This is an English reading version. The legally binding text is the German one; where the two differ, the German version applies.
The controller for data processing on this website is:
Cagri Ersöz, Ricklinger Stadtweg 77, 30459 Hannover, Germany.
Data protection contact: info@jobvin.de
Our application runs on Google Cloud (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Server locations: the application on Cloud Run in europe-west4 (Netherlands), the database on Cloud SQL in europe-west1 (Belgium). When you visit the site, Google processes technically necessary server logs (IP address, timestamp, user agent) in order to provide and secure the service. The legal basis is our legitimate interest in secure, stable operation (Art. 6(1)(f) GDPR). A data processing agreement with Google is in place (Art. 28 GDPR).
For creating an account we use Firebase Authentication (Google). Email and password are possible, as is login via Google and LinkedIn. Processed are the email address, display name and, where applicable, the profile picture URL from the chosen provider. The legal basis is performance of the contract (Art. 6(1)(b) GDPR). This may involve a transfer to Google in the USA - on third-country transfers see section 5. A session cookie (__session) is set on login; details in the cookie notice.
Resumes, cover letters, profile details and your application pipeline are stored in our database in the EU (Cloud SQL, Belgium). Your browser has no direct database access; every access runs through our servers and is checked against your account. There is no disclosure to employers or other third parties unless you initiate it yourself. To improve the product we additionally record usage events (e.g. "document exported") exclusively in our own database - without third-party tracking (Art. 6(1)(f) GDPR).
When you actively start an AI feature (e.g. the job check, resume optimisation, reference letter analysis, CV import), we transmit the content required for it (e.g. resume text, job posting, reference letter text) to our AI providers Google (Gemini) and Anthropic (Claude) for processing on our behalf. Processing may take place in the USA; it is based on EU standard contractual clauses and the EU-U.S. Data Privacy Framework respectively (Art. 46 GDPR). Your content is not used by us to train AI models.
Contact details are pseudonymised before transmission: name, email address, phone number, postal address and web addresses from your profile are replaced by placeholders on our side and reinserted locally only after the AI response has been received (Art. 25, 32 GDPR). When importing documents (e.g. a resume PDF) prior replacement is technically impossible, because the data is only recognised through the processing itself; here the document is transmitted as it is.
Please note: resumes and German reference letters may contain special categories of personal data (e.g. indications of health, religion or origin). Only transmit such information if you want it processed - processing takes place exclusively upon your active action (Art. 9(2)(a) GDPR).
AI voice processing (practice interview): When you actively start a voice interview, your microphone audio is transmitted for the duration of the conversation directly from your browser to Google (Gemini API) and processed there to conduct the conversation and to transcribe it. We use the Gemini API on a paid tier; your voice data is not used to train AI models. The legal basis is your consent given by actively starting the interview (Art. 6(1)(a) GDPR); for third-country transfers the information above in this section applies.
The job search uses the public job board interface of the Bundesagentur fuer Arbeit, the German federal employment agency. Your search parameters (e.g. occupation, location) are transmitted to the agency - no account is required for this. Legal basis: Art. 6(1)(b) or (f) GDPR.
The same authority is the data source for further tools: the job scanner keeps saved searches running, the training search queries occupations and course topics from BERUFENET, the salary check queries the Entgeltatlas and the coaching search the offer database. What is transmitted in each case are only the search parameters - occupation, location, radius - never your resume or your contact details. In addition the job scanner reads the public career pages of the companies you have entered; nothing about you is sent there, only a request for the public job listing.
Profile photos you upload are stored in Firebase Storage (Google Cloud). The upload is performed by you alone; the photos are removed when your account is deleted. Legal basis: Art. 6(1)(b) GDPR.
Firebase Storage also holds the attachments you add to your applications - reference letters, certificates and other documents as PDF. For every attachment we store its label, its type, the storage path and the file size in our database. These files sit in your own area, readable only by you; they are delivered only to you, and to third parties only if you attach them to an application yourself and send it. If you delete an attachment it first goes to the recycle bin and is removed together with the file after 14 days. Legal basis: Art. 6(1)(b) GDPR.
If an AI feature generates an image - for instance for the application photo - section 5 applies to the transmission to the AI provider. We store the result like an uploaded photo.
The salary check compares an occupation with the official pay data of the Bundesagentur fuer Arbeit. All we transmit to the agency for this is the occupational code, the requirement level and the region - nothing about you.
In our database we keep the last 20 queries per account: the job title you entered, the official occupation it was matched to, the requirement level, the region, the years of experience you stated and the comparison figures retrieved. The market value calculated from them is deliberately not stored - it is recalculated on every visit.
Your own salary is a voluntary entry. It is attached to your Master Profile and kept separate from your contact details there, so that it cannot accidentally end up in a resume or cover letter. Clearing the field deletes the entry. Legal basis: Art. 6(1)(b) GDPR.
When you filter jobs by commute time or have the travel time to a workplace shown, we need coordinates. Your address is translated into latitude and longitude by the address service of the Bundesagentur fuer Arbeit; what is transmitted is the address you enter.
The travel time itself is calculated by openrouteservice (HeiGIT gGmbH, Heidelberg, Germany). Only coordinates go there - your starting point and the destinations - along with the mode of transport. Your name, your account and your address in plain text are not transmitted. Both services are located in Germany; no transfer to a third country takes place.
Because the coordinates of a home address are personal data, we say it plainly: this processing only happens if you use the commute time feature. We cache results in order to avoid repeated queries. Legal basis: Art. 6(1)(b) GDPR.
You can turn your profile into a public applicant page at an address of your own. This is the only route by which your application data leaves your account - and it is triggered by you alone.
The page has three levels: private (only for you), reachable by link only (not released to search engines) and public (discoverable by search engines). The default is private. Only once you put the page outside is it retrievable by others; for the public level we obtain your express consent.
Which details appear is your decision item by item: photo, email address and date of birth are each released separately. On publication we additionally generate a resume as a PDF for download. Please bear in mind that a public page can be indexed and cached by search engines - and may remain so even after you set it back to private. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by setting the page to private or deleting it.
So that errors do not go unnoticed, we use Sentry (Functional Software, Inc., San Francisco, USA). If an error occurs in your browser or on our server, Sentry sends an error event: the error message, a technical stack trace, the address called, the time, browser and device type and - if you are signed in - your account identifier. The data goes to the European region of the service.
What Sentry expressly does NOT receive is the content of your documents. We have deliberately switched off session replay, the transmission of console output and the attaching of local variable values - each of these three defaults would have transmitted parts of your resume. The automatic collection of IP address and headers is switched off as well. Of the performance data we transmit only a sample in production.
The legal basis is our legitimate interest in error-free and secure operation (Art. 6(1)(f) GDPR). A transfer to the USA is possible; it is based on EU standard contractual clauses (Art. 46 GDPR). A data processing agreement with the provider is in place (Art. 28 GDPR).
Following your consent we use Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The purpose is reach measurement: we want to see which pages are used and where people drop off, in order to improve the product. Processed are a random device identifier, the pages visited, an approximate location (country and region), device and browser, and the events you trigger (for example "resume exported"). If you are signed in, we additionally transmit a pseudonymous identifier for your account so that analyses across several devices are possible. Names, email addresses, search terms and the contents of your documents are not transmitted.
If you have additionally consented to the "marketing" category, we activate Google signals. Google may then link the measurement data with accounts that have personalised advertising switched on; this produces cross-device analyses as well as information on age, gender and interests.
The legal basis is exclusively your consent (Art. 6(1)(a) GDPR, § 25 Abs. 1 TTDSG). Without consent no Google script is loaded and no analytics cookie is set. A transfer to Google LLC in the USA is possible; Google LLC is certified under the EU-US Data Privacy Framework, so an adequacy decision of the EU Commission applies. A data processing agreement with Google is in place (Art. 28 GDPR). We delete the event data after 14 months.
You can withdraw your consent at any time with effect for the future - through "Cookie settings" in the footer or in your profile settings. On withdrawal we switch measurement off immediately and delete the analytics cookies that were set. In addition you can install the Google browser add-on to deactivate Google Analytics.
Record of your decision: Every consent, every refusal and every withdrawal is logged by us - with a random device identifier, the time, the categories chosen and the version of the consent text you were shown. This applies when you refuse as well: without an entry we could not demonstrate the refusal. We do not store your IP address or your browser identifier in doing so. The legal basis is our obligation to demonstrate consent under Art. 7(1) GDPR (Art. 6(1)(c) GDPR). We delete these entries after three years at the latest.
For transactional and notification emails (e.g. welcome mail, "analysis finished", job alerts) we use - once email delivery is switched on - the service Resend (Resend Inc., USA; EU standard contractual clauses). Processed are the email address and the mail content. You can deactivate notifications through the unsubscribe link in every email. Legal bases: Art. 6(1)(b) GDPR (transactional mail) and Art. 6(1)(f) GDPR (product notifications with a right to object).
Jobvin does not send applications on your behalf. You apply from your own mailbox; we only record that and when you did so.
If you write to the address given in the imprint, we process your email address, your name and the content of your message exclusively in order to deal with your request. The legal basis is the performance of pre-contractual measures or of a contract (Art. 6(1)(b) GDPR), otherwise our legitimate interest in answering your enquiry (Art. 6(1)(f) GDPR).
We delete the correspondence once your request has been conclusively dealt with and no statutory retention obligation stands in the way - for enquiries with commercial or tax relevance after the respective period has expired. There is deliberately no contact form on this website; that way your message stays in your own sent folder and is not additionally filed in a database on our side.
For paid subscriptions we use - once the payment function is switched on - the payment service provider Stripe (Stripe Payments Europe, Ltd., Ireland). Stripe processes your payment data (e.g. card details) as an independent controller; we do not receive complete card details. Legal basis: Art. 6(1)(b) GDPR.
Several features produce automated assessments: the job check awards a fit score, the salary check places a salary in context, the reference letter analysis estimates a grade. These assessments are suggestions to help you prepare your own decision.
They do not amount to an automated decision within the meaning of Art. 22 GDPR - that is, a decision which produces legal effects concerning you or similarly significantly affects you. No result causes a service to be withheld from you, and none is transmitted to an employer. Decisions about applying, about what salary to ask for and about what to do with a reference letter are yours alone.
You have the following rights against us regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on Art. 6(1)(f) (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
- Complaint to a data protection supervisory authority (Art. 77 GDPR)
You can delete your account together with all data yourself at any time in your profile settings - the deletion takes effect immediately and covers all stored application data. For all matters: info@jobvin.de.
Competent supervisory authority: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany. You may also contact the supervisory authority of your habitual residence.
Account data and application data are stored until you delete your account. Deleted documents and attachments stay in the recycle bin for 14 days and are then removed permanently. Server logs are deleted after 30 days at the latest. Measurement data from Google Analytics is deleted after 14 months, the record of your cookie decision after three years (see section 12). Error events from monitoring are kept only as long as they are needed for troubleshooting. Statutory retention obligations (e.g. for invoice data once the payment function is switched on) remain unaffected.
Messages sent through the contact form of a public applicant page: If you write through the contact form of a page under /p/…, we process the information you enter (name, optionally company, email address, message text) exclusively in order to deliver it to the owner of that page. That person is the sole recipient; there is no disclosure to third parties. The legal basis is Art. 6(1)(a) GDPR (consent, which you give before sending). We store neither your IP address nor your browser identifier. Messages are deleted automatically 180 days after receipt at the latest; the recipient can delete them earlier at any time. You can request deletion of your message at any time at the address given above.
If you create an employer account, we process the company data you provide (company name, website, name of the contact person, optionally a phone number) for the purpose of checking and activating your account and for fraud prevention. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures and performance of the contract).
The check is performed manually on the basis of publicly available sources (e.g. your website). If your account is rejected, we store the details and the decision for six months from the decision in order to prevent repeated misuse; after that they are deleted. The daily clean-up run performs the deletion automatically.
Candidate profiles you view through the candidate search come from the public applicant pool of the Bundesagentur fuer Arbeit. We do not store these profiles permanently; only short summaries you actively bookmark (occupations, location, availability) are assigned to your account until you remove them.
If you activate visibility to employers, we create a pseudonymised summary from your profile (job title, skills, location, qualifications - without name, contact details, photo and employer names) and show it to registered employers vetted by us in the candidate search. The legal basis is your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time with immediate effect - the summary is then deleted.
If an employer sends a contact request, you decide for each request whether your email address is released. Without your express release no contact details are transmitted. Addresses already released remain known to that employer after a withdrawal of visibility.