Privacy Notice
1. Controller
Serap Kuşu-Eryigit
21, rue Basse
L-3813 Schifflange
Luxembourg
No walk-in customers.
Contact person / Support:
Serap Kuşu-Eryigit
Support:
support@unframed-bit.eu
Contact:
contact@unframed-bit.eu
Phone:
+352 691 868 822
Related service domains: unframed-bit.eu
Technical implementation:
Nejat Philip Eryigit / Ready-4-IT (www.ready-4-it.com)
DPO contact: appointed if legally required by processing volume or scope.
2. Scope
This notice covers data processed in Unframed Bit for:
- lightweight session access
- Identity-provider login (Google, LinkedIn, Xing, and/or GitHub via the UnframedStats GitHub App): profile and email for authentication only
- local structured profile management (candidate)
- published candidate public profile (QR / direct link) when the candidate enables publication
- recruiter workspace access and recruiter-company assignment (B2B)
- CV-template-based Gantt/timeline rendering (structured output only; raw CV is not retained)
- delivered statistics events and credit/reward accounting
- legal, security, and support operations for the Unframed Bit layer
Current scope boundary: candidates may participate worldwide; recruiter-company onboarding is limited to EU/EEA-established entities and the United Kingdom in the current MVP.
Data minimisation: Unframed Bit does not store personal data beyond what is needed for the service. Identity-provider login before registration completion stays session-only. Exceptions are time-limited (for example structured Gantt/timeline data for an active paid period or until the stated retention baseline). Raw CV material is discarded after transformation into structured timeline data.
3. Data categories
Local Unframed Bit data:
- session identifiers and login metadata
- Identity data obtained from the chosen identity provider for login (Google, LinkedIn, Xing, and/or GitHub): subject/handle, profile fields (display name, avatar, profile URL where available), and email address when available. Before registration is completed, this data is kept in the browser session only and is not stored as a durable Unframed Bit account.
- display name
- structured career-template entries entered locally in Unframed Bit (not raw CV text)
- public-profile publication flags, per-element visibility settings, optional external profile URLs (LinkedIn, Xing, GitHub, website), notes text, and diagram visibility choices
- legal acceptance records for Unframed Bit pages where applicable
- candidate plan/license state and credit event metadata where applicable
- after repository-analysis consent and Unframed Stats App install: aggregate GitHub statistics from installation-visible repositories (language / contribution / activity aggregates), coverage metadata (for example analyzed vs total repositories), installation linkage identifiers, and last-known-good cache timestamps needed for honest refresh / rate-limit behaviour
B2B recruiter/accountability data:
- recruiter seat identity and company assignment
- country of company seat and EU/EEA-eligibility declaration
- firm code and email-domain policy match outcome
- onboarding evidence metadata (company registration proof reference, VAT/tax-id validation state, admin authorization state, establishment-license or seat-proof state where applicable)
- verification case timeline (submitted, deficiency notice, response, decision)
- contractual usage-boundary acknowledgments (shortlist-only use, deletion commitment, no out-of-EU/EEA transfer without separate legal basis)
- annual re-attestation and periodic re-check status records
- candidate statistics access records (who, when, which access type)
- delivered/not-delivered result state and billed/not-billed reason
- referral attribution events and granted bonus-credit records
- credit use records (included, carry-over, bonus, gift, extra usage)
- monthly reconciliation and correction records
4. Purposes and legal bases
- Product operation and session security — provide the Unframed Bit web interface and protect the service against abuse. Legal basis: GDPR Art. 6(1)(b) and 6(1)(f).
- Identity-provider authentication — authenticate applicants and recruiters via an identity provider (Google, LinkedIn, Xing, or GitHub). The provider shares profile and email solely to create a temporary Unframed Bit session. A durable account and legal acceptances are created only when the user completes registration and explicitly accepts the Terms and Privacy Notice. Optional repository analysis (GitHub) requires a separate consent and App installation. Abandoning registration clears the Unframed session and any incomplete stub; the provider-side grant remains until revoked in that provider’s account settings. Legal basis: GDPR Art. 6(1)(b) and 6(1)(f) for the session; Art. 6(1)(a)/(b) for durable registration acceptances.
- Local structured profile handling — let a user maintain a lightweight local Gantt or timeline basis in Unframed Bit. Legal basis: GDPR Art. 6(1)(b), and Art. 6(1)(a) where optional fields are processed by consent.
- Public profile publication — deliver the candidate-controlled public profile surface (QR/direct link) with abbreviated identity for anonymous visitors, and fuller identity plus recruiter-scoped elements for authenticated recruiters. External profile links (LinkedIn, Xing, GitHub, website) are never shown to anonymous visitors. Diagrams and notes may be set to recruiters only, hidden, or recruiters plus anonymous visitors. Legal basis: GDPR Art. 6(1)(a) via the explicit publication toggle and per-element visibility choices; Art. 6(1)(b) and 6(1)(f) for authenticated recruiter delivery where applicable.
- Plan-gated GitHub diagram display and progressive coverage — after repository-analysis consent and Unframed Stats App install, request installation-visible GitHub data, compute and display diagram aggregates, and keep operational last-known-good / coverage metadata (for example analyzed vs total repositories). Depth and audience remain plan-dependent (Free self-dashboard teaser about the last one year; Young Professional / Professional self windows; complete recorded diagrams for authenticated recruiters viewing a candidate in an active paid phase). Analysis proceeds in plan-sized batches; Free coverage may remain incomplete; paid plans target complete coverage of non-idle repositories over successive refreshes. Idle forks may be skipped. Elevated GitHub product levers, when operator-enabled, are limited to entitled paid accounts. Plan/licence metadata selects display window, throughput, and access rule. Legal basis: GDPR Art. 6(1)(a) for optional repository-analysis consent; Art. 6(1)(b) for contracted plan features; Art. 6(1)(f) for audience-appropriate recruiter delivery and operational rate-limit / integrity controls.
- Recruiter company onboarding and auditability (B2B) — assign recruiter users to the correct company workspace and ensure traceable access. Legal basis: GDPR Art. 6(1)(b) and 6(1)(f).
- Recruiter verification lifecycle controls (B2B) — perform one-time onboarding checks, periodic integrity checks, and event-driven re-verification. Legal basis: GDPR Art. 6(1)(b), 6(1)(f), and Art. 6(1)(c) where legal obligations apply.
- Recruiter geography and export-boundary enforcement (B2B) — restrict recruiter onboarding to EU/EEA-established entities and the United Kingdom in the MVP and record contractual no-export/no-hoarding commitments for released candidate analytics. Legal basis: GDPR Art. 6(1)(b) and 6(1)(f).
- Delivered-statistics billing and referral credits (B2B) — calculate contract usage, apply referral or gift credits, and produce auditable monthly invoice and correction trails. Legal basis: GDPR Art. 6(1)(b) and 6(1)(f).
- Compliance and support — accountability, abuse handling, illegal-content reports, and legal request handling. Legal basis: GDPR Art. 6(1)(c) and 6(1)(f).
5. Retention
Default retention baselines (subject to legal holds and statutory accounting where applicable):
- Session data: active session only, plus short technical timeout windows. Incomplete sign-in before registration completion is session-only.
- Incomplete registration after identity-provider sign-in: no durable Unframed Bit account is created; the session (and any legacy incomplete stub) is deleted when the user cancels registration or signs out before completion. Provider-side OAuth grants are managed by the identity provider until the user revokes them there.
- Raw CV uploads or raw CV text: no storage after transformation into structured timeline data.
- Structured career-template / Gantt entries: while actively maintained under an applicable paid/storage window, otherwise 90 days inactivity baseline; then deletion or scheduled cleanup.
- QR stats-link window for own statistics: 30 days (product setting).
- Paid structured-storage window: 30 days per paid period (product setting), without retaining raw CV material.
- No Vetter-origin cache in the current launch mode.
- Recruiter audit / onboarding / acknowledgment records: 24 months after contract end (or longer if legal hold/dispute).
- Billing ledgers: statutory accounting period (minimum 10 years where required).
- Security logs: 90 days unless incident handling requires longer.
- Released recruiter-side candidate analytics: shortlist/search context only; delete after the access phase or at the latest after 90 days unless a legal obligation requires longer retention.
6. Account closure and retention
Self-service account closure ends access. Profile data is deleted where feasible; statutory billing and tax ledgers are retained where required for compliance and authorities. Payhip payment data is governed by Payhip terms. Unused time on an active paid plan is not automatically refunded. Mandatory consumer rights remain unaffected.
7. Data subject rights
Users can request access, correction, deletion, restriction, objection where applicable, and data portability where applicable. Self-service account closure is available where offered. Contact: contact@unframed-bit.eu.
8. Automated decision-making
Unframed Bit MVP does not perform fully automated legal or similarly significant decisions on candidates or recruiters.
9. Changes
Material changes to this notice require a version bump, date update, and corresponding updates in the retained legal pack.