Jobs Talents Pricing
en
en English
ar العربية
de Deutsch
es Español
fr Français
it Italiano
pt Português
ru Русский
zh 官话
Sign In Get Started
Jobs
Talents
Pricing
Sign In
Get Started
Language
en ar de es fr it pt ru zh
Compliance & Accountability

Data ProtectionImpact Assessment

This page is the public summary of the Data Protection Impact Assessment (DPIA) we maintain under Article 35 of the GDPR. It describes the indexing of publicly available developer artifacts, the safeguards in place, and how risks to data subjects have been mitigated.

Alion operates a developer discovery and portfolio service. Because we index publicly available professional artifacts and use automated and AI-assisted analysis to generate profile descriptions, technical indicators and matching signals, we maintain this assessment to identify risks and document safeguards. Publication of this summary does not mean that every processing activity is risk-free.

This summary is informational. It does not replace our Privacy Policy, Terms of Service, Legitimate Interest Assessment or Record of Processing Activities, all of which are available on this Site.

01 - Nature
Nature of theProcessing

Alion is a discovery tool that helps developers showcase their public work. We index publicly available professional artifacts - public Git repositories, public package registries and public model hubs - and let developers claim, edit, hide or permanently delete the auto-generated portfolio we built from their public work.

Analysis may produce skill descriptions, matching signals, technical indicators scored on limited scales and estimated authorship ratios. These are uncertain inferences rather than verified facts or a single measure of a person's value. Alion does not use them to make a solely automated decision producing legal or similarly significant effects within GDPR Article 22. Employers remain responsible for independent human review.

02 - Scope
Scope andContext

Categories of data subjects: software engineers, machine-learning engineers and other technical professionals who have published professional artifacts in public repositories under their own name or pseudonym.

Categories of personal data: public username and display name, public commit email, public repository and contribution content and metadata, packages and models, declared languages and topics, public links, and inferred descriptions, skills, matching signals, technical indicators and authorship estimates. We do not intentionally collect special-category data (GDPR Art. 9) or criminal-conviction data for this flow.

Sources: public APIs and public web pages of source platforms (Git hosting providers, package registries, model hubs). We honour robots.txt, rate limits and the published terms of use of those platforms.

03 - Purpose
Purpose andLegal Basis

Purpose: to enable developers to discover and claim an auto-generated public portfolio built from their own publicly published professional work, and to enable employers to discover such public portfolios.

Where the GDPR applies, the legal basis is legitimate interest under Article 6(1)(f), assessed in our Legitimate Interest Assessment. A public commit or profile email may be used for one invitation about the draft and is not used for a follow-up series. This data-protection basis does not replace any consent or other rule required by applicable electronic-communications law.

04 - Necessity
Necessity andProportionality

Data minimisation: collection is limited to public professional material and derived fields used for the draft and invitation. The contact address is removed with the invited operational record; a one-way identifier hash may remain in the suppression registry.

Retention: an unclaimed operational record is scheduled for deletion 21 days after the invitation is queued. First opening changes the scheduled deletion to four days from that opening; repeat visits may extend it, but not beyond seven days from the first opening. Claim, rejection or deletion ends the pre-registration flow.

Transparency: the invitation links to the private draft, identifies the public source and AI-assisted nature of the analysis, explains limitations and provides claim, correction, objection and immediate bearer-link deletion options.

05 - Risks
Identified Risksand Mitigations

Risk: a data subject is unaware that their public artifacts have been indexed. Mitigation: a public lookup endpoint allows any person to check whether they are indexed and to request erasure with a single click, without registration.

Risk: change of purpose for data published for a different reason. Mitigation: one invitation rather than a series, a private pre-claim draft, short retention, suppression after objection, no sale and no disclosure for third-party advertising.

Risk: inaccurate or unfair profiling. Mitigation: indicators are narrowly labelled, their AI-assisted and estimated nature is disclosed, the invited person can review and contest them, and the draft can be corrected, claimed or deleted. The outputs must not be treated as verified facts or the sole basis for a hiring decision.

Risk: processor access and international transfer. Mitigation: service providers receive only material needed for hosting, scanning, email or AI processing; transfer safeguards must be assessed and documented for each provider and destination before use.

Risk: draft profiles persisting indefinitely. Mitigation: scheduled operational deletion after 21 days, shortened to four-to-seven days after first opening, plus monitoring of the purge process and suppression of another invitation.

06 - Rights
Data SubjectRights

Available rights depend on applicable law and the processing involved. A request can be started without an account, although proportionate verification may be required. Where the GDPR applies, verified requests are normally answered within one month.

A recipient can immediately delete the invited operational record through the valid private bearer link. A general request made by email address or username requires confirmation or other proportionate verification.

07 - Review
Review andUpdate

This DPIA summary is reviewed at least annually and whenever there is a material change in the nature, scope, context or purposes of the processing. Updates are reflected on this page.

.