GDPR
How TheirStack complies with the GDPR — our lawful basis for processing personal data, what personal data our dataset actually contains, why we consider the balance justified, and the safeguards we apply.
Most of what TheirStack publishes is information about companies, not people. But job postings are written by people, and sometimes they name one — a hiring manager, a recruiter, a team lead. Where that happens we are processing personal data, and the GDPR requires us to have a lawful basis for it.
This page explains that basis, what personal data is involved, and the principles that govern how we handle it.
Disclaimer: This page describes our compliance practices but does not constitute legal advice. For specific legal questions about your use case, please consult your own counsel.
Our lawful basis: legitimate interests
We process this personal data under legitimate interests, Article 6(1)(f) GDPR. We do not rely on consent, and we do not ask individuals for permission — the data is already published by their employer on a public page, and consent would be neither meaningful nor obtainable at the scale of a public job market.
Relying on legitimate interests is not a free pass. It requires that our interest is not overridden by the rights and freedoms of the people whose data we process. We have assessed that question in writing and keep the assessment on record, as GDPR accountability requires. Customers and partners who need to review it can request it here.
What personal data is involved
Only a narrow slice of our data is personal data at all. The rest is company-level information (industry, size, technologies, hiring volume) and job-level information (title, location, salary band, description, employment type). Personal data enters the dataset only in these forms:
- Names and job titles of company representatives named in a public job posting or careers page.
- Public professional profile URLs (such as LinkedIn) where the source page shows them.
- Incidental mentions of individuals inside the free text of a job description.
We do not collect or store individual email addresses, phone numbers, home addresses, or any special category data. We do not build profiles of individuals, do not track people across sources, and do not make automated decisions about anyone.
The interest we pursue
We build an accurate, current picture of what companies are building, buying and hiring for, derived from the recruitment material those companies publish themselves. Our customers use it for market and competitive research, technology adoption analysis, account and territory planning, recruitment benchmarking, and finding companies whose stated needs match what they offer.
Aggregating publicly published business information for market intelligence is an established commercial activity, and Recital 47 GDPR expressly contemplates commercial interests as capable of being legitimate. The processing here is narrower than direct marketing: we describe organisations, not individuals.
Why we consider it balanced
- The data is professional, published by the employer. A job posting exists to be seen, indexed and amplified. A person named on a public vacancy would reasonably expect that posting to be read and analysed.
- The sensitivity is low. Names and roles in a recruitment context. No special category data, no financial data, no data about private life.
- The impact is minimal. We do not contact individuals, do not market to them, do not score or rank them, and do not hold data that would let anyone reach them directly.
- The riskiest fields are excluded by design. Personal emails and phone numbers are the fields most likely to cause harm or annoyance in a commercial dataset. We do not store them — a deliberate limitation, not a gap in coverage.
The safeguards we apply
- Public sources only — we collect only what is publicly displayed, without authentication or paywall. We never log in, never use credentials, and never bypass authentication, paywalls, CAPTCHAs or other access controls. If a page is gated, we leave it alone. See Data Collection.
- No personal contact data — no individual emails, phone numbers or home addresses.
- No person-level profiling — no cross-source identity resolution, no person records, no automated decision-making about individuals.
- Data minimization — we collect only the fields necessary to describe a job opportunity or a company's hiring activity, and avoid personal information that is not pertinent to the posting.
- Retention tied to the source — postings expire when the publisher removes them, so our datasets reflect what is currently public rather than accumulating indefinitely.
- Data security — we apply appropriate technical and organisational measures to protect the data we hold from unauthorised access, loss and disclosure. See our Data Processing Agreement for the detail.
- Individual rights — we respect the rights the GDPR grants individuals, including the right to object to this processing. See Data Collection.
Further reading
How is this guide?
Last updated on
