JOBMECHANISMUS
Privacy policy
Version date: 18 September 2026 · 2026-09-18.1
1. Controller and contact
Richard Borisov, Jobmechanismus, Jakob-Haringer-Str. 3, 5020 Salzburg, Austria. Phone: +43 660 3888700. Privacy and DSA: info@jobmechanismus.com. General order contact: mail@jobmechanismus.com.
2. Purposes and legal bases
We process data to operate the platform, communicate, fulfil listing orders and payments, maintain security and comply with legal duties. Depending on the activity, the bases are Article 6(1)(b) GDPR (contract/pre-contract steps), (c) (legal duty), (f) (legitimate interests) and, where required, (a) (consent). Business contact data of a customer’s employees are generally processed in our legitimate interest in handling the business relationship. Consent may be withdrawn prospectively at any time.
3. Website operation, hosting and logs
Hosting and technical email operation are provided through World4You Internet Services GmbH, Austria. Servers may log IP address, time, requested URL, browser/device information, referrer and errors for delivery, security and troubleshooting (Article 6(1)(f) GDPR). Records are kept only for necessary operational/security purposes; specific incidents may require justified preservation for investigation.
4. External services
Website design resources are supplied locally. Payment and security features may connect to the providers described below. Loading or using payment features may transmit IP address, device and transaction information. External application links lead to independently controlled websites.
5. Domain and DNS
The domain is managed through united-domains GmbH, Gautinger Straße 10, 82319 Starnberg, Germany. Form contents are not transmitted for domain management. DNS infrastructure handles necessary domain-resolution requests based on our legitimate interest in availability and secure domain management.
6. Cookies, cart, language and saved jobs
We do not use our own marketing campaign attribution or Google Analytics tracking; WooCommerce order attribution and Site Kit are disabled. Necessary storage supports login, security, language, cart and checkout. WooCommerce may use woocommerce_cart_hash, woocommerce_items_in_cart and a wp_woocommerce_session_ session. Cart cookies typically last for the session; the guest cart session normally expires after about two days. Security/login cookies follow the applicable session.
“Save job” stores your selected listing IDs under jm_saved_jobs in local browser storage. They remain on your device until you remove entries or website data; they are not sent to us as an applicant profile. Language and other feature storage can also be removed by clearing website data. Strictly necessary storage operates within section 165(3) Austrian TKG 2021; associated processing serves a contract, requested feature or legitimate security interests. Non-essential tracking requires separate consent. Payment services may use their own storage necessary for payment and fraud protection; see section 10.
7. Contact and email
Contact forms and email process name, email, optional subject and message to respond, on pre-contract or legitimate communication grounds. FluentSMTP handles delivery; technical sending logs are deleted after 14 days. General correspondence is reviewed after resolution and normally deleted within six months. Contract, invoice and dispute records follow their separate retention rules.
8. Listings and order details
We process supplied job, company and contact details, such as title, employer, location, country, description, engagement type, language, remote rules, pay, application route and deadline, plus order contact, package and recorded declarations. This supports preparation, moderation and fulfilment (Article 6(1)(b) or (f) GDPR). Step 1 stores the listing internally; the binding order is placed in checkout. Publication follows payment and manual approval.
Published listing details, including application email and link, are public. Internal billing and order details are not published as part of the listing. After expiry, listings and their company photos are no longer publicly served. Unpublished submissions are normally deleted three months after review closes; unprocessed submissions without an open or paid order after three months. Removed/expired listings are normally retained non-publicly for no more than six months. Open service obligations and justified statutory or legal preservation needs are reviewed separately.
9. Company photos
Up to three optional images may be submitted with descriptions and a rights declaration. We process image content, description and declaration time for review and agreed display. Images may contain people or other personal information. Upload only permissible content and inform people shown; any required consent must exist. Checking the upload declaration does not replace that consent.
Files are checked for type and size, resized and re-encoded. Original uploads are not published. Processed images remain internal until approval; they are then served through an access check of the listing’s publication status. Public serving ends on expiry/removal. Internal copies are deleted with the listing under section 8. Processing supports the agreed service, legitimate display/evidentiary interests and, where required, consent of the people shown. We cannot technically recall copies already saved by third parties.
10. Orders, payment and invoices
WooCommerce processes orders within our WordPress installation: company, contact, billing address/email, optional VAT ID, package, price, tax, duration, terms acceptance, order number, payment status and transaction references. The accepted terms are saved as evidence. PDF invoices are sent after confirmed payment to the billing email. Full card numbers and security codes are not stored in our WordPress database.
Depending on the payment option offered and selected, necessary contact, billing, transaction and device details are sent to the relevant payment service. Technical security connections may arise when its payment feature loads. Mollie (Mollie B.V., Netherlands) handles offered Mollie methods. PayPal payments may be passed through Mollie or the PayPal integration to PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg. Payments offered through WooPayments use WooPayments services of the Automattic group and Stripe as payment partner. Checkout shows methods actually available.
We use these data for contract performance, reconciliation, refunds, accounting and abuse prevention (Article 6(1)(b), (c) and (f) GDPR). Payment services also fulfil independent legal duties, including fraud and money-laundering prevention, and act as independent controllers in that respect. Details of roles, recipients, retention and any automated security checks: Mollie, PayPal, Automattic and Stripe.
Contract and invoice documents follow applicable statutory retention periods, generally seven years for tax-relevant documents calculated under statutory rules. Ongoing proceedings may require longer retention. These records are managed separately from public listings. Open orders are reviewed for payment, performance and refund needs before deletion.
11. Notices and decisions
For a notice we process listing URL, grounds, explanation, name/email where supplied or required, and the good-faith declaration, plus reference, handling, action, scope, duration, grounds, automated assistance and delivery status. Under the Article 16(2)(c) DSA exception, name and email may be omitted; without contact an individual response is not possible.
Records are non-public and support receipt, review, decision, notification and reconsideration under the DSA (Article 6(1)(c) GDPR) or legitimate interests in lawful content and legal defence. Advertisers receive necessary reasons, normally without the reporter’s identity/contact details. Records are deleted three years after final closure unless a justified statutory/legal retention hold applies. Necessary information concerning suspected dangerous offences may be passed to competent authorities under Article 18 DSA.
12. Form protection
Nonces, timing checks, a honeypot and rate limits protect against abuse. A temporary HMAC value derived from the IP address limits requests. It remains valid for up to one hour since its last permitted refresh; expired records are removed by WordPress cleanup. The basis is our legitimate interest in secure operation. If a notice cannot be submitted technically, it may also be sent by email.
13. Wordfence
Wordfence by Defiant, Inc., USA, protects against attacks and malware. Depending on the feature, IP addresses, URLs, request information, account and security events may be processed. This serves our legitimate security interests. Defiant is engaged under its applicable Data Processing Addendum, which includes standard contractual clauses for relevant transfers. Details and safeguards: Wordfence DPA and privacy policy.
14. Language and accounts
TranslatePress stores website translations locally; visitor requests do not use an automatic external translation service. Public registration and automatic account creation on ordering are disabled. Necessary administration accounts support management/security; accounts no longer required are deleted following review.
15. Recipients and transfers outside the EEA
Depending on the activity, recipients include hosting/email providers, security services, the selected payment provider and necessary payment partners, confidential advisers and authorised authorities. Processing agreements are used where required; independent payment controllers must be distinguished from processors.
Security and payment services in particular may process data outside the EEA, including in the USA. Chapter V GDPR requirements apply: an applicable adequacy decision or suitable safeguards, especially standard contractual clauses. The linked provider notices explain the safeguards used. Further information and available copies may be requested at info@jobmechanismus.com.
16. Backups and testing
Backups support recovery and resilience. Deleted data may remain in a backup until routine overwriting; recorded deletions must be reapplied after restoration. Access is restricted to authorised persons. Separate staging supports tests and maintenance; test data are used where possible. The basis is our legitimate interest in secure operation. Real card data are not needed for tests.
17. Retention and required information
Required fields enable communication, review, ordering or qualified notices. Without necessary information, the relevant function may not be fully provided. Optional images and other voluntary information are not prerequisites for booking. Separate privacy consent is not required merely to perform the contract.
Technical deletion runs take place regularly through website maintenance. Justified retention holds are documented and reviewed. Existing legacy records are reviewed first; applicable periods run from documented completion of that review. General correspondence and financial records are reviewed separately from listing deletion.
18. Your rights
Subject to statutory conditions, you have rights of access, rectification, erasure, restriction and portability, and may withdraw consent prospectively. You may object to Article 6(1)(f) processing for reasons relating to your particular situation. We then continue only for compelling overriding grounds or legal claims. Contact: info@jobmechanismus.com.
You may complain to a supervisory authority, including the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at. Jobmechanismus does not make solely automated publication decisions within Article 22 GDPR. Independent payment-service checks are explained in their notices.
19. Changes
We update this information when features or providers materially change. Orders remain subject to the terms incorporated into them; this notice describes current data processing.
Online applications – supplement dated 19 September 2026
Jobmechanismus (Richard Borisov, Jakob-Haringer-Str. 3, 5020 Salzburg, mail@jobmechanismus.com) processes your name, email, message and PDF to provide the transmission service you request to the company identified here (Article 6(1)(b) GDPR). Technical safeguards support our legitimate interest in secure operation (point (f)). That company and authorised administrators have access; hosting and email providers support the service. Documents are encrypted at rest, never published and not used for advertising or automated selection. The employer receives a protected link. The platform copy is deleted after 30 days and access is blocked from that point. Technical backup copies follow the hosting backup cycle; expired records are deleted again after restoration. Copies already downloaded by the employer remain under its responsibility. Providing data is voluntary, but required fields are necessary for transmission. Do not upload health data, identity documents or other particularly sensitive information. See the privacy policy for access, correction, erasure and other rights, recipients and supervisory authority details. No general candidate profile is created and no other employers receive your application.
Protected employer access uses a technically necessary secure HttpOnly session cookie (__Host-jma_…, one hour). Access links are valid for seven days. Email logs may contain email addresses and access links and follow the general 14-day log retention period. Issuing a replacement link revokes previous access. The application pages themselves load no analytics, advertising or payment services. In test mode only test data is intended and all notifications are redirected to mail@jobmechanismus.com.