This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
Interpretation and Definitions
Interpretation
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
Account means a unique account created for You to access our Service or parts of our Service.
Affiliate means an entity that controls, is controlled by or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
Business, for the purpose of CCPA/CPRA, refers to the Company as the legal entity that collects Consumers' personal information and determines the purposes and means of the processing of Consumers' personal information, that does business in the State of California.
CCPA and/or CPRA refers to the California Consumer Privacy Act (the "CCPA") as amended by the California Privacy Rights Act of 2020 (the "CPRA").
Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to VNDCK Consulting BV, Overes 95, 3990 Peer, Belgium.
For the purpose of the GDPR, the Company is the Data Controller.
Consumer, for the purpose of the CCPA/CPRA, means a natural person who is a California resident.
Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
Country refers to: Belgium
Data Controller, for the purposes of the GDPR (General Data Protection Regulation), refers to the Company as the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data.
Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.
Do Not Track (DNT) is a concept that has been promoted by US regulatory authorities for the Internet industry to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across websites.
GDPR refers to EU General Data Protection Regulation.
Job Listing means a job vacancy published on the Service that We have collected from a public source such as a company career page or an applicant tracking system.
Personal Data is any information that relates to an identified or identifiable individual.
For the purposes of GDPR, Personal Data means any information relating to You such as a name, an identification number, location data or an online identifier.
For the purposes of the CCPA/CPRA, Personal Data means any information that identifies, relates to, describes or is capable of being associated with, or could reasonably be linked, directly or indirectly, with You.
Service refers to the Website.
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used. For the purpose of the GDPR, Service Providers are considered Data Processors.
Third-party Sign-in Service refers to any third-party service through which You can log in or create an account to use the Service.
Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
Website refers to HiddenRemote, accessible from https://hiddenremote.io
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Under GDPR, You can be referred to as the Data Subject or as the User as you are the individual using the Service.
Collecting and Using Your Personal Data
Types of Data Collected
Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
Email address
First name and last name
Billing country and, where required for tax purposes, billing address (collected and held by Our payment processor, not by Us)
Usage Data
You can browse a large part of the Service, including Job Listings outside the members-only window, without an Account and without providing any of the above.
Data You Generate in the Service
When You are signed in, the Service stores the actions You take on Job Listings so that Your feed reflects them: the roles You save or mark as interesting, and the roles You hide. These records are linked to an internal account identifier, are visible only to You, and are deleted when Your Account is deleted.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
We also process Your IP address for a short period to apply rate limits and to protect the Service against automated scraping and abuse.
Information from Third-Party Sign-in Services
The Company allows You to create an account and log in to use the Service through third-party sign-in services offered by Our authentication provider, such as Google. If You decide to register through or otherwise grant us access to such a service, We may collect Personal Data that is already associated with that account, such as Your name and Your email address.
Tracking Technologies and Cookies
We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. The technologies We use may include:
- Cookies or Browser Cookies. A cookie is a small file placed on Your Device. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service.
- Web Beacons. Certain sections of our Service and our emails may contain small electronic files known as web beacons that permit the Company, for example, to count users who have visited those pages or opened an email and for other related website statistics.
Cookies can be "Persistent" or "Session" Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser.
We use both Session and Persistent Cookies for the purposes set out below:
Necessary / Essential Cookies
Type: Session Cookies
Administered by: Us and Our authentication provider
Purpose: These Cookies are essential to provide You with services available through the Website and to enable You to use some of its features. They keep You signed in, help to authenticate users and prevent fraudulent use of user accounts. Without these Cookies, the services that You have asked for cannot be provided.
Functionality Cookies
Type: Persistent Cookies
Administered by: Us
Purpose: These Cookies allow us to remember choices You make when You use the Website, such as Your filter settings, so You do not have to re-enter Your preferences every time You use the Website.
Analytics and Performance Cookies
Type: Persistent Cookies
Administered by: Us and Our analytics provider
Purpose: These Cookies are used to understand how visitors use the Website, which pages and features are used, and where people run into problems, so that We can improve the Service. The information collected is typically linked to a pseudonymous identifier associated with the device You use to access the Website.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
To provide and maintain our Service, including to monitor the usage of our Service.
To manage Your Account: to manage Your registration as a user of the Service, including determining whether You have access to the members-only part of the feed.
For the performance of a contract: the development, compliance and undertaking of the purchase contract for the products or services You have purchased or of any other contract with Us through the Service.
To contact You: To contact You by email or other equivalent forms of electronic communication regarding updates or informative communications related to the functionalities, products or contracted services, including security updates, when necessary or reasonable for their implementation.
To manage Your requests: To attend and manage Your requests to Us.
To protect the Service: To detect, prevent and address technical issues, fraud, automated scraping and other abuse of the Service.
For business transfers: We may use Your information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, in which Personal Data held by Us about our Service users is among the assets transferred.
For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Service, products, marketing and Your experience.
We may share Your personal information in the following situations:
- With Service Providers: We may share Your personal information with Service Providers to operate the Service, to process payments, to analyze the use of our Service and to contact You.
- For business transfers: We may share or transfer Your personal information in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
- With Affiliates: We may share Your information with Our affiliates, in which case we will require those affiliates to honor this Privacy Policy.
- With Your consent: We may disclose Your personal information for any other purpose with Your consent.
We do not share Your Personal Data with the employers whose Job Listings appear on the Service. When You apply for a role, You leave the Service and continue on the employer's own site or applicant tracking system, where that party's privacy policy applies.
Job Listings and Their Sources
Job Listings shown on the Service are collected from publicly accessible sources, such as company career pages and applicant tracking systems, and are stored in a job database operated by the Company that is shared with Our other services. Job Listings are information about vacancies, not information about You. Browsing, saving or hiding a Job Listing does not notify the employer and does not send them any of Your data.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, invoicing and accounting records, which Belgian law requires Us to keep for seven years), resolve disputes, and enforce our legal agreements and policies.
The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods.
Transfer of Your Personal Data
Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. Our application and database infrastructure is hosted in the European Union. Some of Our Service Providers may process data outside the European Economic Area, in which case the transfer is covered by an adequacy decision or by the European Commission's Standard Contractual Clauses.
The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other personal information.
Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.
You may update, amend, or delete Your information at any time by signing in to Your Account and visiting the account settings section that allows you to manage Your personal information. You may also contact Us to request access to, correct, or delete any personal information that You have provided to Us. Deleting Your Account also deletes the roles You saved or hid.
Please note, however, that We may need to retain certain information when we have a legal obligation or lawful basis to do so.
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law enforcement
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Other legal requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of Users of the Service or the public
- Protect against legal liability
Security of Your Personal Data
The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.
Detailed Information on the Processing of Your Personal Data
The Service Providers We use may have access to Your Personal Data. These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their Privacy Policies.
Analytics
PostHog
PostHog is a product-analytics platform that helps Us understand how users navigate the Service so We can improve features and fix issues. Event data may include page views, clicks and feature usage; personal identifiers are limited to internal account IDs.
Their Privacy Policy can be viewed at https://posthog.com/privacy
Authentication
We use a third-party identity provider to manage user sign-up, sign-in, and session management.
Clerk
Clerk handles account creation, password storage (Clerk never shares passwords with Us in plaintext), social sign-in, multi-factor authentication, session tokens and the account-related emails that go with them. We receive only the public account information (such as Your email and name) needed to provision and identify Your HiddenRemote account.
Their Privacy Policy can be viewed at https://clerk.com/legal/privacy
Payments
We provide paid products and services within the Service. In that case, we use a third-party service for payment processing.
We will not store or collect Your payment card details. That information is provided directly to Our third-party payment processor whose use of Your personal information is governed by their Privacy Policy. This payment processor adheres to the standards set by PCI-DSS as managed by the PCI Security Standards Council.
Stripe
Stripe processes payments, subscriptions and invoices, and collects the billing details required to determine the applicable VAT rate.
Their Privacy Policy can be viewed at https://stripe.com/privacy
Hosting and Infrastructure
We rely on third-party cloud-infrastructure providers to host the Service, store Your data, protect it against abuse and process background jobs. These providers process Personal Data on Our behalf under data-processing agreements; they do not use Your data for their own purposes.
Microsoft Azure hosts the application, the database and the content-delivery layer in the European Union. Their Privacy Statement can be viewed at https://privacy.microsoft.com/privacystatement
Upstash provides the Redis instance We use for rate limiting, which briefly processes a hashed form of Your IP address. Their Privacy Policy can be viewed at https://upstash.com/trust/privacy.pdf
The current list of sub-processors is available on request by emailing support@hiddenremote.io.
We may use Your Personal Data to contact You with service messages, and, where You have not opted out, with occasional information about the Service. You may opt out of receiving any, or all, of these communications from Us by following the unsubscribe link or instructions provided in any email We send or by contacting Us. Messages that are strictly necessary to operate Your Account, such as sign-in and payment confirmations, cannot be opted out of while Your Account exists.
GDPR Privacy
Legal Basis for Processing Personal Data under GDPR
We may process Personal Data under the following conditions:
- Consent: You have given Your consent for processing Personal Data for one or more specific purposes.
- Performance of a contract: Provision of Personal Data is necessary for the performance of an agreement with You and/or for any pre-contractual obligations thereof.
- Legal obligations: Processing Personal Data is necessary for compliance with a legal obligation to which the Company is subject.
- Vital interests: Processing Personal Data is necessary in order to protect Your vital interests or of another natural person.
- Public interests: Processing Personal Data is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Company.
- Legitimate interests: Processing Personal Data is necessary for the purposes of the legitimate interests pursued by the Company, such as keeping the Service secure and free of automated abuse.
In any case, the Company will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Your Rights under the GDPR
The Company undertakes to respect the confidentiality of Your Personal Data and to guarantee You can exercise Your rights.
You have the right under this Privacy Policy, and by law if You are within the EU, to:
- Request access to Your Personal Data. The right to access, update or delete the information We have on You. This also enables You to receive a copy of the Personal Data We hold about You.
- Request correction of the Personal Data that We hold about You. You have the right to have any incomplete or inaccurate information We hold about You corrected.
- Object to processing of Your Personal Data. This right exists where We are relying on a legitimate interest as the legal basis for Our processing and there is something about Your particular situation which makes You want to object. You also have the right to object where We are processing Your Personal Data for direct marketing purposes.
- Request erasure of Your Personal Data. You have the right to ask Us to delete or remove Personal Data when there is no good reason for Us to continue processing it.
- Request the transfer of Your Personal Data. We will provide to You, or to a third-party You have chosen, Your Personal Data in a structured, commonly used, machine-readable format.
- Withdraw Your consent. You have the right to withdraw Your consent on using Your Personal Data. If You withdraw Your consent, We may not be able to provide You with access to certain specific functionalities of the Service.
Exercising of Your GDPR Data Protection Rights
You may exercise Your rights of access, rectification, cancellation and opposition by contacting Us at support@hiddenremote.io. Please note that we may ask You to verify Your identity before responding to such requests. If You make a request, We will try our best to respond to You as soon as possible, and in any case within one month.
You have the right to complain to a Data Protection Authority about Our collection and use of Your Personal Data. In Belgium, that authority is the Gegevensbeschermingsautoriteit (www.gegevensbeschermingsautoriteit.be). If You are elsewhere in the European Economic Area, please contact Your local data protection authority.
CCPA/CPRA Privacy Notice (California Privacy Rights)
This privacy notice section for California residents supplements the information contained in Our Privacy Policy and it applies solely to all visitors, users, and others who reside in the State of California.
Categories of Personal Information Collected
The following is a list of categories of personal information which we may collect or may have been collected from California residents within the last twelve (12) months. The categories and examples provided are those defined in the CCPA/CPRA.
Category A: Identifiers. Examples: a real name, alias, unique personal identifier, online identifier, Internet Protocol address, email address, account name.
Collected: Yes.
Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). Examples: a name, address, telephone number, or any other financial information.
Collected: Yes.
Category C: Protected classification characteristics under California or federal law.
Collected: No.
Category D: Commercial information. Examples: records and history of products or services purchased or considered.
Collected: Yes.
Category E: Biometric information.
Collected: No.
Category F: Internet or other similar network activity. Examples: interaction with our Service.
Collected: Yes.
Category G: Geolocation data. Examples: approximate physical location derived from an IP address.
Collected: No.
Category H: Sensory data.
Collected: No.
Category I: Professional or employment-related information.
Collected: No.
Category J: Non-public education information.
Collected: No.
Category K: Inferences drawn from other personal information.
Collected: No.
Category L: Sensitive personal information. Examples: account login information.
Collected: Yes.
Under CCPA/CPRA, personal information does not include publicly available information from government records, deidentified or aggregated consumer information, or information excluded from the CCPA/CPRA's scope.
Sources of Personal Information
We obtain the categories of personal information listed above from the following categories of sources:
- Directly from You, for example from the forms You complete on our Service.
- Indirectly from You, for example from observing Your activity on our Service.
- Automatically from You, for example through cookies We or our Service Providers set on Your Device.
- From Service Providers, for example our authentication, analytics and payment providers.
Use of Personal Information
We may use or disclose personal information We collect for "business purposes" or "commercial purposes" (as defined under the CCPA/CPRA), which may include operating the Service, responding to Your inquiries, processing Your payment, complying with law, internal administration and auditing, and detecting security incidents and fraudulent or illegal activity.
Disclosure of Personal Information
We may use or disclose and may have used or disclosed in the last twelve (12) months the following categories of personal information for business or commercial purposes: Category A, Category B, Category D and Category F.
When We disclose personal information for a business purpose or a commercial purpose, We enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.
Sale of Personal Information
We do not sell personal information as the term sell is commonly understood. We do allow Service Providers to use Your personal information for the business purposes described in Our Privacy Policy, for activities such as analytics, and these may be deemed a sale or sharing under CCPA/CPRA.
Sale of Personal Information of Minors Under 16 Years of Age
We do not knowingly collect personal information from minors under the age of 16 through our Service. If You have reason to believe that a child under the age of 16 has provided Us with personal information, please contact Us with sufficient detail to enable Us to delete that information.
Your Rights under the CCPA/CPRA
If You are a resident of California, You have the right to notice, the right to know and access Your personal information, the right to say no to the sale or sharing of Your personal information, the right to correct Your personal information, the right to limit the use and disclosure of sensitive personal information, the right to delete Your personal information subject to legal exceptions, and the right not to be discriminated against for exercising any of these rights.
Exercising Your CCPA/CPRA Data Protection Rights
In order to exercise any of Your rights under the CCPA/CPRA, You can contact Us by email at support@hiddenremote.io.
Only You, or a person registered with the California Secretary of State that You authorize to act on Your behalf, may make a verifiable request related to Your personal information. Your request must provide sufficient information that allows Us to reasonably verify You are the person about whom We collected personal information, and describe Your request with sufficient detail that allows Us to properly understand, evaluate, and respond to it.
We will disclose and deliver the required information free of charge within 45 days of receiving Your verifiable request. The time period may be extended once by an additional 45 days when reasonably necessary and with prior notice.
Do Not Sell or Share My Personal Information
You have the right to opt out of the sale or sharing of Your personal information. To exercise this right, contact Us at support@hiddenremote.io, or disable analytics and advertising cookies in Your browser. Please note that any opt out is specific to the browser You use.
"Do Not Track" Policy as Required by the California Online Privacy Protection Act (CalOPPA)
Our Service does not respond to Do Not Track signals. You can enable or disable DNT by visiting the preferences or settings page of Your web browser.
Children's Privacy
Our Service does not address anyone under the age of 16. We do not knowingly collect personally identifiable information from anyone under the age of 16. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 16 without verification of parental consent, We take steps to remove that information from Our servers.
Links to Other Websites
Our Service contains links to other websites that are not operated by Us, including the career pages and applicant tracking systems where You apply for a Job Listing. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.
We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective and update the "Last updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, You can contact us by email at support@hiddenremote.io, or by post at VNDCK Consulting BV, Overes 95, 3990 Peer, Belgium.