JOBLOO

Privacy Policy

Last updated: April 21, 2026 · version 1.0

Preamble

This English translation is provided for convenience. In case of conflict, the French version available at jobloo.co/fr/privacy/ prevails.

This Privacy Policy explains how JOBLOO SASU ("the Company") collects, processes, uses, stores and protects personal data of users of the Jobloo service ("the User"), available from jobloo.co and the related iOS and Android applications (together, the "Service").

It is prepared in accordance with Regulation (EU) 2016/679 of 27 April 2016 (the "GDPR") and the French Data Protection Act of 6 January 1978, as amended.

1. Data Controller

The data controller is JOBLOO SASU, a French company registered with the Bobigny Trade and Companies Register under number 101 236 461.

The single point of contact for personal data requests is [email protected]. The publisher's full postal details are available in the Legal Notice.

In the absence of a regulatory obligation, the Company has not appointed a Data Protection Officer (DPO).

2. Data Collected, Purposes and Legal Bases

The Company collects only the data strictly necessary to provide the Service (data minimization, GDPR article 5.1.c).

Data categoryPurposeLegal basisRetention period
Identity (first name, last name, email, encrypted password)Account creation and managementContract performance (art. 6.1.b)Account lifetime + 30 days after deletion
SSO identifiers (Google ID, Apple ID)Authentication through third-party providersContract performance (art. 6.1.b)Account lifetime
CV, cover letter, work experience, education, skills, languagesApplication file preparation, ATS submission, cover letter generationContract performance (art. 6.1.b)Account lifetime + 30 days
Job search preferencesJob matching and personalizationContract performance (art. 6.1.b)Account lifetime + 30 days
Swipe and application historyApplication tracking, recommendation improvement, proof of mandate executionContract performance + legitimate interest for proof3 years from last activity
Emails received through the unified inbox (recruiter replies routed through @jobloo-mail.com aliases)Classification and display in the unified inboxContract performance (art. 6.1.b)Account lifetime + 30 days
Technical data (IP address, device ID, browser type, operating system)Security, fraud prevention, abuse preventionLegitimate interest (art. 6.1.f)12 months
Connection logsSecurity, incident investigation, legal obligationsLegal obligation + legitimate interest12 months
Billing dataSubscription execution, invoicing, accounting obligationsContract performance + legal obligation10 years
Referral codes and referral links usedReferral program managementContract performanceAccount lifetime

The Company does not knowingly collect sensitive data within the meaning of GDPR article 9. If a User chooses to include such information in a CV, the User does so under their own responsibility and authorizes its transmission to recruiter recipients of applications.

3. Recipients and Processors

User data may be accessed by the following categories of recipients, strictly to the extent necessary for their mission.

3.1 Recipients: recruiters and ATS platforms

When the User validates a job offer in order to apply, the Company transmits the elements necessary for the application to recruiters or applicant tracking systems (ATS): identity, CV, cover letter, contact details and answers to mandatory questionnaires. The platforms concerned depend on available offers and technical compatibility with the Service; they notably include Greenhouse, SmartRecruiters, Lever and Ashby.

Once the application is transmitted, the employer becomes an independent data controller for the transmitted data, according to its own privacy policy.

3.2 Categories of technical processors

Processor categoryRoleMain data location
Backend and database hostingApplication services and main PostgreSQL database hostingEuropean Union (Amsterdam, Netherlands)
User file storageObject storage for CVs and uploaded documentsEuropean Union (Paris, France)
CDN, DNS and network securityWebsite and web app distribution, DNS routing, web application firewall, edge processing for incoming emailsGlobal network with European points of presence
Artificial intelligence analysisAssistance with rewriting work experience descriptions and cover letters, through Mistral AI. Directly identifying data (name, email, phone number) is never sent to the model: deterministic application code filters data upstream and only sends elements strictly necessary for rewriting (job descriptions, titles, skills, city). Transmitted data is not used to train models.European Union (France)
PaymentsSubscription and credit pack payments through Stripe Payments Europe Ltd., an Irish entity. Jobloo does not collect or store card data. Any technical processing or Stripe processors outside the EU are covered by the safeguards in section 4.Contracting entity: Ireland (EU)
Transactional emailsVerification emails, notifications, application follow-up and recruiter reply routing to the unified inbox, operated by Brevo (Sendinblue SAS, Paris, France).European Union (France)
Job aggregation and geocodingCollection of public job postings and location normalization. No User personal data is transmitted to these services.European Union, countries benefiting from a European Commission adequacy decision

The nominative list of processors used for each category, and a copy of applicable contractual safeguards, may be obtained by written request to [email protected].

3.3 Third-party services initiated by the User

If the User chooses to authenticate through a Google or Apple account (optional), these companies directly receive the information necessary for authentication under their own privacy policies. They do not act as processors of the Company in that context.

The mobile applications are distributed through the official Apple App Store and Google Play stores. The Company does not transmit User personal data to these stores.

3.4 Other recipients

The Company may disclose User data to administrative or judicial authorities when legally required, to advisers for legal obligations or defense of rights, or to a successor in case of merger, acquisition or asset transfer.

4. Transfers Outside the European Union

Some processor categories may involve transfers outside the European Economic Area. These transfers are covered by adequacy decisions, the European Commission's standard contractual clauses, or, where applicable, the EU-US Data Privacy Framework for certified US providers.

The User may obtain a copy of safeguards for a specific transfer by contacting [email protected].

5. User Rights

Under GDPR articles 15 to 22, the User has rights of access, rectification, erasure, restriction, portability, objection, and the right not to be subject to automated individual decision-making. The User may also define instructions regarding personal data after death under French law.

These rights can be exercised from account settings for most account actions, or by email at [email protected].

The Company responds within one month, extendable by two months in complex cases. Proof of identity may be requested in case of reasonable doubt.

The User may also lodge a complaint with the competent supervisory authority, the CNIL.

6. Automated Decision-Making and Profiling

The Service uses algorithmic processing for job matching and Auto-Apply, which submits applications to ATS platforms when the User validates an offer through a Swipe Right.

These processes do not constitute automated decisions producing legal or similarly significant effects within the meaning of GDPR article 22.1: they automate tasks that the User would otherwise perform manually, at the User's request and under the User's control. The Company does not select or reject candidates; hiring decisions belong exclusively to recruiters.

The User remains in control of future applications by choosing which offers to validate in the Service.

7. Data Security

The Company implements appropriate technical and organizational measures, including password hashing, TLS transmissions, administrator multi-factor authentication, restricted access, sensitive access logs, encrypted backups and a data breach notification procedure where required by law.

No system is entirely invulnerable. In case of a relevant incident, Users will be informed according to regulatory obligations.

8. Cookies and Trackers

The Service uses only cookies and trackers strictly necessary for operation (session, language preference, security), which do not require prior consent under French law.

No analytics or targeted advertising cookie is placed without prior consent. If such cookies are introduced, a consent banner will be displayed.

9. Minors

The Service is reserved for persons aged at least sixteen (16). If the Company becomes aware that a minor under 16 created an account without parental authorization, the relevant data will be deleted without delay upon request to [email protected].

10. Changes to this Policy

The Company may modify this Privacy Policy at any time, in particular to comply with legal or regulatory changes. The User will be informed of any material change by in-app notification or email at least fifteen (15) days before it takes effect.

11. Contact

For any question relating to this Policy or to the exercise of User rights: