jobdownup
PRIVACY POLICY

Your CV is yours. We never sell profiles to companies.

That is the whole point of this product. Every other job tool is paid by companies — recruiters, boards, ATS vendors — so the tool answers to them. jobdownup is paid by one person: you. Which means your data answers to you. Below is the full policy in plain language.

Effective 16 August 2026 · Applies to jobdownup.app and the jobdownup service
DRAFT — LEGAL REVIEW PENDING
Substantive template — not a substitute for advice from a qualified lawyer. Every placeholder in [[BRACKETS]] below must be filled with real information before ads run.

1. Who we are (data controller)

The controller of your personal data under GDPR Article 4(7) is:

  • jobdownup, operated by Filip Markovic (Einzelunternehmer)
  • Registered address: Maria-Fels-Straße 2, 93309 Kelheim, Bavaria, Germany
  • Contact: contact@jobdownup.app
  • Data-subject requests: contact@jobdownup.app

We are established in Germany. A Data Protection Officer is not mandatory for a business of our size and processing profile (Art. 37 GDPR), and none is currently appointed. You can reach the person responsible for privacy at the email above.

2. What we collect and why

The categories of personal data we process:

CategoryExamplesWhy
AccountEmail, hashed password, account creation date, timezoneTo create and secure your account
ProfileCV file, self-reported skills/experience, target roles, salary range, work-location preferencesTo score real roles against your profile
Search activityRoles you shortlisted, hid, or applied to; interview prep sessions; drafted messagesTo run your search and improve suggestions to you
BillingName and address as provided at checkout, currency, tax status; payment tokens held by our payment processorTo charge for the paid plan and issue invoices
TechnicalIP address, browser and device metadata, coarse country from IP, error logsTo operate the site securely, prevent fraud, debug incidents
Marketing (optional)Meta Pixel and Conversions API events (ViewContent, StartTrial, Subscribe) with UTM parametersTo measure ad performance. See Cookie Policy. Fires only after consent in EU/UK.

We do not collect special-category data (Art. 9 GDPR) intentionally. If your CV contains such data (health, religion, union membership, etc.) you provide it voluntarily so we can process it as part of your profile; you can remove it at any time.

3. Lawful bases (GDPR / UK-GDPR)

  • Contract (Art. 6(1)(b)): account, profile, search activity, and billing — we need these to provide the service you paid for.
  • Legitimate interests (Art. 6(1)(f)): security logs, fraud prevention, debugging, and product analytics with no personal-level segmentation. Our interest is running a safe, functional product; we balance it against your privacy and can justify the balance on request.
  • Consent (Art. 6(1)(a)): marketing cookies (Meta Pixel and Conversions API) in the EU/UK. You can withdraw consent at any time via the cookie banner or from /cookies.
  • Legal obligation (Art. 6(1)(c)): tax records, VAT invoice retention, complying with lawful requests.

4. How we use your data

  • To run your job search: read public company career pages, score roles against your profile, deliver morning briefs.
  • To coach you: mock-interview prep, message drafts, weekly reviews — using your actual pipeline, not invented content.
  • To operate and secure the service: session management, rate-limiting, incident response.
  • To bill you and issue compliant invoices.
  • To communicate with you about the service: transactional email only. We do not send marketing email without your explicit opt-in.
  • To measure ad performance and understand which creatives work — using only aggregated results wherever possible and, in the EU/UK, only after your consent.

We do not sell your data. We do not share your profile with employers, recruiters, ATS vendors, data brokers, "candidate marketplaces", or any other third party for their own purposes. This is not a promise for one region — it is the business model.

5. Sharing and subprocessors

To operate the service we rely on a small number of vetted processors. Each has a data processing agreement in place and is bound to process personal data only on our instructions. See the live list at /subprocessors.

Typical categories:

  • Hosting and edge network (Vercel Inc. — EU/US)
  • Payment processing (Stripe Payments Europe, Ltd. — EU/US)
  • AI/LLM inference for scoring and coaching (Anthropic PBC)
  • Transactional email (Resend)
  • Advertising measurement (Meta Platforms Ireland Ltd. — EU/US)
  • Authentication and account management (Clerk, Inc.)
  • Application database (Neon, Inc. — USA)
  • Webhook delivery (Svix, Inc. — EU)

6. International transfers

Some of our processors are based outside the EEA (primarily in the United States). Where personal data is transferred outside the EEA/UK, we rely on:

  • The EU-U.S. Data Privacy Framework where the processor is certified, or
  • The European Commission’s Standard Contractual Clauses (Module 2, Controller-to-Processor), together with a transfer risk assessment, or
  • An adequacy decision under Art. 45 GDPR where one applies to the destination country.

A copy of the safeguards for any specific transfer is available on request.

7. How long we keep it

DataRetention
Account & profileFor the life of your account. Deleted within 30 days of your deletion request.
Search activityFor the life of your account, or until you delete individual items.
Billing records10 years, per §147 AO (German tax law).
Access & security logs90 days.
Meta Pixel events (post-consent)Held by Meta per their retention policy; we hold aggregated ad-performance reports for 24 months.

8. Security

We take reasonable and appropriate technical and organizational measures to protect your data: encryption in transit (TLS 1.2+), encryption at rest for databases, least-privilege access, MFA on admin accounts, monitored access logs, and regular dependency updates. See /security for details.

No system is perfectly secure. If we become aware of a personal- data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours (Art. 33 GDPR) and notify you where required by Art. 34.

9. Your rights and how to exercise them

Regardless of jurisdiction, you can email contact@jobdownup.app to make a request. We aim to respond within 30 days (extendable by two months for complex requests, per Art. 12(3) GDPR). We will not charge you a fee unless the request is manifestly unfounded or excessive.

If you are in the EU or UK (GDPR / UK-GDPR)

  • Access (Art. 15): get a copy of the personal data we hold about you.
  • Rectification (Art. 16): correct inaccurate data.
  • Erasure (Art. 17): delete your account and personal data, subject to legal retention (billing).
  • Restriction (Art. 18): limit how we process your data in specific situations.
  • Portability (Art. 20): receive your data in a machine-readable format, or have it transmitted to another controller.
  • Objection (Art. 21): object to processing based on legitimate interests.
  • Withdraw consent at any time where processing is based on it (Art. 7(3)) — without affecting the lawfulness of processing before the withdrawal.
  • Complain to a supervisory authority — for Germany, the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA). For the UK, the Information Commissioner's Office (ICO) — ico.org.uk.

If you are a California resident (CCPA/CPRA)

  • Right to know the categories and specific pieces of personal information we collect, use, and disclose.
  • Right to delete personal information, subject to legal exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale/sharing. We do not sell personal information as defined by the CCPA. We do not "share" it for cross-context behavioral advertising in ways that require a “Do Not Sell or Share” link beyond the standard Meta consent flow — but if we ever do, this policy and the site will be updated accordingly.
  • Right to limit use of sensitive personal information.
  • Non-discrimination for exercising your rights.

You may designate an authorised agent to make a request on your behalf. We will verify the agent’s authority and your identity before disclosing personal information.

If you are in Australia (Privacy Act 1988 / APPs)

You have the rights described under the Australian Privacy Principles, including access (APP 12) and correction (APP 13). If you believe we have breached the APPs, you can complain to us first at contact@jobdownup.app; if unresolved, to the Office of the Australian Information Commissioner (OAIC) — oaic.gov.au.

If you are in New Zealand (Privacy Act 2020)

You have the rights described in Information Privacy Principles 6 (access) and 7 (correction). Complaints unresolved by us can be taken to the Office of the Privacy Commissioner NZ — privacy.org.nz.

10. Children

jobdownup is not directed to and not for use by children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal data, contact us at contact@jobdownup.app and we will delete it.

11. Changes to this policy

When we make material changes we will update the “Effective” date at the top and notify active users by email. Older versions are available on request.

12. Contact

Privacy questions and rights requests: contact@jobdownup.app
General contact: contact@jobdownup.app
Postal: Maria-Fels-Straße 2, 93309 Kelheim, Bavaria, Germany