Last updated: 8th September 2026
Privacy Policy
This Privacy Policy explains how Skiftr ApS ("Skiftr", "we", "us", or "our") processes personal data when you use our website and services.
Data Controller
We are the controller responsible for the processing of your personal data.
Personal Data We Process
We may process:
- account and contact information, such as your name and email address
- login and authentication data
- CV and profile information
- job applications and preferences
- usage and interaction data, such as clicks, searches, and use of features
- AI interaction data, such as prompts, chat interactions, and generated outputs
- payment and billing information
- support communications
- technical and diagnostic data, such as IP address, device information, logs, and latency measurements
- records of marketing consent
We only process information that is necessary to provide, secure, improve, and support our services.
Purposes and Legal Bases
We process personal data to:
- provide and operate our services
- manage user accounts and authentication
- match users with relevant job opportunities
- process payments and subscriptions
- improve, monitor, troubleshoot, and secure our platform
- provide customer support
- generate AI-powered recommendations and insights
- analyse service usage and stability
- prevent misuse, fraud, and unauthorised access
- send marketing communications with consent
Our legal bases are:
- performance of a contract (Article 6(1)(b) GDPR)
- compliance with a legal obligation (Article 6(1)(c) GDPR)
- legitimate interests (Article 6(1)(f) GDPR)
- consent (Article 6(1)(a) GDPR)
Cookies and Analytics
We use cookies and similar technologies to operate, secure, analyse, and improve our services.
Cookies may include:
- necessary cookies required for the operation and security of the platform
- analytics cookies used to understand usage and improve the service
- preference cookies used to remember preferences and settings
- marketing cookies used for communications and campaign measurement, where relevant
Non-essential cookies are only used with consent.
Users may manage or withdraw their cookie consent at any time through our cookie consent tools and settings. We use Cookiebot to manage cookie consent and preferences, where applicable.
Limited session telemetry may be processed to operate, secure, troubleshoot, and improve Skiftr, including for operational reliability, analytics, and usability. Sensitive inputs and content are excluded or masked where technically possible.
Marketing and Campaign Measurement
With the user's consent, we use the Meta Pixel and Reddit Pixel to measure the effectiveness of our advertising, record conversions, and make our marketing more relevant.
In this context, we may process and share information such as:
- IP address
- browser, device, and technical information
- pages visited and interactions with the platform
- actions such as starting registration, completing registration, and making a purchase
- cookie, pixel, and other online identifiers
Information may be shared with Meta Platforms Ireland Limited and Reddit Ireland Limited. If the user has an account with Meta or Reddit, the provider may be able to associate this information with the user's account. Meta and Reddit may process information for their own purposes in accordance with their respective privacy policies.
This processing is based on the user's consent under Article 6(1)(a) GDPR. The Meta Pixel and Reddit Pixel are activated only after the user has consented to marketing cookies.
Consent may be changed or withdrawn at any time through our cookie settings. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
You can learn more about processing by:
Meta: https://www.facebook.com/privacy/policy/
Reddit: https://www.reddit.com/policies/privacy-policy
AI Processing and Automated Analysis
Skiftr uses artificial intelligence ("AI") to analyse profiles, match users with relevant opportunities, generate recommendations, improve CV relevance, and provide labour market insights.
AI Providers and Infrastructure
We use selected third-party AI, analytics, and cloud service providers to process certain user data in connection with our services, including:
- Google Gemini (default model: gemini-2.5-flash-lite) as an AI model provider
- Google Cloud DLP to detect and de-identify personal data before processing
- PostHog for analytics, observability, tracing, operational diagnostics, error monitoring, and quality assurance of AI-powered and other platform functionality
Processing is primarily carried out in European data regions, including europe-west1, where applicable.
However, certain providers may process or access limited data outside the EU/EEA for support, maintenance, security, or infrastructure purposes, subject to appropriate safeguards such as the Standard Contractual Clauses and the EU-U.S. Data Privacy Framework, where applicable.
Processing of User Content
CVs, profile information, job-related data, prompts, chat interactions, AI-generated outputs, and other submitted content may be processed by AI systems to:
- generate recommendations
- improve profile matching
- identify relevant skills
- optimise CV relevance
- analyse labour market matches
- generate salary and career insights
- monitor and improve AI-powered functionality
- troubleshoot, secure, and maintain the operational reliability of the platform
Before certain data is processed by AI models or monitoring systems, automated measures may be applied through Google Cloud DLP to de-identify data and reduce personally identifiable information.
Training of AI Models
Skiftr does not use customer content to train general-purpose AI models.
Neither Skiftr nor our AI, analytics, observability, or infrastructure providers use customer content submitted through the platform to train general-purpose AI models.
Retention of AI and Observability Data
Certain AI interaction data and technical telemetry may be processed for analytics, monitoring, troubleshooting, misuse prevention, operational stability, security, and quality assurance.
This may include prompts, chat history, generated outputs, token usage, latency measurements, operational traces, error diagnostics, and associated technical metadata.
Data processed through PostHog is stored on EU-based infrastructure.
Analytics, observability, and AI interaction data may be retained for up to 12 months unless a shorter retention period applies.
Certain short-term diagnostic data, replay data, and operational monitoring data may be retained for shorter periods, typically for up to 90 days.
Specific users and associated event data may be deleted upon request or through internal administrative tools and APIs.
Certain technical logs and secure backups may be retained temporarily in accordance with backup cycles.
Automated Recommendations and Decision-Making
Skiftr uses automated systems to generate recommendations, rankings, and matching insights relating to jobs, skills, and career opportunities.
These systems are designed to support users and advisers and should not be interpreted as guarantees of employment outcomes or suitability.
We carry out ongoing quality controls and sample-based evaluations of recommendation systems before they are put into production.
Skiftr's automated systems present publicly available job postings based on the user's profile and preferences. The systems do not make decisions about the user and have no direct impact on the user's access to job opportunities.
This processing therefore does not constitute automated individual decision-making with legal or similarly significant effects under Article 22 GDPR.
Access Control and Security
Access to production systems and AI-related data is restricted through role-based access controls.
Only authorised administrative users may access production data where necessary for security, operational support, legal compliance, prevention of misuse, or incident investigation.
Analytics, Observability, and Service Providers
Certain analytics, observability, and operational tools may process technical and AI-related metadata to maintain, secure, and improve the platform, including:
- PostHog
- Google Cloud Logging and Trace
- Slack alerts
- Resend infrastructure for transactional emails
- Brevo infrastructure for newsletters and contact emails
We implement reasonable technical and organisational measures to minimise unnecessary personal data in logs and monitoring systems, including filtering, access controls, retention limits, and data minimisation where relevant.
Sharing of Information
We may share information with service providers such as:
- cloud hosting providers (Google Cloud)
- payment processors (Stripe)
- analytics and observability providers
- communications and email providers (Resend and Brevo)
- support and CRM tools
- AI infrastructure providers
- advertising and campaign measurement providers (Meta and Reddit), when the user has consented to marketing cookies
Depending on the processing activity, our providers may act as processors, independent controllers, or joint controllers. We enter into the necessary agreements where required.
We do not sell personal data.
International Transfers
Some providers may process or access data outside the EU/EEA, including for support, maintenance, security, and infrastructure purposes.
Where applicable, we use appropriate safeguards such as the Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
Retention
We retain personal data only for as long as necessary to provide our services, comply with legal obligations, and fulfil the purposes described in this Privacy Policy.
Retention periods vary depending on the type of data:
- account and profile data, including CVs and user preferences: retained while the account is active and for up to 90 days after deletion
- authentication and session data: retained for a short period, typically up to 90 days
- job-related data, including job postings, saved jobs, and recommendations: retained while the account is active and for up to 90 days after inactivity or deletion
- usage, analytics, observability, and AI interaction data, including prompts, generated outputs, traces, token usage, and operational telemetry: retained for up to 12 months
- session recordings and short-term diagnostic data: typically retained for up to 90 days
- payment and transaction information: retained for up to five years in accordance with applicable bookkeeping legislation
- support communications: retained for up to two years after the matter has been closed
- records of marketing consent: retained while the account exists and for up to three years after withdrawal
- security and error logs: typically retained for up to 90 days
- data subject requests: retained for up to three years after completion
- cookie consent records: typically retained for 12–24 months
Some data may remain in secure backups for a limited period before being permanently overwritten in accordance with the system's backup cycles.
Security
We use appropriate technical and organisational measures to protect personal data, including encryption, access controls, monitoring, logging measures, and infrastructure security.
Access to sensitive systems and production environments is restricted based on role and operational necessity.
Your Rights
Under applicable data protection law, including the GDPR, you may have the right to:
- request access to your personal data
- request correction of inaccurate or incomplete personal data
- request deletion of your personal data
- object to certain processing activities
- request restriction of processing in certain circumstances where provided by law
- request data portability for personal data you have provided to us, where technically feasible
- withdraw consent to consent-based processing, such as marketing communications and non-essential cookies
- lodge a complaint with the Danish Data Protection Agency
Certain rights may be limited where processing is necessary to provide the core functionality of the service, comply with legal obligations, establish or defend legal claims, or protect the rights and security of other users.
Users can update certain personal and profile information directly through the platform.
To exercise your rights, contact us at privacy@skiftr.com.
We may request proof of identity before responding to a request.
If you believe that our processing of your personal data violates applicable law, you also have the right to lodge a complaint with:
Children
Our services are intended only for individuals aged 18 or over.
We do not knowingly collect personal data from individuals under the age of 18.
Changes
We may update this Privacy Policy from time to time.
The latest version will always be available on our website.