Privacy policy
This Policy describes personal data processing by jobs.max3d.pl. The Service does not store candidate applications or operate a newsletter, but it uses analytics and — after obtaining any consent required — remarketing tools.
1. Data controller
The controller is kajda.com Adrian Kajda, Technologiczna 2, 45-839 Opole, Polish tax ID 637-193-99-09.
Privacy contact: adrian.kajda@gmail.com. The controller has not appointed a data protection officer.
2. Data we process
- Account data: user name, email address, hashed password, preferred language, email verification date and accepted document version.
- Company data: name, website, location, description, profile language, recruitment address and verification status.
- Job data: listing content and parameters, application destination and moderation, publication and deletion history.
- Technical and security data: session identifiers, security and password-reset tokens, the reCAPTCHA risk score, and technical information such as IP address, request time, URL, browser type, form-interaction signals and error details.
- Listing statistics: aggregate page views, Apply clicks and external redirects. These counters are available to the signed-in company and administrator, not publicly.
- Analytics and advertising data: visited pages, traffic source, approximate location, device and browser information, interactions with the Service, and cookie or similar identifiers. We use CookieYes to manage consent and Google Tag Manager, Google Analytics and Google advertising services for analytics, advertising measurement and remarketing. Google may link this data with information it holds under its own terms.
- Correspondence: messages, complaints, notices and appeals sent to the controller.
3. Purposes and legal bases
- Providing accounts, profiles and listings — performance of a contract or steps requested before entering into it (Article 6(1)(b) GDPR).
- Email verification, password reset, registration protection through Google reCAPTCHA, abuse prevention and maintenance — contract performance and the controller’s legitimate interest in a secure, reliable service (Article 6(1)(b) and (f)).
- Moderation, company verification, complaints and illegal-content notices — contract performance, legal obligations and legitimate interests in a trustworthy service (Article 6(1)(b), (c) and (f)).
- Basic listing statistics and service improvement — legitimate interests in measuring and improving the Service (Article 6(1)(f)).
- External traffic analytics — measuring Service usage, traffic sources and development effectiveness, based on consent (Article 6(1)(a)).
- Remarketing and advertising measurement — creating audiences, showing ads to previous Service visitors, limiting ad frequency and measuring campaign effectiveness, based on consent (Article 6(1)(a)).
- Establishing, exercising or defending legal claims — legitimate interests (Article 6(1)(f)).
- Future paid-service accounting — contract performance and legal tax or accounting obligations (Article 6(1)(b) and (c)). Standard publication is currently free and no payment data is collected.
Required fields are necessary to provide the relevant feature. Optional information may be omitted.
4. Public information
The company name, description, location, website and approved listings may be public. The login email is not published. A recruitment email or external URL is used after an Apply click, according to the company’s selection. Companies should not include unnecessary personal data in public content.
5. Candidates and applications
Apply reveals the recruitment email or redirects directly to an external page. The candidate sends the email, CV and attachments directly to the company or recruitment-system provider, which becomes responsible for the data it receives. The Service records only an aggregate click-counter increase.
6. Data recipients
Data may be made available as necessary to hosting, server, backup, IT support and email providers; CookieYes to display cookie settings, remember choices and maintain consent records; Google in connection with reCAPTCHA used as necessary registration security and, separately only after the relevant consent is given, Google Tag Manager, Google Analytics, advertising measurement and remarketing; legal, accounting and security advisers; competent public authorities; and, only after a paid service is launched and selected, a payment provider. We do not sell personal data. CookieYes and Google process data under applicable agreements, selected settings and their own legal obligations.
7. Transfers outside the EEA
Some email, infrastructure, analytics, advertising or support providers may process data outside the European Economic Area. Where this occurs, the controller relies on a GDPR transfer mechanism such as an adequacy decision or standard contractual clauses and applies supplementary safeguards where required.
8. Retention
- account, profile and job data — while the account and service remain active;
- deleted data — for secure removal from active systems and backups, and afterwards only as required by law, accounting duties or legal claims;
- terms acceptances, moderation decisions and relevant correspondence — until the applicable claim or accountability period expires;
- sessions and security tokens — for their validity and technical invalidation periods;
- the audit log of important account, company, job and administrator activity, including user identifier, time, IP address and browser information — normally for 365 days, longer only where an entry concerns an incident or claim;
- analytics and advertising data — for the retention period configured in the relevant tool, no longer than necessary for its purpose, or until consent is withdrawn; individual cookie lifetimes are available in the consent settings;
- future payment records — for statutory tax and accounting periods.
Data is deleted or irreversibly anonymised after the relevant period.
9. Your rights
Subject to GDPR conditions, you may request access and a copy, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Where consent is used, it may be withdrawn at any time without affecting earlier lawful processing.
You may lodge a complaint with the President of the Polish Personal Data Protection Office. Requests may be sent to adrian.kajda@gmail.com; identity verification may be required.
10. Cookies, analytics and remarketing
The Service uses cookies and similar information necessary for login, sessions, form protection and security. Disabling them may prevent account use. Consent is not required where these technologies are necessary to provide a requested service.
The registration form is protected by Google reCAPTCHA, which analyses technical signals and form interactions to assess automated-abuse risk. reCAPTCHA is loaded as security necessary to create an account, independently of analytics or advertising consent. We do not use its risk score for advertising or candidate assessment.
The Service uses CookieYes to manage consent and optional Google tools loaded through Google Tag Manager, including Google Analytics and Google advertising services. They help measure traffic and listing effectiveness, understand Service usage, measure campaigns and show Service advertising to people who previously visited it.
Optional analytics and advertising technologies are activated only after consent. Refusing consent does not restrict access to the Service. Consent can be changed or withdrawn at any time through the cookie settings as easily as it was given. Withdrawal does not affect processing carried out lawfully beforehand.
Separately, the Service maintains aggregate server-side listing view and click counters. They are not used to track a user across different websites.
11. Automated decisions and security
We do not make solely automated decisions producing legal effects. Remarketing may assign a browser or device to an advertising audience based on Service interactions, but it does not affect recruitment or candidate assessment. Company verification and job moderation are performed by an administrator.
Risk-appropriate safeguards include access controls, password hashing, email verification, session protection and backups. No online service can guarantee zero risk.
12. Policy changes
This Policy may be updated following changes in law, providers or Service functionality. Each version states its effective date. Material changes may also be communicated by email or through the dashboard.