In short
What this document says, in five points.
- Only the minimum needed to run the job board is collected: account details, what you post or save, and how you use the product.
- Personal data is never sold. It is shared only with the subprocessors listed below, and only for the things they help run.
- You can export your data, correct it, or delete your account at any time from Settings → Privacy. Requests are answered within 30 days.
- Browsing and applying for jobs never requires an account. Applications happen on the employer’s own site and never pass through Remoteli.
- Data is stored in the EU (Frankfurt) and the US (us-east-1). Cross-border transfers use Standard Contractual Clauses.
Who we are
remoteli.io is operated by Raven Digital, a private company registered in the Netherlands (KvK 83768106). For the purposes of the GDPR and the UK GDPR, Raven Digital is the data controller of personal data processed through the remoteli.io job board, except where this policy says otherwise.
We can be reached for any privacy question via our contact page.
What we collect
We collect three kinds of personal data: what you give us, what we observe as you use the product, and what we receive from third parties you connect.
| Category | Examples | Source |
|---|---|---|
| Account | Name, email, password hash, role (employer / job seeker), country of residence. | You, at signup. |
| Listings & activity | Job posts you publish, roles you save or bookmark, and which listings you click "apply" on. | You, in normal product use. |
| Usage | Pages viewed, searches run, features used, time-in-app, errors, device type, IP-derived approximate city. | Observed automatically. |
| Billing | Company name, billing address, VAT ID, last 4 digits and expiry of card. Full card numbers never touch our servers. | You + Stripe. |
We do not knowingly collect special categories of personal data (health, religion, biometrics, etc.). Please don't put any in a job listing or message — if you do, we will treat it like any other field and you grant us the same processing rights.
How we use it
We use personal data for a small number of purposes, each tied to a specific legal basis under Article 6 GDPR:
- Run the job board — publishing listings, search, and billing. Legal basis: performance of the contract you signed up under.
- Keep it safe — fraud detection, abuse prevention, blocking bad actors. Legal basis: legitimate interest in a trustworthy product.
- Improve the product — aggregated analytics, A/B tests, debugging. Legal basis: legitimate interest; opt out from Settings → Privacy.
- Tell you things — transactional emails always, marketing only with consent. Legal basis: consent for marketing; contract for transactional.
- Comply with the law — tax records, valid legal requests, court orders. Legal basis: legal obligation.
react got X% more apply-clicks when …"). If we ever change this we'll tell you and ask first.Your rights
Wherever you sit, you have meaningful control over your data. If you're in the EU, UK, Switzerland, Brazil, or California, you have specific statutory rights — but we extend the same controls to everyone.
- Access & export — download a full ZIP of everything we hold from Settings → Privacy → Export. JSON for structured data, original files for uploads.
- Correction — most fields are directly editable. For anything you can't edit, email us.
- Deletion — Settings → Privacy → Delete account. Soft-deleted for 30 days (in case you change your mind), then hard-deleted from primary storage. Backups roll off within 90 days.
- Restriction & objection — pause processing for analytics, marketing, or specific automated decisions.
- Portability — your export is machine-readable JSON, suitable for taking elsewhere.
- Withdraw consent — any time, without affecting prior lawful processing.
- Complain — to us first, please; if we can't fix it, to your local data protection authority. In the Netherlands that's the Autoriteit Persoonsgegevens.
We answer rights requests within 30 days. No charge, no jumping through hoops. If we need to confirm it's really you, we'll do that with the email on the account.
International transfers
Personal data is processed primarily in the European Economic Area. Some subprocessors and tooling sit in the United States. When data leaves the EEA we rely on:
- The European Commission's Standard Contractual Clauses (2021/914), in the controller-to-processor configuration, plus a transfer impact assessment for each vendor.
- The EU–U.S. Data Privacy Framework where the receiving vendor is certified.
- Additional technical measures: encryption in transit (TLS 1.3) and at rest (AES-256), and minimisation before transfer.
You can request a copy of the SCCs we use via our contact page.
Retention
We keep data only as long as it's useful to you or required of us. After that, it's deleted on a rolling basis.
| Kind | Kept for | Why |
|---|---|---|
| Active account | Lifetime of account | To run the service. |
| Closed account | 30 days soft + 90 day backup wash | Recovery + backup rotation. |
| Job posts | 24 months after the role closes | Reporting; companies sometimes re-open roles. |
| View & apply-click logs | 12 months | Listing analytics for employers. |
| Invoices & tax records | 7 years | Legal obligation (NL). |
| Server logs | 30 days | Security and debugging. |
Security
Security is not a checkbox; we treat it as part of the product. Highlights:
- Encryption in transit (TLS 1.3) and at rest (AES-256, AWS KMS-managed keys).
- 2FA available on every account; required for employer admins and our entire team.
- Least-privilege access. Production access is restricted and audited.
- Responsible disclosure: if you find a vulnerability, please report it via our contact page.
If we ever experience a personal-data breach that's likely to risk your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and you without undue delay.
Children
remoteli.io is built for working professionals and is not intended for anyone under 18. We don't knowingly collect personal data from children. If you believe a child has signed up, contact us and we'll close the account and delete the data within 7 days.
Changes to this policy
We update this policy when the product changes meaningfully or when the law does. For material changes we email everyone at least 30 days before the new version takes effect, and we publish a changelog at the bottom of this page so you can see exactly what moved.
Cosmetic edits — typo fixes, clarifications, renamed sections — happen without notice; the "last updated" date will change.
Contact us
For anything privacy-related:
- Contact form: remoteli.io/contact
- EU representative under Art. 27 GDPR: not required — we are established in the EU.
Something here doesn’t make sense?
These are living documents. If a clause reads ambiguously or contradicts what the product actually does, it should be fixed.