The legal bit
Privacy policy
This describes what this platform actually does with your data, not what such documents usually say. It was written against the source code. Where something is uncomfortable, it is in here anyway. The Swiss Data Protection Act (FADP) governs.
Last changed 2026-08-24 · version 3bdfad4a1c8c
Who is responsible
The controller is Ritzl & Gietz, Switzerland. The full operator details are in the legal notice. Data protection questions: hello@ritzl-gietz.ch. We answer data protection requests within 30 days.
This platform is being built. It is currently being trialled with a limited number of organisations and professionals.
What we collect
Everything below is given by you. We buy no data, we scrape no other portals, and we create no profile before you create one.
- Account: email address, password (only as a scrypt hash, never in clear text), preferred language, timestamps.
- Profile: name, profession, canton and town, experience, workload, salary expectation, availability, skills, languages, qualifications, employment history, switching criteria.
- A phone number, if you give one. It appears in no search and on no profile, it is released only when you accept an offer.
- Documents: CV, certificates, references, identity copies, if you upload them. A CV can contain sensitive details you wrote into it yourself; we ask for no such details and do not evaluate them.
- For organisations: company name, UID, organisation type, address, website, phone number, contact person's name and function.
- Offers, conversations, attachments and meeting proposals that run through the platform.
- Contact form: role, topic, name, email address and your message. The message is delivered to our team as email and not additionally stored in the database; what is stored is only that a send happened, with category and time.
What we use the data for
- Operating the marketplace: showing profiles, answering searches, delivering offers and conversations.
- Review: the manual release of profiles and organisations, verification marks included.
- Communication: confirmation codes, notifications about offers and messages, answers to your requests.
- Security: spotting abuse, limiting access, tracing who decided what.
- Not: advertising. There is no ad network, no tracking across other websites, and no selling of data.
Who sees what, and what they do not
This is the section that matters most. The limits are implemented in the database queries, not in the display: your name does not leave the server at all when the other side may not see it.
- Signed-out visitors and unverified organisations see initials, profession, canton, experience and workload. No name, no town, no employer, no salary expectation.
- Verified organisations additionally see the details you explicitly released for verified organisations, such as name, town or photo, depending on your switches.
- Your email address and phone number are released only by your acceptance of a specific offer, and only to that one organisation. Asking a question does not release them.
- Your profile is visible only after a person here has reviewed and released it. It cannot publish itself.
We can read conversations
Our oversight team can read conversations between professionals and organisations. That is for quality and safety, spotting harassment, or attempts to take a deal off the platform.
Every such access is logged, with the name of the person and the time. It is also stated above every conversation in the application, not only here.
We do not read them to target advertising, and we do not process conversations automatically.
Automated reading of CVs
When you upload a CV we extract the text and send that text to a language-model provider so it can be turned into fields. The file itself is not sent; the text is.
Depending on the configured provider, that text leaves Switzerland and the EU. Which provider is configured right now is stated at the foot of this page, it is read from the running configuration, so it cannot go stale.
The result is a suggestion, not a decision: you see every field it read and correct it before anything is saved. No model decides anything about you, and there is no automated individual decision with legal effect.
The ordering of search results is not decided by a model either. It follows a fixed, inspectable calculation over the criteria both sides stated.
For each reading we store the provider, model, duration, cost and a checksum of the text, never the text itself.
Active job search by our team
When we have agreed with you to support your job search actively, a person on our team hands your profile over to our internal placement tool: the details from your profile including your wishes and switching criteria, and your uploaded documents.
That tool is Ritzl & Gietz's own system and runs on the same service providers as this platform (Vercel and Supabase, see below). It exists solely to find fitting positions for you and to coordinate approaching organisations on your behalf.
The handover never happens automatically: a person triggers it individually, every handover is logged with name and time, and the links to your documents expire after 15 minutes and work only for that tool.
This support also includes creating a dossier (PDF) from your profile and presenting it to a specific organisation. Such a dossier never contains private contact details, that is email address, phone number or home address; contact runs through us.
Service providers and transfers abroad
We run no data centres of our own. The following providers process data on our behalf; each is bound by a data processing agreement under its standard terms.
- Supabase (database and file storage): account, profile and organisation data, conversations, and uploaded documents. Servers in Frankfurt (EU).
- Vercel (hosting): the application runs in the Frankfurt region (EU); page delivery goes over Vercel's worldwide network. Vercel is a US company. Vercel also measures anonymous page performance for us (Speed Insights), without cookies and without recognising individuals.
- Resend (email delivery): confirmation codes and notifications, USA.
- Twilio (SMS delivery): confirmation codes to organisations, USA. Used only while SMS sending is switched on.
- Language-model provider for CV reading: see the section above and the live statement at the foot of this page.
- swisstopo (address search, Switzerland): when you type a Swiss address, for an organisation during registration or as your home address in the profile, your browser fetches suggestions directly from the federal geoportal (api3.geo.admin.ch). Your IP address and the typed text reach that federal service, Switzerland.
- komoot GmbH (address search, Germany): when your profile states that you live in Germany and you type an address, your browser fetches suggestions directly from the Photon geocoder (photon.komoot.io), which is based on OpenStreetMap data. Your IP address and the typed text reach that service, Germany. Only the address you accept is stored, with us.
- Apogo GmbH, Switzerland (placement settlement): when a placement comes about, Apogo GmbH receives the details needed for it — organisation, professional, position and start — to process and invoice the placement. No data flows to it before that.
- For providers in the USA we rely on their certification under the Swiss-U.S. Data Privacy Framework or on the standard contractual clauses recognised by the FDPIC.
Data security and incidents
- All connections are encrypted (TLS). Passwords are stored only as scrypt hashes. Documents sit in private storage and are retrievable only through short-lived signed links.
- Access by the review and oversight team is logged with the person and the time.
- In the event of a data security breach we assess the incident without delay and notify the FDPIC and the affected persons where the law requires it (Art. 24 FADP), affected persons in particular where necessary for their protection.
How long we keep what
The periods are in a table further down. They are not merely described: the same values drive the cleanup jobs, so the text and the behaviour cannot drift apart. Where a period is still enforced by hand, the table says so.
Backups are kept for a limited time. Deleted data therefore does not vanish from backups instantly, but with their expiry.
Your rights
- Access and a copy: download a complete copy as a file from your account at any time, profile, document list, offers, conversations, consents. For access without an account, write to the address above.
- Correction: change anything yourself in your profile.
- Deletion: one click in your account. The account is locked immediately and removed for good after 30 days; within that window you can take it back.
- Objecting to being visible: set your profile to private at any time, without deleting it.
- Complaint: to the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
What we do not do
- We do not sell data and pass none to advertising networks.
- We set no advertising or tracking cookies. Only a session cookie and your language choice.
- We show your profile to no organisation before a person here has checked that organisation.
- We check no professional register and no identity document against any official source. What we do is: a person looks at the uploaded documents and makes a decision, recorded with a name and a time. We claim nothing beyond that.
Changes to this statement
When this statement changes materially, signed-in people see a notice in their account and confirm the new version. Every agreement is recorded with document, version and time; you can see your own agreements in your account.
Retention schedule
These same values drive the cleanup jobs, so this table and the behaviour cannot drift apart.
| What | How long |
|---|---|
| Account, profile, CV and certificates | As long as the account exists. After a deletion request: a 30-day grace period, then removed for good. |
| Paused profiles (no longer being confirmed) | 24 months from being paused. After that the profile and its documents are deleted; the account itself remains. |
| Uploaded documents | With the profile. Deletable individually at any time, which removes the file from storage, not just from the list. |
| Conversations and offers | 24 months after the last message. The message contents and attachments are then removed; the fact that an exchange happened remains. |
| Log of CV readings | 24 months. Never contains the CV text, only a checksum of it plus provider, duration and cost. |
| Delivery log | 12 months. Holds the recipient address, subject and delivery status, never the content of a conversation. |
| Page views through campaign links | 12 months. Holds the campaign, the page opened, the time and a random visitor token, never an IP address, device or name. |
| Audit log (who decided what)by hand | 5 years. Holds actions and timestamps, never message contents or filenames. |
| After a placementby hand | The conversation is kept for the periods above. The profile stays as long as you want it to, a placement does not delete it. If you no longer want to be found, set the profile to private or delete the account. |
“By hand” means the period is our stated policy but no job enforces it yet. We would rather say so than imply an automation that does not exist.
Which provider is switched on right now
Currently switched on: OpenAI (USA). The text of your CV is sent there to be read, and therefore leaves Switzerland and the EU. The file itself is not sent.
Read from the running configuration when this page was rendered, not typed into the text.
Questions about any of this: hello@ritzl-gietz.ch · Terms of use