Privacy policy
Information under Articles 13 and 14 GDPR.
Only the German version of this privacy notice is legally binding. German version
1. Controller
(1) The controller for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG) is: Rehavio e.U. Seitenstettengasse 5/37, 1010 Wien, Österreich Email: datenschutz@trazio.eu (2) No data protection officer has been appointed, because the conditions of Article 37 GDPR are not met.
2. Overview and roles
(1) trazio.eu is a job board for Austria. Companies publish job ads; applicants search, read and apply without an account. (2) For company account data, orders and invoices we are the controller within the meaning of Article 4(7) GDPR. (3) Application data we process on behalf of someone else: the controller is the company that placed the job ad, and we are its processor under Article 28 GDPR. Questions about a particular application therefore go to that company; we will help you get there. (4) We use no tracking, analytics or advertising services.
3. Applications
(1) When you apply, we process: – your first name and last name, – your phone number, – your email address, if you give one (optional), – your answers to three questions: work experience, EU citizenship and – only if you are not an EU citizen – a visa, – the language you were using the site in, – the time of the application and the job ad it relates to. (2) We never ask for a CV, a covering letter or a photo, and there is no field for one. (3) Only the company that placed the job ad receives these details, so that it can call you. We do not pass them on to any other company. (4) If you give an email address, we send you a short confirmation of receipt. We send no marketing. (5) To protect the form against automated mass applications we keep short-lived counters. They use an irreversible hash of your IP address and of the phone number you entered; the IP address itself is not stored. (6) Applications for apprenticeships may come from minors. In that case we collect no additional data and send no marketing.
4. Company accounts
(1) For a company account we process the login email address, the password as an Argon2id hash only and never in clear text, the details of the company profile (company name, address, industry, website, short description, contact person, phone number, billing address, VAT ID, company register number, logo), the times of sign-ins and, where two-factor sign-in is enabled, the data needed for it. (2) For orders and invoices we process the customer numbers held by our payment provider and our invoicing service, the order and payment data and the invoice data. (3) Actions that change data in the administration area of the platform are logged so that they remain traceable. (4) The legal basis is the performance of the contract with the company and, for the logging, our legitimate interest in running the platform securely.
5. Reporting a job ad
(1) “Report this ad” lets you point us at a job ad. We process the reason you select, your optional message and the email address you optionally give us so that we can ask you follow-up questions. (2) A report can be made without an email address. The legal basis is our legitimate interest in running the platform lawfully. (3) To protect the form against automated mass reports we keep short-lived counters. They use an irreversible hash of your IP address; the IP address itself is not stored. (4) We keep reports while we are handling them, and beyond that for as long as is needed to prevent repeated breaches.
6. Legal bases
(1) We process personal data on the following bases: – Article 6(1)(b) GDPR (contract and steps prior to a contract): your application, the company account and the services booked, – Article 6(1)(c) GDPR (legal obligation): keeping invoices under section 132 of the Austrian Federal Fiscal Code, – Article 6(1)(f) GDPR (legitimate interests): protection against abuse, logging, handling reports, – Article 6(1)(a) GDPR (consent): where explicitly given, for instance for notifications to a separately confirmed email address. (2) The legal basis for processing application data in the employment context lies with the company as controller.
7. Where data is stored, and how it is protected
(1) All data is stored on servers inside the European Union. We run the application and the database at Hetzner Online GmbH, located in Germany or Finland. (2) Technical and organisational measures: encrypted transmission over HTTPS/TLS, passwords stored as a hash only, two-factor sign-in for every account of our team, separation of data by company so that a company only ever sees the applications to its own ads, logging of administrative access, and suppression of personal data in our operational logs. (3) Our team does not see application data in day-to-day operation. Access is possible only through a separate area for handling data subject requests, requires a stated reason and is logged.
8. Service providers and processors
(1) We use the following service providers and have concluded data processing agreements under Article 28 GDPR with them: – Hetzner Online GmbH, Germany: hosting of the application, the database and files, – Mollie B.V., Netherlands: handling company payments, – easybill GmbH, Germany: issuing invoices, – Sendinblue SAS (Brevo), France: sending email. (2) For the translation of a job ad, which a company can book as an option, we use the interface of Anthropic PBC, USA. Only the four free-text fields of the ad, written by the company itself, are transmitted. Application data is never transmitted. The transfer to a third country is based on the European Commission's standard contractual clauses. (3) When a job ad goes online or offline we report that to Google's indexing interface, so that it appears in job search sooner and disappears sooner. Only the address of the public ad page is transmitted, no personal data. (4) Application data is not transferred to any third country outside the European Union.
9. How long we keep data
– Applications: 210 days from receipt, then deleted automatically. The company can delete an application earlier at any time. – Company accounts: for the term of the contract, and after that until the general three-year limitation period has run. – Invoice and payment data: seven years (section 132 of the Austrian Federal Fiscal Code). – Log of administrative access: three years. – Log of sent email: contains a masked recipient address only. – Abuse-detection counters: only for the length of the window in question, so hours to days.
10. Your rights
(1) You have the right of access (Article 15 GDPR), to rectification (Article 16), to erasure (Article 17), to restriction of processing (Article 18), to data portability (Article 20) and to object (Article 21), as well as the right to withdraw consent at any time with effect for the future (Article 7(3) GDPR). (2) To exercise them, write to datenschutz@trazio.eu. If your request concerns an application, we act on it on behalf of the company responsible or forward it to that company. (3) You also have the right to lodge a complaint with the supervisory authority: Österreichische Datenschutzbehörde Barichgasse 40–42, 1030 Vienna, Austria dsb@dsb.gv.at, www.dsb.gv.at
11. Cookies
(1) We only use cookies that are technically necessary: a session cookie for signing in to the company area, and a cookie that remembers your choice of language. (2) We use no analytics or advertising cookies. No consent is therefore required, and there is no cookie banner.
12. Changes to this notice
We update this notice when the processing changes. Registered companies are informed of material changes by email. The current version is always on this page.