Legal
Privacy Policy
Datenschutzerklärung
Last updated: 30 July 2026
1. Who we are and who is responsible
JobWin is operated by the company named below (“JobWin”, “we”, “us”), a company incorporated in the United States. We decide what personal data JobWin collects and how it is used, and we are responsible for it. If you have a question about anything on this page, the email address below reaches the people who can answer it — support@jobwin.ai, for every privacy question and every request.
- Legal name
- VS Technologies LLC
- Postal address
- 30 N Gould St, Ste R, Sheridan, WY 82801, USA
- support@jobwin.ai
2. Who this policy applies to
This policy covers the JobWin website, the JobWin dashboard, the JobWin browser extension, and the background services that find, rank and submit job applications on your behalf. It does not cover the job boards, employer websites or applicant-tracking systems you reach through JobWin. Those are run by other organisations under their own privacy policies. We have no control over what they do with an application once you have submitted it to them.
This policy applies to everyone who uses JobWin, wherever you are. We give every user the same protections — we did not build one standard for some people and a weaker one for others. If your local law gives you extra rights on top, you will find them in the regional notices at the end of this page. If anything here is unclear, or you want your data back, email support@jobwin.ai and a person will answer.
3. Personal data we process
Everything below is tied to your account and to a single user identifier. We process these categories of personal data:
- Account data — your email address, a cryptographic hash of your password (never the password itself), sign-in and session timestamps, and the language and theme you last chose.
- Career profile — the profile you build or import: name, contact details, work history, education, skills, languages, certifications, work authorisation, and your target roles, locations, salary expectations and other job-search preferences.
- Documents — CVs, cover letters and supporting files you upload, such as certificates, references and work permits, together with the text we extract from them so it can be matched against job postings.
- Application answers — the answers you give to employers' application questions, and the drafts we generate for you from your own profile. A draft stays labelled as a draft until you approve it.
- Job and application activity — the postings in your pipeline, how each one was assessed and why, the status of each application, and an append-only history of every change to it. That history exists so an application record is auditable — including by you.
- Captured job pages — when you use the extension on a job page, the posting's own content (title, employer, location, description, application URL) and the structure of the application form we need in order to fill it in.
- Technical data — IP address, browser and device type, and the server logs generated when you use the service. These are security and reliability records, not a profile of you.
- What you send us — the contents of emails you write to us. We keep the exchange so that we can answer you and follow up.
Some things we deliberately do not collect. We do not store your passwords for LinkedIn, StepStone, XING, Indeed or any employer site: the extension works inside the session you are already signed in to in your own browser, and never sees those credentials. We do not track your browsing beyond the job pages you are actively working on. We do not use advertising or analytics trackers. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
4. Why we use your data
We use personal data only for the purposes below. Each one is here because the service cannot do what you asked without it, because the service has to keep working and stay secure, or because the law requires it of us. We do not use your data for anything that is not on this list. The regional notices at the end set out the legal basis we rely on for each purpose where a law requires us to name one.
- Providing the service — creating and maintaining your account, storing your profile and documents, finding and ranking postings, preparing applications and submitting the ones you approve.
- Generating application material — drafting cover letters, tailoring CVs and drafting answers to employers' questions from the profile and documents you supplied.
- Keeping the service working and secure — logging, rate limiting, abuse and fraud prevention, backups, and diagnosing faults.
- Improving how well we read job sites — measuring where our reader fails on a job page so we can fix it centrally, and improving how application questions are recognised. We use aggregated and de-identified data for this wherever it is sufficient, which for coverage measurement it always is.
- Communicating with you — service messages about your account, your applications and material changes to this policy. Marketing email, if we ever send any, goes out only if you asked for it, and always carries an unsubscribe link.
- Answering your enquiries — replying to a message you send us by email, and keeping the exchange so we can follow up.
- Meeting our legal obligations — responding to lawful requests and keeping the records we are required to keep.
A CV can contain data that is sensitive by any standard — a disability, a trade-union membership, a religious or political affiliation, health information, or a photograph from which ethnicity might be inferred. We never ask for it and we do not process it deliberately. Where you choose to include it in a document or an answer, you are giving us your explicit permission to process it, and we use it only to perform the service you asked for. You can take that permission back at any time by deleting the document or the answer.
5. AI-generated material and automated processing
JobWin uses large language models to read job postings, draft cover letters, tailor CVs and draft answers to application questions. Three properties of how that works are commitments in this policy, not just descriptions of the product:
- We never invent qualifications. Generated material is grounded in the profile, documents and answers you supplied. Where a posting asks for something you have not told us you have, the system reports it as a gap; it does not fill one in. Fabricated experience would be worse than useless to you, so the system is built not to produce it.
- You approve before anything is sent. No application is submitted to an employer without your approval of that job. Automated steps that run after your approval carry out the decision you already made — they do not make a new one on your behalf.
- No automated decision produces a legal effect for you. JobWin ranks and prioritises postings against your profile, so your own list is ordered for you. The ranking is not shared with employers, decides nothing about you, and is not an automated decision that produces legal effects for you or similarly significantly affects you. You can ignore, override or dismiss any ranking, and you can ask us how one was reached.
What we send to an AI provider is limited to what the task requires — the text of the posting and the profile fields relevant to it — and never your record as a whole. AI providers act as our processors under written contract; they are named in *Who we share data with*, and those contracts do not permit your data to be used to train their models. Which provider handles a given task can change; a provider is added to that list before it is enabled, never afterwards.
6. Where data comes from when it does not come from you
Most of the data in this policy comes from you. Two categories do not, so we say here where they come from:
- Job postings come from employers' own public application systems (Greenhouse, Lever, Ashby, Workable, Personio, SmartRecruiters, Recruitee, Teamtailor, Join and similar), from public job boards, from official sources such as the Bundesagentur für Arbeit, and from licensed job-data providers. These records describe roles, not people. Where a posting names a recruiter or hiring manager, that name reaches us only because the employer published it in the posting itself.
- Pages you capture with the extension are read in your own browser session, on pages you opened yourself and could read without us. Our servers never sign in to LinkedIn, StepStone, XING or Indeed, and never scrape them. This is an architectural rule in the product, not only a policy statement: there is no server-side path to those sites to misuse.
8. International data transfers
JobWin is operated from the United States and stores user data in Frankfurt, Germany. We serve users worldwide, so personal data crosses borders: from wherever you are to our EU servers, and between the EU and the US for operations. Concretely:
- Storage stays in the EU. Your profile, documents, applications, answers and captured postings are stored on servers in Germany.
- Our own access is from the US. The company that operates JobWin, its staff and its administrative systems are in the United States, and they can access data stored in the EU in order to run, support and secure the service.
- Some processors are in the US. The processors marked “United States” in *Who we share data with* receive the specific data their task requires, and nothing beyond it.
Every one of those transfers is covered by a written contract that binds the processor to protect your data to the standard we owe you, supplemented by the technical and organisational measures described in *How we protect data*, and by an assessment of each processor before we enable it. The regional notices at the end name the specific legal instruments we rely on. You can ask us for a copy of the safeguards for a particular transfer — write to support@jobwin.ai.
We want to be direct about one thing, because it is easy to imply the opposite: we do not claim that your data never leaves Germany or never leaves the EU. It does, for the reasons set out above. What we commit to is that every such transfer rests on a lawful safeguard, is limited to what the purpose requires, and is disclosed here rather than buried.
9. How long we keep data
We keep personal data only as long as we need it for the purposes in *Why we use your data*, or as long as the law requires. In practice that means:
| Data category | Retention period | Deletion trigger |
|---|---|---|
| Profile, CVs and uploaded documents | Kept while your account exists | Deleted when you delete your account; physically erased at day 30 |
| Captured job postings, evaluations and applications | Kept while your account exists | Deleted when you delete your account; physically erased at day 30 |
| Saved answers and generated documents | Kept while your account exists | Deleted when you delete your account; physically erased at day 30 |
| Account record and sign-in identity | Kept while your account exists | Erased at day 30 together with the authentication record |
| AI request audit rows (no prompt or response text, no key material) | Kept while your account exists | Erased with your account |
| Deactivated accounts | Retained until you reactivate or delete | Reversible — deactivation erases nothing |
| Operational audit log | Retained after deletion with your identifier removed | Anonymised, not deleted — it records administrative actions, not you |
The window of up to 30 days after account deletion is the time it takes for a deletion to work through our encrypted backups. During that window your data is already inaccessible in the product and is not processed for any purpose. Records we are legally required to retain survive account deletion — only those, and only for as long as the obligation lasts.
10. Your rights over your personal data
These are the rights you have over your data at JobWin — all of them, wherever you live. We give every user the same rights rather than sorting people by where they happen to be. If your local law gives you more, your local law wins, and the regional notices at the end say what it adds. Exercising any of these is free. We answer within one month of receiving your request; if a request is unusually complex we may need up to two further months, and we will tell you within the first month if that happens.
- Access — a copy of the personal data we hold about you, together with the information set out in this policy about how it is used.
- Correction — correction of data that is wrong, and completion of data that is incomplete. Most of this you can do yourself: your profile, documents and saved answers are editable in the dashboard at any time.
- Deletion — deletion of your personal data. Deleting your account removes your profile, documents, applications, answers and AI-generated drafts.
- Restriction — we pause processing while a dispute about whether data is accurate, or whether we may use it, is resolved.
- Portability — the data you gave us, in a structured, commonly used, machine-readable format, or sent directly to another provider where that is technically possible.
- Objection — you may object at any time to processing we base on our own legitimate interests, and you may always object to direct marketing.
- Withdrawing permission — where we rely on your permission, you can take it back at any time. Doing so does not make what we did beforehand unlawful.
- Complaining — tell us first if you can, so we can fix it; you can also complain to a data-protection regulator. The regional notices at the end say which regulator that is for you.
The dashboard's own controls cover editing and deleting your records. For access, portability, restriction, objection or a complete copy of your data, email support@jobwin.ai — that one address is the route for every request, from every user, everywhere. We may ask you to confirm your identity before we act — not to obstruct the request, but because handing your data to somebody else would be the worse failure.
11. How we protect data
We protect your data with measures that match the risk. Data is encrypted in transit over TLS, and encrypted at rest. Every database record is scoped to the account that owns it, enforced by row-level access control. Passwords are stored only as salted hashes. Provider credentials are stored encrypted. Production access is restricted to the people who need it, and every use is logged. Administrative actions go into an audit log that cannot be edited. Backups are encrypted and held in the EU.
No system is perfectly secure, and we will not claim ours is. If a personal-data breach happens that is likely to put your rights at risk, we notify the competent regulator within 72 hours of becoming aware of it, and we tell you directly, without undue delay, where the risk to you means you need to know. The regional notices at the end name the specific rules we follow when we do.
13. Children
JobWin is not intended for children. You must be at least 16 years old to use it, or older where local law sets a higher age for entering into this kind of contract. We do not knowingly collect personal data from children below that age, and if we learn that we have, we delete it. If you believe a child has provided us with personal data, email support@jobwin.ai and we will remove it.
14. Changes to this policy
We update this policy when what we actually do changes. The date at the top of the page is the date of the last substantive change. Where a change materially affects how we use your personal data, we will tell you before it takes effect — by email or in the product — and where the law requires your consent for the change, we will ask for it rather than assume it. Earlier versions of this policy are available on request.
Additional regional notices
Everything above applies to you. These notices add what particular laws require for people in particular places — they never take anything away from the policy above. If none of them covers where you live, nothing here changes your rights. Whatever the notice, the route is the same: support@jobwin.ai.
For users in the EU, the EEA, Switzerland and the UK
This notice states the mechanics that the EU and UK General Data Protection Regulation require us to set out. It supplements the policy above; where it names an article, that article is the source of the right or the duty described in plain words earlier on this page.
**Controller.** For the personal data described in this policy we are the controller within the meaning of the EU and UK GDPR. Our identity and contact details are in *Who we are and who is responsible* (Art. 13(1)(a)).
- Legal bases (Art. 6(1)). Each purpose in *Why we use your data* rests on one of these:
- Providing the service; generating application material; communicating with you about your account — performance of our contract with you, Art. 6(1)(b).
- Keeping the service working and secure; improving how well we read job sites — our legitimate interests in running a service that stays available and is not abused, Art. 6(1)(f).
- Answering your enquiries — performance of a contract, or steps taken at your request before entering one, Art. 6(1)(b), where you are a user or a prospective one; otherwise our legitimate interest in answering people who write to us, Art. 6(1)(f).
- Marketing email, if we ever send any — your consent, Art. 6(1)(a).
- Meeting our legal obligations — legal obligation, Art. 6(1)(c).
- Special category data in a CV or an answer — your explicit consent under Art. 9(2)(a), given by uploading or entering it. Withdrawing it is described in *Why we use your data*.
**Data not obtained from you (Art. 14).** The categories in *Where data comes from when it does not come from you*, and their sources, are stated there to satisfy Art. 14.
**Your rights, with their sources.** The rights in *Your rights over your personal data* are guaranteed here by: access, Art. 15; rectification, Art. 16; erasure, Art. 17; restriction, Art. 18; portability, Art. 20; objection, Art. 21; withdrawal of consent, Art. 7(3). Our one-month response time is the Art. 12(3) deadline, and the extension of up to two further months is the one that article allows.
**Complaints (Art. 77).** You may lodge a complaint with the data protection supervisory authority of the country where you live, where you work, or where you believe the infringement took place. You do not have to raise it with us first — though we would rather you did, so we can fix it.
**Transfers (Chapter V).** The written contracts described in *International data transfers* are the European Commission's Standard Contractual Clauses under Art. 46(2)(c), together with a transfer impact assessment for each processor. Where a US processor is certified under the EU–US Data Privacy Framework, we may instead rely on the Commission's adequacy decision for that transfer. For the UK, the equivalent transfer terms apply.
**Automated decision-making (Art. 22).** The ranking described in *AI-generated material and automated processing* is not a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you, so Art. 22 does not apply to it. We state this because the distinction matters, not to narrow it: the ranking orders your own list, is never shared with employers, and can be ignored or overridden by you.
**Breach notification (Art. 33 and 34).** The 72-hour regulator notification described in *How we protect data* is the Art. 33 deadline, and we notify you directly where Art. 34 requires it.
**Cookies (§ 25(2) TTDSG; ePrivacy Directive).** We ask for no cookie consent because everything we set is either strictly necessary for the service or stores a preference you chose, and storage of that kind does not require consent. If that ever stops being true, we will ask before setting anything else.
For residents of the United States
This section applies to residents of California. It sets out your rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. Residents of other US states with comparable privacy laws — including Colorado, Connecticut, Virginia, Utah, Oregon, Texas and Montana — have substantially similar rights. We handle those requests the same way, without asking which statute you are invoking.
What we collect, in CCPA terms. In the past twelve months we have collected the categories of personal information described in *What we collect*: identifiers, such as your name and email address; professional and employment information; education information; internet and network activity relating to your use of the service; geolocation only to the extent an IP address implies it; and the contents of documents, answers and messages you provide. We collect it from you and from the sources named in *Where data comes from when it does not come from you*. We use it for the purposes named in *Why we use your data*. We disclose it to the service providers named in *Who we share data with*.
We do not sell or share your personal information. We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the past twelve months, and we do not do either of those things at all. There is therefore no "Do Not Sell or Share My Personal Information" opt-out to offer you. If that ever changes we will say so in this section and provide a working opt-out before the change takes effect, not after.
Sensitive personal information. A CV or an application answer may contain information California treats as sensitive. We use it solely to perform the service you requested, for the purposes in *Why we use your data*. We never use it to infer characteristics about you, and never for advertising. Because we do not use it for any purpose that triggers the right to limit, there is no separate “Limit the Use of My Sensitive Personal Information” control. You can remove the information at any time by editing or deleting the document or answer that contains it.
- Right to know — what personal information we collect, the sources it comes from, the purposes we use it for, and the categories of third parties we disclose it to.
- Right to access — a copy of the specific pieces of personal information we hold about you.
- Right to delete — deletion of the personal information we collected from you, subject to the exceptions the CCPA allows, such as records we must keep to comply with a legal obligation or to detect security incidents.
- Right to correct — correction of inaccurate personal information we hold about you.
- Right to opt out of sale or sharing — not applicable, because we do neither, as stated above.
- Right to limit the use of sensitive personal information — not applicable, because we do not use it for any purpose that triggers this right.
- Right to non-retaliation — we will not deny you the service, charge you a different price, or give you a lower level of service because you exercised any of these rights.
To exercise any of these rights, email support@jobwin.ai, or use the self-service controls in the dashboard. You may use an authorised agent, in which case we will ask for proof that you authorised them to act for you. We confirm receipt within ten business days and respond within forty-five days; if a request is complex we may extend that once by a further forty-five days, and we will tell you why. We will ask you to verify your identity to a standard proportionate to what you are asking for.
15. How to contact us, and how to complain
- support@jobwin.ai
Data-protection questions, requests to exercise any of the rights in *Your rights over your personal data*, and complaints all go to the address above. That single address — support@jobwin.ai — is the route for every privacy request, for every user, everywhere, for every right. A request does not need any particular form, and you do not need to cite a law or an article number for us to act on it. The regional notices below add, for some places, a regulator you may also complain to.