Privacy policy
Version 1.1 · In force from 2 October 2026
This policy explains what personal data Navigent processes, why, for how long, and what rights you have. It has a part for each of the ways you may meet us:
- You visit navigent.io: see section 2.
- You use Navigent in your work: see section 3.
- A business using Navigent has found you as a candidate: see section 4.
1. Who we are and the roles we play
Navigent.io ApS, CVR 46285395, Nørre Voldgade 70, 4., 1358 København K, Denmark. E-mail: info@navigent.io.
We have two roles:
- We are the controller of data about visitors to navigent.io, about our users and customers, and about demo requests. We are also the controller of the requests to be removed from Navigent, made through the page navigent.io/en/remove-me, and of the suppression list.
- We are a processor of candidate data. The business that finds a candidate through Navigent is the controller of that candidate's data, and we process it on the business's behalf under a data processing agreement.
2. When you visit navigent.io
2.1 Operation and security
When you visit navigent.io, our hosting provider, Vercel, processes your IP address and technical details of the request, such as the page address, the time and your browser. This is done to serve the site and protect it from misuse. The basis is our legitimate interest in running a secure website (Article 6(1)(f) of the GDPR). The data is kept in Vercel's logs for as long as operation and security require.
2.2 Visitor statistics
If you say yes in the cookie banner, we measure visits with Vercel Web Analytics. It sets no cookies and uses no identifier that follows you across websites. We see only aggregate figures, such as which pages are viewed, which page a visit came from, country, device type, browser and operating system. If you say no, your visit is not measured. The basis is your consent (Article 6(1)(a)), which you can withdraw at any time under "Cookie settings" at the bottom of every page; see the cookie policy.
2.3 Demo requests
If you book a demo at navigent.io/en/demo, we receive your name, your work e-mail, your company and what you write about the role you are recruiting for. The form sends this as an e-mail to info@navigent.io and a confirmation to you, and we use it only to reply to you and hold the demo. We send you nothing else, and your address is not added to any list. The basis is our legitimate interest in answering your enquiry (Article 6(1)(f)). The request is kept for 12 months in the info@navigent.io mailbox. If you become a customer, section 3 applies.
2.4 The requirements profile tool
The tool at navigent.io/en/requirements-profile turns a job ad you paste into a requirements profile, without you signing up. The text is sent to our AI provider, which produces the profile, and we store neither the text, the profile nor your IP address. Paste only the job ad itself and no other personal data. The basis is our legitimate interest in offering the tool (Article 6(1)(f)).
2.5 Protecting the forms
The demo form, the early-access sign-up, the "Remove me from Navigent" page and the requirements profile tool limit how many requests can be sent from one IP address, for example ten requirements profiles an hour. The IP address is held only in the memory of the part of the system that counts the requests, and it is not stored. The basis is our legitimate interest in protecting the forms from misuse (Article 6(1)(f)).
2.6 When you sign up to get access when we open
If you sign up under "Get access when we open", we receive your name, your work e-mail and your company. We use them only to let you know when Navigent opens.
- Basis: your consent (Article 6(1)(a)). You can withdraw it at any time by writing to info@navigent.io, and we then delete your details.
- Where: the form sends them as an e-mail to info@navigent.io and a confirmation to you, and they are kept only in the info@navigent.io mailbox, from which we write to you when Navigent opens.
- How long: until 12 months after Navigent opens, or until you ask us to delete them.
2.7 When you write to us
If you write to info@navigent.io, we use your name, your e-mail address and what you write to reply to you. The basis is our legitimate interest in answering enquiries (Article 6(1)(f)) or, if you are a customer, our agreement. We keep the correspondence for as long as we need to answer your enquiry and follow up on it. If you write to us as a candidate and want to be removed, we send you the link to navigent.io/en/remove-me. For anything else about your data, please ask the business that contacted you, because it is the controller.
3. When you use Navigent
Here we are the controller of your account data. Section 3.4 describes the data about you that your employer is the controller of.
3.1 What data we process
- Account: your name, e-mail address, language, your role in the organisation (owner, admin or member) and the workspaces you can access. If you sign in with Google, we receive what Google shares: your name, e-mail address and profile picture.
- Getting started: the role that best describes you, such as agency recruiter, and where you heard about us, if you answer.
- Sign-in and security: when and how you sign in, and technical details such as your IP address. Invitation links and Chrome extension tokens are stored only as hashes.
- Invitations: the e-mail address you were invited with, and who invited you.
- Connected accounts: the name and type of your LinkedIn account or mailbox, and its state, such as whether it needs reconnecting or LinkedIn has restricted it.
- Settings: your choice of e-mails and notifications, and whether you have closed "Get started" or an announcement.
- Usage: which parts of the service you use, such as a search being started or a candidate being assessed. This is recorded by our own servers with your user ID. The app contains no third-party analytics tools.
- Billing, for owners: the company's name, country, VAT number and billing address, the billing contact, and the payment history. Card details are handled by Stripe, and we never see the full card number.
- Support: what you write to us and, if our support staff have had access to your organisation's data, a log of who had access, when and why.
- Acceptance: which version of the terms and the data processing agreement you accepted, and when.
3.2 Why, and on what basis
| Purpose | Basis |
|---|---|
| Creating and running your account and providing the service to the organisation you use it for | Our legitimate interest in providing the service the organisation has bought (Article 6(1)(f)). If you are the customer yourself, for example as a sole trader, our agreement (Article 6(1)(b)) |
| Sending e-mails the service cannot do without, such as sign-in links, invitations and payment notices | As above |
| Sending e-mails you can turn off, such as "Search ready" and "New reply" | Our legitimate interest in keeping you informed (Article 6(1)(f)). You turn them off in Settings or with the link in the e-mail |
| Security, preventing misuse, and logging support access | Our legitimate interest in a secure service (Article 6(1)(f)) |
| Billing and bookkeeping | Our legitimate interest in being paid (Article 6(1)(f)) and the Danish Bookkeeping Act (Article 6(1)(c)) |
| Improving the service from usage data | Our legitimate interest in developing the service (Article 6(1)(f)) |
| Documenting what was agreed | Our legitimate interest in being able to document the agreement (Article 6(1)(f)) |
3.3 For how long
- Account, sign-in and settings: for as long as you are a user and the organisation exists. The data is deleted 30 days after your account or the organisation is deleted.
- Expired invitations: deleted 30 days after they expire.
- Usage data: kept, but when your account is deleted, the link to you is removed and only counts remain.
- Notifications in the app: 90 days.
- Acceptance of the terms and the data processing agreement: 5 years after the organisation is deleted.
- Invoices and accounting records: 5 years from the end of the financial year they relate to, as the Danish Bookkeeping Act requires.
- Log of support access: 2 years.
- Support correspondence: for as long as we need to resolve the matter and follow up on it.
3.4 When your employer is the controller
Some of what you do in Navigent is part of your employer's data: the roles you own, your decisions about candidates, your notes and @mentions, the messages you send from your connected accounts, the activity feed, your CSV exports and the statistics per team member. Here your employer is the controller and we are the processor under the data processing agreement. Please direct questions about that processing to your employer.
4. If you are a candidate
4.1 Why does Navigent have data about me?
Navigent is a tool that businesses and recruitment agencies use to find candidates for specific roles. If one of our customers has searched for profiles like yours, your data may have been fetched into that customer's workspace in Navigent.
We do not sell your data, use it for advertising or share it between customers. If two customers have found you, each has its own separate record.
4.2 Who is the controller?
The customer that found you is the controller of your data, and Navigent is the processor. If you have been contacted through Navigent, the controller is the business that contacted you.
The customer has a duty to inform you about its processing. This section describes what Navigent does on the customer's behalf and how you can use your rights, but it does not replace the customer's own information. To find out what is held about you, to have something corrected or to object, ask the business that contacted you; see section 4.11. To be removed from Navigent across all customers, use the "Remove me from Navigent" page; see section 4.8.
4.3 Where does the data come from?
- Prospeo, a database of professional profiles, each with a link to the person's LinkedIn profile. This is where your profile comes from when a search fetches candidates. Your e-mail address also comes from here, but it is looked up only when an active campaign has reached the step where you are to receive an e-mail, and never in advance or by hand.
- Your LinkedIn profile, through Bright Data: your profile photo and your "About" text, only if you have passed the role's filters, and the photo only if the customer has turned photos on.
- Your LinkedIn profile, through the customer's own LinkedIn account: your full profile, such as education, skills and languages, once the customer has said yes to you.
- The Chrome extension: your profile, when a recruiter has it open on LinkedIn and clicks the extension.
- MillionVerifier: whether your e-mail address works, before the first e-mail is sent.
- You: your replies to messages.
- The customer: the recruiter's assessments, decisions and notes about you.
4.4 What data?
- Profile: name, headline, current title and employer, city, region and country, career history with titles, employers and periods, LinkedIn URL, and an ID from Prospeo.
- Photo and "About" text, if they have been fetched.
- Full profile, if it has been fetched: education, skills, languages, certifications and descriptions of positions.
- E-mail address, if it has been looked up, and whether it has been verified.
- Derived data, such as career length, average tenure, promotions, types of employer and distance to the role's location.
- Assessments: how well the profile fits the role's requirements, with reasons citing the positions in your career history they rest on.
- The customer's decisions and notes.
- Messages: invitations, messages and e-mails to you, your replies, and whether a reply is labelled interested, not interested or auto-reply.
- That you do not want to be contacted, if you have told the customer so.
We do not process your phone number, and the service does not ask for sensitive data.
4.5 How AI is used
Navigent uses AI to read the requirements in a job ad, rank candidates, write assessments and label replies. The model that ranks and assesses candidates does not see your name, e-mail address or phone number, and the ranking does not use sex, age, ethnic origin, health, religion or trade union membership. Photos are never sent to an AI model.
AI makes no decisions about you. A recruiter says yes or no to each candidate, and nobody is contacted without a yes. No decision about you is based solely on automated processing. Each assessment is logged so that it can be checked; section 4.7 says for how long.
If you reply to a message, AI labels your reply as interested, not interested or auto-reply. The label only sorts the recruiter's inbox; it neither stops nor removes anything.
4.6 If you are contacted
If the customer has said yes to you, you may be contacted from the recruiter's own LinkedIn account or e-mail, with an invitation, messages and possibly an e-mail. The messages carry no open or click tracking. If you reply, the automatic follow-ups stop. If you reply that you do not want to be contacted, you are automatically added to that customer's list of people not to be contacted. To be removed from Navigent across all customers, use navigent.io/en/remove-me.
4.7 How long is the data kept?
- If you are not on a shortlist for an active role, you are deleted 90 days after you were last fetched.
- If the customer has said yes to you, you are kept for as long as the role is active, including once you have been contacted, have replied or have been hired. When the role is closed, you are deleted 90 days later, unless you are held for another role.
- If the customer has marked you as hired for a role, you are kept after the role is closed for as long as the customer has chosen, as a record of the hire: at most 24 months, and 12 months unless the customer has chosen otherwise.
- Your photo is deleted with you, and so are assessments, decisions, notes and messages.
- The AI log is kept for 6 months. If you are deleted earlier, the link to you is removed and the free-text reasoning is deleted. What remains is a pseudonym and the assessment itself until the 6 months have passed, because the AI Act requires the logging of a high-risk AI system to be documented. This also applies when you ask to be removed yourself.
- If you are on a customer's list of people not to be contacted, you stay on it until the customer removes you, so that the customer can respect your wish.
- If the customer has exported data about you from Navigent, that data is outside Navigent and the customer is responsible for it.
4.8 Remove me from Navigent
At navigent.io/en/remove-me you can ask to be removed from Navigent. You are removed across all of Navigent's customers at once, even if you do not know which customers have found you. The customers have given us a standing instruction to do this in the data processing agreement.
How it works:
- You give the link to your LinkedIn profile and an e-mail address.
- We send an e-mail with a link that is valid for 24 hours. Nothing happens until you click it, and a request that is not confirmed is deleted after 7 days.
- Once you have confirmed, we delete you at once across all customers: the candidates matching your LinkedIn URL, and your e-mail address if it has been looked up, are deleted with their photo, assessments, decisions, notes and messages. The AI log is pseudonymised as described in section 4.7.
- Your LinkedIn URL, e-mail address and ID at Prospeo go on the suppression list, so that you are never fetched, assessed or contacted through Navigent again. The page tells you when it is done.
- We forward your LinkedIn URL to Prospeo, where the data comes from.
The page offers removal only. It does not tell you what is held about you or which customers have found you, and the customers are not told about the removal. Your other rights rest with the customers; see section 4.11.
4.9 The suppression list
The suppression list is Navigent's own, and we are its controller. It contains neither your name nor any other readable data, only hashes of your LinkedIn URL, e-mail address and ID at Prospeo, computed with a secret key so that they cannot be read back into a name. When a customer fetches candidates, we compare them with the list, and a match is dropped before it is stored. If a recruiter opens your profile with the Chrome extension, we compare before anything else happens, and you are neither stored nor assessed. When a message is about to be sent, we compare again, and a message to a person on the list is stopped. The list applies to all customers.
The hashes make it possible to recognise the same details if we meet them again, so we treat them as personal data. The basis is our legitimate interest in having a removal apply across the whole service rather than at one customer only (Article 6(1)(f)). The list is permanent. Only if it is shown that someone other than you had you removed do we remove the entries again, and you can then be found by a new search.
4.10 Removal requests
A removal request holds your LinkedIn URL, your e-mail address, the times of the request and the confirmation, how many candidates were deleted, and when we forwarded it to Prospeo. A completed request is kept for 3 years as the record that the removal was carried out. A request that is not confirmed is deleted after 7 days. The basis is our legitimate interest in being able to document and uphold the removal (Article 6(1)(f)). When a request is deleted, the suppression list entries remain.
4.11 Your other rights
Everything else about your data rests with the business that found you, because it is the controller: access, rectification, objection, and deletion at that business. Contact the business that contacted you. It can answer with the tools Navigent provides: everything it holds about you is on your candidate card and in its full export, it can delete you, and it can add you to its list of people not to be contacted. If you write to Navigent about anything other than removal, we refer you to that business.
5. The Chrome extension
The Chrome extension has a single purpose: to show a recruiter Navigent's assessment of the LinkedIn profile they are viewing, against one of their own roles, and to let them add that candidate to one of their Navigent campaigns. The assessment is shown in Chrome's side panel.
The extension reads only the profile that is open, and only when the recruiter clicks the Navigent icon or uses its shortcut. It never navigates, scrolls, clicks or sends anything on LinkedIn on the recruiter's behalf. Campaign messages are sent by Navigent from the recruiter's connected account, on the campaign's schedule. It never reads search results, lists, or pages in LinkedIn Recruiter or Sales Navigator.
When the recruiter clicks, the extension reads what is on the profile: name, headline, location, current title and employer, experience with titles, employers, periods and descriptions, education, skills, languages, certifications, the "About" text and the profile's address. The data is sent to Navigent, and the business the recruiter works for is its controller. A candidate added this way follows the same retention and deletion rules as everyone else; see section 4.7.
Before anything else happens, Navigent compares the profile with the suppression list. If the person is on it, nothing is stored or assessed, nothing is sent to an AI model, and the recruiter is told only that the person has asked not to be contacted through Navigent.
The extension does not read contact details, phone numbers, e-mail addresses, connections, recommendations, activity, posts, messages, anything behind another click, or the profile photo. It does not collect health information, financial or payment information, personal communications, location, web history or user activity. The data is not sold to third parties, not used or transferred for purposes unrelated to the extension's purpose, and not used to determine creditworthiness or for lending.
On the device, the extension stores only the recruiter's sign-in token and last chosen role. Navigent stores the token as a hash; it lasts 180 days, can be revoked under Settings → Chrome extension, and is revoked when the recruiter signs out in the extension.
The extension asks only for the permissions it needs: to read the active tab and run the one function that reads the profile when the recruiter clicks, to show the assessment in the side panel, to store the token and role on the device, and to talk to Navigent's own server and no other. It has no standing access to LinkedIn and loads no remote code.
6. Cookies
The app at app.navigent.io uses only necessary cookies: for sign-in, language and theme. The site navigent.io sets no cookies. It keeps three small values in your browser, which disappear when you close the tab, and your choice in the cookie banner, which lasts 12 months. Visits are measured only if you say yes in the banner, and without cookies. Read more in the cookie policy.
7. Providers, recipients and transfers
We use providers for hosting, the database, e-mail, payments, AI and the other parts of the service. They are listed with their purpose, the data, the location and the transfer mechanism at navigent.io/en/sub-processors, and they process data only on our instructions.
Beyond that, we disclose data only:
- to Prospeo, when we forward a removal;
- to authorities, when the law requires it;
- to our advisers, such as auditors and lawyers, who are bound by confidentiality;
- to a buyer, if Navigent's business is transferred, under the same rules.
The service's database and files are in the EU (Frankfurt). If a provider processes data outside the EU/EEA, it does so only with a valid transfer mechanism, such as an adequacy decision or the European Commission's standard contractual clauses. Write to info@navigent.io for the mechanism for a given provider.
8. Security
We protect the data with measures including:
- separation of customers in the database, tested with every new version of the code;
- sign-in without passwords, with Google or a link sent by e-mail;
- encryption of the data, both in transit and at rest;
- no access for our staff to candidate data without a justified, time-limited grant that is logged and visible to the customer's owners;
- logs and error reports without personal data;
- photos in private storage, shown through links that expire quickly;
- daily backups.
Annex B to the data processing agreement describes the measures in detail.
9. Your rights
Under the GDPR you have the right:
- to access the data processed about you;
- to have inaccurate data corrected;
- to have data erased;
- to have processing restricted;
- to receive your data in a common, machine-readable format (data portability);
- to object to processing based on legitimate interests, and always to direct marketing;
- to withdraw consent, without affecting processing that took place before;
- not to be subject to a decision based solely on automated processing. Navigent makes no such decisions.
These rights may be subject to limitations. Where we are a processor, the customer that is the controller answers and we help; as a candidate you can also ask to be removed from Navigent at navigent.io/en/remove-me. In every other case, write to info@navigent.io. We answer within one month.
10. Complaints
You can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, www.datatilsynet.dk, or to the supervisory authority in the EU country where you live or work. You are also welcome to write to us first at info@navigent.io.
11. Changes and language
We update this policy when the service or the rules change. The version and date are shown at the top, and users are told about material changes. The policy exists in Danish and English. If the versions differ, the Danish version prevails.
Version 1.1 changes only sections 2.5 and 2.6: early-access sign-ups are sent as an e-mail to info@navigent.io and kept in that mailbox. In version 1.0, in force from 1 October 2026, they were kept in the database behind the site's editing system, at Supabase in Frankfurt.
12. Contact
Navigent.io ApS · CVR 46285395 · Nørre Voldgade 70, 4., 1358 København K, Denmark · info@navigent.io