Jobcamp logo Jobcamp

Jobcamp for Education

Privacy Policy

Hirecamp Platforms Limited, trading as Jobcamp, registered in Ireland · Lead supervisory authority: Data Protection Commission of Ireland

Effective date:

On this page

1. Who We Are and Our Role

Hirecamp Platforms Limited, trading as Jobcamp, is a company registered in Ireland. We provide Jobcamp, a career support technology platform for schools, colleges, universities, and students. The platform helps students build career profiles, prepare CVs and cover letters, find job opportunities, track applications, and prepare for interviews.

Each participating institution is assigned its own dedicated Jobcamp web address — typically a subdomain such as [institution].jobcamp.ai, or a custom domain agreed at onboarding. Students and staff must use that institution-specific address to sign in. This keeps each institution's data in a separate environment and prevents access through another institution's address.

As a Data Processor

For the core student career service, the institution acts as the data controller and Jobcamp acts as a data processor on the institution's behalf, processing student personal data only as instructed by the institution. Governed by Article 28 GDPR.

As an Independent Controller

For platform security, abuse prevention, fraud detection, legal compliance, and service reliability monitoring, Jobcamp acts as an independent data controller, determining the purposes and means of processing itself.

Joint Controllership

Where both Jobcamp and the institution jointly determine purposes or means of processing for a specific feature or reporting arrangement, the parties may act as joint controllers under Article 26 GDPR.

Hirecamp Platforms Limited is established in Ireland. Our lead supervisory authority under the GDPR one-stop-shop mechanism is the Data Protection Commission of Ireland (DPC).

2. What Data We Collect

We collect only the information needed to provide, secure, and improve the platform.

Account & Identity Data

  • Name and university or school email address
  • Account identifiers and institution/cohort/tenant information
  • Profile photo, if the student chooses to add one to their CV

Student Career Profile Data

  • Education history, work experience, skills and proficiency levels
  • CV or resume content, certifications, credentials, volunteer experience
  • Awards, language proficiencies, professional profile links (LinkedIn, GitHub, portfolio)
  • Job preferences, applications, target roles, job descriptions, notes, and interview preparation

AI-Generated Career Content

  • CV summaries and tailored CV sections
  • Cover letters and career fit analysis
  • Job match assessments and skills gap analysis
  • Interview preparation reports

Authentication Data

To verify user identity, we process institutional email addresses for one-time passcode (OTP) delivery during sign-in, OTP verification status and timestamps. OTP delivery is handled by an email delivery provider. The email address is shared only for sending the authentication message and is not used for marketing.

Technical & Security Data

We collect limited technical data to keep the service secure and reliable, including IP address, browser and device information, session identifiers, login and security event logs, error and performance information, and rate-limiting identifiers derived from IP address and tenant. We do not use this information to sell advertising or track students across unrelated services.

Support Chat Data (Optional)

Where support chat is enabled and the student opts in, we process name, email, chat message content, IP address, and browser metadata through our support chat provider (Crisp). The widget loads only after explicit consent where that setting is enabled.

3–4. Special Category Data & How We Collect Data

Special Category Data

Jobcamp does not intentionally collect special category data as part of the core service. This includes health data, biometric data, genetic data, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life, or sexual orientation.

Students should avoid adding special category data to CVs, free-text fields, or uploaded documents unless it is strictly necessary for their own career materials.

How We Collect Data

We collect data when:

  • A student or staff member creates an account
  • The institution authorises access through an approved email domain or other access method configured for that institution
  • A student enters information into forms
  • A student uploads a CV or resume for parsing
  • A student uses AI-assisted features
  • The platform records security, audit, and performance events

Where CV files are uploaded for parsing, the file is processed to extract structured information into the student's profile. The original uploaded file is not kept as a separate stored document after parsing completes.

5–6. Why We Use Personal Data & Lawful Basis

We use personal data to create and manage accounts, verify authorisation, provide career tools, generate AI-assisted support, maintain tenant isolation, protect accounts, monitor reliability, provide support, and comply with legal obligations. We do not sell student personal data. We do not share student data with other universities. We do not use student data for unrelated third-party advertising.

Lawful Basis — Where Jobcamp Acts as an Independent Controller

Processing Activity
Platform security, fraud prevention, and abuse detection
Lawful Basis
Legitimate interests (Article 6(1)(f)) — protecting the integrity of the platform and security of all users
Processing Activity
Service reliability monitoring and error diagnostics
Lawful Basis
Legitimate interests (Article 6(1)(f))
Processing Activity
Legal compliance, audit, and regulatory obligations
Lawful Basis
Legal obligation (Article 6(1)(c))
Processing Activity
Responding to rights requests and complaints
Lawful Basis
Legal obligation (Article 6(1)(c))

Where Jobcamp acts as a processor, the institution (as controller) is responsible for identifying, documenting, and communicating to students the lawful basis for its use of the platform. Common bases used by institutions include: Public task (Article 6(1)(e)), Legitimate interests (Article 6(1)(f)), and Contract (Article 6(1)(b)).

We do not rely on consent as a lawful basis for any core processing. Where an optional feature requires consent, this will be made clear at the point of collection and can be withdrawn at any time without affecting access to the core service.

7. AI Processing

Jobcamp uses AI to support career-related tasks. AI features may parse CVs, suggest profile improvements, tailor CVs to job descriptions, draft cover letters, analyse fit for a role, and generate interview preparation materials.

Student-Initiated

AI processing is initiated by the student or by an authorised workflow agreed with the institution — never triggered without user action.

Data Minimisation

Processing is limited to the data needed for the specific feature requested. No unnecessary data is passed to AI providers.

Assistive Only

Used to provide assistive recommendations, not final employment or academic decisions. Students can review and edit all AI outputs before using them.

No Model Training

Jobcamp does not allow AI providers to use student data to train their general models.

Automated Decision-Making (Article 22 GDPR): Jobcamp's AI features do not constitute solely automated decision-making that produces legal effects or similarly significant effects on students. All AI outputs are recommendations and drafts that require the student's own review and action. No automated system makes a binding decision about a student's employability, suitability, or academic standing. Students are not subject to profiling that produces such effects without human involvement.

8–9. How We Protect Data & Where Data Is Stored

Data Isolation

Each institution has its own dedicated database. Student records from one university are never stored alongside or accessible to another institution — they are physically separated, not merely flagged differently in a shared system.

Encryption

All data in transit between users and Jobcamp is encrypted using HTTPS/TLS. Data at rest in hosted database infrastructure and credential stores is encrypted.

Access Controls

Students can only access their own records. Sensitive operations — such as account deletion, administrative actions, and connections to external services — are handled on secured servers, never exposed to the student's browser. Access credentials with elevated system permissions are kept server-side only.

Abuse & Reliability Controls

Rate limiting and automated abuse detection are in place to protect accounts and the platform. Security events are logged for audit purposes. Error monitoring is configured to capture diagnostic information without collecting unnecessary personal data.

Identity Verification

Access is restricted to users with an authorised institutional email address. Each institution's approved email domains are configured at setup and enforced on every login attempt.

Where Data Is Stored

Jobcamp serves institutions across multiple regions, including Europe, the UK, Southeast Asia, and East Asia. Each institution's primary student database is provisioned in a geographic region chosen to be as close as possible to the institution, in line with the institution's data residency requirements or preferences. The specific hosting region is confirmed with each institution during onboarding and documented in the applicable agreement.

Where supporting services involve processing outside the institution's primary region or outside the EEA/UK, Jobcamp ensures appropriate safeguards are in place in accordance with GDPR Chapter V. The primary mechanism used is Standard Contractual Clauses (SCCs) as approved by the European Commission. Where UK GDPR applies, Jobcamp may also rely on the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs. Where an adequacy decision exists (such as the EU-US Data Privacy Framework), Jobcamp may rely on that decision as an alternative or additional basis.

10. Sub-processors

Jobcamp uses sub-processors to provide hosting, authentication, AI processing, monitoring, content delivery, and background processing. Institutional customers may request the current register from privacy@jobcamp.ai.

Sub-processor
Supabase
Purpose
Database hosting, authentication, serverless functions, and related infrastructure
Notes
Hosted in the region agreed with the institution
Sub-processor
Cloudflare
Purpose
Content delivery, security, and AI gateway routing
Notes
Global network
Sub-processor
Google Cloud Vertex AI
Purpose
Selected AI generation and analysis features
Notes
AI processing
Sub-processor
Mistral AI
Purpose
CV parsing and document analysis
Notes
AI processing
Sub-processor
Amazon Web Services (Bedrock)
Purpose
Text embeddings used in semantic matching features
Notes
AI processing
Sub-processor
Upstash
Purpose
Distributed rate limiting
Notes
Processes IP address and tenant identifiers to prevent abuse
Sub-processor
Postmark
Purpose
Transactional email and authentication OTP delivery
Notes
Processes email address only
Sub-processor
Cloudflare Email
Purpose
Email routing and delivery infrastructure
Notes
Processes email address only
Sub-processor
ScrapegraphAI / Jina Reader
Purpose
Job description retrieval where a student provides a job URL for analysis
Notes
On-demand only
Sub-processor
Sentry
Purpose
Error monitoring and reliability diagnostics
Notes
Diagnostic data only
Sub-processor
Hatchet
Purpose
Background workflow processing
Notes
Self-hosted on Hetzner EU
Sub-processor
Crisp
Purpose
Optional in-app support chat
Notes
Consent-gated
Sub-processor
AWS CloudFront
Purpose
Static content delivery
Notes
Global CDN

Where Jobcamp acts as a processor under GDPR, institutions have the right to be notified of intended changes to the sub-processor list and to raise reasonable objections. The applicable Data Processing Agreement sets out the notification period and objection process.

11–12. Data Sharing & Retention

When We Share Data

We share personal data only when necessary to:

  • Provide the service requested by the student or institution
  • Use approved sub-processors under contract
  • Comply with law, regulation, court order, or lawful authority request
  • Protect the security, rights, and safety of users, institutions, Jobcamp, or the public

We do not sell student data. We do not provide one institution's data to another institution.

Data Retention

Unless a different period is agreed with the institution, the following default retention periods apply:

Data Type
Account and profile data
Default Retention
Duration of enrolment plus 12 months after graduation or last login, whichever is later
Data Type
Job applications and AI-generated career content
Default Retention
Duration of enrolment plus 12 months after graduation or last login, whichever is later
Data Type
Session and security logs
Default Retention
Up to 12 months
Data Type
Audit logs
Default Retention
Up to 24 months

When retention periods expire, data is deleted or anonymised unless we need to retain it for legal, security, dispute resolution, or audit purposes.

13. Student Choices and Rights

GDPR is our primary framework. Students also have the right to lodge a complaint with a supervisory authority under Article 77 GDPR; see Section 17 for details. The rights set out below apply to all students where GDPR or UK GDPR applies to the processing of their personal data — which includes students at institutions in Ireland, the EEA, the UK, and institutions worldwide that are subject to GDPR through their operations or student base.

Right of Access (Art. 15)

Access your personal data held by Jobcamp.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete data.

Right to Erasure (Art. 17)

Erasure where data is no longer needed or consent is withdrawn with no other lawful basis.

Right to Restrict (Art. 18)

Restrict processing in certain circumstances, for example while accuracy is contested.

Right to Object (Art. 21)

Object to processing based on legitimate interests, including profiling.

Data Portability (Art. 20)

Receive a machine-readable copy of data provided by the student and processed by automated means.

Withdraw Consent (Art. 7(3))

Withdraw consent at any time where processing is based on consent, without affecting prior lawful processing.

No Automated Decisions (Art. 22)

Not be subject to solely automated decision-making that produces legal or similarly significant effects. All Jobcamp AI outputs require human review and action.

Right to Lodge a Complaint (Art. 77)

Lodge a complaint with a supervisory authority — in particular in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement. See Section 17 for authority contact details.

Response Timeframes

Under GDPR, we will respond to rights requests within one month of receipt. Where a request is complex or we receive multiple requests, we may extend this period by a further two months and will inform you of the extension and the reason within the first month.

How to Submit a Request

Students can edit much of their profile and application information directly in the platform. Requests that cannot be completed in the product can be sent to privacy@jobcamp.ai or to the institution's designated contact. To protect your data, we may need to verify your identity before fulfilling a rights request. We will not charge a fee for reasonable requests.

In other jurisdictions, equivalent rights apply under local law — including access and correction rights under Singapore's Personal Data Protection Act and Hong Kong's Personal Data (Privacy) Ordinance.

14–15. Institutional Administration & Children's Data

Institutional Administration

Where institutional staff or admin tools are enabled under agreement with the institution, authorised staff may manage access settings, tenant configuration, or agreed reporting. Staff should access student data only for legitimate education, careers support, safeguarding, compliance, or support purposes authorised by the institution.

Jobcamp does not make one institution's student data available to another institution.

Children's & Young People's Data

Jobcamp may be used by students in schools, colleges, and universities, including younger learners where the institution has approved the deployment. The platform is designed to collect career-support data, not unnecessary sensitive information.

GDPR (Article 8): Children under 16 require parental or guardian consent where consent is the lawful basis. Some EEA member states have lowered this to a minimum of 13.

Singapore (PDPA): The age of consent is 21 unless a lower age of capacity applies under general law.

Hong Kong: No fixed statutory threshold, but institutions should ensure appropriate parental notification for young students.

The institution is responsible for ensuring appropriate notices, consents, or other legal requirements are satisfied for its deployment. Jobcamp does not knowingly collect personal data from users under 13 without institutional confirmation that appropriate safeguards are in place.

16. Security Incidents & Breach Notification

If Jobcamp becomes aware of a personal data breach affecting institutional data, we will investigate and take immediate steps to contain and remediate the incident.

Detect & Contain

Immediate investigation and containment steps upon becoming aware of a breach.

Notify Institution

Where acting as a processor, notify the institution (as controller) without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

Notify Supervisory Authority

Where acting as an independent controller, notify the relevant supervisory authority within 72 hours of becoming aware of a breach likely to result in risk to individuals.

Support Individual Notification

Where a breach is likely to result in high risk to individuals, Jobcamp will assist the institution with the information needed to communicate with affected students.

For institutions outside the EEA and UK, Jobcamp will notify the institution and cooperate with applicable breach notification requirements under local law.

17. Supervisory Authorities & Regulatory Rights

Hirecamp Platforms Limited is established in Ireland. Under the GDPR one-stop-shop mechanism (Article 56), our lead supervisory authority for cross-border processing within the EEA is the Data Protection Commission of Ireland (DPC) — dataprotection.ie. EEA institutions and students may raise concerns with the DPC or with the supervisory authority in their own member state.

🇮🇪 Ireland

Data Protection Commission (DPC) dataprotection.ie

🇵🇱 Poland

Urząd Ochrony Danych Osobowych (UODO) uodo.gov.pl

🇭🇰 Hong Kong

Office of the Privacy Commissioner for Personal Data (PCPD) pcpd.org.hk

🇬🇧 United Kingdom

Information Commissioner's Office (ICO) ico.org.uk

🇸🇬 Singapore

Personal Data Protection Commission (PDPC) pdpc.gov.sg

🇪🇺 Other EEA States

The supervisory authority in the member state where the institution is located.

We would always welcome the opportunity to address concerns directly before a formal complaint is raised. Please contact privacy@jobcamp.ai in the first instance.

18–20. Cookies, Policy Changes & Contact

18. Cookies and Browser Storage

Jobcamp uses browser storage for essential functions such as keeping you signed in and remembering your language preference. Where support chat is enabled, the chat provider may set cookies only after you give explicit consent.

We do not use advertising or cross-site tracking cookies.

19. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will notify institutional customers and, where appropriate, users.

20. Contact Us

Hirecamp Platforms Limited, trading as Jobcamp Registered in Ireland Company number: 800067 Registered address: Seafield Road, Blackrock, Co. Louth, Ireland

Website: jobcamp.ai/edu Email: privacy@jobcamp.ai Data protection contact: privacy@jobcamp.ai Lead supervisory authority: Data Protection Commission of Ireland — dataprotection.ie

Students may also contact their university or school data protection team directly.