Privacy Policy
Not yet published
On this page
- 1.Who We Are
- 2.Personal Data We Collect
- 3.How We Use Your Personal Data
- 4.CVs and Job Applications
- 5.Sharing Your Data and Who Receives It
- 6.International Data Transfers
- 7.How Long We Keep Your Data
- 8.Your Rights
- 9.Cookies and Similar Technologies
- 10.How We Protect Your Data
- 11.Automated Decision-Making
- 12.Changes to This Policy
- 13.Contact and Complaints
1.Who We Are
Awaiting legal text
AWAITING LEGAL TEXT — this section must identify the data controller: the registered legal entity name, company registration number, registered address in Cyprus, and VAT number where applicable. It must give a contact address for data protection enquiries, and name a Data Protection Officer or a designated contact point if one is appointed.
2.Personal Data We Collect
Awaiting legal text
AWAITING LEGAL TEXT — this section must list every category of personal data the platform collects, how it is obtained, and whether providing it is required. At minimum it needs to cover:
- account data: name, email address, hashed password, account role, email verification status
- candidate profile data: contact details, location, work history, education, skills, salary expectations
- uploaded CV files and everything a candidate chooses to put inside them
- employer and company profile data, including company details and billing contacts
- application data: applications submitted, cover letters, application status and employer notes
- payment data processed through our payment provider (we do not store card numbers)
- technical data: IP address, device and browser information, and server logs
- job alert preferences, saved jobs and saved searches
3.How We Use Your Personal Data
Awaiting legal text
AWAITING LEGAL TEXT — this section must state each purpose for which we process personal data and the legal basis for it under Article 6 GDPR (contract, legitimate interests, consent or legal obligation). The purposes to cover include creating and running accounts, publishing job listings, delivering applications to employers, sending job alerts and service emails, taking payment, preventing fraud and abuse, providing support, and meeting legal obligations. It must also explain how we handle special-category data that a candidate may volunteer inside a CV (Article 9 GDPR).
4.CVs and Job Applications
Awaiting legal text
AWAITING LEGAL TEXT — this section must explain what happens to a candidate's CV and application data: which employers can see it and when, what an employer receives when an application is submitted, how long employers keep access, whether a profile is discoverable by employers who have not received an application, and how a candidate withdraws an application or deletes a CV. It must be clear that once an application is sent, the employer becomes an independent controller of that data.
6.International Data Transfers
Awaiting legal text
AWAITING LEGAL TEXT — this section must state whether personal data leaves the European Economic Area, name the destination countries and recipients, and set out the safeguard relied on for each transfer (adequacy decision, Standard Contractual Clauses or another Chapter V GDPR mechanism), plus how to obtain a copy of those safeguards.
7.How Long We Keep Your Data
Awaiting legal text
AWAITING LEGAL TEXT — this section must give a retention period, or the criteria used to determine one, for each category of data: active accounts, closed accounts, CVs, submitted applications, employer job listings, billing and invoicing records (which have a statutory retention period under Cyprus tax law), marketing preferences and server logs. It must also explain what happens to data when an account is deleted.
8.Your Rights
Awaiting legal text
AWAITING LEGAL TEXT — this section must set out the data subject rights under Articles 15 to 22 GDPR — access, rectification, erasure, restriction, portability, objection, and withdrawal of consent — explain how to exercise each one, state our response time, and confirm that exercising a right is free of charge in normal circumstances. It should point to the in-app privacy controls where those rights can be exercised directly.
10.How We Protect Your Data
Awaiting legal text
AWAITING LEGAL TEXT — this section must describe, at a level that does not itself create risk, the technical and organisational measures protecting personal data: encryption in transit, access controls, password hashing, backups and restricted staff access. It must also state how we handle a personal data breach and when affected users would be notified.
11.Automated Decision-Making
Awaiting legal text
AWAITING LEGAL TEXT — this section must state whether any automated processing produces legal or similarly significant effects for candidates, including any ranking, matching or filtering applied to applications or job alerts. If Article 22 GDPR applies, it must explain the logic involved, the consequences, and the right to human intervention. If it does not apply, it must say so plainly.
12.Changes to This Policy
Awaiting legal text
AWAITING LEGAL TEXT — this section must explain how we notify users of changes to this policy, how much notice is given for material changes, and where previous versions can be found.
13.Contact and Complaints
Awaiting legal text
AWAITING LEGAL TEXT — this section must give the postal address and email address for privacy enquiries, and inform users of their right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus, including that authority’s contact details.