Skip to content

GDPR & Data Requests

How to exercise your rights, who processes your data, and where it is stored.

Last updated

Who this is for

This page is for users in the EU, UK, and other GDPR-equivalent jurisdictions, plus enterprise customers’ legal and procurement teams. Most data subject requests can be completed in seconds with the self-serve buttons on your account page.

Self-serve: fastest path

  • Export your data: the “Export my data” button on the account page produces a JSON file with everything we hold (profile, tracked jobs, search history, resume text, alerts).
  • Delete your account: the “Delete account” button immediately removes your profile, CV, tracked jobs, searches and alerts from our live database. There is no soft-delete and no recovery window. Two carve-outs, both disclosed on Privacy: encrypted off-site backups roll off on a 14-day cycle, and administrator audit-log entries are kept for accountability.
  • Edit your profile: your display name is editable on the account page.

Self-serve completes in seconds. Use email-based requests only if self-serve doesn’t fit your need.

Email-based requests

For any other data subject request, email privacy@jobzyl.com with the subject line DSAR: <type of request>. Include the email address on your Jobzyl account so we can verify your identity.

We will respond within:

  • 30 days for GDPR / UK GDPR requests (Art. 12(3)). Extendable by 60 days for complex requests, with notice.
  • 45 days for CCPA / CPRA requests. Extendable by 45 days, with notice.

What rights you have

  • Access: get a copy of your personal data.
  • Rectification: correct inaccurate data.
  • Erasure (“right to be forgotten”): have your data deleted.
  • Restriction: pause processing while a dispute is resolved.
  • Portability: receive your data in a machine-readable format (the JSON export).
  • Objection: object to processing for direct marketing or based on legitimate interests.
  • Withdraw consent: for processing based on consent (e.g. analytics opt-in).
  • Lodge a complaint: with your supervisory authority.

Automated decision-making (Art 22)

We use Anthropic Claude (Haiku) to produce advisory automated outputs: cover-letter drafts, interview prep, and CV-tailoring tips. The CV match score is not among them - it is computed in our own database or in your browser and never reaches a third party. None of these gate your access to features, and none are used to make legal or similarly significant decisions. If you disagree with a score or want a human to review the output, email privacy@jobzyl.com and we will manually review within 30 days. You can contest a score or output in the same email.

Data controller

Jobzyl, operated by Hammad Ahmad. Contact: privacy@jobzyl.com.

Personal data is stored on our self-hosted database (a PostgreSQL/Supabase stack we operate ourselves) on Oracle Cloud Infrastructure in Frankfurt, Germany (EU). The backend application is served from AWS App Runner (Frankfurt, eu-central-1). The static frontend is served from AWS S3 with CloudFront (origin in EU; edges global). Some processing is performed in the United States by Anthropic (AI) and Logo.dev (company logo images); see “International transfers” below for safeguards. Error tracking runs in Sentry’s EU region in Germany, so it is not among them.

Sub-processors

  • Oracle Cloud Infrastructure: Hosts our self-managed database and authentication server (a self-hosted Supabase/PostgreSQL stack at sb.jobzyl.com). Oracle provides the server only; it has no access to the data. EU (Frankfurt, eu-frankfurt-1).
  • AWS App Runner: Backend application hosting (Frankfurt, eu-central-1). EU (eu-central-1).
  • AWS S3 + CloudFront: Static frontend hosting (origin in eu-central-1; CloudFront edges global). EU (S3 origin EU, edges global).
  • Resend: Transactional email (account verification, OTP, password reset, support replies) and the job-alert digests you subscribe to. Every digest carries a one-click unsubscribe link. EU.
  • Plausible: Anonymous, aggregated traffic analytics. No cookies. EU (plausible.io). Loaded only after your consent.
  • PostHog: Product behaviour analytics (feature usage, funnels). Autocapture and session recording disabled; identified-only profiles. EU (eu.i.posthog.com). Loaded only after your consent.
  • Anthropic: Cover-letter generation, interview prep, and CV-tailoring tips. The CV match score is not one of these: it is computed in our own database or in your browser and is never sent to Anthropic. Data is processed transiently; per Anthropic API terms, content is not used to train models. US.
  • Sentry: Backend error tracking and performance monitoring. send_default_pii is disabled and stack-frame local variables are not sent, so exception traces carry the file, line and error chain but not the data in scope. URL paths are captured. EU (ingest.de.sentry.io (Germany)).
  • Logo.dev: Company logo images on job cards. The request carries the employer's domain and no user data. Only fired for employers whose domain we can verify; everyone else renders as initials. US (img.logo.dev). Loaded only after your consent.

International transfers

Where personal data is transferred outside the EU/UK we rely on the European Commission’s Standard Contractual Clauses (Module 2 controller-to-processor) and, for UK data, the UK International Data Transfer Addendum (IDTA). Specifically:

  • Anthropic, United States. EU SCCs Module 2 + UK IDTA addendum
  • Logo.dev, United States. EU SCCs

We do not transfer data to any country without an adequacy decision unless an SCC- or IDTA-equivalent safeguard is in place. A current copy of the relevant agreement is available on request.

Supervisory authorities

If you believe we have not handled your data correctly, you may complain to:

  • The UK Information Commissioner’s Office (ICO) at ico.org.uk.
  • Your EU member state’s data protection authority. The full list is at edpb.europa.eu.
  • The California Attorney General at oag.ca.gov.

Contact

Privacy questions: privacy@jobzyl.com. General support: support@jobzyl.com.