What Marple does with personal data, written in the order a reader usually wants it: who we are, which data is whose, where it is processed, and what you can ask us to do with it.
Marple is a recruitment platform operated by Letzbytes, in Luxembourg. We are the people you are dealing with, and hello@letzbytes.lu reaches us.
This is the distinction everything else follows from. Data about the people who use Marple, meaning our customers and the colleagues they invite, is data we decide about: we hold their name, their work email and the record of what they did in the product, and we are the controller of it. Data about candidates, clients and contacts inside a customer's workspace belongs to that customer. They decide what goes in, why it is there and how long it stays; we process it on their instructions and for no purpose of our own. We do not sell it, we do not use it to train models, and we do not move it between customers. If you are a candidate and want to know why an agency holds your details, that agency is the one who can answer, and we will help you reach them.
From a customer: the account details of each person on the team, the workspace they build in the product, and a record of significant actions taken in it. From the candidates, clients and contacts a customer works with: whatever that customer chooses to record, which in practice is contact details, a CV, a work history, notes, and the emails exchanged through a connected mailbox. From someone who applies through a customer's careers site: the details on the application form and the CV attached to it. From a visitor to this site: the details typed into the demo form, which we use to arrange that demo and for nothing else.
Inside the European Union. The application, the database, the search index and the file storage run on European infrastructure, and backups stay there. The models Marple uses to read, rank and draft run in a European region of Amazon Bedrock, so a CV is not sent outside the EU to be read. Payments are taken through Stripe, which is the one place a transfer outside the EU happens, and it carries no candidate data.
Marple has an optional extension that a recruiter installs in their own browser. It is worth describing precisely, because it works inside a session that already belongs to them. It reads a LinkedIn page only when the recruiter asks it to, in the LinkedIn session they are already signed into, and sends what it reads to their own Marple workspace. It reads LinkedIn's own cookie in the browser in order to make that request as them, and that cookie is never transmitted anywhere: it does not reach our servers, and it is not stored. Our servers never contact LinkedIn. The extension holds a token identifying the browser it is paired with, and nothing else. It does not read your browsing, it does not run on any other site, and it does nothing when you are not asking it to.
Marple suggests and a person decides. Nothing generated moves a candidate through a pipeline, rejects an application or sends a message on its own; every suggestion waits for someone to accept, edit or throw it away, and the record shows who did. Where a model's job is to rank or compare people, it is given what someone can do rather than who they are, so a ranking cannot turn on a name. Where a model's job is to read one document or draft one message, it necessarily sees that document. Generated passages are labelled as generated wherever they appear. We keep a short record of these exchanges so we can tell whether the product is working, and that record is deleted after thirty days. Recruitment is a high-risk use of AI under the EU AI Act, and the product is built for that rather than adapted to it.
Customer workspace data stays for as long as the customer keeps it, because that is their decision rather than ours. When a customer leaves, their workspace is deleted. Records of AI exchanges are deleted after thirty days. A CV uploaded to a form and never submitted is deleted within a day, because a file nobody finished sending should not outlive the attempt. Anything we hold to meet an accounting or legal obligation is kept for as long as that obligation runs and no longer.
We use a small number of suppliers, each for one job: European cloud hosting for the application and its data, Amazon Bedrock in a European region for the models, an email provider for the messages the product sends, and Stripe for payments. Each one is bound by a written agreement, processes only what its job needs, and is not permitted to use anything for its own purposes. We will tell you who they are, in writing, if you ask.
You can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, and object to processing we base on a legitimate interest. Where we are the controller, write to us and we will answer within a month. Where the data sits in a customer's workspace, that customer is the controller and we will pass your request to them and help them act on it. You can also complain to the Commission Nationale pour la Protection des Données in Luxembourg, or to the authority where you live.
The application sets a session cookie so that signing in works, and remembers the language you chose. That is the whole list. These public pages carry no advertising cookies, no analytics that follow you elsewhere, and no third-party trackers.
When the product changes in a way that changes this page, we change this page, and the review date at the top moves with it. If a change is significant for customers, we tell them rather than leaving them to notice.
Write to us at hello@letzbytes.lu and we will answer. If you are a candidate rather than a customer, say which organisation you dealt with, so we can point your request to the right place.