if you have been found this way. Because we obtain this data from public sources rather than from you, Article 14 GDPR applies. Providing individual notice to every person surfaced by a search would involve disproportionate effort in the sense of Article 14(5)(b), so we provide this notice publicly here instead. You have the right to object to this processing at any time under Article 21 GDPR, and to request access, correction, or erasure of what we hold. Write to service@thepending.app with the web address where you were found or the name under which you appear. We will act on your request without undue delay and in any event within one month, and we will not require you to create an account to exercise these rights.


5.7 Automatically Collected Technical Data


We automatically collect IP addresses, device and browser information, and access logs for security, performance, and troubleshooting. Successful logins and signups are recorded with IP address and browser information for fraud prevention and account security; these records are deleted after 90 days. Login, signup, public forms, and password-protected public pages are rate-limited by IP address.

We also operate privacy-preserving, cookieless first-party page statistics: page views are counted using a daily-rotating pseudonymous identifier together with coarse device class, browser, referrer domain, and country (for visits to public Listing pages and to listing share links also region and city). Country and location are derived on our own servers from a local geo-database — nothing leaves our infrastructure for this purpose — and no raw IP addresses are stored in these statistics. Public portfolio pages use the same cookieless approach to count views for the creative. The same local geo-database, again without any data leaving our infrastructure, is used for the regional availability check at registration and the country declaration (Section 5.1), for the purchase-availability notice, and for country restrictions on partner content (Section 5.10).

Legal basis: Article 6(1)(f) GDPR (legitimate interest in platform security, stability, and aggregate usage measurement).


5.8 Billing and Financial Data


The Pending GmbH is the seller and merchant of record for all purchases on the Platform. Payment processing is handled by Stripe Payments Europe, Ltd. ("Stripe") as our payment processor. We store a Stripe customer reference, subscription references and status, billing period information, checkout and transaction references, and order records (product, price, credits) needed for accounting and to operate your subscription and credit balance. No payment card details are stored on our servers — card data is handled exclusively by Stripe (PCI-DSS compliant). To support fraud prevention and dispute resolution, the IP address used at checkout is transmitted to Stripe with the transaction. VAT on plan and Pen purchases is calculated at checkout via Stripe Tax. Some payment methods (for example SEPA Direct Debit) settle with a delay; your plan or Pens are activated once Stripe confirms the payment. Where we credit Pens to your balance without a payment (for example a goodwill credit, a referral credit, or a feedback credit), we record the credit in your usage ledger with a zero price. Invoices and payment history are available through the Stripe billing portal linked from your account settings. If you submit a cancellation request through our public cancellation form, we store the email address and details you provide, the time of receipt, and the outcome, as evidence that your cancellation was received and processed. Legal basis: Article 6(1)(b) GDPR; fraud prevention: Article 6(1)(f) GDPR; retention of billing records: Article 6(1)(c) GDPR (statutory accounting obligations).


5.9 Social Login Data


If you register or log in via Google, Apple, or Microsoft, we receive your name, email, and (where provided) profile picture from that provider. Legal basis: Article 6(1)(a) GDPR (consent, expressed via your choice of login method).


5.10 Partner Program Data


The Platform may display clearly labeled advertising from partner companies (cards and strips marked "Partner", "Sponsored", or "Presented by") under our Partnership Program, for example in the Listings list, on a public Listing, on the creative dashboard, and on the perks page. In connection with this program, we process:

  • Partner accounts and inquiries — If you submit a partnership inquiry or request an offer, we store your company name, contact email address, message, country of establishment, tax residency, the markets you want to reach or exclude, and the requested run length, to process your request, decide whether we may accept the partnership under tax and regulatory rules, and manage the partnership. Partner account holders additionally see their own company's booking and performance overview in the partner dashboard. Legal basis: Article 6(1)(b) GDPR (performance of a contract or pre-contractual measures); Article 6(1)(c) GDPR for tax-related checks.
  • How partner content is selected — Partner content is matched against interests you have explicitly selected in your profile, against the page you are currently looking at (for example the category filter you have applied), or shown untargeted to all users. In addition, a partner may limit its placements to, or exclude, certain countries; in that case the country your connection resolves to on our own servers decides whether the placement is shown to you at all. We never use behavioural profiles, your usage history, or AI-based targeting to select partner content, and every partner card includes a "Why this?" explanation.
  • Advertising measurement — When a partner card is displayed to you, confirmed as visible in your browser, or clicked, we record that event together with your account reference (for signed-out visitors: the session cookie only) and a snapshot of your platform role, subscription plan, the interests you have chosen yourself, the basis on which the card was selected, your language, device type, browser, and country. We do not store IP addresses, precise locations, or browsing profiles in these records. Clicks that our systems classify as invalid traffic are flagged and excluded from partner reporting. When you click a partner card, a random click identifier is appended to the partner's link, and the partner may later report a resulting order (its own order reference and value) back to us against that identifier so that we can measure the placement; no name, email address, or account identity is passed to the partner. Partners receive aggregate statistics only — your identity is never shared with them. These records are deleted after no more than 14 months. Legal basis: Article 6(1)(f) GDPR (legitimate interest in measuring and billing partner placements).
  • Partner payments — Partner placements are paid for through prepaid credit packs purchased via Stripe (checkout or invoice). We store checkout and invoice references only. Legal basis: Article 6(1)(b) GDPR.

5.11 Messaging and User Content


We store the content and metadata of messages you send via the Platform's messaging and chat features (including group conversations, message requests, quoted replies, @mentions, and file attachments), together with your blocking, muting, and archiving preferences, in order to deliver them and let you manage your conversations. Other participants in a conversation can see when you have read a message (read receipts); you can switch this off for each conversation, in which case you are neither shown nor counted in that conversation's read status. When you @mention a participant, they are notified. Messages you delete are removed from all participants' view. Messages are private to their participants; we access their content only where necessary to investigate a report of unlawful or abusive use, to comply with a legal obligation, or to resolve a technical fault. If you report a message or a user, we store the report in order to review it. Legal basis: Article 6(1)(b) GDPR; moderation and abuse prevention: Article 6(1)(f) GDPR.


5.12 Submissions About Other People


Some features let one person submit information about another. Creatives can submit themselves or a casting to an opportunity, and agents and representatives can submit the creatives they represent to a Listing. Where you submit information about someone else, you are responsible for having a lawful basis to do so and for informing that person; we process the submission on behalf of the listing owner, who is the Data Controller for it. A creative who is submitted by someone else can contact us at service@thepending.app to ask who submitted their data, to object, or to have the submission removed. Legal basis: Article 6(1)(b) GDPR (performance of the contract with the submitting and receiving users); our own interest in preventing abuse of these channels: Article 6(1)(f) GDPR.


5.13 Notifications and Emails


We send in-app notifications and emails about activity relevant to you (e.g., new applications, messages, matching opportunities, reminders, and digests). You can manage notification and email preferences in your settings, and every non-essential email contains a one-click unsubscribe link, which we also expose to your email provider so that its own unsubscribe button works. Purely transactional messages (e.g., password resets, purchase receipts, cancellation confirmations) do not carry an unsubscribe option because they are required to operate your account. Product news and announcements are sent only if you have opted in (at signup or in your settings), and we keep a record of that consent; for existing customers we may send news about similar products of ours under § 7(3) UWG, always with a reminder that you can object at any time. Legal basis: Article 6(1)(b) GDPR for service communications; Article 6(1)(a) GDPR for product news; Article 6(1)(f) GDPR for digests and re-engagement communications, which you can object to at any time via the unsubscribe link or your settings.


5.14 Data Provided Without an Account


Some public features accept submissions from people without a Platform account: the public job posting form, Talent Database intake links (including via QR code), the public inquiry form on a creative's portfolio (Section 5.5), the partnership inquiry form, the needs-evaluation form on our website (which asks for an email address to send you the result), the public cancellation form, and the Spotty preview. External reviewers who open an application review link (Section 5.15) do so without an account. We process the data you submit to handle your submission; where the form belongs to a specific manager or creative (e.g., Talent Database intake, portfolio inquiry), that user is the Data Controller and we process on their behalf. Public submissions are protected by rate limiting and bot detection. Legal basis: Article 6(1)(b) GDPR (steps prior to or performance of a contract) or processing on behalf of the responsible user.


5.15 Public Sharing Links


Talent Database share links. Managers can generate links that make selected Talent Database or profile information viewable outside the Platform, optionally protected by a password. For each link the manager chooses what is shown: name, profession, location, picture, and portfolio link, and — each only if the manager switches it on — the manager's own notes about the person, a rating, custom fields, and download links to attached files (for example CVs). Where a password is used, we set a short-lived, strictly necessary cookie on the visitor's device to remember that the link was unlocked. We count how often a link is opened and when it was last opened; we do not record who opened it. Pages reached through these links are marked so that search engines do not index them. If you are a creative whose profile is shared this way, the sharing manager is responsible for having a basis to do so; creatives with a Platform portfolio can exclude their profile from such links in their portfolio settings.

Application review links. Managers can give a person without a Platform account — for example a client or a colleague — read-only access to the applications received for one Listing, through a link that always requires a password and expires (after 30 days by default; the manager can extend or revoke it). A reviewer sees the applicants' names, photos, contact details, messages, form responses, attachments, portfolio links, discussion stage, AI fit score, and the team's notes and ratings, and can reply to the manager only. We record how often and when the link was opened, and we set a signed cookie valid for 12 hours, bound to a hashed form of the reviewer's IP address, so the password does not have to be re-entered. Pages reached through these links are not indexed or cached. The manager is the Data Controller for what is shared this way (Section 13).


5.16 Campaign, Share, and Referral Links


We use tracked short links in our own marketing and in materials shared by our representatives. Visits through such a link are counted using a daily-rotating pseudonymous identifier together with coarse device class, browser, country, and referrer domain — no raw IP addresses or user agents are stored in these records. If you create an account after following a tracked link, we record which link you arrived through, so that we can measure and account for our campaigns. You can object to this measurement at any time by contacting service@thepending.app. Legal basis: Article 6(1)(f) GDPR (legitimate interest in measuring our own marketing).

Listing share links. Managers can create share links for their public Listings tagged by channel (for example LinkedIn, Instagram, WhatsApp, email, or their own website). Visits through such a link are counted using the same pseudonymous method together with the channel, referrer domain, device class, browser, country, region, and city. If you apply after following such a link, your application records the channel and link you arrived through, so that the manager can see which channels bring applications. Legal basis: Article 6(1)(f) GDPR (the manager's and our legitimate interest in measuring the reach of a Listing).

Referral links. Members can share an invite link that contains their personal invite code. If you open such a link while signed out, we store the code in your session and in a 30-day cookie (tp_ref); if you then register, we record who invited you so that both of you can receive a Pen credit once the programme's conditions are met. The person who invited you learns only that their invitation was rewarded. Legal basis: Article 6(1)(b) and (f) GDPR.


6. How We Use AI


The Platform uses AI extensively. AI features include:

  • Spotty (Manager and Creative) — Conversational AI assistants, via in-app chat and email, that can perform actions on the Platform on your behalf. Actions that change data require your confirmation. A limited preview is available to visitors (Section 5.4).
  • Talent Finder — AI-assisted talent discovery that processes your search queries and publicly available profile data to suggest creatives, and which ranks and filters the results shown.
  • Application Analysis — AI evaluation of incoming and imported applications, producing two scores (professionalism and project fit, each 0–10), an overall rating, a recommendation, and a written summary, to help managers review candidates. The analysis is told how the application reached the Platform (listing form, guest form, email, import, or agent submission) so that answers an applicant was never asked for are not held against them. This analysis runs automatically for new applications unless the manager switches it off in their settings. Scores are decision-support only (see below).
  • Profile Analysis and Embeddings — AI analysis of portfolio profiles and semantic vector representations of profile, job, and listing content to power search rankings and recommendations.
  • Email Classification — Categorizes inbound emails (application, inquiry, spam) for inbox management. Messages classified as spam are not deleted: they are held in a separate "Filtered" area where the manager can review and restore them, and are deleted after 30 days if not restored.
  • Job Finder and Job Matching — AI-assisted matching of publicly accessible job listings to creative profiles based on skills, location, and portfolio content. The Job Finder compiles a Search Profile from your portfolio and settings and searches public job boards, websites you ask us to watch, and — through our web search provider (Section 7), never by logging in anywhere — public hiring posts in a curated set of public social-media groups and accounts (for example public Facebook casting groups and public Instagram accounts). To tell how old an undated social post is, we keep a platform-wide index of post addresses and when we first and last saw them; this index contains no post content and no names. Platform-initiated match suggestions are reviewed by a person before any creative is contacted.
  • Application Assistant — Generates form responses and cover letters from your portfolio and the opportunity requirements, and can pre-fill external application forms at your request.
  • Client Finder (Pocket CRM) — AI-assisted discovery of potential clients for Creatives, based on portfolio data and industry context.
  • Content creation aids — AI drafting of emails, invitations, and outreach messages (which may include applicant or contact data you reference); AI-assisted creation of projects, Listings, profiles, and CRM contacts from text, images, or links you provide, including text extraction from uploaded documents (PDF, Word, and text files) and images; AI-generated application form structures; and personalized onboarding content.
  • Job aggregation — AI classification of publicly available job listings collected from external public sources.
  • Translation — AI translation of interface and dynamic content, and machine translation of our legal documents into further languages (marked as such; the English version prevails).

All AI model inference runs on AWS Bedrock using EU inference infrastructure (API endpoint in eu-central-1, Frankfurt; execution within EU AWS regions). The models used are Claude by Anthropic (Haiku, Sonnet, and Opus 4.5 generations, selected per feature) and Amazon Titan for text embeddings. To speed up responses, Bedrock may hold the beginning of a conversation in a short-lived cache for a few minutes. AWS Bedrock does not use your data to train AI models, and we do not train AI models on your data.

Some AI features perform web research: search queries derived from your search briefs, profile, or instructions, and the addresses of pages to be read, are sent to our web search and page-reading provider, Jina AI (Section 7). We do not send your account identity to that service, but text you include in a search or brief is transmitted as part of the query.

AI interaction is disclosed. Wherever you interact directly with an AI assistant, this is marked in the interface, and AI-generated emails sent on your behalf are identified as such.

Matching and ranking parameters. Search, matching, and application ranking are based on the correspondence between a profile or application and the requirements stated in the listing or search — skills, experience, location, portfolio content, and keywords — weighted by discipline: for location-independent disciplines such as performers, vocalists, and musicians, role fit is weighted more heavily than location so that touring professionals are not disadvantaged. Where a listing explicitly states a required gender, creatives whose profile gender differs (Section 5.2) are not matched to or suggested for that listing. Paid plans, partner status, and advertising never influence how profiles or applications are ranked.

Human decision, not automated decision. Where AI features influence the visibility or ranking of creative profiles or applications, this constitutes automated processing that may affect you. No decision producing legal or similarly significant effects is taken by AI alone: the Platform does not automatically accept, reject, advance, or contact anyone on the basis of an AI score. Application scores and rankings are shown to the responsible manager as advisory input, ordering of applications by AI score is optional and off by default, and every screen presenting AI scores carries a notice that a person must make the final decision. We also measure, in anonymous form, how often the final human decision differs from the AI ranking, as an internal check that the tool is being used as decision support rather than relied on by default. You have the right to request human review of any AI-generated outcome that affects you, to express your point of view, and to contest the result. Contact service@thepending.app to exercise this right.

Partner advertising does not use AI-based or behavioral targeting of any kind (Section 5.10).


7. Third-Party Service Providers


We share personal data with the following third-party processors, each subject to a Data Processing Agreement:

  • Infrastructure (AWS, Frankfurt) — Hosting, database, file storage, email sending and receiving (Amazon SES), AI model inference (AWS Bedrock, EU), and content delivery (Amazon CloudFront) for public website assets and public portfolio media, with edge locations in Europe and North America; CloudFront processes the requesting IP address transiently at the edge and we keep no CloudFront access logs.
  • Payment (Stripe Payments Europe, Ltd., Ireland) — Payment processing, subscription billing, VAT calculation, invoicing, and the billing portal for all purchases on the Platform, including Partnership Program credit packs. Stripe is PCI-DSS compliant. Pages offering purchases load Stripe's checkout components in your browser.
  • Web Search and Page Reading (Jina AI) — Web search and retrieval of public web page content for AI research features. Search queries derived from your search briefs, profile, or instructions are transmitted, as are the addresses of pages to be read. Your account identity is not transmitted, but text you include in a search or brief forms part of the query.
  • Product Analytics (PostHog, EU hosting) — Where enabled, usage analytics and session replay, active only after you consent via the cookie banner (Section 9). We use a pseudonymous user reference; text you type is masked in session replays; IP addresses are discarded at ingestion.
  • Social Login (Google, Apple, Microsoft) — Authentication data from third-party login providers, where you choose that login method. Transfers to the US rely on the EU-US Data Privacy Framework or Standard Contractual Clauses.
  • Bot Protection (Cloudflare Turnstile) — Anti-bot verification on login, signup, and public forms (job posting, applications, portfolio inquiries, the cancellation form, and the needs-evaluation form). Your browser communicates with Cloudflare to solve the challenge and Cloudflare may set its own cookies; we transmit only the resulting token for verification.
  • Geocoding (OpenCage, Germany) — Location text (city/country) converted to geographic coordinates for profile and search features.

Public portfolio pages can contain media embeds chosen by the creative (e.g., YouTube, Vimeo, Spotify, SoundCloud players, Instagram or TikTok embeds). When you view a page containing such an embed, your browser connects to that platform, which receives your IP address and browser information and may set its own cookies under its own privacy policy.

All JavaScript libraries, stylesheets, and fonts used by the Platform itself are hosted on our own infrastructure. Apart from Amazon CloudFront and the services named above, no third-party content delivery networks are loaded.


8. International Data Transfers


The Platform is hosted in AWS eu-central-1 (Frankfurt, Germany), and AI inference runs within EU AWS regions. Public website assets and public portfolio media may be served from CloudFront edge locations in North America as well as Europe; at the edge, CloudFront processes the requesting IP address transiently and no access logs are kept. Some of our processors are based in the United States or other countries outside the EU/EEA. For all such transfers we rely on the EU-US Data Privacy Framework where the recipient is certified, and otherwise on Standard Contractual Clauses (2021 version) approved by the European Commission, supplemented by Transfer Impact Assessments where required.


9. Cookies and Similar Technologies


We use the following cookies and browser storage:

  • pending_sessionid — Keeps you logged in (7 days; strictly necessary, no consent required).
  • csrftoken — Security token to prevent cross-site request forgery (strictly necessary).
  • django_language — Stores your language preference (functional, no consent required).
  • tp_cookie_consent — Records your cookie preferences (365 days; strictly necessary).
  • Share-link unlock cookies — Set only when you unlock a password-protected Talent Database share link or an application review link, to remember that this link was unlocked on your device (12 hours; the review-link cookie is signed and bound to a hashed form of your IP address; strictly necessary for that feature).
  • tp_ref — Set only when you open an invite link while signed out, to remember the invite code until you register (30 days; Section 5.16).
  • Interface preferences (browser storage) — Entries in your browser's local storage that remember interface choices such as open filters, dismissed notices, and unsent drafts. They never leave your browser (functional, no consent required).
  • Product analytics (consent-only) — If, and only if, you accept analytics in the cookie banner, our analytics provider stores an analytics cookie and browser storage entries to recognize your session, and may record masked session replays (Section 7). Nothing is stored for analytics before you consent, and you can withdraw consent at any time.

Cloudflare Turnstile and Stripe may set their own cookies when their components load, for security and fraud prevention. Partner advertising measurement (Section 5.10) and our first-party page statistics (Section 5.7) are performed server-side without cookies or device storage.

You can change your cookie preferences at any time via the cookie banner or the "Manage cookies" control on our Cookie Policy page. Consent under § 25 TDDDG / Article 6(1)(a) GDPR can be withdrawn there with effect for the future.


10. Data Retention


  • Account data: Retained for the duration of your account. When you delete your account in the Platform settings, your account and the personal data associated with it are deleted immediately, including the associated files in our file storage; residual copies in encrypted backups are overwritten within 30 days. Records we must keep by law (in particular billing records) are retained with the account reference removed.
  • Application data, including AI evaluations: Applications — together with their attachments and any AI scores — are permanently deleted six months after the opportunity stops accepting applications. That period starts at whichever happens first: the listing is closed to applications, the project is archived or completed, the listing is deleted, or the manager deletes the application. Every application is kept for at least six months from the date it was submitted, so a late application is never deleted early. Where a listing is never formally closed, its application data is deleted after eighteen months without any activity on it — but never silently: we first notify the manager at least 30 days in advance, and the deletion only proceeds if that warning goes unanswered. The manager can confirm the process is still running, which restarts the period, or download an archive of the data beforehand. Deletion is automatic and runs daily.
  • Listings and projects themselves: Not affected by the rule above. They remain until the managing user deletes them or closes their account — closing a listing is always the manager's own decision and is never done automatically.
  • Anonymous statistics about applications: When application data is deleted, we may keep an anonymous statistical summary for the listing — a distribution of match scores and a measure of how often the final human decision differed from the AI ranking. These contain no personal data, are only produced where at least five applications were analysed, and are kept indefinitely.
  • AI interaction data: Spotty conversations are retained until you delete them or your account. Internal AI processing logs, including the feedback signals described in Section 5.4, are deleted after at most 12 months; AI usage accounting records (which contain no conversation content) after at most 400 days.
  • Security records (successful login/signup with IP address): 90 days.
  • Billing records: Retained for the period required by applicable tax law (typically 10 years in Germany).
  • Manual profiles and CRM contacts: Retained until you delete them; deleted entries are permanently removed after a further 180 days, or immediately with your account.
  • Talent search results about non-users (Section 5.6): Retained while they remain useful to the searching manager, and deleted when that manager deletes them or closes their account. If you object under Section 5.6, your record is removed.
  • Partner advertising measurement records: Deleted after no more than 14 months.
  • Messaging delivery logs: Deleted after no more than 120 days. Message content and attachments remain until you delete them or your account.
  • Linked accounts, Studio Access grants, and share links: Retained until you unlink, revoke, or delete them, or close your account. Application review links expire after 30 days by default and are retained as a record until the manager deletes them.
  • Country declaration, purchase waitlist opt-ins, and referral records: Retained for the duration of your account; a waitlist opt-in is withdrawn as soon as you ask.
  • Records of consents and confirmations you give (for example product-news consent, listing-requirement confirmations, AI-disclosure acknowledgements, and retention extensions): Retained after account deletion, together with the email address they were given under, for as long as we need to demonstrate that they were given (Article 6(1)(c) and (f) GDPR).
  • Partner conversion reports: Retained with the related partner booking records for billing and dispute purposes.
  • Social post sighting index (Section 6): Post addresses and timestamps only; retained while we monitor the source.
  • Filtered (spam-classified) inbound email: 30 days, unless restored by the manager.
  • Read in-app notifications: 180 days. Cookieless page statistics, listing share-link visits, and campaign-link visits: no more than 400 days (about 13 months). Payment webhook records: 90 days.
  • Data export archives: The archive generated for a data export request is deleted after 7 days; download links expire after 1 hour and can be re-sent.

11. Your Rights


Under GDPR, you have the following rights:

  • Right of Access (Art. 15) — Obtain a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16) — Correct inaccurate or incomplete data.
  • Right to Erasure (Art. 17) — Request deletion of your data where it is no longer necessary or processing is unlawful. Account deletion is available in the Platform settings and takes effect immediately.
  • Right to Restriction (Art. 18) — Request that we limit processing in certain circumstances.
  • Right to Data Portability (Art. 20) — You can request a machine-readable export of your data directly in your account settings; we email you a secure download link when it is ready. You can also contact service@thepending.app and we will provide a copy within 30 days. If you applied to an opportunity without a Platform account, contact us and we will provide your application data on verification of your identity.
  • Right to Object (Art. 21) — Object to processing based on legitimate interest, including partner advertising measurement (Section 5.10), feedback signals used to improve our assistants (Section 5.4), share-link measurement (Section 5.16), and digest or re-engagement communications (Section 5.13). Contact service@thepending.app.
  • Automated decision-making (Art. 22) — We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Where AI scores or rankings support human decisions, you may request human review, express your point of view, and contest the result (Section 6).
  • Right to Withdraw Consent — For processing based on consent (including special category data and analytics), you may withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact service@thepending.app. We will respond within 30 days. If you believe your rights have been violated, you may lodge a complaint with the competent Bavarian data protection authority:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany | poststelle@lda.bayern.de


12. Security


We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption in transit (HTTPS/TLS, WSS) and at rest (AWS RDS, S3, ElastiCache encryption), with additional application-layer encryption for particularly sensitive stored credentials.
  • Role-based access control and object-level permission enforcement, including tiered administrator access.
  • CSRF protection, Content Security Policy headers, and bot detection (Cloudflare Turnstile).
  • Rate-limited login, signup, public forms, and password-protected public pages, with IP-based logging of successful authentications.
  • Time-limited presigned URLs for access to private files (up to 1 hour); public portfolio media is served through a content delivery network without personal identifiers.
  • Removal of embedded metadata (EXIF, XMP, IPTC — including GPS position, capture time, and camera identifiers) from every uploaded image.
  • Passwords for share links and review links are stored only in hashed form and shown once at creation.
  • Internal analytics by administrators run through a read-only database role; every such query is logged.
  • Secrets management via AWS Secrets Manager (no hardcoded credentials).
  • Signature verification for all inbound webhook endpoints.
  • Automated removal of common personal identifiers from internal AI tool logs.

13. Manager Responsibility for Applicant and Contact Data


When managers set Listings or Projects public to receive applications, import applications, or share applications with external reviewers through review links, personal data of applicants is collected and processed. Managers act as the Data Controller for this applicant data. The Pending GmbH processes it as a Data Processor on the manager's behalf, as described in the Data Processing Agreement embedded in the Terms of Use (Section 9).

Managers are responsible for:

  • Informing applicants of the processing of their data (e.g., via a privacy notice linked within the public Listing). We provide a template notice you can adapt, linked in the footer and in your account settings.
  • Deciding what a share link or review link discloses, sharing such links only with people who need the information, and ending access when it is no longer needed.
  • Ensuring application forms do not collect unnecessary or disproportionate personal data, and in particular not requesting protected characteristics unless there is a genuine, lawful occupational requirement.
  • Obtaining explicit consent before collecting special category data through custom form fields.
  • Complying with all applicable data protection laws in their jurisdiction, including retention, deletion, and responding to data subject rights requests.
  • Complying with local rules on the use of automated tools in recruitment — including candidate notice, audit, and record-keeping obligations that apply in certain jurisdictions — when using AI-assisted evaluation features.

The Pending GmbH does not independently notify applicants about data processing on behalf of managers. This is the manager's responsibility.


14. Jurisdiction-Specific Notices


  • United Kingdom — For users in the UK, references to the GDPR include the UK GDPR and the Data Protection Act 2018. Complaints may be addressed to the Information Commissioner's Office (ico.org.uk). Where we are required to designate a UK representative under Article 27 UK GDPR, their details will be published here.
  • Switzerland — For users in Switzerland, this policy also serves as information under the Swiss Federal Act on Data Protection (FADP). Data is disclosed to the countries and recipients listed in Sections 7 and 8; transfers to the US rely on the Swiss-US Data Privacy Framework or equivalent safeguards. The competent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC).
  • Canada — We process personal information in accordance with PIPEDA. Enquiries and access requests can be addressed to service@thepending.app; the person accountable for our privacy compliance is named in Section 2. Where a recommendation or evaluation is generated by automated processing, you may request an explanation and human review (Section 6). For users in Quebec, the person in charge of the protection of personal information is Niklas Kornel (Section 2); where a decision concerning you is based exclusively on automated processing, we inform you of this, and you may submit observations to a member of our staff who is in a position to review the decision.
  • United States — The Platform is offered from Germany. We do not sell or share personal information as those terms are defined by US state privacy laws, and we do not use sensitive personal information for purposes that would require a right to limit. Verified requests submitted to service@thepending.app are honored where state-specific rights apply.
  • Australia — We handle personal information consistently with the Australian Privacy Principles to the extent they apply. The automated processing used in the Service is described in Section 6. Complaints may be raised with us first and with the OAIC.
  • Brazil — For users in Brazil, we process personal data in accordance with the LGPD (Lei Geral de Proteção de Dados). The legal bases stated in this policy correspond to those of Article 7 LGPD, and the rights under Article 18 LGPD can be exercised through the channels in Section 11. The competent authority is the ANPD.
  • Japan — For users in Japan, we handle personal information in accordance with the APPI. The purposes of use are those described in Section 5, and we do not provide personal data to third parties except as described in this policy or with your consent. Requests may be addressed to service@thepending.app.
  • Singapore — For users in Singapore, we handle personal data consistently with the PDPA. Our data protection contact is set out in Section 2; unresolved concerns may be raised with the PDPC.
  • New Zealand — For users in New Zealand, we handle personal information consistently with the Privacy Act 2020 and its Information Privacy Principles. Complaints may be raised with us first and with the Office of the Privacy Commissioner.
  • India — For users in India, we process digital personal data consistently with the Digital Personal Data Protection Act, 2023, to the extent it applies. Our grievance channel is service@thepending.app; the rights described in Section 11 can be exercised through it.
  • Thailand — For users in Thailand, we process personal data consistently with the PDPA. The rights described in Section 11 can be exercised via service@thepending.app; the competent authority is the PDPC.

15. Updates to This Privacy Policy


We may update this Privacy Policy to reflect changes in our practices or legal requirements. The current version is always available on the Platform. We will notify registered users of material changes by email or in-platform notice.

This policy is written in English. Where we offer it in other languages, those versions are machine translations provided for convenience and marked as such; in the event of any inconsistency, the English version prevails.




Contact
The Pending GmbH · Nestroystraße 13, 81373 Munich, Germany · Email: service@thepending.app
© 2026 The Pending GmbH. All rights reserved.

Product analytics and session replay (PostHog)

With your consent, we use PostHog, a product-analytics service, to understand how our platform is used and to improve it. Data is hosted exclusively in the European Union (Frankfurt, Germany). We have concluded a data processing agreement with the provider, PostHog, Inc., pursuant to Art. 28 GDPR.

PostHog receives only pseudonymous identifiers and usage data — we never transmit your name or e-mail address. Your IP address is discarded at ingestion and not stored. With the same consent, we may record how the interface is used (session replay); everything you type is masked and never recorded, and payment forms are handled by our payment provider outside of any recording.

The legal basis for this processing is your consent (Art. 6(1)(a) GDPR), given via the cookie banner. Analytics is off by default and only starts after you opt in. You can withdraw your consent at any time with effect for the future — withdrawal stops analytics and session replay immediately. Details, including the cookies used and how to change your choice, are in our Cookie Policy.