Privacy Policy
Effective: July 1, 2025 · Last updated: July 16, 2026 · SIKER Legal Framework 2025 (TalentOS / AI update)
This Privacy Policy explains how SIKER (hereinafter SIKER, we, us or our) collects, uses, discloses, transfers, retains and protects personal data in connection with our platform and related services, including Seek (career discovery and matching), TalentOS (educational talent guidance and institutional tools) and PathMaker (content and organizational operations), as well as associated websites, applications, APIs and business integrations (collectively, the Services). By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. SIKER designs and operates the Services with reference to applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (GDPR), applicable Latin American laws (including Law 25,326 of Argentina and Law 1581 of 2012 of Colombia), the CCPA/CPRA, COPPA, FERPA and other applicable privacy rules. This Policy describes practices; it does not constitute a certification of compliance.
1. Identification
Depending on the relationship (direct use versus institutional deployment), SIKER and/or the contracting educational institution may act as controller or processor. The provisional public identification of the Services operator is:
- SIKER, operator of the TalentOS, Seek and PathMaker services.
- Privacy requests email: privacy@siker.info
- Website: https://siker.info/privacy · Subprocessors: https://siker.info/subprocessors
2. Scope of Application and Products
This Privacy Policy applies to users of the Services, including:
- Individual users: students, recent graduates, job seekers, professionals in career transition, and workers who access Seek and related products.
- Families and guardians: parents or legal guardians who create or supervise accounts where that function is offered.
- Enterprise customers: businesses and organizations that access PathMaker or other enterprise features under a commercial agreement.
- Educational institutions: schools, universities, colleges and training programs that implement TalentOS and related products for student guidance and institutional services.
- Visitors: people who browse our website or marketing pages without creating an account.
Product-specific overview
Each product may process personal data according to the features contracted and used:
- Seek – May process career interests, academic background, skills, assessments and preference data to support career discovery, matching and path recommendations.
- TalentOS – May process educational and guidance data on behalf of contracting institutions (see section below). The concrete data set depends on the modules activated by each institution.
- PathMaker – May process content preferences, business goals and usage patterns to support content and organizational workflows for subscribed accounts.
2.1 TalentOS and educational data
TalentOS may process, on behalf of educational institutions and according to the functionalities contracted and used, categories such as:
- Identity and contact data
- Institution, course or group
- Activities and assessments
- Interests, skills, strengths and preferences
- Educational results and profiles
- Longitudinal evolution over time
- Objectives and agreements
- Communications or observations entered by authorized users (for example, counselors or teachers)
- Technical and usage information
3. Personal Data We Collect
3.1 Data You Provide Directly
- Account registration data: full name, email address, password (stored in protected form), date of birth where collected, country of residence and preferred language.
- Profile data: academic history, degrees, certifications, work experience, skills, career interests, goals, and uploaded documents where the feature is used.
- Assessment responses: answers to aptitude tests, questionnaires, preference surveys and competency assessments administered within the Services.
- Communications: messages, comments, support tickets and survey responses sent to SIKER.
- Payment details: billing name, address and payment method details. We use specialized payment processors and do not store full card numbers.
- Business or institutional account data: organization name, sector, size, role and authorized user data submitted during onboarding.
3.2 Automatically Collected Data
- Device and technical data: IP address, browser type and version, operating system, device identifiers, screen resolution and network information.
- Usage and interaction data: pages visited, functions used, dwell time, click paths, in-product searches, error logs and, where enabled, session diagnostics.
- Cookies and similar technologies: first-party and third-party cookies, pixel tags, local storage and other technologies described in our Cookies Policy.
- Derived insights: patterns and AI-assisted inferences about preferences or engagement derived from use of the Services, where those features are enabled.
3.3 Data Received from Third Parties
- Single sign-on providers: If you register or sign in using Google, LinkedIn, or Microsoft, we may receive your name, email address and profile photo, subject to your settings with those providers.
- Educational institutions: Enrollment status, student identifiers, program or course information, academic metrics and other data transmitted under an institutional agreement.
- Employer or enterprise partners: Organizational or role data shared under a commercial agreement for the relevant product.
- Publicly available data: Professional or labor-market information from public sources used to supplement recommendations where applicable.
4. Legal Bases for Processing (GDPR)
Where the GDPR applies, SIKER processes personal data on one or more of the following bases (Art. 6 GDPR). The applicable base depends on the relationship and product:
- Performance of a contract (Art. 6(1)(b)): creating and managing accounts, providing the Services, processing payments and fulfilling contractual obligations.
- Legitimate interests (Art. 6(1)(f)): fraud prevention, platform security, service improvement and internal analysis, where such interests are not overridden by your rights and freedoms.
- Consent (Art. 6(1)(a)): non-essential cookies and marketing communications where consent is required. You may withdraw consent at any time.
- Compliance with a legal obligation (Art. 6(1)(c)): responding to lawful authority requests, retaining accounting/tax records, and handling data-subject requests within legal deadlines.
- Vital interests (Art. 6(1)(d)): exceptional circumstances involving serious risk to the safety of a user or a third party.
If special categories of personal data under Art. 9 GDPR are processed, we rely on explicit consent or another applicable exception. TalentOS is not designed to process health or clinical diagnoses; users must not enter such data into free-text fields unless a specific contractual and legal framework allows it.
5. Purposes of Processing
- Service delivery: provide career guidance support, talent analysis for institutions, content operations and the functionality described in product documentation.
- Account management: maintain profiles, manage subscription status and enable access across products where authorized.
- AI-assisted features: generate or enrich activities, summaries, patterns and recommendations for review by authorized professionals (see sections 6 and 6.1). This does not mean that SIKER uses TalentOS student data by default to train foundation models.
- Security: detection, investigation and prevention of fraudulent or abusive activity and unauthorized access.
- Customer support: responding to queries and maintaining service continuity.
- Product analysis and improvement: aggregate or anonymized usage analysis to understand feature performance.
- Legal compliance: meeting applicable legal obligations and responding to lawful processes.
- Marketing communications: newsletters and product updates where consent or another valid basis applies, with an unsubscribe mechanism.
- Research and sector reports: anonymized or aggregate labor-market and educational trend analysis where permitted.
5.1 Roles and responsibilities (subject to legal validation)
The allocation of roles depends on the contract and applicable law. Without prejudice to a final legal determination:
- The educational institution normally determines the essential purposes and means of processing its students’ data when TalentOS is deployed for the institution.
- SIKER processes that information to provide TalentOS following the institution’s contractual instructions (typically as processor / encargado), where that model applies.
- For other processing of its own—such as billing, platform security, or management of SIKER accounts—SIKER may act with a different responsibility (for example, as controller). This distribution is not universal and must be confirmed in each agreement.
6. Artificial intelligence and human review
TalentOS may use artificial intelligence services to assist with generating activities, personalizing content, preparing summaries, identifying patterns and preparing recommendations for review by authorized professionals. Before sending information to these services, SIKER applies minimization and pseudonymization measures intended to exclude identifying data that is not necessary for the task. Providers do not receive direct access to the TalentOS database. Outputs generated by these systems are assistive in nature and must be interpreted and reviewed by authorized personnel. TalentOS does not use these outputs alone to take educational or professional decisions with legal or similarly significant effects on students. Pseudonymization does not mean the data are anonymous while a correspondence can still be established within SIKER or the institution. Additional product notes:
- Seek may use AI to match profiles with career paths, opportunities or programs. Recommendations are probabilistic and do not constitute guaranteed outcomes, certified professional advice or accredited psychological evaluations.
- TalentOS AI outputs (insights, narratives, activity drafts, recommendations) are support tools for educators and counselors. They are not diagnoses and do not by themselves determine a student’s educational or professional future.
- PathMaker may use language models to generate professional content. Users remain responsible for reviewing, editing and publishing generated content.
- Sensitive situations require human review. Authorized users may review and contextualize information before acting on it.
- Where AI systems produce results that may significantly affect you, you may request human review via privacy@siker.info. Institutional customers may also define review workflows in their DPA.
- Nothing in the Services constitutes psychological evaluation, psychiatric diagnosis, therapeutic advice or medical guidance.
- Institutional customers remain responsible for how AI-assisted outputs are used within their organization.
6.1 Anthropic (Claude commercial API)
For certain functions, SIKER may use the commercial API of Anthropic. According to the provider’s published commercial terms, inputs and outputs of its commercial services are not used by default to train its models, except with express authorization or voluntary submission of information for feedback. SIKER limits the information sent to what is necessary for the corresponding function and applies controls to avoid sending identifying data that is not required. This does not mean that Anthropic retains absolutely no data. Retention and processing by the provider are governed by Anthropic’s commercial terms and data processing terms applicable at the time of use. Anthropic may act as a technological provider or potential subprocessor for those features.
- Anthropic Privacy Policy (commercial): https://www.anthropic.com/legal/privacy
- Anthropic Commercial Terms: https://www.anthropic.com/legal/commercial-terms
- Anthropic Data Processing Addendum: https://www.anthropic.com/legal/data-processing-addendum
- Information for commercial customers (Privacy Center): https://privacy.claude.com/en/collections/10663361-commercial-customers
7. Minors and educational contexts
TalentOS is intended for educational contexts and may process data relating to minors under the instructions of the contracting institution. Applicable age thresholds and bases for processing vary by country and by the legal basis relied upon; SIKER does not establish a single universal age of consent in this Policy.
- The institution must have the corresponding authority or legal basis to use TalentOS with its students and to involve families where required.
- SIKER does not knowingly use student data from TalentOS for behavioral advertising.
- Features should respect the level of information and participation required for students and families under applicable law and institutional policy.
- Rights may be exercised through the institution or through the channel indicated by SIKER, as appropriate to the role allocation. Contact: privacy@siker.info.
8. Sharing of Personal Data
SIKER does not sell personal data. We share personal data only in the circumstances described below.
8.1 Service providers and subprocessors
SIKER may use providers for infrastructure and hosting; databases; authentication; communications; billing; analytics; AI-assisted generation; and security and monitoring. These providers receive only the information necessary to perform their service and are subject to applicable contractual conditions and protection measures. An updated list is published at https://siker.info/subprocessors. Enterprise and institutional customers may receive notice of material changes as required by their Data Processing Agreements.
8.2 Business and institutional partners
When you access the Services through an employer or educational institution, your data may be shared with that organization in accordance with the applicable agreement. In that relationship, the organization often acts as controller and is responsible for managing privacy rights in that context, subject to the contract and applicable law.
8.3 Business transfers
In the context of a merger, acquisition, reorganization, bankruptcy or sale of all or a substantial part of SIKER’s assets, personal data may be transferred to the acquirer or successor. We will provide notice as required by law before a transfer that would materially change this Privacy Policy.
8.4 Legal and safety disclosures
We may disclose personal data: (i) when required by applicable law, regulation, court order or governmental request; (ii) to enforce our Terms of Service and protect our legal rights; (iii) to protect the safety, rights or property of SIKER, our users or the public; or (iv) to detect, prevent or address fraud, security issues or technical problems.
9. International data transfers
Some providers may process information outside the European Economic Area. Where required, SIKER uses recognized mechanisms such as adequacy decisions or Standard Contractual Clauses. The specific mechanism and destination for each provider depend on the contract in force with that provider and may be confirmed upon request for institutional customers. This Policy does not claim that all transfers have already been validated in every jurisdiction, nor that personal data never leave the EEA, nor that processing always occurs in the European Union.
- Standard Contractual Clauses (SCCs) or equivalent clauses, where incorporated into provider or customer agreements.
- Adequacy decisions adopted by competent authorities, where applicable to the destination.
- Other safeguards required by applicable national laws (including in Latin America), as relevant to each transfer and the agreement in force with the provider.
Location or transfer details for each provider are described, when confirmed, at https://siker.info/subprocessors.
10. Data security
SIKER applies technical and organizational measures designed to protect personal data. These measures include, without claiming absolute security:
- Access control for authorized users and roles
- Separation of data by institution (tenant isolation) in TalentOS
- Encryption in transit
- Data minimization for AI and other processing where applicable
- Security and operational logs
- Protection of credentials and secrets
- Review and contractual controls regarding providers
In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify you and, where required, the competent supervisory authority within the timeframes required by applicable law.
11. Data retention
Personal data are retained as needed for the purposes described in this Policy. In particular, data may be kept:
- While the service is provided
- For the periods agreed with the institution or customer
- For as long as necessary for legal obligations, security, or the establishment, exercise or defense of legal claims
- Afterwards, data are deleted or anonymized in accordance with the applicable policy and contractual instructions
Specific numeric retention periods (years or months) are not published in this Policy until approved. Institutional agreements may set additional retention or deletion rules.
12. Your privacy rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right to information about how your data are processed
- Right of access
- Right to rectification
- Right to erasure (deletion), subject to legal retention requirements
- Right to restriction of processing
- Right to object
- Right to data portability, where applicable
- Right to obtain human review of decisions based solely on automated processing that produce legal or similarly significant effects, where that right applies
- Right to lodge a complaint with the competent data protection authority
- Additional rights under CCPA/CPRA or other local laws, where applicable
To exercise these rights, contact privacy@siker.info or use in-product privacy settings where available. When the school or institution is the controller, SIKER will cooperate with that institution to respond to requests. We may need to verify identity. If you reside in the EEA or another jurisdiction with a data protection authority, you may also lodge a complaint with the competent authority in your country or region.
13. Business and institutional clients
When SIKER provides Services to an enterprise customer or educational institution under a separate agreement, the following typically applies (subject to that agreement):
- The customer often acts as controller of personal data of its employees, students or end users; SIKER processes such data according to documented instructions where it acts as processor.
- The customer is responsible for providing appropriate notices to end users and ensuring its use of the Services complies with applicable law.
- Enterprise and institutional customers should execute a Data Processing Agreement (DPA) with SIKER before processing personal data of identified individuals through the Services.
- For U.S. educational institutions, FERPA allocations (for example, school official) depend on the written agreement and configuration; institutions remain responsible for their FERPA compliance.
- Audit rights, if any, are governed by the applicable DPA.
14. Cookies and tracking technologies
Please see our Cookies Policy for information about how we use cookies and similar technologies and how you can manage preferences.
See our Cookie Policy for full details and preference management.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, products or applicable law. We will notify you of material changes by posting a notice on our website and, where required by law, by email to the address associated with your account before the changes take effect. Continued use of the Services after the effective date constitutes acceptance of the updated Privacy Policy where permitted by law.
16. Contact
Data Protection Contact: SIKER Privacy Team
Related documents
Use of SIKER services is also subject to our Terms of Service. Subprocessors: https://siker.info/subprocessors
Document from the SIKER Legal Framework 2025 (Seek · TalentOS · PathMaker), updated for TalentOS educational processing and AI providers. Institutional Data Processing Agreements (DPA) are signed separately.