JOBLOO
Privacy Policy
Last updated: April 21, 2026 · version 1.0
Preamble
This English translation is provided for convenience. In case of conflict, the French version available at jobloo.co/fr/privacy/ prevails.
This Privacy Policy explains how JOBLOO SASU ("the Company") collects, processes, uses, stores and protects personal data of users of the Jobloo service ("the User"), available from jobloo.co and the related iOS and Android applications (together, the "Service").
It is prepared in accordance with Regulation (EU) 2016/679 of 27 April 2016 (the "GDPR") and the French Data Protection Act of 6 January 1978, as amended.
1. Data Controller
The data controller is JOBLOO SASU, a French company registered with the Bobigny Trade and Companies Register under number 101 236 461.
The single point of contact for personal data requests is [email protected]. The publisher's full postal details are available in the Legal Notice.
In the absence of a regulatory obligation, the Company has not appointed a Data Protection Officer (DPO).
2. Data Collected, Purposes and Legal Bases
The Company collects only the data strictly necessary to provide the Service (data minimization, GDPR article 5.1.c).
| Data category | Purpose | Legal basis | Retention period |
|---|---|---|---|
| Identity (first name, last name, email, encrypted password) | Account creation and management | Contract performance (art. 6.1.b) | Account lifetime + 30 days after deletion |
| SSO identifiers (Google ID, Apple ID) | Authentication through third-party providers | Contract performance (art. 6.1.b) | Account lifetime |
| CV, cover letter, work experience, education, skills, languages | Application file preparation, ATS submission, cover letter generation | Contract performance (art. 6.1.b) | Account lifetime + 30 days |
| Job search preferences | Job matching and personalization | Contract performance (art. 6.1.b) | Account lifetime + 30 days |
| Swipe and application history | Application tracking, recommendation improvement, proof of mandate execution | Contract performance + legitimate interest for proof | 3 years from last activity |
Emails received through the unified inbox (recruiter replies routed through @jobloo-mail.com aliases) | Classification and display in the unified inbox | Contract performance (art. 6.1.b) | Account lifetime + 30 days |
| Technical data (IP address, device ID, browser type, operating system) | Security, fraud prevention, abuse prevention | Legitimate interest (art. 6.1.f) | 12 months |
| Connection logs | Security, incident investigation, legal obligations | Legal obligation + legitimate interest | 12 months |
| Billing data | Subscription execution, invoicing, accounting obligations | Contract performance + legal obligation | 10 years |
| Referral codes and referral links used | Referral program management | Contract performance | Account lifetime |
The Company does not knowingly collect sensitive data within the meaning of GDPR article 9. If a User chooses to include such information in a CV, the User does so under their own responsibility and authorizes its transmission to recruiter recipients of applications.
3. Recipients and Processors
User data may be accessed by the following categories of recipients, strictly to the extent necessary for their mission.
3.1 Recipients: recruiters and ATS platforms
When the User validates a job offer in order to apply, the Company transmits the elements necessary for the application to recruiters or applicant tracking systems (ATS): identity, CV, cover letter, contact details and answers to mandatory questionnaires. The platforms concerned depend on available offers and technical compatibility with the Service; they notably include Greenhouse, SmartRecruiters, Lever and Ashby.
Once the application is transmitted, the employer becomes an independent data controller for the transmitted data, according to its own privacy policy.
3.2 Categories of technical processors
| Processor category | Role | Main data location |
|---|---|---|
| Backend and database hosting | Application services and main PostgreSQL database hosting | European Union (Amsterdam, Netherlands) |
| User file storage | Object storage for CVs and uploaded documents | European Union (Paris, France) |
| CDN, DNS and network security | Website and web app distribution, DNS routing, web application firewall, edge processing for incoming emails | Global network with European points of presence |
| Artificial intelligence analysis | Assistance with rewriting work experience descriptions and cover letters, through Mistral AI. Directly identifying data (name, email, phone number) is never sent to the model: deterministic application code filters data upstream and only sends elements strictly necessary for rewriting (job descriptions, titles, skills, city). Transmitted data is not used to train models. | European Union (France) |
| Payments | Subscription and credit pack payments through Stripe Payments Europe Ltd., an Irish entity. Jobloo does not collect or store card data. Any technical processing or Stripe processors outside the EU are covered by the safeguards in section 4. | Contracting entity: Ireland (EU) |
| Transactional emails | Verification emails, notifications, application follow-up and recruiter reply routing to the unified inbox, operated by Brevo (Sendinblue SAS, Paris, France). | European Union (France) |
| Job aggregation and geocoding | Collection of public job postings and location normalization. No User personal data is transmitted to these services. | European Union, countries benefiting from a European Commission adequacy decision |
The nominative list of processors used for each category, and a copy of applicable contractual safeguards, may be obtained by written request to [email protected].
3.3 Third-party services initiated by the User
If the User chooses to authenticate through a Google or Apple account (optional), these companies directly receive the information necessary for authentication under their own privacy policies. They do not act as processors of the Company in that context.
The mobile applications are distributed through the official Apple App Store and Google Play stores. The Company does not transmit User personal data to these stores.
3.4 Other recipients
The Company may disclose User data to administrative or judicial authorities when legally required, to advisers for legal obligations or defense of rights, or to a successor in case of merger, acquisition or asset transfer.
4. Transfers Outside the European Union
Some processor categories may involve transfers outside the European Economic Area. These transfers are covered by adequacy decisions, the European Commission's standard contractual clauses, or, where applicable, the EU-US Data Privacy Framework for certified US providers.
The User may obtain a copy of safeguards for a specific transfer by contacting [email protected].
5. User Rights
Under GDPR articles 15 to 22, the User has rights of access, rectification, erasure, restriction, portability, objection, and the right not to be subject to automated individual decision-making. The User may also define instructions regarding personal data after death under French law.
These rights can be exercised from account settings for most account actions, or by email at [email protected].
The Company responds within one month, extendable by two months in complex cases. Proof of identity may be requested in case of reasonable doubt.
The User may also lodge a complaint with the competent supervisory authority, the CNIL.
6. Automated Decision-Making and Profiling
The Service uses algorithmic processing for job matching and Auto-Apply, which submits applications to ATS platforms when the User validates an offer through a Swipe Right.
These processes do not constitute automated decisions producing legal or similarly significant effects within the meaning of GDPR article 22.1: they automate tasks that the User would otherwise perform manually, at the User's request and under the User's control. The Company does not select or reject candidates; hiring decisions belong exclusively to recruiters.
The User remains in control of future applications by choosing which offers to validate in the Service.
7. Data Security
The Company implements appropriate technical and organizational measures, including password hashing, TLS transmissions, administrator multi-factor authentication, restricted access, sensitive access logs, encrypted backups and a data breach notification procedure where required by law.
No system is entirely invulnerable. In case of a relevant incident, Users will be informed according to regulatory obligations.
8. Cookies and Trackers
The Service uses only cookies and trackers strictly necessary for operation (session, language preference, security), which do not require prior consent under French law.
No analytics or targeted advertising cookie is placed without prior consent. If such cookies are introduced, a consent banner will be displayed.
9. Minors
The Service is reserved for persons aged at least sixteen (16). If the Company becomes aware that a minor under 16 created an account without parental authorization, the relevant data will be deleted without delay upon request to [email protected].
10. Changes to this Policy
The Company may modify this Privacy Policy at any time, in particular to comply with legal or regulatory changes. The User will be informed of any material change by in-app notification or email at least fifteen (15) days before it takes effect.
11. Contact
For any question relating to this Policy or to the exercise of User rights:
- Email: [email protected]
- Postal mail: JOBLOO SASU, Data Protection Service, 3 rue Charles Cathala, 93360 Neuilly-Plaisance, France