Privacy policy

Last updated: 5 February 2025. This policy complies with the Swiss Federal Act on Data Protection (nFADP) and, where applicable, the GDPR.

1. Controller

Who manages your data and how to contact them.

  • WeJob Sàrl

    Route de Pré-Bois 14, 1216 Cointrin, Switzerland
  • Contact

    support@wejob.ch

2. Data we process

Quick overview of collection purposes and main data families.

  • Why

    Provide the service, secure the platform, comply with our legal obligations, and improve features.
  • Main categories

    Account/profile, usage, provided content, technical data, billing, support.
  • Account and profile

    Identity, contact details, role (candidate/recruiter), professional information (candidates), company information, published offers, and preferences (languages, notifications).
  • Usage data

    Logins, settings, preferences, activity logs, search/application history, interactions with features (AI, messaging), device/browser, and time zone.
  • Provided content

    CVs, letters, messages, attachments, AI prompts, and files sent for analysis, fields entered in forms (job, training, skills).
  • Technical data

    Session identifiers, functional cookies, IP addresses, browser/fingerprint identifiers, or technical UUIDs used for security, abuse prevention, AI rate limiting, and consent management.
  • Potentially sensitive data

    Certain information voluntarily provided (health, affiliations, photo/voice, freely entered content) may qualify as sensitive personal data (art. 5 let. c nFADP). It is processed because you provide it in your CV or exchanges, on the basis of contract performance and, where required, your explicit consent.
  • Billing

    Payment references and invoices; card data does not pass through WeJob and is processed directly by our payment provider (e.g. Stripe, policy here).
  • Support

    Exchanges with support, tickets, and associated metadata.

2.1 Candidate data and uses

For each type of candidate data, its concrete use.

  • Identity and contact

    Last name, first name, email, phone: account creation, communication with you, notifications related to applications.
  • Professional profile

    Title, seniority, location, availability, salary expectations, mobility: matching with offers and relevant recommendations.
  • Career path and skills

    Training, experience, technical/soft skills, languages and levels: relevance assessment against offers, generation of AI suggestions, and initial sorting for recruiters when you apply or make your profile visible.
  • Documents

    CVs, cover letters, attachments: made available to recruiters when you apply, writing/optimization assistance (AI), and storage in your space while you keep them.
  • Applications and history

    Offers viewed/applied to, statuses, exchanged messages: follow-up of your applications, notifications, continuity of exchanges with recruiters.
  • Preferences and settings

    Alerts, languages, consents, visibility choices: personalization of the experience and respect for your choices (e.g. profile visibility, communications).
  • Technical data

    IP, session identifiers, functional cookies, UUID/fingerprint: account security, anti-abuse, AI usage limits, session and consent management.

3. Purposes and legal bases

Why and on what basis we process your information.

  • Provide the service and perform the contract

    Account creation, publication and management of offers, matching and recommendations, messaging, AI feature usage limits.
  • Security and abuse prevention

    Fraud detection, abnormal usage controls, protection of accounts and the platform.
  • Profiling (within the meaning of the nFADP)

    Matching, recommendations, and initial sorting constitute non-high-risk profiling; they are necessary for contract performance or based on legitimate interest, without automated decisions producing legal effects. You may object by contacting us.
  • Service improvement and statistics

    Aggregated audience measurement and product improvement, without targeted advertising.
  • Communications

    Notifications related to the account, recruitment, or legal obligations. Marketing communications are based on your consent or our legitimate interest, with the possibility to object.
  • Legal obligations

    Billing, accounting retention, responses to authorities.
  • Processors and providers

    Hosting (Switzerland/EEA), payment (Stripe), emailing and support, audience measurement (Google, with your consent), AI assistance and CV analysis (Mistral AI, France), document text extraction (OCR), job posting on professional networks (LinkedIn, Meta). All are subject to confidentiality and data protection commitments.

4. Cookies and trackers

How we use cookies/identifiers and your options.

  • Necessary

    Functional cookies for the session (authentication, login persistence), security (anti-CSRF, anti-fraud, abuse limitation), and consent management (recording your choices).
  • Advertising

    No advertising or targeting cookies are deployed.
  • Audience measurement

    We use Google Analytics 4 and Google Tag Manager (Google LLC, United States) for aggregated audience measurement. These tools are only loaded after your consent via the cookie banner, with no targeted advertising. Indicative duration 6 to 12 months, withdrawal possible at any time.
  • Control

    You can manage your preferences via the consent banner (enable/disable) and through browser settings (cookie deletion, blocking). Strictly necessary cookies are required for the service to work.

5. Recipients and processors

With whom and why certain data is shared.

  • Providers

    Hosting, security, payment (Stripe), support, emailing, audience measurement (Google), AI assistance and CV analysis (Mistral AI, France), document text extraction (OCR) - under confidentiality obligations.
  • Companies

    When you apply or make your profile visible. If the company uses an external recruitment tool (ATS, e.g. Zoho Recruit), your application and CV are transmitted to it; that company then acts as a separate data controller for its own system.
  • Authorities

    If required by law.
  • Data origin

    Certain data may be obtained from third parties (recruiters, ATS/HR tool imports, internal recommendations) or from public employment-related information. We inform the person concerned within a reasonable time if required.

6. Data location and international transfers

Where your data is hosted and what applies to transfers.

  • Main location

    Switzerland (including our servers in Geneva) and EEA through providers.
  • Transfers outside Switzerland/EU

    Some data is transferred outside Switzerland/EU, in particular to the United States, to the following providers: Stripe (payment), Google (audience measurement, only with your consent), LinkedIn and Meta (job posting by recruiters), as well as our text extraction provider (OCR). These transfers rely on appropriate safeguards (Swiss–U.S. Data Privacy Framework adequacy decision or standard contractual clauses). In addition, if the company you apply to has configured its Zoho Recruit recruitment tool on a data center located outside Switzerland/EU (for example in the United States), your application and CV are transferred there; this transfer is the responsibility of the receiving company and relies, as the case may be, on the Swiss–U.S. Data Privacy Framework, standard contractual clauses, or your explicit consent collected at the time of application.

7. Retention periods

How long we retain each type of data.

  • Account and content

    For the life of the account, then deletion or anonymization on request, unless legal obligations apply.
  • Technical and security logs

    Limited periods necessary for security and abuse prevention (for example 6 to 12 months depending on the purpose).
  • Billing

    Retention according to Swiss legal obligations (e.g. accounting rules, generally 10 years).
  • Technical identifiers (functional cookies, UUID/fingerprint)

    Indicative maximum duration: 12 months, or shorter if you withdraw consent or delete your cookies.
  • Aggregated statistics

    Anonymized data retained without a specific limit.
  • Backups

    After deletion, some data may temporarily remain in backups or technical logs, without active use, until scheduled rotation/destruction.

8. Security

Protections applied to data in transit and at rest.

  • Encryption

    TLS in transit, encryption at rest in our environments, encrypted flows to processors.
  • Controls

    Access control, environment segmentation, logging, backups, regular testing.
  • Best practices

    Use strong passwords and activate available protections.
  • Security breach (data breach)

    In the event of a breach presenting a high risk, we will notify the Federal Data Protection and Information Commissioner (FDPIC) and, if necessary, the persons concerned, in accordance with art. 24 nFADP.

9. NO GUARANTEES

Limits on content accuracy and service availability.

  • Accuracy

    No guarantee as to completeness/reliability of generated or analyzed content (including AI).
  • Availability

    No guarantee of continuous service availability.
  • User responsibility

    Verify and validate results before use.

10. AI: data used, operation, and limits

How data is used in AI features and their limits.

  • Use

    Assistance (writing, suggestions, matching). No automated legal decision; final validation by the user.
  • Processed data

    Prompts, messages, files, profile/offer elements needed for context, anti-abuse technical logs.
  • Models

    Internal or partner models, executed in our secure environments; no training of external models with your data.
  • Sharing

    No advertising use. Technical processors only to provide AI and associated security.
  • Retention

    Time necessary for the response and minimal security/traceability; no reuse to train external models.
  • Objection

    Stop using AI or contact us to exercise your rights.
  • Automated decisions

    No individual automated decision producing legal effects is in place. If such a mechanism were introduced, you would be informed and could request human intervention, express your point of view, and contest the decision.

11. Your rights (GDPR / nFADP)

Your levers to control your data.

You may exercise your rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent (for processing based on consent). You may also define what happens to your data after death where the law allows it. You have the right to file a complaint with the Federal Data Protection and Information Commissioner (CH, www.edoeb.admin.ch) or, where applicable, with your competent EU supervisory authority. We generally respond within 30 days, free of charge unless requests are manifestly abusive.

12. Contact and exercising rights

How to contact us or exercise your rights.

By email: support@wejob.ch
Via the contact form
In your account for certain requests (account update or deletion).

13. Updates

How we evolve this policy.

We may modify this policy to reflect legal or functional changes. In the event of a major change, we will inform you through the platform or by email.