Privacy Policy
This policy explains how we collect, use and protect your personal data when you use InfinitumJobs, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish LOPDGDD.
1. Data controller
The controller of your personal data is InfinitumJobs, owned by [LEGAL ENTITY TBD], Tax ID [TBD], with registered office at [ADDRESS TBD], Spain. You can contact us at info@infinitumjobs.com for any matter related to the processing of your data or the exercise of your rights.
2. Personal data we collect
We collect only the data strictly necessary to provide the service. Specifically: (a) identification data — first name, last name, email, optional photo; (b) contact data — phone, professional links (LinkedIn), contact preferences; (c) professional data — education, work experience, skills, languages, technical knowledge, certifications, references; (d) technical data — IP address (stored as SHA-256 hash), user agent, session identifiers; (e) consent data — immutable record of consents granted, with timestamp.
3. Purposes of processing
We use your data to: (a) create and maintain your user account; (b) allow presentation of your professional profile to authorised companies; (c) process your CV using artificial intelligence when you expressly authorise it; (d) ensure service security (fraud prevention, rate limiting, auditing); (e) send you essential service communications (email verification, password reset); (f) send you commercial communications only if you grant separate explicit consent.
4. Legal basis
The legal bases that legitimise each processing activity are: (a) contract performance (Art. 6.1.b GDPR) for account creation, profile management and service provision; (b) consent (Art. 6.1.a GDPR) for AI CV processing, commercial communications and public profile visibility; (c) legitimate interest (Art. 6.1.f GDPR) for platform security and fraud prevention; (d) legal obligation (Art. 6.1.c GDPR) when required by applicable regulations.
5. Retention periods
We retain your data while your account is active. If you request deletion, data is removed or anonymised within a maximum of 30 days, unless legislation requires retention (e.g., to respond to legal requirements). Security and audit logs are kept for 90 days. IP addresses stored as hash are removed after 90 days. Consents are recorded immutably as legal proof of the authorisations granted.
6. Recipients and processors
We do not sell or transfer your data to third parties for commercial purposes. We share data only with the following processors, with whom we maintain contracts guaranteeing GDPR compliance: (a) Hostinger — website and database hosting (Lithuania/EU); (b) OpenAI — AI CV processing, only if you authorise it (United States, with Standard Contractual Clauses); (c) Google — OAuth authentication and reCAPTCHA services; (d) transactional email provider (Hostinger or Mailrelay) — sending service emails. Where applicable, competent judicial or administrative authorities upon legal request.
7. International transfers
Some of the processors mentioned (notably OpenAI and Google) are located outside the European Economic Area. These transfers are carried out on the basis of Standard Contractual Clauses approved by the European Commission, or other appropriate safeguards provided in Chapter V of the GDPR.
8. Rights of the data subject
You can exercise the following rights recognised by the GDPR and LOPDGDD at any time: access, rectification, erasure ("right to be forgotten"), restriction of processing, objection, portability, and not to be subject to automated decisions with legal effects. You may also withdraw consents at any time, without the withdrawal affecting the lawfulness of prior processing.
9. How to exercise your rights
You can exercise your rights by sending an email to info@infinitumjobs.com indicating the right you wish to exercise and attaching a copy of an identification document. We will respond within a maximum of one month (extendable for two additional months in complex cases). If you consider that the processing infringes the regulations, you can file a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es).
10. Security measures
We apply appropriate technical and organisational measures to protect your data: password encryption with Argon2id, mandatory HTTPS connections, single-use cryptographic verification tokens, protection against common attacks (CSRF, XSS, SQL injection, brute force), access auditing, secure sessions with httpOnly, Secure and strict SameSite flags, and environment separation. Access to systems is limited to authorised personnel via two-factor authentication.
11. Cookies
We use only technical cookies strictly necessary for the operation of the service (session management and CSRF protection). We do not use profiling or advertising cookies. Consent for technical cookies is not required by regulations as they are essential to provide the requested service.
12. Minors
InfinitumJobs is aimed at persons over 16 years of age. We do not knowingly collect data from minors under that age. If we detect that we have received data from a minor under 16 without the corresponding consent, we will proceed to delete it.
13. Changes to the policy
We may update this Policy to adapt to regulatory, technical or service changes. Relevant modifications will be communicated by email at least thirty (30) days prior to their entry into force, allowing you to cancel your account before the change if you do not agree. Each version is archived in a traceable manner in our systems.
14. Contact
For any queries about this policy or the processing of your data, write to info@infinitumjobs.com.