The short version
The full text below is the legally binding version. This summary is here so you can understand the essentials in thirty seconds.
- Where your data lives: your account, CV and job data are stored in Amazon Web Services’ Frankfurt region (
eu-central-1) — inside the EU. - AI processing: CV tailoring and match scoring run on Amazon Bedrock. Your data is not used to train any model and is not retained by the model provider.
- We never sell your data and we do not share it with advertisers or recruiters unless you explicitly ask us to.
- No tracking cookies. We use only technically necessary cookies plus cookieless, aggregated analytics — so no consent banner is required.
- You stay in control: export or delete your account and all associated data at any time from Settings, or by e-mailing us.
Controller and contact
The controller responsible for data processing on this service within the meaning of Art. 4(7) GDPR is:
We have not appointed a Data Protection Officer. As a sole proprietorship we do not meet the thresholds of Art. 37 GDPR or § 38 BDSG. Please direct all privacy enquiries to the address above.
What data we process, and why
We process only what the service actually needs. Each category below states its legal basis under Art. 6 GDPR.
| Category | What it includes | Purpose | Legal basis |
|---|---|---|---|
| Account data | E-mail address, password hash, display name, locale, verification status | Creating and securing your account, logging you in | Art. 6(1)(b) — contract |
| Profile & CV data | CV files you upload, work history, skills, education, desired role, salary expectation, location and remote preference | Matching you to jobs and generating tailored CVs and cover letters | Art. 6(1)(b) — contract |
| Job & application data | Saved and matched listings, match scores and reasoning, application status in your pipeline, notes | Running your job feed and application tracker | Art. 6(1)(b) — contract |
| Payment data | Subscription plan, billing status, Stripe customer ID. We never see or store your card number. | Processing your subscription | Art. 6(1)(b) — contract |
| Technical & log data | IP address, user agent, request timestamps, error traces | Delivering the service, detecting abuse, debugging | Art. 6(1)(f) — legitimate interest |
| Usage analytics | Page views, CTA clicks, A/B variant — cookieless and not linked to your identity | Understanding which parts of the product work | Art. 6(1)(f) — legitimate interest |
| Browser extension data | Job listings you explicitly capture, plus the page URL and captured fields | Saving a job to your pipeline from an external site | Art. 6(1)(b) — contract |
How AI processing works
Match scoring, CV tailoring and cover-letter drafting use large language models hosted on Amazon Bedrock, operated by Amazon Web Services EMEA SARL. Requests are routed to models from Anthropic (Claude family) and Amazon (Nova family) depending on your plan.
- Only the data needed for the specific task is sent — typically the relevant sections of your CV and the text of the job listing.
- AWS Bedrock does not store your prompts or outputs after the request completes, and does not use them to train or improve any foundation model. This is contractually guaranteed in the AWS Service Terms.
- Model providers have no access to data processed through Bedrock.
- AI output is a draft, not advice. Match scores are an estimate; always read a generated CV or cover letter before sending it.
We do not use automated decision-making that produces legal effects concerning you within the meaning of Art. 22 GDPR. A match score ranks listings in your feed; it never rejects you from anything and no employer sees it.
Sub-processors and recipients
We use the following processors, each under a data processing agreement pursuant to Art. 28 GDPR. We do not sell data and we do not pass it to advertisers.
| Processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Application hosting, database, authentication (Cognito), queues, AI inference (Bedrock) | Frankfurt, Germany (eu-central-1) | No third-country transfer for stored data |
| Vercel Inc. | Frontend hosting, edge middleware, cookieless analytics | USA / EU edge regions | EU-US Data Privacy Framework + SCCs |
| Stripe Payments Europe Ltd. | Subscription billing and payment processing | Ireland (EU) | EU-based; SCCs for onward transfer |
| LaunchDarkly Inc. | Feature flag delivery (no personal content, pseudonymous key only) | USA | Standard Contractual Clauses |
Job sources
To build your feed we collect listings from external sources. During the day we query job APIs — the Bundesagentur für Arbeit, Arbeitnow, Adzuna, FreeHire and, on paid plans, partner aggregators such as Jooble, Careerjet, WhatJobs, Findwork and TheMuse. Overnight we additionally collect publicly accessible listings from large career platforms and from the public job APIs of applicant-tracking systems used by employers (Greenhouse, Lever). Every one of these requests carries search criteria only (job title, location, keywords). Your name, e-mail address, CV and profile are never transmitted to a job source, and no request is made on your behalf or under your identity.
When you apply
When you apply for a job, your documents go to that employer, who then becomes an independent controller for your data. Their privacy policy governs what happens next — we have no control over it and cannot delete data on your behalf once it has left our system.
How long we keep data
| Data | Retention period |
|---|---|
| Account and profile data | Until you delete your account |
| CV files and generated documents | Until you delete them, or 30 days after account deletion (backup rotation) |
| Matched job listings | Rolled out of the active feed periodically; retained in aggregate for your statistics |
| Server and access logs | 30 days, then deleted automatically |
| Invoices and billing records | 10 years — statutory retention under § 147 AO and § 257 HGB |
When you delete your account, we remove your data from live systems immediately and from encrypted backups within 30 days, except records we are legally required to keep (invoices).
Your rights
You have the following rights over your personal data. Exercising them is free and we respond within one month.
- Access (Art. 15) — a copy of the data we hold about you.
- Rectification (Art. 16) — correction of inaccurate data.
- Erasure (Art. 17) — deletion of your data, the “right to be forgotten”.
- Restriction (Art. 18) — freeze processing while a dispute is resolved.
- Portability (Art. 20) — your data in a machine-readable format.
- Objection (Art. 21) — object to processing based on legitimate interest.
- Withdraw consent (Art. 7(3)) — at any time, without affecting past processing.
Most of these you can exercise yourself in Settings. Otherwise write to privacy@jobsuchpro.com. See our GDPR page for step-by-step instructions.
Security
- All traffic is encrypted in transit with TLS 1.2 or higher.
- Data at rest is encrypted with AWS-managed keys.
- Passwords are never stored in plain text; authentication is handled by Amazon Cognito.
- Access to production systems is restricted, logged and monitored (CloudWatch, GuardDuty, AWS Config).
- Infrastructure is defined as code and reviewed before deployment.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to support@jobsuchpro.com — we will acknowledge within two business days and will not pursue good-faith researchers.
Children
JobsuchPro is not directed at children. You must be at least 16 years old to create an account. If we learn that we hold data from a child under 16 without parental consent, we delete it.
Changes to this policy
We update this policy when the service changes. The date at the top of the page always reflects the current version. For material changes affecting your rights, we notify registered users by e-mail at least 14 days before the change takes effect.
Questions about anything here? Write to privacy@jobsuchpro.com — a person reads it.