Under Article 6(1)(f) of the GDPR, processing is lawful where it is necessary for the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. The three-step test is purpose, necessity and balancing. This page documents how we apply that test.
Our legitimate interest is to operate a discovery tool that helps developers showcase their own publicly published professional work, and to help employers discover such public portfolios. We invite developers to claim their auto-generated public portfolio built from their public work. This is a recognised commercial and societal interest: improving labour market matching while respecting authorship and attribution of public artifacts.
Third-party interests served: employers seeking technical talent, the open-source ecosystem (more visibility and attribution for contributors), and the data subjects themselves, who receive a self-service portfolio they can claim, edit, hide or permanently delete.
Limited indexing of public artifacts allows a draft to reflect work already published by its author. Less intrusive alternatives include asking the person to create a profile first; we use the public-artifact approach only where the expected benefit, limited access and short retention can justify the additional privacy impact.
We minimise data by limiting the draft to public professional content and metadata needed to describe projects, skills and technical activity. We do not intentionally collect special-category data, private repositories, private communications or leaked data.
Reasonable expectations vary. Public professional work may be read and discussed by third parties, but an author may not expect a separate service to assemble a draft profile, infer technical indicators or contact them. We treat that unexpected use as a material privacy impact rather than assuming that public availability equals consent.
Nature of the data: primarily public professional data, but an email address, location inference, code-authorship estimate or combined profile may still be sensitive in context. We do not intentionally process special-category data or private communications for this flow.
Potential impact: AI-generated descriptions, skill indicators, matching signals and authorship estimates may be inaccurate or perceived as an evaluation. They are shown to the invited person through a private link before claim, are contestable and deletable, and are not used by Alion to make a decision with legal or similarly significant effects.
Safeguards: one invitation rather than a series; review and immediate deletion through the private bearer link; confirmation for general requests; deletion scheduled 21 days after queueing, shortened to four days after first opening with a maximum of seven days from that opening; suppression against another invitation; no sale of indexed data; and no disclosure for third-party advertising.
Conclusion: we consider the limited processing capable of relying on legitimate interest only while these safeguards, data minimisation and jurisdiction-specific communication rules are maintained. The assessment must be revisited if access, scoring, recipients, purposes or retention materially change.
The communication informs the author about the draft and offers review, claim, correction, objection and deletion options. We do not send a follow-up marketing series to the public address. The label used internally does not determine its legal classification: where electronic-communications law treats the invitation as direct marketing, its additional rules still apply.
Under Article 21 of the GDPR you may object at any time to processing based on legitimate interest. In this invitation flow, using the private deletion link immediately removes the invited operational record and adds a one-way identifier hash to the suppression registry. A general request submitted by email address or username requires confirmation or proportionate verification before we act.