Draft — to be reviewed by a lawyer before public launch.
Privacy policy
Last updated 13 September 2026
This policy explains which personal data Hoijob processes when you use the web app at hoijob.ch, why, where, and for how long. It follows the Swiss Federal Act on Data Protection (revFADP / nDSG) and, where it applies to you, the EU General Data Protection Regulation (GDPR). If you received a job application sent with Hoijob, the information for recipients applies to you.
1. Who is responsible
The controller is:
Data-protection contact: legal@hoijob.ch.
Representative in the EU under Article 27 GDPR: [EU representative, if required — to be completed].
2. Data we process
- Sign-in. Your email address, and your name if you sign in with Google or Microsoft. Six-digit sign-in codes are stored hashed and expire after 5 minutes. Each session stores its IP address and browser user agent for security; sessions end after 30 days at the latest.
- CV and profile. The CV file you upload and the profile read from it and confirmed by you (experience, education, skills, languages, target roles, work permit, earliest start). Date of birth, photo and nationality are dropped by default and kept only if you choose to keep them.
- Search settings. Your field and specialisations, your base location and radius, commute modes and limits, and your sending caps.
- Companies. Employers found for you (commercial register Zefix, company websites, lists you import): name, address, website, published application address, estimated commute times and your shortlist decisions.
- Letters. Drafts and every version of your motivation letters and emails.
- Applications. Recipient address, subject, status, send and delivery events, and the caps and cool-down periods applied.
- Mailbox connection. For SMTP: server, port, user name and sender name and address; the SMTP password is stored encrypted (AES-256-GCM).
- Google and Microsoft. If you connect a Google or Microsoft mailbox, the OAuth tokens for a send-only permission (Gmail
gmail.send, Microsoft GraphMail.Send), stored encrypted. - Replies. Emails that employers send to your personal reply address (reply+…@hoijob.ch): sender, subject, text and date, so they can be matched to your application, classified and forwarded to you.
- Plan and payments. Your plan, the limits it includes, and the period it runs for. If you pay, Stripe or Revolut processes the payment: we store only their customer and subscription references, the plan, amounts, dates and payment status, never card numbers.
- Usage and activity. A count of the actions your plan limits (emails sent, AI letters, scans and imports, generated CVs), the days on which you were signed in and when you were last active, and for each AI request the feature, model, number of tokens and cost. No page views, no IP addresses and no content are kept for these counts.
3. Send-only access to Gmail and Microsoft
Gmail and Microsoft Graph access is send-only: Hoijob uses it to send the application emails you approve from your own mailbox. Mail is never read, listed, searched or deleted. Signing in with Google or Microsoft only reads your name and email address; the send permission is a separate step in Settings, and you can revoke it at any time with Disconnect or in your Google or Microsoft account settings.
Hoijob's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data received from Google APIs (your name, email address and the access tokens) is used only to sign you in and to send the emails you approve. It is not used for advertising, not sold, not used to train AI models, and not read by people unless you ask us to for support, it is needed for security, or the law requires it.
4. Purposes and legal basis
- Providing the service you signed up for: finding employers, drafting letters, sending the emails you approve and following up replies (GDPR Art. 6(1)(b)).
- Security, abuse prevention and sending limits, such as rate limits, sending caps and the suppression of addresses that objected (GDPR Art. 6(1)(f)).
- Keeping date of birth, photo or nationality only when you choose to (consent, GDPR Art. 6(1)(a) and Art. 9(2)(a) where applicable).
- Paid plans: taking payment, applying your plan's limits and keeping accounting records (GDPR Art. 6(1)(b) and (c)).
- Running and supporting the service: administrators see your account details, plan, and counts of your activity (for example emails sent, replies received, AI cost) and aggregated statistics across all users. They do not see your CV contents, your letters, employer replies or recipients' addresses (GDPR Art. 6(1)(f)).
We do not sell your data, do not use it for advertising and do not create profiles for third parties. Nothing is sent to an employer without your approval.
5. Processors and locations
We use these service providers, bound by data-processing agreements, only for the purposes listed:
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Hosting of the web app and its server functions | Server functions in Frankfurt (EU); US company |
| Supabase | Database (account, profile, companies, letters, applications, replies) | Zurich, Switzerland |
| Vercel Blob | Storage of uploaded CV files (private) | Frankfurt (EU) |
| Resend | Sign-in codes, receiving employer replies at your reply address, forwarding them to you | EU (Ireland) |
| Vercel AI Gateway → Anthropic | Reading your CV into a profile, drafting letters from your confirmed facts, classifying employer replies | Anthropic, USA |
| Postmark SpamCheck | Spam score of an email before you send it; receives the email text, never your CV | USA |
| geo.admin.ch (swisstopo) | Geocoding of your base location and of company addresses | Switzerland |
| openrouteservice (HeiGIT) | Car and bicycle travel times; receives coordinates only | Germany (EU) |
| Stripe Payments Europe Ltd. | Payment of paid plans by card or TWINT, receipts and the billing portal; receives your email address and payment details | Ireland (EU); Stripe group in the USA |
| Revolut Bank UAB | Payment of paid plans with Revolut Pay or card; receives your email address and payment details | Lithuania (EU) |
If you connect Google, Microsoft or another mailbox provider, your emails leave through that provider under its own terms. For the AI features, your CV, your confirmed profile facts, company facts and employer replies are sent to Anthropic through the Vercel AI Gateway; the spam check receives the email text and headers with a placeholder instead of your CV.
Transfers to the USA rely on the Swiss-U.S. and EU-U.S. Data Privacy Framework where the provider is certified, otherwise on standard contractual clauses: [safeguard per provider — to be completed].
6. How long we keep data
- Account, profile, companies, letters, applications and replies: as long as your account exists.
- Accounts without activity for 24 months are deleted together with all their data.
- Sign-in codes: 5 minutes. Sessions: 30 days at the latest.
- Days on which you were signed in: 13 months. Usage counts and AI usage records: 13 months.
- Payment and accounting records: 10 years, as Swiss law requires (Art. 958f CO), also after your account is deleted.
- Records of administrator actions on your account: 24 months; your email address is kept there only as a one-way hash.
- When you ask us to delete your account, we delete your data, including the CV file and stored tokens, unless the law requires us to keep it.
7. Security and cookies
All connections use TLS. SMTP passwords and OAuth tokens are stored encrypted, and access to production systems is restricted. Hoijob sets only the cookie needed to keep you signed in; there are no analytics or advertising cookies.
8. Your rights
You can ask for access to your data, a copy in a common format, correction, deletion or restriction, and you can object to processing or withdraw a consent at any time. Write to legal@hoijob.ch. You can also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch) or, in the EU, to the supervisory authority where you live.
9. Changes
We will update this policy when the service changes and show the date of the latest version at the top.