Privacy Policy
Datenschutzerklärung — how we process personal data (GDPR / DSGVO)
Last updated: —
[bracketed] placeholder and have your data-protection officer / lawyer confirm the final wording before launch. A German-language version may be legally required.1. Controller
The controller responsible for processing within the meaning of the GDPR is:
[COMPANY LEGAL NAME], [ADDRESS]
Email: [EMAIL] · Phone: [PHONE]
Data protection officer (if appointed): [NAME / EMAIL, or “not required”].
2. What data we process
Account data: name, email address, hashed password, role, and (if enabled) two-factor authentication data.
Content you upload: CSV datasets and the project configurations you create. These datasets may contain personal data of third parties (e.g. candidates). You are responsible for having a lawful basis to upload and process that data.
Usage & security data: audit logs of sensitive actions, login attempts, and technical data such as IP address and browser user-agent.
3. Purposes & legal bases
We process the above to provide the service and your account (Art. 6(1)(b) GDPR — performance of a contract), to keep the service secure and prevent abuse (Art. 6(1)(f) — legitimate interest), and to meet legal obligations where applicable (Art. 6(1)(c)). For any processing based on consent, the basis is Art. 6(1)(a). [Confirm bases with counsel.]
4. Recipients & processors
We host and store data with the following processors, under data-processing agreements (AVV), in the EU:
Hetzner Online GmbH (Germany) — server hosting and encrypted object storage (Falkenstein, DE).
IONOS SE (Germany) — domain and transactional email.
Uploaded files are encrypted at rest; we do not sell or share personal data with advertisers.
5. Storage location & retention
Data is stored in the European Union. We keep account data for the life of the account and delete or anonymise it after closure. Datasets are kept until you delete them. Audit logs and login records are retained for [RETENTION PERIOD, e.g. 12 months] and then deleted. [Confirm retention periods with counsel.]
6. Cookies
We use only a strictly necessary cookie to keep you signed in. We do not use advertising or tracking cookies, so no cookie-consent banner is required.
7. Security
We apply appropriate technical and organisational measures, including TLS encryption in transit, AES-256 encryption of stored datasets, hashed passwords, role-based access control, optional two-factor authentication, and audit logging.
8. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to object (Art. 21). To exercise these, contact [EMAIL]. You also have the right to lodge a complaint with a supervisory authority — for example [COMPETENT STATE DPA, e.g. the data protection authority of your federal state].
9. Changes
We may update this policy; the current version is always available on this page.