Who is responsible for the data processing.
The controller within the meaning of Art. 4 No. 7 GDPR and Art. 5 lit. j revFADP is:
Address
Fakten Verlagshaus AGChurerstrasse 160b
CH-8808 Pfäffikon SZ
Switzerland
UID: CHE-357.801.789
Contact
Data Protection Officercompliance@sentinel.jobs
Phone on request
Brand: Sentinel.jobs
For users in the European Union and the EEA, Sentinel.jobs appoints a representative pursuant to Art. 27 GDPR with registered seat in Berlin (Sentinel.jobs Deutschland GmbH, Friedrichstrasse 68, D-10117 Berlin). Upon expansion into third countries with their own representative requirements (e.g. UK GDPR Representative, KVKK representative for Turkey), the respective representation will be added at this point.
One standard for Switzerland and Europe.
This policy applies to users in Switzerland and throughout the entire European Economic Area (EU/EEA). Sentinel.jobs operationally targets Switzerland, Germany and Austria for the time being; the expansion into further European markets is foreseen and already covered by this policy.
We process personal data consistently in accordance with the highest applicable standard — in practice, the requirements of the GDPR in conjunction with the revFADP. Where the national law of a Member State imposes stricter or more specific requirements (e.g. on cookies, employee data protection or the age of consent), we apply the stricter provision in each case.
What data we collect.
We collect only the data necessary to provide the platform and to perform the contractual relationship:
- §Master and profile data: name, salutation, email, telephone, place of residence, career history.
- §Application data: CV, cover letter, references, certificates, suitability profiles.
- §Login and security data: encrypted password, two-factor token, login history.
- §Usage data: jobs viewed, search queries, click paths, device and browser information.
- §Communication data: messages between applicants and employers.
Data of special categories (Art. 9 GDPR / Art. 5 lit. c revFADP) — such as health or criminal record data — are processed only if you explicitly submit them in the application context, and only with your informed consent.
On what basis we process.
Depending on the processing purpose, we rely on the following legal bases:
- §Contract performance — Art. 6 para. 1 lit. b GDPR / Art. 31 para. 1 revFADP: provision of the user account, brokering of job offers.
- §Legitimate interests — Art. 6 para. 1 lit. f GDPR / Art. 31 para. 2 revFADP: platform security, fraud prevention, statistical analyses.
- §Consent — Art. 6 para. 1 lit. a GDPR / Art. 6 para. 6 revFADP: newsletter, optional tracking, publication of profiles.
- §Legal obligation — Art. 6 para. 1 lit. c GDPR: accounting, tax retention, disclosure obligations vis-à-vis authorities.
What your data is used for.
- §Matching suitable job offers based on your profile.
- §Communication with employers when you actively apply.
- §Editorial quality control and verification of listings.
- §Protecting the platform against abuse, fraud and automated access.
- §Anonymised analyses to improve search and recommendation logic.
A fully automated decision within the meaning of Art. 22 GDPR or Art. 21 revFADP does not take place. Recommendations from our matching system are non-binding suggestions.
Sensitive data in the application process.
Professions in security, police and forensics & medicine often require extended proofs of suitability. These include criminal record extracts, medical certificates or security clearances.
- §Such documents are only forwarded if you actively submit an application.
- §Storage is encrypted and only for the duration of the application procedure.
- §Withdrawal of the application leads to immediate deletion — subject to statutory retention periods.
Cookies, logfiles and reach measurement.
We use cookies and comparable technologies only where necessary to provide the platform (technically required cookies) or where you have given your explicit consent (analytical and convenience cookies).
- §Necessary: session management, login status, CSRF protection — legal basis Art. 25 para. 2 TTDSG / § 165 TKG / Art. 45c FMG.
- §Analytics: aggregated reach measurement via a self-hosted solution — opt-in, revocable at any time.
- §Convenience: storing your search preferences — opt-in.
An overview of all cookies used as well as the option to adjust your consent can be found under Cookie settings.
To whom data is disclosed.
Disclosure of your data occurs only in the following situations:
- §To employers when you actively apply for a posted job.
- §To technical service providers in the context of order processing (hosting, email dispatch, identity verification).
- §To authorities, where there is a statutory disclosure obligation (e.g. Art. 19 revFADP, § 24 BDSG, § 4 DSG).
Written contracts pursuant to Art. 28 GDPR or Art. 9 revFADP exist with all processors.
Data transfers to third countries.
A mutually recognised level of protection exists between Switzerland and the EU/EEA. Transfers to other third countries take place only when an adequate level of protection is ensured:
- §Adequacy decision of the EU Commission or the FDPIC.
- §EU Standard Contractual Clauses (SCC) including the FDPIC's Swiss supplements.
- §For US recipients: certification under the EU-US Data Privacy Framework or the Swiss-US Data Privacy Framework.
How long we retain data.
- §Active accounts: for the duration of use plus 12 months of inactivity.
- §Application data: up to 6 months after completion of the application procedure (DE: AGG deadline).
- §Accounting data: 10 years (CH: OR 958f / DE: § 257 HGB / AT: § 132 BAO).
- §Logfiles: max. 14 days, unless security incidents are documented.
What you can request.
As a data subject, you are entitled — regardless of the applicable law — to the following rights:
Please send requests in writing to compliance@sentinel.jobs. We respond within 30 days (GDPR) or without undue delay, but at the latest within 30 days (revFADP).
Right to lodge a complaint.
If you consider that the processing of your data is unlawful, you may contact the competent supervisory authority:
CH-3003 Bern
edoeb.admin.ch
D-53117 Bonn
bfdi.bund.de
A-1030 Vienna
dsb.gv.at
Technical and organisational measures.
- §Encrypted transmission via TLS 1.3 as well as encrypted data storage (AES-256 at rest).
- §Strict access permissions; four-eyes principle for critical operations.
- §Regular penetration tests by independent third parties.
- §ISO/IEC 27001-compliant processes, annual re-audit.
- §Notification obligation in the event of data breaches: 72 h GDPR / "as soon as possible" revFADP.
Updates to this policy.
This privacy policy may be adapted to reflect changed legal or technical conditions. In the event of material changes, registered users will be informed in advance by email. The current version published on this page applies in each case.