Legal
Privacy Policy
Datenschutzerklärung
DRAFT — pending legal review. The text on this page was drafted for a qualified lawyer to review and has not yet been reviewed. It describes how JobWin is built and intended to work, but it is not yet a binding legal document and should not be relied on as one.
This page is not published yet. Every value shown as a placeholder still has to be supplied by the operator.
Last updated: {{POLICY_LAST_UPDATED}}
1. Who we are and who is responsible
JobWin is operated by the company named below ("JobWin", "we", "us"), a company incorporated in the United States. For the personal data described in this policy we are the controller within the meaning of the EU and UK General Data Protection Regulation, and the business within the meaning of the California Consumer Privacy Act. If you have a question about anything on this page, the email address below reaches the people who can answer it.
- Legal name
{{LEGAL_NAME}}- Postal address
{{ADDRESS}}- support@jobwin.ai
- Data protection officer
{{DPO_OPTIONAL}}Optional — omit if it does not apply.- EU / UK representative
{{EU_REPRESENTATIVE_OPTIONAL}}GDPR Art. 27 — required where a controller outside the EU offers a service to people in the EU.
2. Who this policy applies to
This policy covers the JobWin website, the JobWin dashboard, the JobWin browser extension, and the background services that find, grade and submit job applications on your behalf. It does not cover the job boards, employer websites or applicant-tracking systems you reach through JobWin — those are run by other organisations under their own privacy policies, and we have no control over what they do with an application once it has been submitted to them.
JobWin serves users in both the European Union and the United States, so this policy is written to two frameworks at once. Sections 1 to 10 and section 16 state our position under the GDPR and apply to you if you are in the EU, the EEA, Switzerland or the United Kingdom. Section 11 states the additional rights available to residents of California and other US states with comparable laws. Sections that serve only one framework say so in their heading; everything else applies to everyone.
3. Personal data we process
Everything below is tied to your account and to a single user identifier. We process these categories of personal data:
- Account data — your email address, a cryptographic hash of your password (never the password itself), sign-in and session timestamps, and the language and theme you last chose.
- Career profile — the profile you build or import: name, contact details, work history, education, skills, languages, certifications, work authorisation, and your target roles, locations, salary expectations and other job-search preferences.
- Documents — CVs, cover letters and supporting files you upload, such as certificates, references and work permits, together with the text we extract from them so it can be matched against job postings.
- Application answers — the answers you give to employers' application questions, and the drafts we generate for you from your own profile. A draft stays labelled as a draft until you approve it.
- Job and application activity — the postings in your pipeline, how each one was graded and why, the status of each application, and an append-only history of every change to it. That history exists so an application record is auditable — including by you.
- Captured job pages — when you use the extension on a job page, the posting's own content (title, employer, location, description, application URL) and the structure of the application form we need in order to fill it in.
- Technical data — IP address, browser and device type, and the server logs generated when you use the service. These are security and reliability records, not a profile of you.
- What you send us — the contents of emails you write to us, and everything submitted through the contact form on our website: your name, your email address and your message. Alongside a form submission we also record the language of the page you used, your browser's user-agent string, and a SALTED HASH of your network address — never the address itself. Those last two exist only to stop the form being used for spam; the rest is kept so that we can answer you and follow up.
Some things we deliberately do not collect. We do not store your passwords for LinkedIn, StepStone, XING, Indeed or any employer site: the extension works inside the session you are already signed in to in your own browser, and never sees those credentials. We do not track your browsing beyond the job pages you are actively working on. We do not use advertising or analytics trackers. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
4. Why we process it, and on what legal basis (GDPR Art. 6)
We process personal data only for the purposes below. Each purpose is paired with the legal basis under GDPR Art. 6(1) that we rely on for it — a purpose without a basis would not be lawful, so there is no purpose here without one.
- Providing the service — creating and maintaining your account, storing your profile and documents, finding and grading postings, preparing applications and submitting the ones you approve. Legal basis: performance of a contract with you, Art. 6(1)(b).
- Generating application material — drafting cover letters, tailoring CVs and drafting answers to employers' questions from the profile and documents you supplied. Legal basis: performance of a contract, Art. 6(1)(b).
- Keeping the service working and secure — logging, rate limiting, abuse and fraud prevention, backups, and diagnosing faults. Legal basis: our legitimate interests in running a service that stays available and is not abused, Art. 6(1)(f).
- Improving how well we read job sites — measuring where our reader fails on a job page so we can fix it centrally, and improving how application questions are recognised. We use aggregated and de-identified data for this wherever it is sufficient, which for coverage measurement it always is. Legal basis: legitimate interests, Art. 6(1)(f).
- Communicating with you — service messages about your account, your applications and material changes to this policy. Legal basis: performance of a contract, Art. 6(1)(b). Marketing email, if we ever send any, is sent on the basis of your consent, Art. 6(1)(a), and always carries an unsubscribe link.
- Answering your enquiries — replying to a message you send us by email or through the contact form, and keeping the exchange so we can follow up. Legal basis: performance of a contract, or steps taken at your request before entering one, Art. 6(1)(b), where you are a user or a prospective one; otherwise our legitimate interest in answering people who write to us, Art. 6(1)(f). The anti-abuse data named in section 3 rests on our legitimate interest in keeping the form from being used for spam, Art. 6(1)(f).
- Meeting our legal obligations — responding to lawful requests and keeping the records we are required to keep. Legal basis: legal obligation, Art. 6(1)(c).
A CV can contain data that GDPR Art. 9 treats as special category — a disability, a trade-union membership, a religious or political affiliation, health information, or a photograph from which ethnicity might be inferred. We never ask for it and we do not process it deliberately. Where you choose to include it in a document or an answer, we process it on the basis of your explicit consent under Art. 9(2)(a), given by uploading or entering it, and only in order to perform the service you asked for. You can withdraw that consent at any time by deleting the document or the answer.
5. AI-generated material and automated processing
JobWin uses large language models to read job postings, draft cover letters, tailor CVs and draft answers to application questions. Three properties of how that works are commitments in this policy, not just descriptions of the product:
- We never invent qualifications. Generated material is grounded in the profile, documents and answers you supplied. Where a posting asks for something you have not told us you have, the system reports it as a gap; it does not fill one in. Fabricated experience would be worse than useless to you, so the system is built not to produce it.
- You approve before anything is sent. No application is submitted to an employer without your approval of that job. Automated steps that run after your approval carry out the decision you already made — they do not make a new one on your behalf.
- No automated decision produces a legal effect for you. Grading a posting from A to F ranks your own list for you. It is not shared with employers, it decides nothing about you, and it is not a decision within the meaning of GDPR Art. 22. You can ignore, override or dismiss any grade, and you can ask us how one was reached.
What we send to an AI provider is limited to what the task requires — the text of the posting and the profile fields relevant to it — and never your record as a whole. AI providers act as our processors under written contract; they are named in section 7, and those contracts do not permit your data to be used to train their models. Which provider handles a given task can change; a provider is added to the list in section 7 before it is enabled, never afterwards.
6. Where data comes from when it does not come from you (GDPR Art. 14)
Most of the data in this policy comes from you. Two categories do not, and GDPR Art. 14 requires us to say where they come from:
- Job postings come from employers' own public application systems (Greenhouse, Lever, Ashby, Workable, Personio, SmartRecruiters, Recruitee, Teamtailor, Join and similar), from public job boards, from official sources such as the Bundesagentur für Arbeit, and from licensed job-data providers. These records describe roles, not people. Where a posting names a recruiter or hiring manager, that name reaches us only because the employer published it in the posting itself.
- Pages you capture with the extension are read in your own browser session, on pages you opened yourself and could read without us. Our servers never sign in to LinkedIn, StepStone, XING or Indeed, and never scrape them. This is an architectural rule in the product, not only a policy statement: there is no server-side path to those sites to misuse.
8. International data transfers
JobWin is operated from the United States and hosted in Germany, which means personal data moves between the EU and the US in both directions. Concretely:
- Storage stays in the EU. Your profile, documents, applications, answers and captured postings are stored on servers in Germany.
- Our own access is from the US. The company that operates JobWin, its staff and its administrative systems are in the United States, and they can access data stored in the EU in order to run, support and secure the service.
- Some processors are in the US. The processors marked "United States" in section 7 receive the specific data their task requires, and nothing beyond it.
For every one of those transfers we rely on the European Commission's Standard Contractual Clauses, supplemented by the technical and organisational measures described in section 12 and by a transfer impact assessment for each processor. Where a US processor is certified under the EU–US Data Privacy Framework, we may rely on the Commission's adequacy decision for that transfer instead. You can ask us for a copy of the safeguards in place for a particular transfer by writing to the address in section 16.
We want to be direct about one thing, because it is easy to imply the opposite: we do not claim that your data never leaves Germany or never leaves the EU. It does, for the reasons set out above. What we commit to is that every such transfer rests on a lawful safeguard, is limited to what the purpose requires, and is disclosed here rather than buried.
9. How long we keep data
We keep personal data only as long as we need it for the purposes in section 4, or as long as the law requires. In practice that means:
| Data category | Retention period | Deletion trigger |
|---|---|---|
| Account data | For as long as your account exists, then up to 30 days | Account deletion |
| Career profile and documents | For as long as your account exists, then up to 30 days | Account deletion, or your deletion of the individual item |
| Application answers and AI drafts | For as long as your account exists, then up to 30 days | Account deletion, or your deletion of the individual answer |
| Applications and their history | For as long as your account exists, then up to 30 days | Account deletion |
| Captured job pages (your copy) | For as long as your account exists, then up to 30 days | Account deletion |
| Job postings in the shared pool | Up to 24 months after the posting was last seen live | Automatic expiry — these records describe roles, not people |
| Server and security logs | Up to 90 days | Automatic expiry |
| Contact-form submissions (name, email, message) | Up to 12 months after the enquiry is closed | Marked archived in the support inbox, then automatic expiry |
| Contact-form anti-abuse data (address hash, user-agent) | Up to 6 months | Automatic expiry |
| Support correspondence | Up to 24 months after the conversation ends | Automatic expiry |
| Aggregated, de-identified statistics | Kept indefinitely | Not applicable — this is no longer personal data |
| Records we are required by law to keep | The statutory period | Expiry of the statutory period |
{{RETENTION_TABLE}} | ||
The window of up to 30 days after account deletion is the time it takes for a deletion to work through our encrypted backups. During that window your data is already inaccessible in the product and is not processed for any purpose. Records we are legally required to retain survive account deletion — only those, and only for as long as the obligation lasts.
10. Your rights under the GDPR (Art. 15–22)
If the GDPR applies to you, you have the following rights over your personal data. Exercising any of them is free, and we answer within one month of receiving the request. If a request is unusually complex we may extend that by up to two further months, and we will tell you within the first month if we do.
- Access (Art. 15) — a copy of the personal data we hold about you, together with the information set out in this policy about how it is processed.
- Rectification (Art. 16) — correction of inaccurate data and completion of incomplete data. Most of this you can do yourself: your profile, documents and saved answers are editable in the dashboard at any time.
- Erasure (Art. 17) — deletion of your personal data. Deleting your account removes your profile, documents, applications, answers and AI-generated drafts.
- Restriction (Art. 18) — processing paused while a dispute about the accuracy or the lawfulness of processing is resolved.
- Portability (Art. 20) — the data you gave us, in a structured, commonly used, machine-readable format, or transmitted directly to another provider where that is technically feasible.
- Objection (Art. 21) — you may object at any time to processing we base on our legitimate interests, and unconditionally to processing for direct marketing.
- Withdrawal of consent (Art. 7(3)) — where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
- Complaint (Art. 77) — you may lodge a complaint with the data protection supervisory authority of the EU or EEA country where you live, where you work, or where the alleged infringement took place. You do not have to raise it with us first, though we would rather you did so we can fix it.
The dashboard's own controls cover editing and deleting your records. For access, portability, restriction, objection or a complete export, write to the address in section 16. We may ask you to confirm your identity before we act — not to obstruct the request, but because handing your data to somebody else would be the worse failure.
11. Your US privacy rights (California / CCPA)
This section applies to residents of California and sets out the rights the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you. Residents of other US states with comparable privacy laws — including Colorado, Connecticut, Virginia, Utah, Oregon, Texas and Montana — have substantially similar rights, and we handle those requests in the same way rather than asking you which statute you are invoking.
What we collect, in CCPA terms. In the past twelve months we have collected the categories of personal information described in section 3: identifiers (such as name and email address); professional and employment information; education information; internet and network activity relating to your use of the service; geolocation only to the extent implied by an IP address; and the contents of documents, answers and messages you provide. We collect it from you and from the sources named in section 6, for the business purposes named in section 4, and we disclose it to the service providers named in section 7.
We do not sell or share your personal information. We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the past twelve months, and we do not do either of those things at all. There is therefore no "Do Not Sell or Share My Personal Information" opt-out to offer you. If that ever changes we will say so in this section and provide a working opt-out before the change takes effect, not after.
Sensitive personal information. A CV or an application answer may contain information California treats as sensitive. We use it solely to perform the service you requested and for the purposes in section 4 — never to infer characteristics about you, and never for advertising. Because we do not use it for any purpose that triggers the right to limit, there is no separate "Limit the Use of My Sensitive Personal Information" control; you can remove the information at any time by editing or deleting the document or answer that contains it.
- Right to know — what personal information we collect, the sources it comes from, the purposes we use it for, and the categories of third parties we disclose it to.
- Right to access — a copy of the specific pieces of personal information we hold about you.
- Right to delete — deletion of the personal information we collected from you, subject to the exceptions the CCPA allows, such as records we must keep to comply with a legal obligation or to detect security incidents.
- Right to correct — correction of inaccurate personal information we hold about you.
- Right to opt out of sale or sharing — not applicable, because we do neither, as stated above.
- Right to limit the use of sensitive personal information — not applicable, because we do not use it for any purpose that triggers this right.
- Right to non-retaliation — we will not deny you the service, charge you a different price, or give you a lower level of service because you exercised any of these rights.
To exercise any of these rights, write to the address in section 16, or use the self-service controls in the dashboard. You may use an authorised agent, in which case we will ask for proof that you authorised them to act for you. We confirm receipt within ten business days and respond within forty-five days; if a request is complex we may extend that once by a further forty-five days, and we will tell you why. We will ask you to verify your identity to a standard proportionate to what you are asking for.
12. How we protect data
We protect personal data with technical and organisational measures appropriate to the risk: encryption in transit over TLS and at rest; row-level access control in the database, so that every record is scoped to the account that owns it; passwords stored only as salted hashes; provider credentials stored encrypted; production access restricted to the people who need it and logged when used; and an immutable audit log of administrative actions. Backups are encrypted and held in the EU.
No system is perfectly secure, and we will not claim ours is. If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it, as GDPR Art. 33 requires, and we notify you directly without undue delay where Art. 34 or applicable US state law requires it.
14. Children
JobWin is not intended for children. You must be at least 16 years old to use it, or older where local law sets a higher age for entering into this kind of contract. We do not knowingly collect personal data from children below that age, and if we learn that we have, we delete it. If you believe a child has provided us with personal data, write to the address in section 16 and we will remove it.
15. Changes to this policy
We update this policy when what we actually do changes. The date at the top of the page is the date of the last substantive change. Where a change materially affects how we use your personal data, we will tell you before it takes effect — by email or in the product — and where the law requires your consent for the change, we will ask for it rather than assume it. Earlier versions of this policy are available on request.
16. How to contact us, and how to complain
- support@jobwin.ai
Data-protection questions, requests to exercise any of the rights in sections 10 and 11, and complaints all go to the address above; a request does not need to be in any particular form, and you do not need to cite an article number for us to act on it. If you are in the EU or the EEA you may also complain directly to your local data protection supervisory authority, as described in section 10.