This Privacy Policy describes how the OFMJobs platform collects, uses, shares, and protects personal data when you use the Platform. This Privacy Policy applies to Job Seekers, Employers, Organisation Members, and any other visitors to the Platform.
1. Controller and contact
For all privacy queries, requests, and complaints, contact: support@ofmjobs.com.
2. Scope and roles
Controller. We act as controller for personal data you provide through your use of the Platform — profile data, applications, test attempts, in-platform messages, account activity, and similar data.
Processor. For personal data submitted to a specific Employer as part of an application or via in-platform messaging, we act as processor on behalf of that Employer once the data has been received by them. Employers are responsible for their own use of that data under their own privacy practices.
User-to-user communication. Communication between Job Seekers and Employers takes place through the Platform's in-platform chat. Messages are stored on our infrastructure and may be reviewed by AI moderation systems for compliance with our Terms of Service.
3. Personal data we collect
We collect personal data in the following categories:
Account and profile data — name, email address, password (hashed), date of birth (for age verification), country and city, profile photo, professional title, skills, languages, experience, education, role preferences.
Application and hiring data — job applications, cover letters, candidate notes, screening responses, attached materials.
Test data — skills test responses and scores; Chatbot Test full conversation transcripts, AI judge scores and verdicts, session metadata (start time, end time, duration, message count, completion percentage); test integrity signals (tab-switch events and counts, copy/paste blocks, time per question, session duration, device fingerprint, IP address).
Live observation logs. When an Employer observes a Chatbot Test session in real time, the observation event is logged. The Job Seeker is not notified of observation, but the event is retained for audit, abuse-review, and data-subject-rights purposes.
Result-sharing logs. When a Job Seeker chooses to recycle a previously completed Chatbot Test result for a subsequent Employer (rather than running a fresh attempt), the sharing event is logged — recording which Employer received the recycled result and when — for audit and data-subject-rights purposes.
Communication data — content of in-platform messages, attachments, reactions, message metadata (timing, delivery, read state); content of customer-support conversations; email engagement data (delivery, opens, clicks) for marketing emails.
Billing data — name, billing address, partial payment-card details (handled by Stripe; we do not store full card numbers), subscription state, invoices, transaction history.
AI processing outputs — application scores, candidate summaries, AI moderation flags, AI judge verdicts on Chatbot Tests, prompt-filter results, generated as outputs of AI processing on your data and stored as part of your record on the Platform.
Technical and device data — IP address, browser type and version, operating system, device identifiers, cookie identifiers, log data (timestamps of access, pages viewed, actions taken), referring URL.
Affiliate data — referral codes generated, attributed sign-ups, paid conversions, payout election and payout history.
4. How we collect personal data
We collect personal data: (a) directly from you when you create an account, complete your profile, post or apply to a job, take a test, send a message, contact support, or otherwise interact with the Platform; (b) automatically through cookies and similar technologies when you access the Platform; (c) from third parties such as identity-verification services, payment processors, and (with your consent) social-sign-in providers.
5. Purposes and legal bases for processing
We process personal data for the following purposes. Where the General Data Protection Regulation (GDPR) or similar laws apply, the corresponding legal basis is identified.
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide and operate the Platform; create and manage your account | Performance of a contract (Art 6(1)(b)) |
| Process payments and provide billing services | Performance of a contract (Art 6(1)(b)); legal obligation (Art 6(1)(c)) |
| Process applications, tests, and communications between users | Performance of a contract (Art 6(1)(b)) |
| AI processing (scoring, summary, moderation, search, Chatbot Test dialogue and scoring, off-platform funnelling detection) | Performance of a contract (Art 6(1)(b)); legitimate interests in delivering and securing the Platform (Art 6(1)(f)); where required, consent (Art 6(1)(a)) |
| Maintain Platform security, prevent fraud, detect abuse | Legitimate interests (Art 6(1)(f)); legal obligation (Art 6(1)(c)) |
| Send service / system / transactional emails | Performance of a contract (Art 6(1)(b)) |
| Send marketing emails | Consent (Art 6(1)(a)) where required; legitimate interests (Art 6(1)(f)) otherwise |
| Comply with legal, regulatory, tax, and accounting obligations | Legal obligation (Art 6(1)(c)) |
| Establish, exercise, or defend legal claims | Legitimate interests (Art 6(1)(f)) |
| Affiliate program administration and payout | Performance of a contract (Art 6(1)(b)) |
| Share previously generated Chatbot Test results with subsequent Employers at the Job Seeker's direction | Consent of the Job Seeker (Art 6(1)(a)) given at the point of recycling the result |
Where we rely on legitimate interests, we have carried out a balancing assessment to ensure those interests are not overridden by your rights and freedoms. You have the right to object to processing based on legitimate interests; see Section 14.
6. Artificial intelligence processing
We use artificial intelligence ("AI") across the Platform to provide and enhance core features. AI processing covers, among other things: candidate scoring, profile summary generation, AI-assisted job-post drafting, AI-powered candidate search, content moderation, off-platform funnelling detection, Chatbot Test persona dialogue, Chatbot Test scoring (AI judge), and test-response quality evaluation.
Automated decision-making (GDPR Art 22). Some AI processing produces decisions with significant effects on you, including AI applicant scoring that may inform a hiring decision, AI moderation that may automatically reject or remove a job post or content, AI test evaluation affecting test scores, and automatic termination of a test attempt for excessive tab-switching. Where this applies, you have the right to:
- Request human review of the decision;
- Express your point of view;
- Contest the decision.
To exercise these rights, contact support@ofmjobs.com.
No training on your data. We do not use your data to train AI models. Our data processing agreements with our AI service providers prohibit those providers from training their models on data submitted to them via the Platform.
AI service providers. Our current AI service providers are OpenAI and Anthropic; we may add or change providers from time to time. See Section 11 for our full list of sub-processors.
Accuracy. AI outputs may contain errors. We do not warrant the accuracy of AI-generated content. Employers using AI outputs to inform hiring decisions are responsible for reviewing those outputs.
7. Chatbot Test data
Chatbot Tests are AI-powered conversation simulations between Job Seekers and AI personas. When you take a Chatbot Test:
- The full chat transcript between you and the AI persona is recorded and stored on the Platform;
- Test metadata (start time, end time, duration, message count, completion percentage, anti-cheat signals) is recorded;
- The AI judge's output (score, per-criterion narrative, overall verdict) is recorded;
- Live observation events are logged when an Employer observes your session in real time. You are not notified when an Employer observes your session in real time, as advance notification would invalidate the test, but observation events are logged so that we can provide an audit trail, detect abuse of the observation feature, and so that you can learn (via a data-subject-rights request) whether your session was observed and by whom.
Who can see your Chatbot Test data. The Employer who ran the test (post-completion only — pre-25%-threshold sessions are not surfaced to the Employer); any subsequent Employer to whom you have chosen to recycle the result (see "Recycling a result for subsequent Employers" below); you, in your own test history; our AI moderation and quality-assurance systems (automated review); our staff under access controls (for support, abuse review, and quality assurance only).
Your consent at the time of taking a test. By taking a Chatbot Test, you consent to live observation by the Employer running the test, full transcript storage, AI evaluation and scoring, and sharing of results with the Employer who ran the test.
Recycling a result for subsequent Employers. A Job Seeker only needs to complete a Chatbot Test once. When a subsequent Employer sends the same Chatbot Test to a Job Seeker who has already completed an attempt, the Job Seeker is presented with an active choice — neither option is automatic — to either:
- Recycle the previously completed result — share the existing score, AI verdict, and full chat transcript with the subsequent Employer; or
- Take the test again — run a fresh session whose new score, AI verdict, and transcript replace the previous canonical record going forward.
By selecting to recycle a previously completed result, the Job Seeker authorises the sharing of that previously stored result — including the full transcript that was generated under the original test session — with the subsequent Employer. We log this sharing event (which Employer received the recycled result and when) so that the Job Seeker may, on request, learn how their Chatbot Test result has been shared and with whom. Recycling does not generate a new transcript or AI evaluation; nothing new is created or processed by AI as part of the recycle path.
Retention. Chatbot Test transcripts are retained while your account is active and for 30 days after account closure. You may request earlier deletion of your Chatbot Test transcripts independently of broader account deletion by contacting support@ofmjobs.com. Once a Chatbot Test result has been shared with an Employer (including where you choose to recycle a previous result), that Employer may retain its own copy under its own privacy practices, and OFMJobs cannot guarantee deletion of copies already delivered to Employers. Deleting a transcript prevents it from being shared with any further Employers. We retain a record of deletion requests for audit purposes.
8. Test integrity data
When you take a test on the Platform, we collect integrity-related data:
- Tab-switch events — record of when you switched away from the test browser tab and back. Tab-switch counts above a configured threshold may result in automatic termination of the attempt and a permanent integrity flag on the attempt record, visible to any current or future Employer reviewing your profile.
- Copy/paste attempts — record of attempts to use the clipboard (which are blocked by the Platform during tests);
- Time per question — for skills tests with multiple questions;
- Session duration — overall test duration;
- Device fingerprint and IP address — for fraud detection and pattern analysis across attempts.
These signals are shared with the Employer running the test as integrity flags. We may also use these signals for Platform-wide fraud detection and to invalidate test attempts found to violate Platform rules.
A future Platform release (Phase 6) is expected to introduce webcam screenshot capture as an additional integrity measure; we will update this Privacy Policy with full disclosure (capture frequency, retention, who can see, consent model, deletion rights) before that feature is enabled.
9. Off-platform funnelling detection
We use AI-powered content moderation, and additional platform-enforced controls, to detect attempts by Employers to drive Job Seekers off-platform before they apply (for example, posting external messaging handles, redirecting to external apply websites, or replacing canonical test-invitation messages with custom contact-funnel text). For this detection: we process the content of each job post (title, description, screening questions, attached materials) and the content of platform-generated test invitations and Employer-Job Seeker messages; this happens at the time of posting, sending, or editing; the post or message may be auto-rejected, suspended, or removed if it violates the rule, and the Employer may be flagged or have their account suspended for repeated violations.
Employers may request human review of any automated decision by contacting support@ofmjobs.com.
10. How we share your personal data
We share personal data with:
- Other users of the Platform, in the ordinary course of your use of the Platform — for example, your profile is visible to Employers when you apply for a job; an Employer's job post is visible to Job Seekers browsing the Platform; your test results are shared with the Employer running the test. Where you have chosen to recycle a previously completed Chatbot Test result for a subsequent Employer, the existing score, verdict, and transcript are shared with that subsequent Employer per Section 7.
- Our sub-processors and service providers (see Section 11), strictly for the purposes of operating the Platform and under contractual obligations consistent with applicable data-protection law.
- Affiliate-program participants, where you sign up via a referral — your sign-up and (if applicable) paid-conversion event is attributed to the referring user; the referring user does not see your profile or contact details.
- Authorities, courts, or other third parties where we are required to do so by law, to comply with a legal process, to enforce our Terms of Service, or to protect our or others' rights, property, or safety.
- A successor entity in connection with a merger, acquisition, or sale of all or part of our business.
We do not sell your personal data.
11. Sub-processors and service providers
We use the following third-party services to deliver the Platform. Each is bound by a data processing agreement consistent with applicable data-protection law. Sub-processors may change over time; the current list is maintained on this page and material changes (new sub-processor additions or material scope changes) will be communicated by email and/or in-platform notice.
| Provider | Purpose | Data categories | Location |
|---|---|---|---|
| Stripe | Subscription billing, payment processing, invoicing | Billing data (name, billing address, partial card details), subscription state | United States (global) |
| Resend | Transactional and marketing email delivery | Email addresses, message content, send/open/click metadata | United States |
| Chatwoot | Customer support chat platform | Support conversation content, attachments, user identifiers | Vendor-hosted (Chatwoot Cloud) |
| OpenAI | AI service provider (subset of AI features) | Text content submitted for AI processing | United States |
| Anthropic | AI service provider (subset of AI features) | Text content submitted for AI processing | United States |
| Cloudflare | DNS, CDN, DDoS protection, web application firewall | IP addresses, request headers, transient request data | United States (global) |
| PostHog | Product analytics, autocapture, feature flags | Pageviews, events, user identifiers (post-login) | United States / European Union |
At Phase 1 launch, Stripe is the only payment processor in use. Additional payment processors evaluated for V2 (such as Whop) are not in production at Phase 1.
12. International data transfers
The Platform serves users globally. Personal data may be transferred to, and processed in, countries outside of your country of residence, including countries whose data-protection laws differ from those of your country.
Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country not recognised as providing an adequate level of data protection, we rely on one of: (a) Standard Contractual Clauses approved by the European Commission (and the UK addendum where applicable); (b) adequacy decisions where they apply; or (c) other safeguards required by applicable law.
Sub-processors located outside the EEA / UK at the date of this Privacy Policy include OpenAI (US), Anthropic (US), Stripe (US), Cloudflare (global), Resend (US), and PostHog (US / EU).
13. Data retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including to comply with legal, accounting, or reporting obligations.
| Data category | Retention period | Notes |
|---|---|---|
| Account profile data | While account is active + 30 days after account closure | |
| Application data | While account is active + 30 days after closure | Copies held by Employers are governed by the Employer's own privacy practices |
| In-platform chat messages | While account is active + 30 days after closure | |
| Chatbot Test transcripts | While account is active + 30 days after closure | |
| Test integrity signals (tab-switch counts, flags, etc.) | Same as the parent test attempt | Including any integrity flag |
| AI processing outputs (scores, summaries, moderation flags, AI judge verdicts) | While the parent record (application, job post, test attempt) is retained | |
| Live observation event logs | 30 days after closure | |
| Chatbot Test result-sharing (recycle) logs | 30 days after closure | Records which Employer received the recycled result and when |
| Billing records | 7 years from the relevant transaction | Tax and accounting compliance |
| Marketing email engagement data | 24 months from your last engagement | |
| Support conversations | While account is active + 24 months after closure | |
| Webcam screenshots (future Phase 6) | 90 days from capture, then automatic deletion | Not currently collected |
Self-serve deletion. You may delete your account directly from in-platform account settings. Deletion removes your personal data per the retention schedule above; certain records (billing, fraud-prevention, legal-hold) are retained where required by law.
Once personal data has been anonymised so that it can no longer be linked to a specific user, we may retain it indefinitely for analytical purposes.
14. Your rights
Subject to applicable law, you have the following rights with respect to your personal data:
- Right of access — request a copy of the personal data we hold about you;
- Right to rectification — correct inaccurate or incomplete data (most fields can be edited directly in your account);
- Right to erasure ("right to be forgotten") — request deletion of your data, subject to legal retention requirements (self-serve deletion is available in account settings);
- Right to data portability — receive your data in a structured, commonly used, machine-readable format;
- Right to object — object to processing of your data for specific purposes (including marketing);
- Right to restrict processing — limit how we use your data while a dispute is resolved;
- Right to human review of automated decisions — see Section 6;
- Right to withdraw consent — where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. This includes the right to revoke the sharing of a previously recycled Chatbot Test result.
How to exercise your rights. Submit requests to support@ofmjobs.com. We will:
- Verify your identity before acting on the request;
- Respond within 30 days (extendable by 60 days for complex requests, with notice);
- Provide our response free of charge unless the request is unfounded or excessive.
Complaints. If you believe your rights have been infringed, you may lodge a complaint with the supervisory authority in your country of residence.
15. Cookies and tracking technologies
We use cookies and similar technologies to operate the Platform, remember preferences, measure performance, and personalise content. Cookies include:
- Essential cookies — required for the Platform to operate (session authentication, security, load balancing). These cannot be disabled.
- Functional cookies — remember your preferences (such as language and display options).
- Analytics cookies — track Platform usage (anonymised for non-authenticated users) via PostHog.
- Marketing email engagement cookies — track link clicks and conversion events from our marketing emails, via our email delivery provider.
- Support widget cookies — maintain continuity of customer-support conversations.
You can manage cookie preferences through your browser settings or through the cookie banner where available. Disabling certain cookies may impact Platform functionality.
16. Security
We implement and maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorised access, alteration, disclosure, and destruction. These include access controls, encryption in transit, hashed credentials, logging and monitoring, and vendor due diligence.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security but we work continuously to protect your data.
17. Children
The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe we have collected personal data of someone under 18, contact support@ofmjobs.com and we will take appropriate action.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Platform, by email, or by other reasonable means before the changes take effect (or such longer period as required by applicable law). The "Last updated" date at the top reflects when the policy was last revised.
19. Contact
Questions, requests, or complaints about this Privacy Policy or our handling of your personal data should be directed to:
Email: support@ofmjobs.com