Privacy Policy JOBaza

Effective as of 17 August 2026

At Jobbaza LILIIA-MARIIA HALAN (“Service Provider”, “Administrator”, “we”, “us”), we respect and protect the privacy of our Users. This Privacy Policy specifies how we collect, use, store and protect personal data of persons using our website available at https://jobaza.com/ (“Service”).

We undertake to process personal data in accordance with applicable laws, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”), the Act of 10 May 2018 on the Protection of Personal Data, the Act of 12 July 2024 – Electronic Communications Law, and other applicable provisions concerning the protection of personal data, privacy, electronic communications and the use of cookies.

This Privacy Policy applies to Users who have an account on the Service, persons publishing advertisements, and persons contacting the Administrator.

1. Information We Collect

Depending on how the Service is used, we may collect the following categories of data:

  • Identification and contact data – in particular, first and last name, e-mail address, telephone number and other data provided by the User;
  • Account data – data necessary to create and operate the User’s account;
  • Data concerning advertisements and content – information contained in advertisements, offers, profiles, photographs and other materials published or provided through the Service;
  • Data concerning the use of the Service – in particular, information concerning activity on the Service, IP address, device data, web browser, operating system and technical information concerning the use of the Service;
  • Communication data – information contained in messages, inquiries, reports and complaints addressed to the Service Provider;
  • Payment and transaction data – information necessary to process payments, settlements and fulfil ordered Advertising Services;
  • Telephone number verification data – telephone number, one-time password (OTP), information on the verification status and data related to sending and confirming the code;
  • Data concerning the use of the device and the Service – including online identifiers, information about the browser, operating system, language, device type, IP address, source of access to the Service and information about how individual functionalities are used.

We do not require the provision of personal data that is not necessary to use specific functionalities of the Service.

If the User publishes content containing personal data of other persons, the User should have an appropriate legal basis for sharing and publishing such data.

2. How We Use Personal Data

We may process personal data in particular for the following purposes:

  • creating and maintaining the User’s account;
  • ensuring the proper functioning of the Service;
  • enabling the publication and management of advertisements and other content;
  • providing Advertising Services;
  • handling orders, payments and settlements;
  • processing and confirming payments;
  • verifying telephone numbers and preventing the creation of false or abused accounts;
  • sending e-mail messages, SMS messages and other communications related to the use of the Service;
  • contacting Users and responding to their questions;
  • handling complaints, reports and claims;
  • ensuring the security of the Service and preventing abuse;
  • detecting and preventing violations of the Terms and Conditions and applicable laws;
  • conducting analyses and statistics concerning the use of the Service;
  • analysing how the Service is used and improving its functionality;
  • monitoring the performance and stability of the Service;
  • conducting marketing activities where there is an appropriate legal basis for conducting them;
  • pursuing or defending against claims;
  • fulfilling legal obligations incumbent on the Administrator.

The legal basis for processing data may include, in particular:

  • Article 6(1)(b) GDPR – where processing is necessary for the performance of a contract or for taking steps at the request of the data subject prior to entering into a contract;
  • Article 6(1)(c) GDPR – where processing is necessary for compliance with a legal obligation to which the Administrator is subject;
  • Article 6(1)(f) GDPR – where processing is necessary for the purposes of the legitimate interests pursued by the Administrator or a third party;
  • Article 6(1)(a) GDPR – where data is processed on the basis of consent.

Where data is processed on the basis of consent, the User may withdraw such consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

3. External Service Providers and Data Processors

In order to ensure the proper functioning of the Service, support Users, process payments, provide communication, analytics, marketing and security, we use the services of external technology providers.

Depending on the current configuration of the Service, we may use, in particular, the following services:

  • Google Analytics – for analysing traffic and statistics concerning the use of the Service;
  • Meta Pixel – for analysing the effectiveness of marketing and advertising activities;
  • Microsoft Clarity – for analysing how the Service and its functionalities are used;
  • Stripe – for processing electronic payments and ensuring transaction security;
  • Amazon Web Services (AWS) – for hosting, IT infrastructure, data storage and backups;
  • Google Firebase – for authentication, technical functionalities, analytics and application support;
  • Cloudflare – for security, protection against abuse and ensuring the performance and stability of the Service;
  • Twilio – for sending SMS messages, including one-time codes confirming the telephone number (OTP);
  • SendPulse – for sending e-mail messages and communicating with Users;
  • Google reCAPTCHA – for protecting the Service against spam, automated activities and abuse.

In connection with the use of the above services, providers may process data such as IP address, device and browser data, online identifiers, data concerning the use of the Service, contact data and – to the extent necessary to provide a specific service – payment or communication data.

The scope of data transferred depends on the type of service used and its configuration. In the case of analytical, marketing and other technologies requiring consent, they are activated in accordance with the User’s preferences and applicable laws.

Personal data may also be entrusted to or shared with other providers of technological, hosting, payment, communication, analytical, marketing and security services where this is necessary for the functioning of the Service and the achievement of specific processing purposes.

If an external provider processes personal data on behalf of the Administrator, the Administrator enters into an appropriate data processing agreement with such provider or applies another appropriate legal instrument in accordance with the requirements of the GDPR.

The Administrator selects providers taking into account appropriate security guarantees and compliance with applicable personal data protection laws.

Providers also process data for their own purposes and as separate controllers if this results from the nature of the service provided. In such a case, their own privacy policies and data protection rules also apply.

Data may also be disclosed to competent public authorities, courts or other authorised entities where such obligation results from applicable laws.

4. Transfer of Data Outside the European Economic Area

In connection with the use of external technology providers, personal data may be transferred or made available to entities located outside the European Economic Area (“EEA”), including in the United States, to the extent resulting from the services used and their configuration.

Where data is transferred outside the EEA, the Administrator applies an appropriate mechanism provided for in Chapter V of the GDPR, in particular:

  • a European Commission adequacy decision establishing an adequate level of protection;
  • an appropriate certification mechanism, such as the EU-U.S. Data Privacy Framework, where applicable to the relevant provider;
  • Standard Contractual Clauses (SCCs) adopted by the European Commission;
  • or another mechanism provided for under the GDPR.

The scope of transferred data is limited to data necessary to provide the specific service.

5. Cookies and Tracking Technologies

The Service uses cookies and similar technologies to improve the functioning of the Service, ensure security, remember User preferences and analyse the use of the Service.

Cookies are small files stored on the User’s device that enable, among other things, recognition of the device, remembering settings and analysing the use of the Service.

The Service may use necessary, functional, analytical, marketing and security-related cookies. For this purpose, we may use, among others, the services of Google Analytics, Meta Pixel, Microsoft Clarity, Google Firebase, Cloudflare, Stripe and Google reCAPTCHA.

Cookies whose use requires the User’s consent are used only after such consent has been obtained through the consent mechanism available on the Service.

During the first visit to the Service, the User may accept, reject or customise cookie settings using the available consent banner. The User may also change their preferences at any time using the cookie settings available on the Service.

The User may also manage cookies through the settings of their web browser. Disabling certain cookies may affect the proper functioning of certain functionalities of the Service.

Detailed information concerning the cookies and tracking technologies used may be available in the cookie settings on the Service.

With regard to direct marketing and commercial communications, the Administrator complies with the requirements arising from applicable Polish laws, including the Electronic Communications Law.

6. Data Security

We apply appropriate technical and organisational measures aimed at protecting personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

The scope of the security measures applied is adapted to the nature, scope and purpose of data processing and the associated risk.

Despite applying appropriate security measures, we cannot guarantee the complete security of data transmission over the Internet.

7. Users’ Rights and Data of Minors

Users whose data is concerned have the rights provided for by the GDPR, in particular:

  • the right to access their personal data;
  • the right to rectify or complete it;
  • the right to erasure of data, in cases provided for by law;
  • the right to restriction of processing;
  • the right to data portability, in cases provided for by the GDPR;
  • the right to object to processing, in cases provided for by law;
  • the right to withdraw consent at any time, where processing is based on consent;
  • the right to lodge a complaint with the competent supervisory authority.

In order to exercise their rights, the User may contact the Administrator at support@jobaza.com.

The Administrator may take appropriate measures to verify the identity of the person submitting the request.

The Service is not intended for the independent creation of accounts by persons under 18 years of age. If the Administrator becomes aware that an account has been created by a person who does not meet this requirement, it may take appropriate measures in accordance with applicable laws.

8. Data Retention Period

We retain personal data for the period necessary to fulfil the purposes for which it was collected and thereafter for the period required by law or necessary to establish, pursue or defend against claims.

In particular:

  • account data – for the period during which the account is maintained and for the period necessary to handle any potential claims;
  • data concerning contracts, payments and settlements – for the period required by law;
  • data processed on the basis of consent – until consent is withdrawn, unless there is another legal basis for further processing;
  • communication data – for the period necessary to handle the matter and for evidentiary purposes.

After the expiry of the relevant period, the data is deleted or anonymised unless its further retention is required by law.

9. Changes to the Privacy Policy

The Administrator may update this Privacy Policy, in particular in the event of changes to the functioning of the Service, the technologies used, the services utilised or applicable laws.

The current version of the Privacy Policy is published on the Service.

In the event of material changes that may affect the rights or the manner in which Users’ personal data is processed, the Administrator may inform Users in an appropriate manner.

At the beginning of the document and upon each subsequent update, the effective date of the relevant version of the Privacy Policy is indicated.