1. Who We Are and Our Role
Hirecamp Platforms Limited, trading as Jobcamp, is a company registered in Ireland. We provide Jobcamp, a career support technology platform for schools, colleges, universities, and students. The platform helps students build career profiles, prepare CVs and cover letters, find job opportunities, track applications, and prepare for interviews.
Each participating institution is assigned its own dedicated Jobcamp web address — typically a subdomain such as [institution].jobcamp.ai, or a custom domain agreed at onboarding. Students and staff must use that institution-specific address to sign in. This keeps each institution's data in a separate environment and prevents access through another institution's address.
As a Data Processor
For the core student career service, the institution acts as the data controller and Jobcamp acts as a data processor on the institution's behalf, processing student personal data only as instructed by the institution. Governed by Article 28 GDPR.
As an Independent Controller
For platform security, abuse prevention, fraud detection, legal compliance, and service reliability monitoring, Jobcamp acts as an independent data controller, determining the purposes and means of processing itself.
Joint Controllership
Where both Jobcamp and the institution jointly determine purposes or means of processing for a specific feature or reporting arrangement, the parties may act as joint controllers under Article 26 GDPR.
Hirecamp Platforms Limited is established in Ireland. Our lead supervisory authority under the GDPR one-stop-shop mechanism is the Data Protection Commission of Ireland (DPC).
2. What Data We Collect
We collect only the information needed to provide, secure, and improve the platform.
Account & Identity Data
- Name and university or school email address
- Account identifiers and institution/cohort/tenant information
- Profile photo, if the student chooses to add one to their CV
Student Career Profile Data
- Education history, work experience, skills and proficiency levels
- CV or resume content, certifications, credentials, volunteer experience
- Awards, language proficiencies, professional profile links (LinkedIn, GitHub, portfolio)
- Job preferences, applications, target roles, job descriptions, notes, and interview preparation
AI-Generated Career Content
- CV summaries and tailored CV sections
- Cover letters and career fit analysis
- Job match assessments and skills gap analysis
- Interview preparation reports
Authentication Data
To verify user identity, we process institutional email addresses for one-time passcode (OTP) delivery during sign-in, OTP verification status and timestamps. OTP delivery is handled by an email delivery provider. The email address is shared only for sending the authentication message and is not used for marketing.
Technical & Security Data
We collect limited technical data to keep the service secure and reliable, including IP address, browser and device information, session identifiers, login and security event logs, error and performance information, and rate-limiting identifiers derived from IP address and tenant. We do not use this information to sell advertising or track students across unrelated services.
Support Chat Data (Optional)
Where support chat is enabled and the student opts in, we process name, email, chat message content, IP address, and browser metadata through our support chat provider (Crisp). The widget loads only after explicit consent where that setting is enabled.
3–4. Special Category Data & How We Collect Data
Special Category Data
Jobcamp does not intentionally collect special category data as part of the core service. This includes health data, biometric data, genetic data, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life, or sexual orientation.
Students should avoid adding special category data to CVs, free-text fields, or uploaded documents unless it is strictly necessary for their own career materials.
How We Collect Data
We collect data when:
- A student or staff member creates an account
- The institution authorises access through an approved email domain or other access method configured for that institution
- A student enters information into forms
- A student uploads a CV or resume for parsing
- A student uses AI-assisted features
- The platform records security, audit, and performance events
Where CV files are uploaded for parsing, the file is processed to extract structured information into the student's profile. The original uploaded file is not kept as a separate stored document after parsing completes.
5–6. Why We Use Personal Data & Lawful Basis
We use personal data to create and manage accounts, verify authorisation, provide career tools, generate AI-assisted support, maintain tenant isolation, protect accounts, monitor reliability, provide support, and comply with legal obligations. We do not sell student personal data. We do not share student data with other universities. We do not use student data for unrelated third-party advertising.
Lawful Basis — Where Jobcamp Acts as an Independent Controller
- Processing Activity
- Platform security, fraud prevention, and abuse detection
- Lawful Basis
- Legitimate interests (Article 6(1)(f)) — protecting the integrity of the platform and security of all users
- Processing Activity
- Service reliability monitoring and error diagnostics
- Lawful Basis
- Legitimate interests (Article 6(1)(f))
- Processing Activity
- Legal compliance, audit, and regulatory obligations
- Lawful Basis
- Legal obligation (Article 6(1)(c))
- Processing Activity
- Responding to rights requests and complaints
- Lawful Basis
- Legal obligation (Article 6(1)(c))
Where Jobcamp acts as a processor, the institution (as controller) is responsible for identifying, documenting, and communicating to students the lawful basis for its use of the platform. Common bases used by institutions include: Public task (Article 6(1)(e)), Legitimate interests (Article 6(1)(f)), and Contract (Article 6(1)(b)).
We do not rely on consent as a lawful basis for any core processing. Where an optional feature requires consent, this will be made clear at the point of collection and can be withdrawn at any time without affecting access to the core service.
7. AI Processing
Jobcamp uses AI to support career-related tasks. AI features may parse CVs, suggest profile improvements, tailor CVs to job descriptions, draft cover letters, analyse fit for a role, and generate interview preparation materials.
Student-Initiated
AI processing is initiated by the student or by an authorised workflow agreed with the institution — never triggered without user action.
Data Minimisation
Processing is limited to the data needed for the specific feature requested. No unnecessary data is passed to AI providers.
Assistive Only
Used to provide assistive recommendations, not final employment or academic decisions. Students can review and edit all AI outputs before using them.
No Model Training
Jobcamp does not allow AI providers to use student data to train their general models.
Automated Decision-Making (Article 22 GDPR): Jobcamp's AI features do not constitute solely automated decision-making that produces legal effects or similarly significant effects on students. All AI outputs are recommendations and drafts that require the student's own review and action. No automated system makes a binding decision about a student's employability, suitability, or academic standing. Students are not subject to profiling that produces such effects without human involvement.
8–9. How We Protect Data & Where Data Is Stored
Data Isolation
Each institution has its own dedicated database. Student records from one university are never stored alongside or accessible to another institution — they are physically separated, not merely flagged differently in a shared system.
Encryption
All data in transit between users and Jobcamp is encrypted using HTTPS/TLS. Data at rest in hosted database infrastructure and credential stores is encrypted.
Access Controls
Students can only access their own records. Sensitive operations — such as account deletion, administrative actions, and connections to external services — are handled on secured servers, never exposed to the student's browser. Access credentials with elevated system permissions are kept server-side only.
Abuse & Reliability Controls
Rate limiting and automated abuse detection are in place to protect accounts and the platform. Security events are logged for audit purposes. Error monitoring is configured to capture diagnostic information without collecting unnecessary personal data.
Identity Verification
Access is restricted to users with an authorised institutional email address. Each institution's approved email domains are configured at setup and enforced on every login attempt.
Where Data Is Stored
Jobcamp serves institutions across multiple regions, including Europe, the UK, Southeast Asia, and East Asia. Each institution's primary student database is provisioned in a geographic region chosen to be as close as possible to the institution, in line with the institution's data residency requirements or preferences. The specific hosting region is confirmed with each institution during onboarding and documented in the applicable agreement.
Where supporting services involve processing outside the institution's primary region or outside the EEA/UK, Jobcamp ensures appropriate safeguards are in place in accordance with GDPR Chapter V. The primary mechanism used is Standard Contractual Clauses (SCCs) as approved by the European Commission. Where UK GDPR applies, Jobcamp may also rely on the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs. Where an adequacy decision exists (such as the EU-US Data Privacy Framework), Jobcamp may rely on that decision as an alternative or additional basis.
10. Sub-processors
Jobcamp uses sub-processors to provide hosting, authentication, AI processing, monitoring, content delivery, and background processing. Institutional customers may request the current register from privacy@jobcamp.ai.
- Sub-processor
- Supabase
- Purpose
- Database hosting, authentication, serverless functions, and related infrastructure
- Notes
- Hosted in the region agreed with the institution
- Sub-processor
- Cloudflare
- Purpose
- Content delivery, security, and AI gateway routing
- Notes
- Global network
- Sub-processor
- Google Cloud Vertex AI
- Purpose
- Selected AI generation and analysis features
- Notes
- AI processing
- Sub-processor
- Mistral AI
- Purpose
- CV parsing and document analysis
- Notes
- AI processing
- Sub-processor
- Amazon Web Services (Bedrock)
- Purpose
- Text embeddings used in semantic matching features
- Notes
- AI processing
- Sub-processor
- Upstash
- Purpose
- Distributed rate limiting
- Notes
- Processes IP address and tenant identifiers to prevent abuse
- Sub-processor
- Postmark
- Purpose
- Transactional email and authentication OTP delivery
- Notes
- Processes email address only
- Sub-processor
- Cloudflare Email
- Purpose
- Email routing and delivery infrastructure
- Notes
- Processes email address only
- Sub-processor
- ScrapegraphAI / Jina Reader
- Purpose
- Job description retrieval where a student provides a job URL for analysis
- Notes
- On-demand only
- Sub-processor
- Sentry
- Purpose
- Error monitoring and reliability diagnostics
- Notes
- Diagnostic data only
- Sub-processor
- Hatchet
- Purpose
- Background workflow processing
- Notes
- Self-hosted on Hetzner EU
- Sub-processor
- Crisp
- Purpose
- Optional in-app support chat
- Notes
- Consent-gated
- Sub-processor
- AWS CloudFront
- Purpose
- Static content delivery
- Notes
- Global CDN
Where Jobcamp acts as a processor under GDPR, institutions have the right to be notified of intended changes to the sub-processor list and to raise reasonable objections. The applicable Data Processing Agreement sets out the notification period and objection process.
11–12. Data Sharing & Retention
When We Share Data
We share personal data only when necessary to:
- Provide the service requested by the student or institution
- Use approved sub-processors under contract
- Comply with law, regulation, court order, or lawful authority request
- Protect the security, rights, and safety of users, institutions, Jobcamp, or the public
We do not sell student data. We do not provide one institution's data to another institution.
Data Retention
Unless a different period is agreed with the institution, the following default retention periods apply:
- Data Type
- Account and profile data
- Default Retention
- Duration of enrolment plus 12 months after graduation or last login, whichever is later
- Data Type
- Job applications and AI-generated career content
- Default Retention
- Duration of enrolment plus 12 months after graduation or last login, whichever is later
- Data Type
- Session and security logs
- Default Retention
- Up to 12 months
- Data Type
- Audit logs
- Default Retention
- Up to 24 months
When retention periods expire, data is deleted or anonymised unless we need to retain it for legal, security, dispute resolution, or audit purposes.
13. Student Choices and Rights
GDPR is our primary framework. Students also have the right to lodge a complaint with a supervisory authority under Article 77 GDPR; see Section 17 for details. The rights set out below apply to all students where GDPR or UK GDPR applies to the processing of their personal data — which includes students at institutions in Ireland, the EEA, the UK, and institutions worldwide that are subject to GDPR through their operations or student base.
Right of Access (Art. 15)
Access your personal data held by Jobcamp.
Right to Rectification (Art. 16)
Correct inaccurate or incomplete data.
Right to Erasure (Art. 17)
Erasure where data is no longer needed or consent is withdrawn with no other lawful basis.
Right to Restrict (Art. 18)
Restrict processing in certain circumstances, for example while accuracy is contested.
Right to Object (Art. 21)
Object to processing based on legitimate interests, including profiling.
Data Portability (Art. 20)
Receive a machine-readable copy of data provided by the student and processed by automated means.
Withdraw Consent (Art. 7(3))
Withdraw consent at any time where processing is based on consent, without affecting prior lawful processing.
No Automated Decisions (Art. 22)
Not be subject to solely automated decision-making that produces legal or similarly significant effects. All Jobcamp AI outputs require human review and action.
Right to Lodge a Complaint (Art. 77)
Lodge a complaint with a supervisory authority — in particular in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement. See Section 17 for authority contact details.
Response Timeframes
Under GDPR, we will respond to rights requests within one month of receipt. Where a request is complex or we receive multiple requests, we may extend this period by a further two months and will inform you of the extension and the reason within the first month.
How to Submit a Request
Students can edit much of their profile and application information directly in the platform. Requests that cannot be completed in the product can be sent to privacy@jobcamp.ai or to the institution's designated contact. To protect your data, we may need to verify your identity before fulfilling a rights request. We will not charge a fee for reasonable requests.
In other jurisdictions, equivalent rights apply under local law — including access and correction rights under Singapore's Personal Data Protection Act and Hong Kong's Personal Data (Privacy) Ordinance.
14–15. Institutional Administration & Children's Data
Institutional Administration
Where institutional staff or admin tools are enabled under agreement with the institution, authorised staff may manage access settings, tenant configuration, or agreed reporting. Staff should access student data only for legitimate education, careers support, safeguarding, compliance, or support purposes authorised by the institution.
Jobcamp does not make one institution's student data available to another institution.
Children's & Young People's Data
Jobcamp may be used by students in schools, colleges, and universities, including younger learners where the institution has approved the deployment. The platform is designed to collect career-support data, not unnecessary sensitive information.
GDPR (Article 8): Children under 16 require parental or guardian consent where consent is the lawful basis. Some EEA member states have lowered this to a minimum of 13.
Singapore (PDPA): The age of consent is 21 unless a lower age of capacity applies under general law.
Hong Kong: No fixed statutory threshold, but institutions should ensure appropriate parental notification for young students.
The institution is responsible for ensuring appropriate notices, consents, or other legal requirements are satisfied for its deployment. Jobcamp does not knowingly collect personal data from users under 13 without institutional confirmation that appropriate safeguards are in place.
16. Security Incidents & Breach Notification
If Jobcamp becomes aware of a personal data breach affecting institutional data, we will investigate and take immediate steps to contain and remediate the incident.
Detect & Contain
Immediate investigation and containment steps upon becoming aware of a breach.
Notify Institution
Where acting as a processor, notify the institution (as controller) without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Notify Supervisory Authority
Where acting as an independent controller, notify the relevant supervisory authority within 72 hours of becoming aware of a breach likely to result in risk to individuals.
Support Individual Notification
Where a breach is likely to result in high risk to individuals, Jobcamp will assist the institution with the information needed to communicate with affected students.
For institutions outside the EEA and UK, Jobcamp will notify the institution and cooperate with applicable breach notification requirements under local law.
17. Supervisory Authorities & Regulatory Rights
Hirecamp Platforms Limited is established in Ireland. Under the GDPR one-stop-shop mechanism (Article 56), our lead supervisory authority for cross-border processing within the EEA is the Data Protection Commission of Ireland (DPC) — dataprotection.ie. EEA institutions and students may raise concerns with the DPC or with the supervisory authority in their own member state.
🇮🇪 Ireland
Data Protection Commission (DPC) dataprotection.ie
🇵🇱 Poland
Urząd Ochrony Danych Osobowych (UODO) uodo.gov.pl
🇭🇰 Hong Kong
Office of the Privacy Commissioner for Personal Data (PCPD) pcpd.org.hk
🇬🇧 United Kingdom
Information Commissioner's Office (ICO) ico.org.uk
🇸🇬 Singapore
Personal Data Protection Commission (PDPC) pdpc.gov.sg
🇪🇺 Other EEA States
The supervisory authority in the member state where the institution is located.
We would always welcome the opportunity to address concerns directly before a formal complaint is raised. Please contact privacy@jobcamp.ai in the first instance.
18–20. Cookies, Policy Changes & Contact
18. Cookies and Browser Storage
Jobcamp uses browser storage for essential functions such as keeping you signed in and remembering your language preference. Where support chat is enabled, the chat provider may set cookies only after you give explicit consent.
We do not use advertising or cross-site tracking cookies.
19. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will notify institutional customers and, where appropriate, users.
20. Contact Us
Hirecamp Platforms Limited, trading as Jobcamp Registered in Ireland Company number: 800067 Registered address: Seafield Road, Blackrock, Co. Louth, Ireland
Website: jobcamp.ai/edu Email: privacy@jobcamp.ai Data protection contact: privacy@jobcamp.ai Lead supervisory authority: Data Protection Commission of Ireland — dataprotection.ie
Students may also contact their university or school data protection team directly.