Legal
Privacy Policy
Last updated: March 17, 2025 · Effective for all AI Jobr users.
AI Jobr is committed to protecting your personal data. This policy explains what we collect, how we use it, and your rights.
1. Controller and Contact
The controller responsible for processing personal data on this platform is the operator listed in our Imprint. Contact: privacy@aijobr.com.
2. Personal Data We Collect
Candidate data: email, name, password hash, resume/CV (if uploaded), work history, skills, and job preferences.
Company/employer data: company name, email, contact details, and job listings posted.
Usage data: Jobs viewed, applications submitted, search queries, and session data — to personalize your experience.
Technical data: IP addresses, browser type, OS, and access logs for security and operations.
Payment data: Billing details processed by our payment provider for employer subscription plans.
Communication data: Messages you send via email or the contact form.
3. Legal Basis for Processing
Contract performance (Art. 6(1)(b) GDPR): Account management, job applications, and employer job posting services.
Legitimate interests (Art. 6(1)(f) GDPR): Security, fraud prevention, platform improvement, and recommended job matching.
Consent (Art. 6(1)(a) GDPR): Email job alerts, marketing newsletters. Withdraw consent anytime.
Legal obligation (Art. 6(1)(c) GDPR): Billing records retained as required by law.
4. Special Categories of Data
You may choose to include information in your profile or CV that falls into special categories (e.g. disability status for accessibility requests). We process this data only based on your explicit consent and only to the extent necessary for the purpose you provide it.
5. Third-Party Services
Payment Processing: Employer subscriptions handled by a PCI-DSS-certified provider.
Email Delivery: Transactional and alert emails via a third-party email service.
Hosting & Infrastructure: Cloud infrastructure within or outside the EU.
All processors are bound by GDPR-compliant data processing agreements (Art. 28 GDPR).
6. International Data Transfers
Where data is transferred outside the EEA, we ensure adequate protection through Standard Contractual Clauses (SCCs) or other Art. 46 GDPR safeguards.
8. Data Retention
Candidate profiles: Retained while account is active; deleted within 30 days of deletion request.
Job listings: Active listings retained while employer account is active; expired listings retained for 12 months for audit purposes.
Applications: Retained for 6 months after application decision or account closure.
Billing records: 7–10 years as required by law.
Technical logs: 90 days.
9. Your Rights Under GDPR
EEA residents have rights to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), and withdrawal of consent (Art. 7(3)).
Contact privacy@aijobr.com. We respond within 30 days. You may also complain to your national supervisory authority.
10. Security
We use TLS/SSL encryption in transit, bcrypt password hashing, role-based access controls, and regular security audits to protect your data.
11. Children's Privacy
The Service is not directed to individuals under 16. We do not knowingly collect data from minors.
12. Changes
Material changes to this policy will be communicated by email or prominent website notice. Continued use after changes constitutes acceptance.
13. Contact
Privacy inquiries: privacy@aijobr.com. Full contact details in our Imprint.