Legal
Privacy policy
Openings is a job-alert service for people looking for work. This page explains exactly what personal data we process, why, who else gets to see it, and what you can ask us to do about it.
Last updated:
1. Who is responsible for your data
Openings is not a company. It is a free service run by one private individual based in the Netherlands, with no business, no revenue and no staff behind it. Under the GDPR that person is nonetheless the controller of your personal data and carries the responsibilities this policy describes.
Because this is not a business, there is no Chamber of Commerce (KvK) registration and no VAT number, and none is required for a non-commercial service of this kind. There is also no Data Protection Officer; appointing one is not required here, and with one person running the service it would be a fiction.
For anything in this policy — a question, a correction, or a request to delete your data — write to hello@marketing-jobs.nl. It goes directly to the person who built the service.
2. What we process, why, and on what legal basis
Everything below is data we actually store or handle. We have tried to keep this list exhaustive rather than reassuring.
| What | Why | Legal basis |
|---|---|---|
| Account details — your email address, a bcrypt hash of your password (never the password itself), whether you have confirmed your email address, when the account was created, roughly when you were last active, and whether the account is active or frozen. | To create your account, sign you in, confirm your address, let you reset a forgotten password, and to stop spending AI budget scoring jobs for accounts that have gone dormant. | Performance of a contract, Art. 6(1)(b) GDPR — you asked us to run an account for you. |
| Job preferences — the companies you follow, the countries and cities you want, language filters, and the minimum match score you set. | To decide which openings appear in your feed and which ones are worth alerting you about. | Contract, Art. 6(1)(b). |
| Your CV and the profile built from it — the text extracted from the PDF you upload (we keep the first 20,000 characters) and the structured profile the AI derives from it: a summary, seniority, years of experience, recent roles, skills, tools, spoken languages, industries, strengths and suggested job titles. Also the free-text brief you write about what you are looking for. | To score openings against your actual background, and to draft application material when you ask for it. | Your consent, Art. 6(1)(a) — and your explicit consent, Art. 9(2)(a), for any special-category data your CV happens to contain. Uploading a CV is optional. See section 3. |
| Match results — for each job, a score from 1 to 10, a short verdict, the reason the model gave, and a fingerprint of the profile version it was based on. | So your feed can be ranked and filtered, and so we do not pay to score the same job against the same profile twice. | Contract, Art. 6(1)(b). |
| Applications you track — company, job title, the date you applied, the status, your own notes, and any cover letter or other material you generate. | To run the application tracker you chose to use. | Contract, Art. 6(1)(b). |
| Alert settings and delivery — whether email alerts are on, and, if you switch on browser notifications, the push endpoint URL your browser issues, the two keys needed to encrypt a message to it, and your browser's user-agent string. | To send you the alerts you asked for, on the channel you asked for. | Consent, Art. 6(1)(a). You can switch either off at any time in Settings. |
| AI usage records — for each AI request: which feature it was for, the model, token counts, what it cost, when it happened, and your internal account id. No CV or job text is kept in these records. | To keep a free service affordable, to apply the per-account fair-use budget, and to notice abuse. | Legitimate interests, Art. 6(1)(f): running the service within a sustainable cost. |
| Company suggestions — a company name, website and note when you suggest a company we should monitor, plus any CSV file you upload for that purpose. | To decide which career pages to add next. | Legitimate interests, Art. 6(1)(f): improving coverage. |
| Technical request data — your IP address is held in the server's memory to rate-limit sign-ins, sign-ups and outgoing email. It is not written to our database. Our hosting provider's own server logs may record IP addresses and request paths. | Security: slowing down credential stuffing, sign-up spam and email bombing. | Legitimate interests, Art. 6(1)(f): keeping accounts and the mail domain safe. |
Things we do not do: we run no advertising, no analytics and no tracking tools; we do not profile you for marketing; we do not sell or rent personal data; and because nothing on Openings is paid for, we hold no payment or billing data at all.
Automated scoring
AI scores rank and filter your feed, so in that narrow sense the service makes automated decisions about which jobs you are shown first. This is not automated decision-making with legal or similarly significant effects under Art. 22 GDPR: no employer ever sees your score, nothing about you is decided by it, and you can see every opening regardless of its score by lowering the minimum score in Settings. If you disagree with a score you can tell us at hello@marketing-jobs.nl, and you can always change the brief or CV the score is based on.
3. Your CV and the AI — the part worth reading carefully
This is the most sensitive data the service touches, so here is precisely what happens to it.
- When you upload a CV, the PDF is read in memory and the text is extracted. The PDF file itself is never stored on our servers. The extracted text (first 20,000 characters) and the profile built from it are stored in our database.
- To build your profile, the first 15,000 characters of that CV text are sent to OpenRouter, which forwards the request to the AI model configured for the service.
- Every time a job is scored for you, your derived profile and your search brief are sent to OpenRouter together with the text of the job posting.
- When you ask for a cover letter or other application material, your full stored CV text is sent along with the job details.
- Your email address, your password and your tracked applications are never sent to the AI provider. Your CV text, however, will normally contain your name and contact details, because that is what CVs contain.
Upload less than you think you need to
A CV often carries far more than a work history: a photograph, date of birth, nationality, home address, phone number, marital status, health or disability information, a religious or political affiliation implied by volunteering, or trade-union membership. Several of those are special categories of personal data under Art. 9 GDPR, and they are of no use to the matching at all — the model only benefits from your roles, skills, tools, languages and industries.
We therefore ask you to strip anything you do not need before uploading, and to remember that you never have to upload a CV in the first place: describing what you are looking for in your own words works, and the rest of Openings runs perfectly well without a CV.
Withdrawing this consent
You can withdraw your consent at any time. Uploading a different CV in Settings replaces the stored text and profile. To have it removed entirely, email hello@marketing-jobs.nl and we will delete the stored CV text, the derived profile and the match scores calculated from it. Withdrawing consent does not affect processing that already happened, and it does not delete the rest of your account unless you also ask for that.
4. Who else receives your data
A small number of providers are used to actually run the service. They act as processors: they handle the data to provide their service and are not permitted to use it for their own purposes. Each is used under its standard terms and data processing terms; because this is a one-person, non-commercial project, there are no individually negotiated contracts with them.
| Recipient | What it receives |
|---|---|
| OpenRouter (United States) AI routing |
The text extracted from your CV, the profile derived from it, your free-text search brief, and the text of job postings. OpenRouter does not run the models itself: it forwards each request to the model provider it routes to, which may be a different company in a different country. |
| Resend Email delivery |
Your email address and the contents of the message we send you: the confirmation and password-reset emails, and the job alert emails, which list the openings matched to you. |
| Railway Hosting and the Postgres database |
Everything described in section 2 is stored on Railway's infrastructure, in the region
Amsterdam, the Netherlands (Railway's europe-west4 region), so the database itself stays inside the EEA. Their server logs may also contain your IP address. |
| Your browser vendor's push service (for example Google for Chrome, Mozilla for Firefox, Apple for Safari) |
Only if you switch on browser notifications. The notification body is encrypted to your browser's own keys, but the push service necessarily sees that a message was delivered to your device and when. |
| cdn.tailwindcss.com and Google Fonts (fonts.googleapis.com, fonts.gstatic.com) | Nothing is sent by us, but your browser fetches the stylesheet and fonts directly from those servers, which therefore see your IP address, your user-agent string and a trimmed referrer. See the Cookie policy. |
Company logos shown next to jobs are SVG files stored on our own server, not loaded from the companies' websites, so browsing your feed does not tell any employer anything.
Employers never hear from us
We do not share your data with employers or recruiters, ever. The companies whose career pages we monitor do not learn that you exist, that you viewed their opening, or how well you scored against it. If you decide to apply, you do so on the employer's own website, and from that point their privacy policy applies, not ours.
We may disclose personal data where we are legally obliged to, for example on a valid order from a Dutch authority.
5. Transfers outside the European Economic Area
OpenRouter and Resend are US-established providers, and the AI model that ends up handling a request may be run by a provider elsewhere in the world. That means your CV-derived text can be processed outside the EEA.
Where that happens, the transfer relies on the European Commission's Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework where the recipient is certified under it, together with the provider's own data processing terms. You can ask us at hello@marketing-jobs.nl which safeguard applies to a given provider.
Be aware of an honest limitation: because OpenRouter chooses the model provider per request, the exact destination of your CV text can vary between requests. This is one more reason to upload only what the matching actually needs.
6. How long we keep things
- Account, preferences, CV text and profile, match scores, tracked applications and generated material: for as long as your account exists. When the account is deleted, these are deleted with it.
- Session cookie: up to 30 days, or until you sign out or change your password, whichever comes first.
- Email confirmation links: valid for 48 hours. Password reset tokens: stored only as a hash, single-use, and valid for a short window.
- Alert records (which job was already alerted to which account, so you are not told twice): removed with your account.
- AI usage records: kept for cost accounting and not automatically removed when an account is deleted — they still carry the internal account id, though they contain no CV or job text. If you want yours deleted or anonymised, ask at hello@marketing-jobs.nl and we will do it.
- Job listings scraped from career pages are not personal data about you and are kept while the opening is live, plus a history of URLs and titles so we can tell genuinely new postings from re-listed ones.
- Hosting logs are kept according to our hosting provider's own retention period, which we do not control.
7. Your rights
Under the GDPR you have the following rights, all of which you can exercise free of charge:
- Access (Art. 15) — a copy of the personal data we hold about you, and the explanation of what we do with it.
- Rectification (Art. 16) — correction of anything inaccurate or incomplete. Much of this you can do yourself in Settings.
- Erasure (Art. 17) — deletion of your account and the data attached to it. There is currently no self-service delete button; email us and we will do it and confirm when it is done.
- Restriction (Art. 18) — asking us to park your data instead of using it, for example while a dispute about accuracy is sorted out.
- Portability (Art. 20) — the data you gave us, in a structured, machine-readable format, or sent directly to another provider where that is technically feasible.
- Objection (Art. 21) — objecting to processing we base on legitimate interests. We will stop unless we can show compelling grounds that override your interests.
- Withdrawing consent (Art. 7(3)) — for your CV, your search profile, email alerts or browser notifications, at any time, without affecting processing that already took place.
To exercise any of these, email hello@marketing-jobs.nl from the address on your account. We may ask you to confirm you are the account holder, because handing your data to the wrong person would be worse than the inconvenience. We reply within one month; if a request is complex we may extend that by two months and will tell you why within the first month.
Complaining
If you think we are handling your data wrongly, please tell us first — it is usually the fastest fix. You also have the right to lodge a complaint with the Dutch supervisory authority:
Autoriteit Persoonsgegevens
Postbus 93374, 2509 AJ Den Haag, the Netherlands
autoriteitpersoonsgegevens.nl
If you live or work in another EU country, you may complain to your local supervisory authority instead.
8. How we protect your data
- Passwords are stored only as bcrypt hashes. Nobody, including us, can read your password.
- The session cookie is HttpOnly, SameSite=Lax and, in production, Secure — so it cannot be read by scripts and does not travel to other sites.
- The site is served over HTTPS with HSTS, a Content-Security-Policy, and a same-origin check on every state-changing request.
- Sign-in, sign-up, password-reset, CV upload and outgoing email are all rate-limited.
- Changing your password invalidates every existing session.
- Uploaded PDFs are never written to disk.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours and, where the risk to you is high, tell you directly.
9. Minimum age
You must be at least 16 years old to use Openings. Sixteen is the age at which, under Dutch law implementing Art. 8 GDPR, a person can consent to online services for themselves. Openings is a job-search tool for adults entering or moving within the labour market and is not directed at children.
We do not knowingly process data belonging to anyone under 16. If we learn that an account belongs to someone younger, we will delete it and the data attached to it. If you believe a child has created an account, tell us at hello@marketing-jobs.nl.
10. Changes to this policy
When this policy changes we update this page and the "last updated" date at the top. If a change materially affects how we handle your data — a new processor, a new purpose, a new category of data — we will announce it on the site and, where the change is significant, email the address on your account before it takes effect, so that you have the chance to object or delete your account first.