changemaker

Legal

Privacy policy

Last updated ·

This policy explains, in accordance with Articles 13 and 14 GDPR, what personal data changemakerhq.org processes, for what purposes, on which legal bases, who receives it and what rights you have. It is written to be read — if anything is unclear, write to info@changemakerhq.org.

1. Controller

The controller responsible for data processing on changemakerhq.org is:

Company
Loistava Holding UG (haftungsbeschränkt)
Address
Asternring 9
15732 Schulzendorf, Germany
Represented by
Antti Savolainen (Managing Director)

Full company details are in the Impressum.

2. Summary in plain words

  • We run a jobs index hosted in the EU. You can browse every vacancy without an account, and every listing links to the hiring organization's official application — applications never pass through us.
  • An account needs exactly one piece of data: your e-mail address. Sign-in works with a magic link, so we never store passwords.
  • Your page is private until you publish it. You decide what becomes public, and you can unpublish or delete it at any time.
  • Analytics runs on EU servers (PostHog EU): an anonymous, cookie-free reach measurement for everyone, plus — only if you accept in the banner — persistent cross-session analysis. We show no ads, sell no personal data, and build no advertising profiles.

3. Data we process, by context

Visitors

When you open the site, our hosting infrastructure processes the technical data every web server needs: your IP address, browser and device information (user agent), the requested URL, the referring page and a timestamp. These server and CDN logs are used to deliver the site, keep it secure and diagnose faults; they are short-lived. We also record pseudonymous product-analytics events (see section 9).

Account holders

To create an account we process your e-mail address, the sign-in links we send to it, sign-in timestamps and a session cookie that keeps you signed in. There are no passwords.

Page authors

If you build a page, we process the content you add to it: profile text, photo URLs, projects, experience, skills and — if you choose to record or upload one — a short video introduction, which is processed and streamed by Mux. An unpublished page is not accessible to anyone but you; a published page is public at your chosen address (changemakerhq.org/p/your-slug) until you unpublish or delete it.

Job seekers browsing the index

Browsing and searching the index requires nothing beyond the visitor data above. We never receive your applications, CVs or cover letters — those go directly to the hiring organization on its own site.

Employers submitting a job

If you submit a vacancy for listing, we process the contact details you provide with the submission so that we can review and publish it and reach you with questions.

Correspondence

If you write to us, we process your e-mail address and the content of your message for as long as needed to handle the matter.

4. Purposes and legal bases

  • Contract (Art. 6(1)(b) GDPR). Providing your account, hosting and displaying your page, and — once online checkout opens — running the premium subscription.
  • Legitimate interests (Art. 6(1)(f) GDPR). Operating and securing the index (server logs, abuse prevention), aggregating publicly posted vacancies from official career sites, and the anonymous, cookie-free reach measurement (page views, visitor counts) that helps us improve the product without storing anything on your device.
  • Consent (Art. 6(1)(a) GDPR). The extended analytics tier only — persistent cross-session cookies and session replay — which runs only after you accept it in the cookie banner. You can withdraw consent at any time with effect for the future.

On the balancing of interests behind the index: the vacancy data we aggregate is professional information that hiring organizations have published on their official career sites precisely so that candidates can find it. Indexing it and linking back to the source serves that same purpose, has minimal impact on the persons concerned, and is subject to the removal process described in section 11.

5. Recipients and processors

We use a small set of infrastructure providers, bound by data processing agreements, to run the service:

ProcessorRoleLocationSafeguard
Vercel Inc.Application hosting and content delivery (CDN)EU-region serving; US companyEU standard contractual clauses
Cloudflare, Inc.DNS, TLS, CDN, bot/DDoS protection and cookieless, aggregate web analyticsEU-region edge; US companyEU standard contractual clauses; the web-analytics feature sets no cookies and builds no cross-site profile
Supabase Inc.Database and authenticationAWS eu-central-1 (Frankfurt); US companyEU standard contractual clauses
Mux Inc.Video upload, encoding and streaming for the video introductionUnited StatesEU standard contractual clauses
PostHog EUProduct analyticsEuropean Union (eu.posthog.com)EU hosting — no transfer outside the EU
ResendTransactional e-mail delivery (service e-mails, magic links)United StatesEU standard contractual clauses
Inngest Inc.Background job orchestration for the aggregation pipelineUnited StatesEU standard contractual clauses; handles no end-user personal data beyond operational logs

Our pages carry verification meta tags for Google Search and Bing; these are static markup and involve no data processing. Beyond the providers above, we disclose personal data only if the law requires it. We do not share data with advertisers or data brokers, and we do not sell personal data.

6. International transfers

Our primary infrastructure serves from the EU, and the database is hosted in Frankfurt, Germany. Where a provider is a US company or processes data in the United States (Vercel, Supabase, Mux, Resend, Inngest), transfers are safeguarded by the EU standard contractual clauses under Art. 46(2)(c) GDPR or, where the provider holds a valid certification, an applicable adequacy decision.

7. Retention

  • Account data — kept until you delete your account.
  • Your page — unpublished pages are never public; page content is deleted when you delete it or your account.
  • Videos — kept until you replace or remove them; uploads that exceed the permitted length are deleted automatically.
  • Job alerts and saved searches — kept until you turn them off, unsubscribe (one click from any alert e-mail) or delete your account.
  • Analytics events — retained by PostHog (EU) for up to 12 months, then deleted or aggregated. Anonymous reach events carry no persistent identifier; persistent cross-session analytics and session replay are collected only after you consent.
  • Server logs — short-lived and rotated within a few weeks.
  • Vacancy listings — delisted when the vacancy expires or disappears from its source; incidental personal data in listings is removed on request (section 11).
  • Correspondence — kept as long as needed to handle the matter, plus any statutory retention periods.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15),
  • have inaccurate data rectified (Art. 16),
  • have data erased (Art. 17),
  • have processing restricted (Art. 18),
  • receive your data in a portable format and transmit it elsewhere (Art. 20),
  • object to processing based on legitimate interests (Art. 21) — note that we do no direct marketing, so there is none to object to, and
  • withdraw any consent at any time with effect for the future (Art. 7(3)).

Signed-in users can exercise the most common rights directly, with no need to write to us: your dashboard offers one-click data export (a complete copy of your data as a JSON file) and account deletion (permanent erasure of your account, page, videos, job alerts and saved searches). Every job-alert e-mail also carries a one-click unsubscribe link and a List-Unsubscribe header.

For anything else — or if you do not have an account — write to info@changemakerhq.org and we will respond without undue delay and within one month at the latest (Art. 12(3) GDPR). You also have the right to lodge a complaint with a data protection supervisory authority — for example the one at your habitual residence or place of work. The authority competent for our seat is the state commissioner for data protection of Brandenburg (Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow).

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR).

9. Cookies and analytics

We keep browser storage to a minimum and set no third-party advertising cookies. Our product analytics & reach measurement uses PostHog (EU-hosted, Frankfurt; eu.i.posthog.com), first-party, in two tiers:

  • Strictly necessary — always on. The Supabase authentication cookie that keeps signed-in users signed in (set only when you use an account), the small record of your cookie choice, and the first-party storage that remembers your saved search tabs. These are required for the site to work and are exempt from consent under § 25(2) TTDSG.
  • Anonymous reach measurement — no consent required. A cookie-free basic measurement of page views and visitor counts runs for every visitor. Nothing is stored on or read from your device (measurement is kept in memory only, with no persistent cross-session identifier), so § 25 TTDSG does not apply; the legal basis is Art. 6(1)(f) GDPR (our legitimate interest in privacy-minimising reach measurement). Session replay is off and search terms are stripped from the URLs it records.
  • Extended analysis — only with your consent. Persistent cookies for cross-session insight, and session replay, run only after you press Accept in the cookie banner (Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG). Pressing Reject disables all analytics. A data-processing agreement and EU hosting are in place, and inputs to password fields are masked in session replay. We never advertise with this data and never share it with ad networks. Our CDN provider Cloudflare additionally measures aggregate traffic without setting cookies and without profiling individuals.

You choose on your first visit and can change your mind at any time via Cookie settings in the footer. Full details are in our cookie policy. You can also clear cookies and site data in your browser at any time — the site keeps working either way.

10. Third-party links

Every listing links to the hiring organization's official career site, and pages may link to other external sites. Once you leave changemakerhq.org, the privacy policy of the site you visit applies. We are not responsible for the data practices of external sites.

11. Personal data in job listings

Vacancy texts published by hiring organizations occasionally contain personal data — for example the name or e-mail address of a contact person. This data originates from the organization's own official publication, which we index and reproduce with a link to the source. If you are such a person and would like your data removed from our index, write to info@changemakerhq.org — we honour removal requests. Note that removal from our index does not affect the original publication on the organization's site.

12. Security

All traffic to and from changemakerhq.org is encrypted in transit (TLS). Data is hosted in EU regions, access to production systems follows a least-access principle, and sign-in is passwordless — so there is no password database to lose.

13. Children

The service is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact us and we will delete it.

14. Changes to this policy

When we change this policy, we publish the new version here with an updated date. If a change materially affects account holders, we will notify you by e-mail before it takes effect.


Questions, objections and removal requests: info@changemakerhq.org · Loistava Holding UG (haftungsbeschränkt), Asternring 9, 15732 Schulzendorf, Germany.