JobHuntix — Privacy Policy (/privacy) — DRAFT

⚠️ This is a draft for legal review, not publication-ready text. Built from what the product actually does per the documentation (Lean Canvas + PRD), not a generic template. Spots needing a lawyer’s decision or missing data are marked [NEEDS REVIEW] and [X]. Key risks that need to be closed separately with a lawyer:

  • Access to the client’s mailbox (Gmail OAuth/IMAP) and sending on their behalf — a non-standard construct that needs a proper AVV/DPA (data processing agreement).
  • Resume processing — potentially special-category data (e.g. if a resume includes a photo, nationality, health information, or organization membership).
  • The employer contact database, collected without direct consent — the legitimate interest basis (Art. 6(1)(f)) requires a documented balancing test (Interessenabwägung) and a working opt-out.
  • International data transfers, if the LLM/infrastructure sits outside the EU.

1. Who we are

[Legal entity name], [registered address], [registration number]. Contact for data protection matters: [DPO / responsible person’s email] [NEEDS REVIEW — whether a dedicated data protection officer is required under Art. 37 GDPR depends on the scale of processing].


2. What data we process

2.1. Job seeker data

  • Registration data: email, password (hashed) or Google Sign-In.
  • Resume data: name, contact details, work experience, education, skills, languages — what you upload at registration.
  • Profile data: profession, search region, preferences, company blacklist.
  • Mailbox access (Active Search plan only): [NEEDS REVIEW — exact scope: gmail.send for sending, gmail.readonly for reading replies]. We do not read or store correspondence unrelated to outreach, [NEEDS REVIEW — how feasible this separation is technically].
  • Technical data: IP address, service usage data.

2.2. Employer data

  • Company name, link to careers/jobs page, region, industry, company size (if provided at registration).
  • Job listing data collected automatically from the page the employer submitted, or from public sources (job parser).
  • General company contact details (e.g. bewerbung@firma.de) — used to receive applications, not published or shared with third parties.
  • Named staff contacts (e.g. i.ivanov@firma.de), where present in the database, are processed as third-party personal data on a legitimate interest basis — see Section 4.

2.3. Analytics

We use Plausible Analytics (self-hosted) — cookie-free analytics that doesn’t collect personal identifiers of site visitors.


3. Why we use this data

Data Purpose Legal basis
Resume, profile Analyzing and improving your resume, matching relevant vacancies and companies Contract performance (Art. 6(1)(b))
Mailbox access Sending applications to employers on your behalf, classifying replies Contract performance (Art. 6(1)(b)) + processing under a DPA
Employer contact database Building the database used for outreach Legitimate interest (Art. 6(1)(f)) [NEEDS: documented balancing test]
Technical/billing data Subscription payment, support, security Contract performance, legitimate interest
Analytics (Plausible) Understanding how the site is used, without identifying the user Legitimate interest (Art. 6(1)(f)), cookie-free — consent not required [NEEDS REVIEW against current practice]

4. Employers: legal basis and right to opt out

We process publicly available business contact details of employers on a legitimate interest basis — to help job seekers reach potential employers (Initiativbewerbung, an unsolicited job application).

  • We never publish or share employer email addresses in the interface, in exports, or directly with job seekers — job seekers only see the company name and reply status.
  • An employer can request removal of their company from the database at any time via the employer page form or by email at [X]. Removal requests are processed within [X] and are irreversible — the company will not be re-added to the database automatically.
  • We honor explicit opt-out markers against unsolicited applications (e.g. a corresponding note in a company’s robots.txt), where an employer has set one [NEEDS REVIEW — how this is implemented technically and how legally significant it is].

5. Data retention and deletion

  • Resume and profile data is stored for as long as your account is active.
  • When you delete your account, data is deleted within [X] [NEEDS: the actual process and timeframe].
  • Inactive accounts are automatically deleted after 24 months.
  • Data is encrypted at rest.

6. Who we share data with

  • Infrastructure and processing providers (hosting, database) — [X, list providers].
  • Payment providers — [Stripe / PayPal — confirm final provider].
  • AI models used for resume analysis and reply classification — [X, list LLM providers and whether they’re based outside the EU].
  • We do not sell user data to third parties or use it for advertising.

Staff members with access to client data are listed in the data processing agreement (AVV/DPA) attached to the terms of service [NEEDS: current list of roles/staff with access].


7. Your rights

You can request access to your data, correction, deletion, restriction of processing, or data portability — write to [email] or use your account settings. You also have the right to file a complaint with a data protection supervisory authority.


8. International data transfers

[NEEDS REVIEW] If data is processed outside the EU/EEA (e.g. infrastructure or an AI provider based in the US), a transfer safeguard (Standard Contractual Clauses, etc.) must be specified — this section cannot be published without it.


9. Changes to this policy

We may update this policy. The last updated date is shown at the top of the page. We’ll notify you by email of any material changes.


What needs to be closed before publishing (summary)

  1. Legal entity, address, responsible person / DPO.
  2. Exact scope of mailbox access (which Gmail permissions are actually requested).
  3. List of infrastructure, payment, and LLM providers — and where they’re physically located.
  4. Mechanism and timeframe for deleting data on request.
  5. Documented legitimate interest justification for the employer database (Interessenabwägung) — a separate document this policy should reference.
  6. Final review of the full text by a GDPR lawyer, including the wording around the DPA for sending on the client’s behalf.