OpenJobs AI Inc. ("OpenJobs AI", "we", "us", "our") operates an AI-powered recruitment automation platform (the "Service") that helps businesses discover, evaluate, and engage potential candidates. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our Service or interact with us.
This policy applies to:
Account Information:
| Data Type | Examples | Purpose |
|---|---|---|
| Identity | Full name | Account creation, communication |
| Contact | Work email address | Account verification, notifications |
| Authentication | Password (hashed), Google OAuth token | Account security |
| Company | Company name, size, industry | Service customization |
| User source | How you heard about us (optional) | Marketing analytics |
Recruitment Content:
| Data Type | Examples | Purpose |
|---|---|---|
| Job descriptions | Role title, requirements, location, salary range | AI candidate matching |
| Candidate notes | Your evaluations, interview notes | Candidate management |
| Communications | Messages sent to/from candidates | Outreach management |
| Data Type | Examples | Purpose |
|---|---|---|
| Device information | Browser type, operating system, device identifiers | Service optimization, security |
| Usage data | Pages visited, features used, session duration | Product improvement, analytics |
| IP address | IPv4/IPv6 address | Security, approximate location |
| Log data | Access times, error logs, API calls | Debugging, security monitoring |
| Data Type | Examples | Purpose |
|---|---|---|
| Subscription details | Plan tier, billing cycle (monthly/annual), subscription start date | Service delivery |
| Credit transactions | Credits issued, consumed, expired; unlock history | Service delivery, usage tracking |
| Role quota usage | Roles created per period, quota resets | Service delivery |
| Payment history | Invoice amounts, payment dates, payment status | Billing, financial records |
| Billing metadata | Stripe Customer ID, Subscription ID | Payment processing |
Important: We do not collect or store your credit card number, CVV, or full payment card details. All payment information is processed directly by our payment processor, Stripe, Inc. (see Section 5.2).
We collect professional information about candidates from the following sources:
Publicly available sources:
Candidate-provided information (when candidates respond to outreach):
| Data Type | Source | Purpose |
|---|---|---|
| Professional profile | Public sources | AI candidate matching |
| Work history | Public sources | Qualification assessment |
| Skills and expertise | Public sources | Role matching |
| Contact information | Public sources / candidate-provided | Outreach |
| Response status | Candidate interaction | Candidate management |
The Service uses artificial intelligence and machine learning for the following purposes:
| AI Feature | Data Used | Output |
|---|---|---|
| Candidate Search | Job descriptions, skill requirements | Matched candidate profiles |
| Resume Screening | Candidate professional data, job requirements | Qualification assessments |
| Automated Outreach | Job descriptions, candidate profiles | Personalized outreach messages |
| Candidate Matching | Job requirements, candidate qualifications | Relevance scores |
Important disclosures about AI processing:
If you are located in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases:
| Legal Basis | Applicable Processing |
|---|---|
| Contract performance (Art. 6(1)(b) GDPR) | Account creation, subscription management, Credit/Role tracking, service delivery |
| Legitimate interest (Art. 6(1)(f) GDPR) | Service improvement, security, fraud prevention, analytics |
| Consent (Art. 6(1)(a) GDPR) | Marketing communications, optional analytics cookies |
| Legal obligation (Art. 6(1)(c) GDPR) | Tax records, regulatory compliance, law enforcement requests |
For candidate data sourced from public sources, we rely on legitimate interest (connecting candidates with relevant job opportunities). Candidates may opt out of outreach at any time (see Section 8).
We share information with third-party service providers who process data on our behalf:
| Provider Category | Examples | Data Shared | Purpose |
|---|---|---|---|
| Payment processing | Stripe, Inc. | Billing metadata, payment amounts | Subscription billing, invoice generation |
| Cloud infrastructure | AWS, Google Cloud | All Service data (encrypted) | Data storage, computing |
| AI/ML processing | Third-party AI providers | Job descriptions, candidate data (de-identified where possible) | Candidate matching, resume screening |
| Email delivery | Transactional email provider | Email addresses, notification content | Service notifications |
| Analytics | Product analytics tools | Usage data (aggregated) | Service improvement |
Stripe, Inc. processes all payment transactions. We do not have access to your full payment card details. Stripe's privacy policy is available at: https://stripe.com/privacy
When a candidate is matched with a Role and the employer unlocks the candidate using Credits:
Data Controller and Processor Roles for Outreach:
When employers use the automated outreach feature, OpenJobs AI acts as a data processor on behalf of the employer (the data controller). We process candidate data and deliver outreach communications based on the employer's instructions (creating Roles and initiating outreach). For details on responsibilities, see our Terms of Service, Section 8.4.
In the event of a merger, acquisition, bankruptcy, or sale of all or a portion of our assets, your information may be transferred to the successor entity. We will notify you via email and/or a prominent notice on the Service before your information becomes subject to a different privacy policy.
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to:
| Data Category | Retention Period | Trigger | Post-Retention |
|---|---|---|---|
| Active account data | Duration of active subscription | Account creation | N/A |
| Roles and candidate data | 90 days after subscription cancellation | Cancellation effective date | Archived to cold storage |
| Outreach records | 90 days after subscription cancellation | Cancellation effective date | Archived to cold storage |
| Account settings | 180 days after subscription cancellation | Cancellation effective date | Soft deleted |
| Billing and invoices | Minimum 7 years (Stripe retains invoice data permanently on their systems) | Invoice date | Retained for tax/legal compliance (IRS requires minimum 7 years) |
| Credit transaction logs | Minimum 7 years | Transaction date | Archived for financial audit |
| Webhook and payment logs | Minimum 7 years | Log date | Archived for financial audit |
| Candidate data (no engagement) | 12 months from last outreach attempt | Last outreach date | Deleted |
| Support communications | 3 years | Ticket closure date | Deleted |
Data archived to cold storage is:
When data reaches the end of its retention period:
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all communications |
| Encryption at rest | AES-256 encryption for stored data |
| Access control | Role-based access control (RBAC) with least-privilege principle |
| Authentication | Multi-factor authentication for internal systems |
| Payment security | PCI DSS Level 1 compliance via Stripe (no card data stored) |
| Infrastructure | Hosted on AWS/Google Cloud with SOC 2 compliance |
We are committed to implementing and maintaining the following organizational security measures:
The scope and maturity of these measures will evolve as our organization grows. We continuously evaluate and improve our security posture.
In the event of a personal data breach:
Regardless of your location, you may:
| Right | Description | How to Exercise |
|---|---|---|
| Access | Request a copy of your personal data | Email contact@openjobs-ai.com |
| Correction | Request correction of inaccurate data | Settings > Profile, or email us |
| Deletion | Request deletion of your personal data | Email contact@openjobs-ai.com |
| Data export | Export your data in CSV/JSON format | Settings > Billing > Export Data |
| Opt-out of marketing | Unsubscribe from promotional emails | Unsubscribe link in emails |
| Account deletion | Delete your account and associated data | Email contact@openjobs-ai.com |
If you are a candidate whose information appears on the platform:
| Right | Description | How to Exercise |
|---|---|---|
| Opt-out of outreach | Stop receiving recruitment messages | Unsubscribe link in outreach emails |
| Access | Request what information we hold about you | Email contact@openjobs-ai.com |
| Deletion | Request removal of your profile from the platform | Email contact@openjobs-ai.com |
| Correction | Request correction of inaccurate information | Email contact@openjobs-ai.com |
| Object to processing | Object to the use of your publicly available data | Email contact@openjobs-ai.com |
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
To exercise these rights, contact us at contact@openjobs-ai.com. As an online-only service, email is our designated method for receiving verifiable consumer requests (per Cal. Civ. Code § 1798.130(a)(1)). We will verify your identity before processing your request and will respond within 45 days (with a possible 45-day extension if reasonably necessary).
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following additional rights:
Automated Decision-Making Disclosure (GDPR Art. 22):
Our AI-powered features assist in candidate matching and assessment, but no fully automated decisions with legal effects are made. Employers make all final hiring decisions. You may request human review of any AI-assisted assessment by contacting us.
International Data Transfers:
Your data may be transferred to and processed in the United States, where OpenJobs AI is headquartered. For EEA/UK transfers, we use Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional technical and organizational safeguards.
| Cookie Type | Purpose | Examples | Optional? |
|---|---|---|---|
| Essential | Service functionality, authentication, security | Session cookies, CSRF tokens | No (required) |
| Payment | Fraud prevention, payment processing | Stripe.js cookies and device fingerprinting | No (required for payments) |
| Analytics | Usage analysis, service improvement | Google Analytics, product analytics | Yes (opt-out available) |
| Preferences | Remember your settings and preferences | Language, theme, billing cycle toggle | Yes |
Our payment processor, Stripe, uses cookies and device fingerprinting technology to detect and prevent fraud. These cookies are placed when you visit pages containing Stripe payment elements. For details, see Stripe's Cookie Policy: https://stripe.com/cookie-settings
You can manage cookie preferences through:
Note: Disabling essential cookies may impair Service functionality.
Some browsers offer a "Do Not Track" (DNT) setting that sends a signal to websites you visit. There is currently no universally accepted standard for how companies should respond to DNT signals. At this time, we do not respond to DNT signals. However, you may opt out of analytics cookies as described in Section 9.3 above. We will update this section if a uniform standard for DNT is established.
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly. If you believe a child has provided us with personal information, please contact us at contact@openjobs-ai.com.
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access through the Service.
We may update this Privacy Policy from time to time. For material changes, we will:
Your continued use of the Service after the effective date of the updated Privacy Policy constitutes acceptance. If you do not agree to the changes, you may cancel your subscription before the changes take effect.
For privacy inquiries, data requests, or complaints:
Data Protection Point of Contact (for EEA/UK inquiries):
Email: contact@openjobs-ai.com
Note: OpenJobs AI has not formally appointed a Data Protection Officer (DPO) under GDPR Article 37 at this time. If our processing activities reach the thresholds requiring a DPO (large-scale processing of special categories of data or systematic monitoring), we will appoint one and update this section accordingly. In the meantime, the above email serves as the primary contact for all data protection inquiries from EEA/UK residents.
We will respond to all privacy requests within 30 days, except where applicable law provides a different timeframe (e.g., CCPA allows up to 45 days with a possible 45-day extension).
OpenJobs AI uses AI systems in the recruitment domain, which is classified as "high-risk" under the EU AI Act (Regulation (EU) 2024/1689). We are committed to:
Our AI systems may reflect biases present in publicly available professional data sources. We are actively working to identify and mitigate such biases, but cannot guarantee that AI-generated outputs are entirely free from bias. Employers using the Service are responsible for making independent, non-discriminatory hiring decisions (see Terms of Service, Section 2.4).
We require Data Processing Agreements (DPAs) with all third-party service providers who process personal data on our behalf, in compliance with GDPR Article 28. We are in the process of executing DPAs with all current service providers and will ensure that DPAs are in place before any new service provider processes personal data on our behalf.
By using the Service, you acknowledge that you have read and understood this Privacy Policy.