Controller
[Configure operator name]
[Configure operator postal address]
Privacy contact: [Configure privacy contact email]
Data used by the service
- Account identity, password hash, and browser-session records.
- Compass answers, structured preferences, corrections, and profile history.
- Optional CV text and the evidence you explicitly merge.
- Saved jobs, references, matching evidence, commute estimates, feedback, and application states.
- Privacy-safe operational metadata such as provider name, purpose, duration, result count, failure type, and configured cost estimate.
Do not enter health data, political opinions, religion, trade-union membership, biometric data, sexual orientation, or other special-category information into the alpha.
Purposes and legal basis
Account and service data is processed to deliver the requested job-search workspace, secure the service, preserve user decisions, and provide export or deletion. The operator must document the applicable GDPR legal basis for each production purpose before launch; this draft does not convert all processing into consent.
External providers
Depending on deployment configuration, structured extraction, public-web discovery, employer research, and routing may use OpenAI, Brave Search, Exa, Google Routes, Transitous, Valhalla/FOSSGIS, OpenRouteService, or public ATS feeds. BetterOption sends only the information needed for that task. The operator must complete processor, subprocessor, transfer, retention, and contract reviews for every enabled provider.
Retention and control
You can export account data and delete the account from Account. Deletion removes the private account aggregate; public job-source records may remain in the shared corpus because they are not private profile data. Provider-side retention and backups require separate production policies and verification.
Your rights
Depending on the circumstances, GDPR rights can include access, rectification, erasure, restriction, portability, objection, and a complaint to a supervisory authority. Contact the configured privacy address. Identity verification may be required before fulfilling a request.
Security and changes
The engineering baseline uses tenant isolation, password hashing, HttpOnly sessions, deletion cascades, output escaping, SSRF-aware URL ingestion, secret-safe configuration, and metadata-only operational ledgers. No software can promise absolute security. Material notice changes receive a new version and can be acknowledged from Account.