This policy explains how Nordic Roles (“we”, “us”) handles personal data when you use nordicroles.example (the “Service”). We are the data controller for your personal data. Operator: Nordic Roles Oy, Helsinki, Finland — full registration details available on request. Questions or requests: privacy@nordicroles.example.
What we collect
- Account: your email address, and a display name if you provide one.
- Your activity in the product: jobs you save, skills you declare, saved searches and alert settings, and onboarding answers (target role, city, language preference).
- Subscription & billing: plan and status. Payments are processed by Stripe — we never see or store your card details.
- Technical data: basic logs needed to run and secure the Service (e.g. request metadata). We do not run advertising or third-party analytics trackers.
Job and company data we aggregate from public company career pages is business information, not your personal data. We store facts and original-language text and link to the employer's page; we scrub incidental personal data (e.g. recruiter emails/phone numbers) at ingestion and exclude sole-trader / natural-person organisations.
Why we use it (legal bases)
- Performance of a contract: to provide your account, saved jobs, roadmap, search, and (for paid plans) alerts and full filters.
- Legitimate interests: to operate, secure, and improve the Service, and to aggregate publicly available company/job data. You can object at any time.
- Consent: for non-essential lifecycle emails (welcome, activation nudges, job-alert digests). You can withdraw consent any time via the unsubscribe link in any such email or in your account. Sign-in (magic link) emails are essential to the Service and are always sent.
Who processes your data (sub-processors)
- Neon — managed PostgreSQL database hosting.
- Vercel — application hosting.
- Stripe — payment processing and billing.
- Resend — transactional and lifecycle email delivery.
- Anthropic — LLM processing of job-posting text to extract structured fields. We do not send your personal data for this.
Some providers may process data outside the EEA (e.g. in the United States). Where they do, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses.
How long we keep it
We keep account and activity data for as long as your account is active. If you delete your account, we remove your personal data within 30 days, except where we must retain limited records (e.g. billing) to meet legal obligations. Company/job data is retained as part of our longitudinal dataset and is not personal to you.
Your rights
Under the GDPR you can request access, correction, deletion, restriction, or portability of your personal data, and object to processing based on legitimate interests. To exercise any of these, email privacy@nordicroles.example. You also have the right to lodge a complaint with your local supervisory authority (in Finland, the Office of the Data Protection Ombudsman).
Companies: if you represent an organisation and want its listings removed, see our Terms or email privacy@nordicroles.example — we operate a delist process.
Cookies
We use only strictly necessary cookies. See our Cookie Policy for details.
Changes
We may update this policy; we'll change the “last updated” date above and, for material changes, notify you in the product or by email.