Talent360Show

Privacy Policy

Last updated: October 6, 2026. Version 1 of this document.

This policy explains what personal data we process when you use Talent360Show, its public website or a shared presentation, and what you can do about it. It describes what the software does, no more and no less.

1. Data controller

The data controller is TALENT360HUB LLC, a Bulgarian company that operates the Talent360Show brand, with its registered and tax address at 10 Stefan Verkovich, Plovdiv 4000 (Bulgaria) and registration number EIK/VAT BG208378160. Our head office is at the European Trade Center, Building D, 1F, 115 M Tsarigradsko Shose Blvd., Sofia 1784 (Bulgaria), and our Western Europe office at Nevelgaarde 8, 3436 ZZ Nieuwegein (Netherlands). For anything concerning your data, write to privacy@talent360hub.com, an address we monitor ourselves.

There is one important exception: for the content you upload, create and share in your account, you are the controller, and we process that content on your behalf. We explain this in 'Your content: when we act as processor'.

2. What data we process, and where it comes from

We process data you give us, data generated by your use of the service, or data entered by another user, for example when they invite you to their team or include you in a presentation. We do not buy data, we do not obtain it from public sources and we do not sell it. We do not send newsletters or marketing emails, and we have no contact forms.

What we process depends on your relationship with Talent360Show. The next five sections set it out for each case: registered users, people invited to a team, visitors to the public website, viewers of shared presentations, and people who appear in a user's content.

3. If you have an account

If you register, or are a member of another user's team, we process:

  • Account data: name, email address and password (stored transformed with the bcrypt algorithm, never in plain text), interface language, plan, role, account status, date of last access, and your use of AI credits and storage.
  • Your content: projects, pages, presenter notes, earlier versions of each project (up to 30), folders, and the files you upload (images, audio and video of up to 200 MB).
  • Teams: the team name, who its members are and each member's role.
  • Subscription and payments: plan, number of users, amount, billing period and dates; for each payment, the billing email address, amount, currency, status, the gateway used and any coupon applied; and the billing details (name or company name, address and tax number) that you give us, directly or on the payment page, so that we can issue the invoice. Card payments are made on the secure page of Stripe or dLocal Go: we never see or store your card details. We only store the references they return (customer, subscription and payment) and, with dLocal Go, a card reference (token) used to charge renewals.
  • Email confirmation and password recovery: when you sign up, we send you a link to confirm your email address, which expires after 24 hours; if you request password recovery, we generate a single-use link that expires after one hour. We store both transformed (hashed), not in plain text.
  • Security data: your IP address and the email address you type when signing in, registering or recovering your password. They are held only in the server's memory to limit repeated attempts and are forgotten automatically within 15 to 60 minutes.
  • Audit log: if a Talent360Show administrator changes anything in your account, your payments or a setting, a record is kept of which administrator made which change.
  • Acceptance of the terms and the privacy policy: to create an account you must expressly tick the box by which you accept the legal notice and terms of use and the privacy policy. We keep a record of that acceptance with the date and time, the version and date of the documents, the language in which they were shown to you, your IP address and your browser identification (user agent, up to 500 characters), so that we can prove it.
  • AI requests: the text you send when you use the AI features. We explain this in 'Artificial intelligence features'.
  • Service emails: we only email you to confirm your email address when you sign up, to recover your password, to deliver the team invitations you send and to send you the invoices for your payments. The payment gateways may also send you their own receipts and payment notices.

View statistics for your shared presentations are described in 'If you view a shared presentation'.

4. If you are invited to a team

If a team owner invites you and you do not yet have an account, we store your email address, who invited you and when the invitation expires, and we send you an email containing it. That email includes the name or email address of the person inviting you and the team name. The invitation expires after 7 days and is then deleted. We do not use your email address for anything else.

If you accept the invitation and create an account, you become a registered user and the previous section applies.

5. If you visit the public website

The public website comprises the home page, the template gallery, the legal documents and the sign-in and registration pages. We do not ask you for any data to browse it. This is what is processed:

  • Your cookie decision: stored in your browser and also in a record on our server with the categories you accept or refuse, the policy version, the language in which the banner was shown to you, the date, your IP address and your browser identification (user agent, up to 500 characters). The IP address is stored solely so that we can demonstrate that consent.
  • Analytics and advertising, only if you accept them: Google Analytics 4, Google Ads, the Meta pixel and the LinkedIn Insight Tag receive your browsing data, their cookies and your IP address. They are used to measure visits and campaigns, including how many registrations come from a campaign.
  • Security data on the sign-in and registration pages, as explained in the previous section.

Full detail is in the Cookie Policy.

6. If you view a shared presentation

You do not need an account to view a presentation that a user has shared by link or embedded in another website, and we do not ask you for any data. For each view we record the date, the type of device (worked out from your browser's data, which we then discard), the source (link or embed), only the domain of the website that linked to or embedded the presentation (for example, https://example.com, without the full page address), the pages you view, and whether the viewer is the owner. We do not record your IP address, your browser identification or any other identifier of yours. The presentation's owner only sees aggregate statistics.

  • Password-protected presentations: if you unlock one, we set a cookie for 7 days so that we do not ask for the password again. To stop anyone from trying passwords endlessly, your IP address is held in the server's memory for no more than 60 minutes.
  • Videos and content from other sites: if the presentation includes a YouTube or Vimeo video, or other embedded content (third-party pages, HTML code or Lottie animations loaded from an external address), your browser connects to those services as soon as the slide containing it is shown, even if you do not press play; those services receive your IP address and apply their own policies. For YouTube we use youtube-nocookie.com and for Vimeo we request no tracking (dnt=1). The decision to embed that content is made by the user who created the presentation.
  • Read aloud: if you switch this feature on, the slide text is turned into speech by your own browser or operating system; it does not pass through our servers. Some browsers use an online service provided by their maker to do this.

Shared presentations and presentation mode do not load any analytics or advertising tools.

7. If you appear in a user's content

Users may include other people's data in their projects: names, photos, voices, videos or other data about pupils, colleagues or clients. It is that user who decides what is included, why and with whom it is shared, and who is the controller of that processing. We host and display it on their behalf.

If you wish to exercise your rights over that content, contact the user who published it. If you write to us at privacy@talent360hub.com, we will pass your request on to that user.

8. What we use the data for

  • Providing the service: creating and managing your account, authenticating you, saving and displaying your projects, sharing them and applying your plan's limits.
  • Enabling teamwork and delivering invitations.
  • Invoicing and meeting accounting and tax obligations.
  • Showing each user the statistics for their shared presentations.
  • Running the AI features you switch on.
  • Protecting accounts against abuse and knowing who changed what in the administration panel.
  • Being able to demonstrate whether or not you consented to cookies.
  • Only if you accept, measuring visits to the public website and the results of our campaigns.

We do not use your data for any other purpose. If we ever wanted to, we would tell you first and, where the law requires it, ask for your permission.

10. Your content: when we act as processor

When you upload, create or share content containing other people's data, you decide what data to include, why, and who to share it with. You are the controller of that processing and we are your processor within the meaning of Article 28 GDPR. This section, together with the Terms of Use, forms the data processing agreement between you and us. We undertake as follows:

  • Instructions: we process that content only to provide the service and in accordance with your instructions, which are the ones you give by using the application (creating, editing, sharing, embedding, exporting, deleting or using AI). We do not use it for our own purposes. If an instruction appeared to us to infringe the law, we would tell you.
  • Sub-processors: you authorise us to use the providers listed in 'Recipients and processors'. If we add or replace any of them, we will update that list and notify you by email in advance so that you can object.
  • Security and confidentiality: we apply the measures described in 'Security'. Administrative access is restricted by role and changes are logged.
  • Assistance: as far as possible, and with the information available to us, we will help you respond to requests from the people concerned and meet your obligations regarding security, breach notification and impact assessments.
  • Breaches: if we suffer a personal data breach affecting your content, we will notify you without undue delay.
  • At the end: when your account is deleted, we delete your content within the periods set out in 'Retention'. Before that, you can export your projects to PDF.
  • Information: we will make available to you the information needed to demonstrate that we meet these obligations. Ask for it at privacy@talent360hub.com.

11. Artificial intelligence features

The AI features (generating a draft, improving text, translating a project and generating images) are available on Pro plans and only run when you use them. When you do, we send our AI provider, OpenAI Ireland Ltd. (1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, Ireland), through its API, only what the task needs: the topic and description you write, the text you ask us to improve, the full text of the project you ask us to translate, or the description of the image you want to generate, together with our own instructions.

We do not send your name, your email address or any identifier of your account. These requests are not used to identify you or to decide anything about you. Bear in mind, however, that if the text contains personal data (for example, names on a slide you translate), that data does reach the provider.

OpenAI acts as a processor under a data processing agreement incorporated into its services agreement. It does not use the data it receives through the API to train its models. It keeps logs for abuse monitoring for up to 30 days, unless the law requires it to keep them longer. It also processes the data in the United States, through its affiliates (such as OpenAI OpCo, LLC) and sub-processors, under the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914) or an adequacy decision (Article 45 GDPR). On the reliability of the results, see the Legal Notice.

12. How long we keep the data

DataPeriodHow it is applied
Account and contentFor as long as the account existsWhen the account is deleted, we delete the account, projects, files and statistics within 30 days at most, and backups within 90 days at most. Projects in a team's space belong to the team and stay with its owner
View statistics24 calendar monthsAutomatic daily deletion
Cookie consent record24 monthsAutomatic daily deletion
Administration panel audit log24 monthsAutomatic daily deletion
Record of acceptance of the terms and the privacy policyWhile the account existsDeleted with the account
Team invitationsExpire after 7 daysDeleted at the next automatic daily deletion
Email confirmation and password recovery linksExpire after 24 hours (confirmation) and 1 hour (recovery)Deleted at the next automatic daily deletion
Proof of an account's deletionAs long as claims about that request can be broughtWithout your email address in plain text: only an irreversible fingerprint (hash), with the dates, the request reference, who handled it and how many items were deleted
Payments and invoicing10 years, under Bulgarian accounting and tax lawOnly the data needed to comply with it. The card reference we use for dLocal Go renewals is deleted when the subscription ends
Uploaded files no longer used by any project24 hoursAutomatic daily process
Security data held in memory (IP address and attempts)15 to 60 minutesForgotten automatically
Your cookie decision, in your browser24 monthsWe then ask you again

Deletion is carried out by an automated process that runs daily on our server; it does not depend on anyone remembering. If a specific legal obligation required us to keep something longer, we would keep only that, and only for as long as the obligation lasted.

13. Recipients and processors

We do not sell your data or pass it on for commercial purposes. To provide the service we use the providers in this table. Some process data on our behalf (processors); others are independent third parties that only your browser connects to.

ProviderWhat it receivesWhereSafeguardWhen
Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany): server and database hostingAll service dataData centre in Helsinki (Finland). Data and support are handled only within the EU (its local sub-processor is Hetzner Finland Oy)Data processing agreement (Article 28 GDPR); ISO/IEC 27001:2022 certification covering Helsinki. No international transferAlways
DigitalOcean, LLC (Broomfield, Colorado, USA): file storage (DigitalOcean Spaces)The files you uploadAmsterdam region (Netherlands). As a US entity, it may process some data in the United States or through sub-processors thereData processing agreement incorporated into its terms; EU-U.S. Data Privacy Framework and its UK Extension and, as a fallback, Standard Contractual ClausesAlways
Mailjet (Sinch group)The recipient's email address and the message content: a link to confirm the email address or to recover the password, or an invitation with the name or email address of the person inviting and the team nameEuropean UnionProcessor established in the EU; no international transferWhenever we send an email
OpenAI Ireland Ltd. (Dublin, Ireland), through its APIThe text and instructions for the AI features, and image descriptions. Never your name or email addressIreland; it also processes the data in the United States through its affiliates and sub-processorsData processing agreement incorporated into its services agreement; Standard Contractual Clauses or an adequacy decision. It does not use this data to train its modelsOnly when you use AI
Stripe Payments Europe, Limited (Dublin, Ireland), part of the Stripe group: payments by card and other payment methodsYour name, email address and customer reference, the plan or product and the amount. On its payment page, your card or other payment method details, your billing address and, if you provide it, your tax numberIreland (EU); as part of the Stripe group, it also processes data in the United StatesProcessor for collecting payments, with a data processing agreement incorporated into its terms, and independent controller for fraud prevention and its legal obligations. EU-U.S. Data Privacy Framework and Standard Contractual ClausesOnly when you pay with Stripe
Dlocal LLP (4 King's Bench Walk, London EC4Y 7DL, United Kingdom), through its dLocal Go service: payments in Latin America and other markets where it is availableYour name, email address and a user identifier, the product and the amount. On its payment page, your card or other payment method details and any data required by the rules of your country (for example, an identity document)United Kingdom and the country you pay fromProcessor for collecting payments and independent controller for fraud prevention and its legal obligations. The United Kingdom benefits from a European Commission adequacy decisionOnly when you pay with dLocal Go
Pexels (Canva Germany GmbH, Pappelallee 78/79, 10437 Berlin, Germany)Only the search term, sent from our server. The result thumbnails also reach you through our server, and when you choose an image or video we copy it to our own storage (it counts towards your plan's storage quota). Neither the person searching nor people viewing the presentation connect to PexelsGermany (EU)Independent third party supplying images and videos; not a processor and receives no personal dataOnly when searching for images
Google (Google Analytics 4 and Google Ads)Browsing data, cookies and IP addressUnited StatesEU-U.S. Data Privacy Framework and its UK ExtensionOnly with your consent
Meta (pixel)Browsing data, cookies and IP addressUnited StatesEU-U.S. Data Privacy Framework and its UK ExtensionOnly with your consent
LinkedIn (Insight Tag)Browsing data, cookies and IP addressUnited States and IrelandEU-U.S. Data Privacy Framework and Standard Contractual ClausesOnly with your consent
YouTube and VimeoIf a presentation includes a video, the viewer's browser connects to these services (we use youtube-nocookie.com, and Vimeo with dnt=1)United StatesIndependent third parties, with their own policiesWhen viewing a presentation that includes a video
Third-party sites embedded by a user (pages, HTML code, Lottie animations from an external address)The viewer's browser connects to the site the user has chosenDepends on the siteResponsibility of the user who embeds itWhen viewing that presentation

The fonts used on the website, in the editor, in presentations and in PDF export are served from our own server: there is no connection to Google Fonts. Whatever you share by link or embed in another website can be seen by anyone with access to it, and members of a team can see that team's space. Beyond these cases, we would only disclose data to authorities or courts where a law requires us to.

14. International transfers

Some providers process data outside the European Economic Area:

  • Google and Meta, only if you accept the relevant cookies. Both are certified under the EU-U.S. Data Privacy Framework and its UK Extension, which the European Commission regards as providing an adequate level of protection.
  • LinkedIn, only if you accept advertising cookies. It is certified under the same Framework and also applies the Standard Contractual Clauses approved by the European Commission.
  • OpenAI, only when you use the AI features. It processes the data in the United States through its affiliates and sub-processors, under the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914) or an adequacy decision, as set out in its data processing agreement.
  • Stripe and dLocal Go, only when you pay with them. Stripe processes data in the United States under the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses. dLocal Go (Dlocal LLP) is based in the United Kingdom, which benefits from a European Commission adequacy decision, and also processes the data in the country you pay from, so that it can charge you using local payment methods.
  • Hosting and file storage: the server and database are in Finland, with Hetzner, and do not leave the EU. Files are stored in Amsterdam with DigitalOcean, which, as a US entity, may process some data in the United States. DigitalOcean is certified under the EU-U.S. Data Privacy Framework and its UK Extension, and its data processing agreement also incorporates the Standard Contractual Clauses, so the transfer remains covered even if the Framework ceased to apply.

If you do not accept analytics and advertising cookies, their tools do not load and no transfer takes place through them. When you watch a YouTube or Vimeo video, or content from another site embedded in a presentation, it is not us who send the data: your browser connects directly to that third party. You can ask us for a copy of the safeguards by writing to privacy@talent360hub.com.

15. Cookies

We use necessary cookies to keep you signed in, protect forms, unlock password-protected presentations and remember your cookie decision, and your browser's local storage to remember the application language. Analytics and advertising cookies are only used on the public website (home page, template gallery and legal documents) and the sign-in and registration pages, and only if you accept them; never in the application, in shared presentations or in presentation mode. Your decision expires after 24 months. Full detail is in the Cookie Policy.

16. Your rights

You can exercise the rights the GDPR gives you at any time, free of charge, by writing to privacy@talent360hub.com. We will reply within one month. We may ask you for additional information, purely to be sure you are who you say you are.

  • Access: find out what data we hold about you and what we do with it.
  • Rectification: correct data that is inaccurate or incomplete. You can change your name and language yourself in Settings.
  • Erasure: ask us to delete data when it is no longer necessary or when you withdraw your consent. To delete your account, see the next section.
  • Restriction of processing: ask us to keep the data but stop using it while a challenge or complaint is resolved.
  • Portability: receive the data you gave us in a machine-readable format, or have us send it to another controller. If you ask us, we send you a JSON file with the data of your account, subscription, payments, folders, files and projects, including their pages.
  • Objection: object to processing based on legitimate interest.
  • Withdrawal of consent: where processing rests on consent, you can withdraw it at any time and as easily as you gave it, without affecting the lawfulness of processing carried out beforehand. For cookies, use the 'Cookie settings' link.

If your request concerns data that another user has included in their content, see 'If you appear in a user's content'.

17. How to delete your account

For now, account deletion is requested by email: write to privacy@talent360hub.com from the address you registered with. Beforehand, if you want to keep your projects, you can export them to PDF or ask us for a copy of all your data in JSON format.

We delete the account, projects, files and statistics within 30 days at most, and backups within 90 days at most. Projects in a team's space belong to the team and stay with its owner. If you own a team, the team is deleted along with your account: the other members keep their accounts and the team projects they created, which become their personal projects, and the ones you created are deleted. If you would rather the team continued, ask us first to transfer ownership to another member: only the owner changes, and the new owner will need their own Pro plan. Data that has its own period in the retention table, such as payments, is kept until that period ends. To be able to show that we handled your request, we keep a record of the deletion without your email address in plain text (only an irreversible fingerprint, or hash): the dates of the request and of the deletion, its reference, who carried it out and how many items were deleted.

18. Complaints to a supervisory authority

If you believe we have not handled your request properly, you can complain to our supervisory authority, the Commission for Personal Data Protection of Bulgaria (Комисия Π·Π° Π·Π°Ρ‰ΠΈΡ‚Π° Π½Π° Π»ΠΈΡ‡Π½ΠΈΡ‚Π΅ Π΄Π°Π½Π½ΠΈ), at 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, website cpdp.bg. If you live or work in another country in the European Economic Area, you may also complain to the authority in that country.

19. Automated decisions and profiling

We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you, and we do not build profiles from your data. The AI features generate or transform content when you ask them to; they decide nothing about people.

20. Children

Talent360Show accounts are aimed at professionals, teachers and organisations. You must be at least 16 years old, or the minimum age set by the law of your country if that is higher, to register. We do not knowingly collect data from anyone below that age; if you believe such a person has created an account, write to privacy@talent360hub.com and we will delete it.

People viewing a shared presentation may be children, for example in a classroom. We do not ask viewers for any data, the statistics do not identify them, and neither shared presentations nor presentation mode load any analytics or advertising. If you share content with or about children, it is you who must have the necessary legal basis, such as the school's authorisation or parental consent where required.

21. Security

  • The site is always served encrypted (HTTPS, with HSTS).
  • Passwords are stored with bcrypt, and recovery links and invitations are stored hashed.
  • Changing your password signs out your other open sessions.
  • Access to the administration panel is restricted by role and changes are kept in an audit log.
  • Uploaded files are served at addresses that cannot be guessed. For that reason, anyone who has the direct link to a file can see it even if the project is private: do not share those links if the file is confidential.

No system connected to the internet can guarantee absolute security. If a breach occurred that posed a risk to your rights, we would notify the supervisory authority and, where required, you.

22. If you live in the United Kingdom

Processing is also governed by the UK GDPR and the Data Protection Act 2018. The rights described above apply to you equally, and you may complain to the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow SK9 5AF, or at ico.org.uk. Transfers to the United States are made with the safeguards set out in 'International transfers', including, for Google and Meta, the UK Extension to the Data Privacy Framework.

23. Changes to this policy

If we change anything material, we will update the date and version shown at the top and publish the new text on this same page. If the change matters to account holders, we will also announce it in the application or by email before it applies. Where it affects tools that require your permission, we will ask you again rather than rely on your earlier answer.

24. Versions in other languages

This document is published in English, Spanish, French, German, Portuguese, Italian and Catalan so that you can read it in your own language. Translations are offered as a courtesy and, in the event of any discrepancy between versions, the English version prevails.