Privacy policy
Last updated: {{TODO: date of publication}}
This document is a template and requires legal review before production use.
Nothing below is legal advice. Every {{TODO: …}} placeholder must be replaced with WorkAmos's real details, and the finished text checked by a qualified data-protection lawyer. Remove this box and the noindex meta tag in src/routes/privacy.tsx only once that has happened.
1. Who is responsible for your data (data controller)
The controller of the personal data described in this policy is {{TODO: legal entity name}}, registered at {{TODO: registered address}}, company number {{TODO: company registration number}}.
You can reach us about anything in this policy at {{TODO: contact email address}}. {{TODO: state whether a Data Protection Officer has been appointed and, if so, their contact details. This is mandatory in the cases listed in Art. 37 GDPR}}
2. Why we process your data and on what legal basis
Each purpose below needs its own legal basis under Art. 6(1) GDPR. Do not reuse "legitimate interests" as a catch-all. For the consent-based items the basis is Art. 6(1)(a), and for delivering the service to a signed-up user it is normally Art. 6(1)(b).
- Creating and running Rover and Host accounts: {{TODO: legal basis, normally performance of a contract, Art. 6(1)(b)}}
- Publishing job listings and delivering applications between Hosts and Rovers: {{TODO: legal basis}}
- Messaging and reviews between users: {{TODO: legal basis}}
- Taking payment for Rover membership: {{TODO: legal basis}}
- Sending transactional email notifications: {{TODO: legal basis}}
- Non-essential cookies (preferences, analytics, marketing): consent, Art. 6(1)(a), collected through the cookie banner described in the cookie policy
- Keeping the platform secure and preventing fraud/abuse: {{TODO: legal basis}}
{{TODO: profile photos, CVs or free-text bios can reveal special-category data (Art. 9 GDPR) such as health or religion, state how that is handled or explicitly discouraged}}
3. What categories of personal data we process
- Account data: {{TODO: list, e.g. email, password hash, role, sign-up date}}
- Rover profile data: {{TODO: list, e.g. name, country, languages, availability dates, preferred destinations, bio, photo, CV file}}
- Host profile data: {{TODO: list, e.g. company name, location, business type, contact person, photos}}
- Content you create: {{TODO: listings, applications, messages, reviews}}
- Payment data: {{TODO: confirm what WorkAmos actually stores. This project keeps Stripe customer and subscription identifiers and a membership period end, while card details are handled entirely by Stripe and never reach WorkAmos servers}}
- Technical data: {{TODO: IP address, browser/user-agent, server log data, state what is logged and for how long}}
4. Who receives your data (processors and recipients)
Other WorkAmos users see what you deliberately publish: a Host sees the profile and application of a Rover who applies to them, and a Rover sees a Host's public listing. {{TODO: confirm and describe exactly what becomes visible to whom}}
We also use the following service providers, which act as processors for us:
- Supabase: database, authentication and file storage. {{TODO: hosting region, entity contracted with, data processing agreement reference}}
- Stripe: payment processing for Rover membership. {{TODO: Stripe entity, its role as processor or independent controller, DPA reference}}
- Resend: delivery of transactional emails. {{TODO: entity, hosting region, DPA reference}}
- Hosting / deployment platform: {{TODO: name the platform actually serving workamos.eu and its DPA; note that the platform may inject its own scripts, which WorkAmos's consent banner cannot control}}
- Google Fonts and Fontshare: web fonts are currently requested from these third-party CDNs on every page, which discloses visitors' IP addresses to them. {{TODO: either describe this transfer and its legal basis, or self-host the fonts and delete this bullet, self-hosting is the recommended fix}}
- Unsplash: some illustrative photographs are hotlinked from Unsplash's image CDN, which sees visitors' IP addresses. {{TODO: describe or remove by re-hosting the images on our own storage}}
- jsDelivr: the animation library used on the homepage is loaded from this CDN, which likewise sees visitors' IP addresses. {{TODO: describe or remove by bundling the library locally}}
- {{TODO: error monitoring, if one is ever added, see the note in the cookie policy}}
{{TODO: also state whether data is ever disclosed to authorities, and under what conditions}}
5. Transfers outside the EEA
{{TODO: for every processor above, state whether personal data leaves the EEA. If it does, name the safeguard relied on: Standard Contractual Clauses, an adequacy decision such as the EU/US Data Privacy Framework, or another Art. 46 mechanism, and say how a copy can be obtained}}
6. How long we keep your data
- Account and profile data: {{TODO: retention period and trigger, e.g. deleted N days after account closure}}
- Listings, applications, messages and reviews: {{TODO: retention period}}
- Invoices and payment records: {{TODO: statutory accounting retention period in the controller's country}}
- Server and security logs: {{TODO: retention period}}
- Cookie consent: the
workamos_cookie_consentcookie expires 6 months after your choice, after which we ask again.
7. Your rights
Under the GDPR you have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict processing (Art. 18), to data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
You can withdraw or change your cookie consent whenever you like using the Cookie settings link in the site footer.
You also have the right to lodge a complaint with a supervisory authority. {{TODO: name the lead supervisory authority for the controller's country and link to it}}
8. How to exercise your rights
Write to {{TODO: contact email for data subject requests}} and we will respond within one month, as required by Art. 12(3) GDPR. {{TODO: describe the identity-verification step, any self-service deletion in account settings, and the internal process for handling such requests}}
9. Changes to this policy
{{TODO: describe how users are told about material changes, and how the "last updated" date is maintained}}
