Privacy Policy

Last updated: 3 August 2026.

Who we are. JobLake is operated by Open Dev GmbH (Switzerland), the data controller for personal data processed through the service.

What we collect. Only data about you, and only what the service needs:

  • Account and sign-in data — your email address, optional name, optional password (stored hashed), sign-in method (email code, Google, or LinkedIn), and short-lived login codes.
  • Profile data you provide — your roles, education, skills, languages, and summary. If you upload a CV, we extract these fields from it only with your explicit consent, given via a required checkbox at upload.
  • Job preferences — the criteria you set to steer your ranking (titles, locations, work mode, and similar).
  • Feedback labels — jobs you mark (e.g. saved / not interested), used to tune your own ranking.
  • Jobs you capture — job postings you explicitly submit via the browser extension. Captures backed by a public URL join JobLake’s shared catalog; text-only manual entries remain private to you.
  • Your own LinkedIn data — only if you run the LinkedIn (DMA) import yourself, with your consent, and only your own data.

Analytics. With your consent, we use Google Analytics 4 to understand how JobLake is used (pages visited, approximate region, device type). Analytics cookies are set only after you accept them in the cookie banner; you can withdraw your choice at any time in Settings → Privacy & data. If you decline, no analytics data is collected.

No third-party person data. We do not collect or store personal data about recruiters, hiring managers, or any person other than you. Job-capture endpoints strip any such fields, and historical recruiter data has been deleted.

Why we process it, and on what legal basis. Providing the matching service — account management, storing your profile and preferences, ranking jobs for you, and sending login codes — is based on the performance of our contract with you (GDPR Art. 6(1)(b)). CV parsing and the LinkedIn (DMA) import are based on your explicit consent (Art. 6(1)(a)), recorded per purpose with the policy version and timestamp; you can withdraw consent at any time by deleting the imported data or your account.

Automated ranking — how it works. Job matching is automated: we combine semantic similarity between your profile and each job description with your stated preferences and your feedback labels. This ranking only orders job suggestions for you — it does not make any decision with legal or similarly significant effects. You always decide where to apply, and you control the ranking through your profile, preferences, and feedback.

Your rights, wired into the product.

  • Export — download a full JSON export of your data in Settings → Privacy & data.
  • Deletion — delete your account and all your data in Settings → Privacy & data (including jobs only you contributed).
  • Rectification — correct your data directly on the profile and preferences pages.

You also have the rights to access, restriction, objection, and data portability under the GDPR / Swiss nLPD, and the right to lodge a complaint with a supervisory authority.

Retention. Login codes are deleted after about one day; rate-limit records after 2 days; and job-capture associations after 365 days. JobLake does not store a raw copy of LinkedIn pages. Your account data is kept until you delete your account. Cleanup runs automatically every day.

Processors. We use Microsoft Azure (hosting, database, storage and AI), Azure Databricks (data processing), Vercel (web hosting), and SendGrid (login and transactional email). Regional AI deployments process in Switzerland North; GlobalStandard deployments may process outside Switzerland or the EU/EEA. Applicable transfers are governed by Microsoft’s Data Processing Addendum and Standard Contractual Clauses.

Payments. If you subscribe to JobLake Plus, payments are processed by Stripe Payments Europe, Ltd. (Ireland). Your card details are entered directly on Stripe’s payment pages and never reach our servers. Stripe receives the data needed to process the subscription (your email address, billing details, card information and country) and acts as our payment processor; for some purposes, such as fraud prevention and its own legal obligations, Stripe acts as an independent controller under its own privacy policy. We store only your plan, subscription status, billing period and opaque Stripe reference ids. Processing is based on the performance of our contract with you (GDPR Art. 6(1)(b)); accounting records are kept as long as accounting law requires (up to 10 years under Swiss law), even after account deletion. Where Stripe transfers data outside the EU/EEA, the transfer is covered by Standard Contractual Clauses and Stripe’s certification under the EU-U.S. Data Privacy Framework.

Contact. For privacy requests or questions: privacy@open-dev.ch