Privacy

Privacy policy

This policy explains clearly what data Joblix processes, why it is needed and which rights you have.

Last updated: August 29, 2026

1. Controller

The controller responsible for processing personal data is: Dominik Bueren Joblix Felix-Hollenberg-Weg 32 46539 Dinslaken Germany Phone: +49 1575 1407091 Email: privacy@hirenio.com

2. Scope and principles

This privacy policy applies to hirenio.com and the Joblix platform offered there. We process personal data only to the extent required to operate and secure the service, provide functions you request or where you have given consent.

We follow the principle of data minimisation. Candidate profiles are not fully public by default. You control visibility and company disclosures yourself.

3. Website access and security

When you access the service, our infrastructure processes technically necessary connection data, including IP address, time, requested address, browser and device information, referrer, status and error data. We use this data for secure delivery, diagnostics, abuse prevention and stability.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the platform. Security logs are retained only as long as necessary for these purposes or legal obligations.

4. Account and sign-in

When you register or sign in, we process identity and contact data such as name, email address, login identifier, account type, language, time zone and security events. Authentication is provided through WorkOS AuthKit.

The legal basis is Article 6(1)(b) GDPR for performing the user agreement and Article 6(1)(f) GDPR for account security and abuse prevention.

5. Career profiles, preferences and company data

Candidates may provide professional experience, education, skills, salary expectations, preferred roles, work model, availability, dealbreakers and visibility settings. Companies may manage organisation details, members, jobs, requirements, salary ranges, hiring processes and benefits.

We process this information to provide your profile or company workspace, identify suitable jobs and profiles and perform the recruiting functions you request. The legal basis is Article 6(1)(b) GDPR. Optional information may be changed or deleted at any time.

6. Matching and company opportunities

Joblix compares structured information such as salary limits, work model, location, role, experience and skills. Dealbreakers are applied transparently; supplementary semantic signals may only be one factor. Companies may then send a specific opportunity to which the candidate can respond.

We do not make decisions based solely on automated processing that produce legal or similarly significant effects, and generative AI does not automatically reject candidates. The legal basis is Article 6(1)(b) GDPR, with security and quality controls additionally based on Article 6(1)(f) GDPR.

7. Disclosures, messages, meetings and offers

After mutual interest, we process profile disclosures, messages, read status, meeting proposals, hiring stages and offer information. Disclosures are logged so it remains clear which company was allowed to view which information. You may withdraw revocable disclosures for the future.

The legal basis is Article 6(1)(b) GDPR. Audit and security logs are processed on the basis of Article 6(1)(f) GDPR.

8. Documents and files

When file uploads are enabled, CVs, certificates and other files you upload are stored in private Cloudflare R2 storage. Access is authorised and time-limited. Metadata such as file name, type, size, storage identifier and creation time is held by the platform.

Files are not made public or used for advertising. Processing is based on Article 6(1)(b) GDPR. This function will only be activated once secure upload is fully configured.

9. Email and payments

Transactional messages such as account, meeting and offer notifications are sent through Resend. We process the email address, language, message type and delivery information. The legal basis is Article 6(1)(b) GDPR and, for security messages, Article 6(1)(f) GDPR.

Paid company services are processed through Stripe. Stripe processes contact, billing, payment and transaction information as a controller or processor under its privacy notice. Joblix does not store complete credit card details. The legal basis is Article 6(1)(b) and (c) GDPR.

10. Strictly necessary storage

We currently use only technically necessary cookies or comparable storage for sign-in, session protection, language and security features. These are permitted under Section 25(2) TDDDG where strictly necessary to provide the service explicitly requested.

We currently do not use optional advertising or profiling cookies and therefore do not display a consent banner. If this changes, consent will be obtained before any optional storage occurs.

11. Recipients and service providers

We use carefully selected providers where necessary: Cloudflare for networking, delivery and private file storage; Convex for database and backend; WorkOS for authentication; Resend for transactional email; and Stripe for company payments.

Providers receive only data required for their task and are bound by data processing agreements where necessary. Within a company, only authorised members can access data disclosed for their role.

12. International transfers

Some providers may process data in the United States or other countries outside the European Economic Area. Depending on the provider, we rely on an adequacy decision, including the EU-US Data Privacy Framework, or EU Standard Contractual Clauses and supplementary safeguards. Further information is available on request.

13. Retention and deletion

We retain data only while your account or the relevant process exists and the information is required for the stated purposes. We then delete or anonymise it unless legal retention duties, the establishment or defence of claims, security reasons or valid consent justify further retention.

Accounts can be deleted using the available account functions. Company billing records are retained for applicable commercial and tax periods. Backups are overwritten through their regular lifecycle.

14. Your rights

Subject to the GDPR, you have rights of access, rectification, erasure, restriction, data portability and objection. You may withdraw consent at any time for the future. Where processing relies on Article 6(1)(f) GDPR, you may object for reasons arising from your particular situation.

To exercise your rights, contact the email address above. We may request reasonable proof of identity to protect your account. You may also complain to a data protection authority, in particular the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, poststelle@ldi.nrw.de.

15. Changes to this policy

We update this policy when functions, providers or legal requirements change. The current version remains available on this page. We will provide appropriate notice of material changes.