Skip to main content
GDPR-aligned

Your Data. Your Control.

What we collect, how we use it, who can see it. GDPR-aligned, in plain language.

EU GDPR-aligned
TLS 1.3 + AES-256
Data Portability

Data Access by Role

See exactly what each party can and cannot access

Student Data Control

You own your data. You decide what to share and when.

Access & Controls

  • +View all your data
  • +Download your data (JSON/PDF)
  • +Delete your account anytime
  • +Control profile visibility
  • +Choose what companies see
  • +Revoke institution verification

Data Sharing

Shared with: Academic Partner

Data: Academic records, courses, grades, projects

Purpose: Verification only

Consent: Required

Shared with: Companies (browsing)

Data: First name + surname initial (e.g. "Fabio C."), institution, courses, grades, skills

Purpose: Searchable profile

Consent: Automatic when profile is public

Shared with: Companies (after you apply or reply)

Data: Full name, email, phone, LinkedIn

Purpose: Contact for opportunities

Consent: Automatic once you apply, reply to a recruiter, opt in to shortlist reveal, or are hired

How Your Data Flows

01

1. Student Creates Profile

  • +Student enters academic info voluntarily
  • +Institution verifies authenticity
  • +Data encrypted at rest and in transit
02

2. Companies Browse

  • -See first name + surname initial only (e.g. "Fabio C.")
  • +See institution, courses, grades
  • -Cannot see email, phone, full name
03

3. Contact

  • +Company contacts you directly
  • +Student gets notified immediately
  • +Student can block future contact

Your GDPR Rights

Under the General Data Protection Regulation (GDPR), you have these fundamental rights

01

Right to Access

Request a copy of all your personal data we hold, in machine-readable format.

Export My Data
02

Right to Erasure

Delete your account from your settings. Related records are anonymized or removed as the deletion runs.

Delete Account
03

Right to Rectification

Correct or update any inaccurate personal information at any time.

Edit Profile
04

Right to Restrict Processing

Limit how we process your data while maintaining your account.

Email us
05

Right to Data Portability

Transfer your data to another service in a structured format.

Download & Transfer
06

Right to Object

Object to processing of your data for marketing or other purposes.

Email us

How We Protect Your Data

How your information is protected: encryption, access control and EU database hosting

01

AES-256 Encryption

Military-grade encryption at rest

02

TLS 1.3

Secure data transmission

03

Primary database in the EU

Neon Postgres in Frankfurt. Some sub-processors are outside the EEA — the processing page lists which, and on what transfer basis.

04

2FA Available

Two-factor authentication

Questions About Your Data?

Contact our Data Protection Officer (DPO) for any privacy concerns or to exercise your GDPR rights.

Export and deletion are immediate from your settings. For requests handled by email, the GDPR 30-day deadline applies.

For DPA-grade detail (sub-processors, retention periods, cross-border transfers, legal bases), see our Data Processing Details page.