Your Data. Your Control.
What we collect, how we use it, who can see it. GDPR-aligned, in plain language.
Data Access by Role
See exactly what each party can and cannot access
Student Data Control
You own your data. You decide what to share and when.
Access & Controls
- +View all your data
- +Download your data (JSON/PDF)
- +Delete your account anytime
- +Control profile visibility
- +Choose what companies see
- +Revoke institution verification
Data Sharing
Data: Academic records, courses, grades, projects
Purpose: Verification only
Consent: Required
Data: First name + surname initial (e.g. "Fabio C."), institution, courses, grades, skills
Purpose: Searchable profile
Consent: Automatic when profile is public
Data: Full name, email, phone, LinkedIn
Purpose: Contact for opportunities
Consent: Automatic once you apply, reply to a recruiter, opt in to shortlist reveal, or are hired
How Your Data Flows
1. Student Creates Profile
- +Student enters academic info voluntarily
- +Institution verifies authenticity
- +Data encrypted at rest and in transit
2. Companies Browse
- -See first name + surname initial only (e.g. "Fabio C.")
- +See institution, courses, grades
- -Cannot see email, phone, full name
3. Contact
- +Company contacts you directly
- +Student gets notified immediately
- +Student can block future contact
Your GDPR Rights
Under the General Data Protection Regulation (GDPR), you have these fundamental rights
Right to Access
Request a copy of all your personal data we hold, in machine-readable format.
Export My DataRight to Erasure
Delete your account from your settings. Related records are anonymized or removed as the deletion runs.
Delete AccountRight to Rectification
Correct or update any inaccurate personal information at any time.
Edit ProfileRight to Restrict Processing
Limit how we process your data while maintaining your account.
Email usRight to Data Portability
Transfer your data to another service in a structured format.
Download & TransferRight to Object
Object to processing of your data for marketing or other purposes.
Email usHow We Protect Your Data
How your information is protected: encryption, access control and EU database hosting
AES-256 Encryption
Military-grade encryption at rest
TLS 1.3
Secure data transmission
Primary database in the EU
Neon Postgres in Frankfurt. Some sub-processors are outside the EEA — the processing page lists which, and on what transfer basis.
2FA Available
Two-factor authentication
Questions About Your Data?
Contact our Data Protection Officer (DPO) for any privacy concerns or to exercise your GDPR rights.
Export and deletion are immediate from your settings. For requests handled by email, the GDPR 30-day deadline applies.
For DPA-grade detail (sub-processors, retention periods, cross-border transfers, legal bases), see our Data Processing Details page.