Privacy policy
This policy explains what personal data we process when you use Vero (website and app), for what purpose, on what legal basis, who sees it, how long we keep it and how you exercise your rights. This English version is provided for convenience; if it differs from the Portuguese version, the Portuguese version prevails.
Preview: the details of the responsible entity are not configured in this environment yet.
The essentials
- Only what is neededNo photo, age, nationality or current salary.
- Anonymous until the interviewBefore that, the organisation only sees your experience and availability.
- We never sell dataNor share it to train third-party artificial intelligence.
- In the European UnionServers in Germany, email delivery in France.
- Short retentionTechnical logs 30 days, backups 14 days, audit IP 12 months.
- Your data is yoursAsk for a copy, correct it or delete it; we answer within a month.
A summary you can read in 30 seconds. The full text below is what applies.
Who processes your data
The controller is entity name, tax number (NIF) tax number, registered office at registered office. For any question about your data or to exercise your rights, write to contact email. We have not appointed a data protection officer; this contact handles all privacy matters.
When you apply for a job, the organisation that published it becomes an independent controller of the data it receives for its recruitment process (see Who sees your data).
What data we process
| Data | What it includes | Where it comes from |
|---|---|---|
| Account | Email, password (stored only as an Argon2id hash, never in plain text), roles, language, account status, dates of registration, email confirmation and last access | From you |
| Sign-in with Google | Your Google account identifier and the associated email. We do not receive your Google password | From Google, if you choose that option |
| Sessions | Start and expiry dates, client type (website or app) and browser or device. The session code is stored only as a hash | From your browser or the app |
| Candidate profile | Name, professional headline, years of experience, date from which you are available and notice period | From you |
| What you are looking for | Roles, minimum net salary, postcode, locality and municipality, maximum commuting time, means of transport, work arrangements, contract types, schedules and red lines, with the history of versions | From you |
| Applications | Job, cover letter (optional), status and history of each step (who and when), deadlines, refusal reason and note | From you and the organisation |
| Organisations | Tax number (NIF), name, address, activity code (CAE), licence, permanent certificate code, email and role of each member, invitations | From whoever registers or manages the organisation |
| Technical and security logs | IP address, browser, request made (address, result and duration) and, for sensitive actions (signing in, changing the password, administration decisions), who did what and when | Generated when you use Vero |
| Service emails | The emails we send you: email confirmation, password reset, security notices and application status | Generated by us |
- Account
- What it includesEmail, password (stored only as an Argon2id hash, never in plain text), roles, language, account status, dates of registration, email confirmation and last access
- Where it comes fromFrom you
- Sign-in with Google
- What it includesYour Google account identifier and the associated email. We do not receive your Google password
- Where it comes fromFrom Google, if you choose that option
- Sessions
- What it includesStart and expiry dates, client type (website or app) and browser or device. The session code is stored only as a hash
- Where it comes fromFrom your browser or the app
- Candidate profile
- What it includesName, professional headline, years of experience, date from which you are available and notice period
- Where it comes fromFrom you
- What you are looking for
- What it includesRoles, minimum net salary, postcode, locality and municipality, maximum commuting time, means of transport, work arrangements, contract types, schedules and red lines, with the history of versions
- Where it comes fromFrom you
- Applications
- What it includesJob, cover letter (optional), status and history of each step (who and when), deadlines, refusal reason and note
- Where it comes fromFrom you and the organisation
- Organisations
- What it includesTax number (NIF), name, address, activity code (CAE), licence, permanent certificate code, email and role of each member, invitations
- Where it comes fromFrom whoever registers or manages the organisation
- Technical and security logs
- What it includesIP address, browser, request made (address, result and duration) and, for sensitive actions (signing in, changing the password, administration decisions), who did what and when
- Where it comes fromGenerated when you use Vero
- Service emails
- What it includesThe emails we send you: email confirmation, password reset, security notices and application status
- Where it comes fromGenerated by us
We do not ask for a photo, date of birth, nationality, identity document, current or previous salary, or health data or other special categories of data. Please do not include them in your cover letter or profile.
Why we use the data and on what legal basis
| Purpose | Legal basis (article 6 GDPR) |
|---|---|
| Creating and managing your account, authenticating you and keeping you signed in | Performance of the contract (the Terms of use) |
| Storing your profile and what you are looking for, and sending your applications to organisations | Performance of the contract |
| Managing response deadlines, reminders, “no answer” and emails about application status | Performance of the contract |
| Verifying organisations and managing their members | Performance of the contract and legitimate interest in protecting candidates from fake offers |
| Recording whether each organisation meets response deadlines | Performance of the contract and legitimate interest in transparency for candidates |
| Security, fraud and abuse prevention, technical and audit logs | Legitimate interest in protecting the platform and the people who use it |
| Moderating content and handling reports and complaints | Legitimate interest and compliance with legal obligations |
| Answering requests from authorities and meeting other legal obligations | Legal obligation |
- Creating and managing your account, authenticating you and keeping you signed in
- Performance of the contract (the Terms of use)
- Storing your profile and what you are looking for, and sending your applications to organisations
- Performance of the contract
- Managing response deadlines, reminders, “no answer” and emails about application status
- Performance of the contract
- Verifying organisations and managing their members
- Performance of the contract and legitimate interest in protecting candidates from fake offers
- Recording whether each organisation meets response deadlines
- Performance of the contract and legitimate interest in transparency for candidates
- Security, fraud and abuse prevention, technical and audit logs
- Legitimate interest in protecting the platform and the people who use it
- Moderating content and handling reports and complaints
- Legitimate interest and compliance with legal obligations
- Answering requests from authorities and meeting other legal obligations
- Legal obligation
We do not send advertising by email, we do not build marketing profiles and we do not take automated decisions with legal or similarly significant effects on you (article 22 GDPR). Decisions about applications are always made by people in the organisation.
Who sees your data
- Organisations you apply to: until the interview they see your professional headline, experience, availability and cover letter, with an anonymous code; from the interview on they also see your name and email. Each organisation is responsible for what it does with this data in its recruitment process.
- The public: job ads and organisation names are public. Candidates’ data is never public.
- Our team: only those who need it, with role-based permissions. Administration actions are logged.
- Service providers: they process data on our behalf, under contracts that require them to protect it: Contabo GmbH (server hosting, in Germany) and OVH SAS (email delivery, in France).
- Google: when the “Continue with Google” button is available, the sign-in and sign-up pages load a Google script to display it, and Google receives your IP address. If you choose to sign in with Google, Google knows you used your Google account to sign in to Vero. Google processes this data as an independent controller, under its own privacy policy.
- Authorities: when the law requires it.
We do not sell your data or share it to train third-party artificial intelligence models.
Where the data is stored
Our servers and backups are in the European Union (Germany). If you sign in with Google, the sign-in request may go through Google LLC, in the United States, under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023).
How long we keep the data
| Data | Period |
|---|---|
| Account, profile, what you are looking for and applications | As long as the account exists |
| After you delete your account | We delete the account, profile and what you are looking for. Applications are kept without name, email or cover letter, only with status and dates, for organisations’ response statistics |
| Ended or expired sessions | 30 days |
| Confirmation and reset links already used or expired | 7 days |
| Request log (IP, browser, requested address) | 30 days |
| Web server logs | 14 days |
| Audit log (sensitive actions) | The action, author and date are kept as evidence; the IP address is deleted after 12 months |
| Backups (encrypted) | 14 days |
| Acceptance of the terms and of this policy | As long as the account exists |
- Account, profile, what you are looking for and applications
- As long as the account exists
- After you delete your account
- We delete the account, profile and what you are looking for. Applications are kept without name, email or cover letter, only with status and dates, for organisations’ response statistics
- Ended or expired sessions
- 30 days
- Confirmation and reset links already used or expired
- 7 days
- Request log (IP, browser, requested address)
- 30 days
- Web server logs
- 14 days
- Audit log (sensitive actions)
- The action, author and date are kept as evidence; the IP address is deleted after 12 months
- Backups (encrypted)
- 14 days
- Acceptance of the terms and of this policy
- As long as the account exists
Your rights
- Access: know what data we hold about you and get a copy.
- Rectification: correct wrong data. You can correct most of it yourself, in your profile and on your account page.
- Erasure: ask us to delete your account and your data, as described in the previous section.
- Restriction: ask us to stop using the data while we look into a question you raised.
- Portability: receive the data you gave us in a structured format, to take it to another service.
- Objection: object to processing based on our legitimate interest.
To exercise any right, write to contact email from your account’s email. We answer within one month, which may be extended by two more months for complex requests (we will tell you if so). It is free. If we have doubts about your identity, we may ask you to confirm it.
If you think we have not handled your data properly, you can lodge a complaint with the Portuguese data protection authority, Comissão Nacional de Proteção de Dados (www.cnpd.pt), Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa.
Security
We protect data with encrypted connections (HTTPS), passwords stored with Argon2id, session codes and links stored only as hashes, role-based permissions, logging of sensitive actions, attempt limits and encrypted backups.
If a data breach puts your rights at risk, we notify the CNPD within 72 hours and, if the risk is high, we also tell you without delay.
Minors
Vero is for people aged 16 or over. If we learn that an account belongs to someone younger, we delete it.
Changes to this policy
When we change this policy, we publish the new version here, with its date. If the change is relevant (for example, a new purpose or a new service provider), we email you before it takes effect. Previous versions are available on request.