Quick summary
| Data Controller | WISELOOK TALENT LAB, S.L. (Tax ID B22539084), Paseo de la Castellana 42, 1st floor, 28046 Madrid, Spain. |
|---|---|
| Privacy contact | privacy@wiselook.ai |
| What we do with your data | We carry out AI-assisted conversational psychometric and competency assessments and make the results available to you and, where applicable, to the organisation that invited you to take the assessment. |
| Legal bases | Consent, performance of a contract, legitimate interests, and legal obligations (see Section 4). |
| Retention | Up to 3 years from your last meaningful interaction, unless the law requires a longer period (see Section 7). |
| Recipients | The organisation that invited you (where applicable), our processors (technology providers), and the competent authorities where legally required (see Section 6). |
| Your rights | Access, rectification, erasure, objection, restriction, portability, the right not to be subject to decisions based solely on automated processing, and the right to withdraw consent. You can exercise these rights at privacy@wiselook.ai and lodge a complaint with the Spanish Data Protection Agency (AEPD) (www.aepd.es). |
| Automated decision-making | Our system supports decision-making but does not replace it. Qualified human review is in place, and you have the right to obtain an explanation and to contest any outcome (see Section 5). |
This is a layered notice in line with the guidance issued by the Spanish Data Protection Agency (AEPD). We strongly recommend reading the detailed information set out below.
Our core commitments to you
- We do not train models on your data. Wiselook does not use your personal data to train third-party language models or any other AI system beyond operating the Service.
- We do not sell your personal data. Wiselook does not sell, rent, or trade your personal data under any circumstances.
- We minimise the data we collect. The only directly identifying information required is your email address (to log in) and, optionally, your name. See Section 4.
1. Who are we and who this policy applies to
Wiselook Talent Lab, S.L. («Wiselook», «we», «us» or «our») is a Spanish company that develops scientifically validated, AI-based conversational competency assessment technology, developed through academic collaborations.
This Privacy Policy explains how we process personal data in relation to:
- Assessed individuals ("you"): people who take an assessment through the Wiselook platform (the "Service"), whether on their own initiative or because a company, educational institution, or other organisation (a "Business Client") invited them to do so.
- Visitors to wiselook.ai and its subdomains.
- Contact persons at Business Clients, partners and suppliers, and candidates applying for a position at Wiselook.
If you have any questions about this policy, write to privacy@wiselook.ai.
2. Data controller
| Legal name | WISELOOK TALENT LAB, S.L. |
|---|---|
| Tax ID (CIF) | B22539084 |
| Registered address | Paseo de la Castellana 42, 1st floor, 28046 Madrid, Spain |
| Privacy contact | privacy@wiselook.ai |
| General contact | hello@wiselook.ai |
Unless expressly stated otherwise, Wiselook acts as Data Controller with respect to the personal data described in this policy. In certain situations, Wiselook acts as Data Processor on behalf of a Business Client (see Section 3).
3. Roles: when we act as Controller and when as Processor
Depending on the context in which you use the Service, Wiselook may act in two different capacities:
3.1. Wiselook as Processor (default option in B2B)
When a Business Client engages Wiselook to assess its candidates, employees, or students, the Business Client acts as Controller and Wiselook acts as Processor under Article 28 GDPR and the corresponding data processing agreement. In these situations:
- The Business Client determines the specific purposes of the assessment process (recruitment, development, training, etc.).
- The Business Client is responsible for informing you and, where applicable, for having an appropriate legal basis under its own privacy policy.
- Wiselook processes data following the Business Client's documented instructions.
- To exercise your rights in relation to the specific assessment process you took part in, you should first contact the Business Client. If they do not respond, Wiselook will help facilitate your request.
3.2. Wiselook as Controller
Wiselook is the Controller — that is, we determine the purposes and means of processing — in the following cases:
- When you access the Service directly, without a Business Client acting as intermediary (self-service or individual assessments).
- For Wiselook's own purposes — including product improvement based on de-identified data, scientific research, and legal compliance — even where the underlying data was originally collected on behalf of a Business Client.
- For operating our website and applications, marketing, and managing relationships with Business Clients, partners, suppliers, and job candidates.
Clarity at every step. Before starting an assessment, the Service will tell you whether a Business Client invited you and, if so, will identify that Business Client. If you have questions about who is the Controller for a particular processing activity, write to privacy@wiselook.ai.
4. What data we process, why, and on what legal basis
The following sets out the categories of data, purposes, and legal bases under Article 13 GDPR.
4.1. Assessed individuals
The Service is designed around strict data minimization. The only directly identifying information we collect about you is the email address used to access the Service and, optionally, your name. We do not collect data about your professional or academic background, behavioral tracking data, browsing data, or cookies in connection with the Service.
| Data category | Purpose | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Email address (only when you log in by entering your email; not collected when you access the Service via a magic-link invitation) and, optionally, name | To allow you to access the Service, communicate with you, and link your responses to your account | Performance of a contract/pre-contractual measures (Art. 6(1)(b)) and/or consent (Art. 6(1)(a)) |
| Assessment responses: voice recordings, transcripts of those recordings, and/or text submitted during the dynamic assessment | To carry out the competency assessment and generate results | Consent (Art. 6(1)(a)) and/or performance of a contract (Art. 6(1)(b)) |
| AI-inferred data: competency scores, psychometric indicators, and qualitative model outputs | To generate the assessment report that is the object of the Service | Consent (Art. 6(1)(a)) and/or performance of a contract (Art. 6(1)(b)) |
| De-identified/anonymised assessment data | Internal improvement of AI and psychometric models and quality audits | Legitimate interest (Art. 6(1)(f)), exercised over data that has already been anonymised |
| De-identified/anonymised assessment data | Scientific research with academic partners (see Section 8) | Public interest in scientific research (Art. 6(1)(e), in conjunction with Art. 89 GDPR), exercised over data that has already been anonymised |
4.2. Contacts at Business Clients, partners, and suppliers
We do not proactively collect identifying or professional data (such as name, job title, phone number, or company) from contact persons at Business Clients, partners, or suppliers. The only personal data processed in this context is the following:
| Data category | Purpose | Legal basis |
|---|---|---|
| Professional email address (only when provided at login) | To allow you to access the Service | Performance of a contract/pre-contractual measures (Art. 6(1)(b)) and/or consent (Art. 6(1)(a)) |
4.3. Website visitors
| Data category | Purpose | Legal basis |
|---|---|---|
| Contact details submitted via web forms | To respond to your enquiry | Consent (Art. 6(1)(a)) |
4.4. Candidates applying to join Wiselook
| Data category | Purpose | Legal basis |
|---|---|---|
| CV, professional profile, and information shared during the recruitment process | To assess your application | Pre-contractual measures taken at your request (Art. 6(1)(b)) and consent (Art. 6(1)(a)) |
We do not process special categories of data (Art. 9 GDPR: health, ethnic origin, political opinions, identifying biometric data, etc.), unless you voluntarily include them in your responses. We expressly ask that you do not include sensitive data that is not strictly necessary. Voice is processed for transcription and linguistic analysis of your response and is not used for biometric identification within the meaning of Article 9 GDPR.
5. Human oversight and decision-making
Wiselook's results are intended to assist, not replace, human judgment. Results are reviewed in accordance with our internal quality control procedures.
Wiselook does not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing within the meaning of Article 22 GDPR. Where a Business Client uses our results as one input for making a decision (for example, in a recruitment process), the final decision rests with the Business Client, who must ensure meaningful human involvement. You have the right to:
- Request meaningful human intervention from Wiselook (when we act as Controller) or from the Business Client (when we act as Processor).
- Express your point of view and provide additional context.
- Contest any result and request its review.
To exercise these rights: privacy@wiselook.ai.
6. Recipients of your data
Personal data may be disclosed to the following categories of recipients.
6.1. The Business Client that invited you
Where the assessment is carried out as part of a process driven by a Business Client, the results (and, depending on the configuration set by the Business Client, the underlying response data) are made available to that Business Client for the corresponding purpose. The Business Client processes this data as an independent Controller under its own privacy policy.
6.2. Processors (technology providers)
Wiselook applies strict data minimisation across all its supplier relationships. Before any assessment content is transmitted to AI model providers or third-party processing services, identifying information is filtered out through technical safeguards, so that such providers only receive de-identified content. If you mention personal information during an assessment, our processing workflows are designed to remove that information before any external processing.
Supplier categories include:
- Cloud infrastructure and data hosting (within the EEA; see Section 6.5).
- Generative AI model and natural language processing providers (LLMs and voice transcription). These providers process only de-identified content and, under our contractual terms with them, do not use that content to train their own models.
- Real-time voice communication infrastructure.
- Transactional email, customer support, and CRM tools.
- Technical and product observability services.
All providers operate under data processing agreements compliant with Article 28 GDPR and with safeguards equivalent to our own.
Sub-processor list. Wiselook maintains an up-to-date list of sub-processors, which it keeps confidential for security and business reasons. The list is shared with Business Clients under the corresponding data processing agreement. If you are an assessed individual, you may request to review it subject to reasonable confidentiality commitments by writing to privacy@wiselook.ai.
6.3. Competent authorities
Where there is a legal obligation to do so, for example in response to judicial, administrative, or law enforcement requests.
6.4. Professional advisors
Legal counsel, tax advisors, and auditors bound by confidentiality obligations, strictly to the extent necessary.
6.5. Location of data processing
All processing of personal data takes place within the European Economic Area. Wiselook does not currently engage processors that process personal data outside the EEA. Should this change in the future, we will update this policy and ensure appropriate safeguards are in place under Chapter V GDPR before carrying out any international transfer.
7. Retention periods
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
| Type of data | Retention period |
|---|---|
| Assessment data (responses, transcripts, and AI-inferred data) when Wiselook acts as Controller | Up to 3 years from your last meaningful interaction. |
| Assessment data when Wiselook acts as Processor on behalf of a Business Client | The period set by the Business Client in the data processing agreement, capped at 3 years unless specific written instructions state otherwise. |
| Contractual data of Business Clients, partners, and suppliers | For the duration of the relationship and, once ended, for the applicable statutory limitation periods (generally up to 6 years for accounting and commercial obligations under Spanish law). |
| Data of candidates applying to join Wiselook | 1 year from the last update, unless consent is withdrawn earlier. |
Once these periods have elapsed, data is deleted or irreversibly anonymised. Anonymisation may take place earlier for the purposes of product improvement and scientific research (see Section 8).
8. Scientific research and product improvement
Scientific validation and continuous improvement of the Service are essential to Wiselook. For this purpose, we may use data that has been irreversibly anonymised beforehand (with no possibility of re-identification) for:
- Internal improvement of psychometric and AI models.
- Validation studies with academic partners (in particular, the Universidad Autónoma de Madrid and other universities).
- Independent bias and quality audits.
Once data has been anonymised, it ceases to be personal data within the meaning of the GDPR, and its subsequent processing therefore does not affect your rights as a data subject.
9. Your rights
Under Articles 15 to 22 GDPR, you have the following rights:
| Right | What it means |
|---|---|
| Access | To know what data we hold about you and obtain a copy. |
| Rectification | To correct inaccurate or incomplete data. |
| Erasure ("right to be forgotten") | To have your data deleted when it is no longer necessary or another ground under Article 17 GDPR applies. |
| Objection | To object to processing based on legitimate interests and to commercial communications. |
| Restriction | To have processing temporarily suspended while a matter is being resolved. |
| Portability | To receive your data in a structured, commonly used format, or have it transmitted to another controller. |
| Not to be subject to decisions based solely on automated processing (Art. 22) | See Section 5 above. |
| Withdraw consent | At any time, without affecting the lawfulness of processing carried out before its withdrawal. |
9.1. How to exercise them
By writing to privacy@wiselook.ai, indicating which right you wish to exercise and, where necessary to verify your identity, attaching a copy of an identification document.
We will respond within one month of receiving your request, extendable by a further two months where the complexity or volume of requests makes this necessary.
9.2. Right to lodge a complaint
You have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) — C/ Jorge Juan, 6, 28001 Madrid; www.aepd.es — in particular if you believe we have not properly addressed your rights.
10. Information security
Wiselook has implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit (TLS) and at rest.
- Access control based on the principle of least privilege and strong authentication.
- Segregation of development, testing, and production environments.
- Monitoring, event logging, and incident management.
- Backup and business continuity procedures.
- Regular staff training on data protection and security.
- Periodic assessment of suppliers and sub-processors.
Wiselook is progressively aligning its controls with the ISO/IEC 27001 framework as a benchmark for information security maturity.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, Wiselook will notify the AEPD within 72 hours (Art. 33 GDPR) and, where the risk is high, will also notify the affected individuals (Art. 34 GDPR).
11. Minors
The Service is not directed at children under 14. Where a Business Client — for example, an educational institution — uses the Service with individuals older than 14 but under 18, that Business Client is responsible for having an appropriate legal basis under Article 7 of Organic Law 3/2018 (LOPDGDD) and Article 8 GDPR, including, where applicable, the consent of holders of parental responsibility. If you become aware that a minor is using the Service without an appropriate legal basis, please notify us at privacy@wiselook.ai so that we can take appropriate action.
12. Applicable legal framework
This policy is governed by:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).
- Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act).
- Law 34/2002 of 11 July on Information Society Services and Electronic Commerce (LSSI).
- Any other applicable Spanish and EU legislation.
13. Changes to this policy
Wiselook may update this policy to reflect legal, technical, or business changes. Where changes are material, we will notify you through an appropriate channel (email, notice within the Service, or notice on the website) with reasonable advance notice. The date of the last update appears at the top of this document. Where changes affect processing based on your consent, we will request that you renew your consent.
14. Contact
For any question relating to this policy or to the processing of your personal data:
WISELOOK TALENT LAB, S.L.
Paseo de la Castellana 42, 1st floor, 28046 Madrid, Spain
Privacy: privacy@wiselook.ai