Privacy Policy
This Privacy Policy explains how YourDataApp Ltd processes personal data when you use JobsBook.app. It is written to comply with Regulation (EU) 2016/679 (the "General Data Protection Regulation") and the Irish Data Protection Act 2018.
1. Who we are (Data Controller)
YourDataApp Ltd ("we", "us", "our") is the data controller for personal data processed via the JobsBook.app service (the "Service"). We are a company incorporated in Ireland (CRO no. 807187, VAT 4597465SH) with registered office at Dublin, Ireland. Director: D Sarbul. You can reach us at info@yourdataapp.com for any privacy-related enquiry, including requests to exercise the rights described in Section 8 below. The same address also serves as our Data Protection contact — while we are not required to appoint a formal Data Protection Officer, this mailbox is monitored by a member of staff with GDPR responsibility.
When you use JobsBook.app to manage your own customers, you are the controller of that customer data and we act as your processor under the Data Processing Addendum available at /dpa.
2. The personal data we collect
We collect only the data we need to run the Service. Categories:
- Account & billing data (managers): name, business email, hashed password, chosen company name, billing country, and Stripe customer/subscription identifiers. Card numbers are collected by Stripe and never reach our servers.
- Staff data: staff name, an optional contact email, a hashed 4-digit PIN, personal working URL slug and the audit trail of jobs assigned to them.
- Customer data (uploaded by our tenants): company/contact name, phone numbers, email addresses, addresses / postcodes / geolocation, booking notes and invoice-related identifiers such as VAT number. This data is uploaded and controlled by the tenant using JobsBook to serve their own customers.
- Operational data: booking codes, invoice numbers, timestamps, staff actions, chat messages between tenant and staff, photos of jobs, customer signatures captured on completion.
- Technical data: IP address (truncated to the last 4 octets and stored with failed logins only), user agent string, session tokens (JWTs), device timezone.
- Communication data: emails we send on your behalf via Resend (booking confirmations, invoices, receipts) — subject line, recipient address, and delivery status.
3. Purposes and lawful bases for processing (Art. 6 GDPR)
| Purpose | Lawful basis |
|---|---|
| Providing the Service (auth, dashboard, invoicing, calendar) | Art. 6(1)(b) — performance of the contract |
| Charging your subscription via Stripe | Art. 6(1)(b) — contract |
| Sending transactional emails (invoices, receipts) to the tenant's customers | Art. 6(1)(f) — legitimate interest of the tenant (as their processor) & Art. 6(1)(b) |
| Preventing fraud, brute-force attacks, abuse | Art. 6(1)(f) — legitimate interest |
| Marketing / product-update emails | Art. 6(1)(a) — consent (opt-in only, withdrawable at any time) |
| Retaining invoices & ledger for tax records | Art. 6(1)(c) — legal obligation (Irish Revenue: 7-year retention, s.886 TCA 1997) |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects (Art. 22 GDPR). We do not perform profiling for advertising.
4. Who we share your data with (sub-processors)
We only share the minimum data required. Current sub-processors are vetted for GDPR compliance and bound by written data-protection agreements:
- Stripe Payments Europe, Ltd. (Dublin, Ireland) — subscription billing. Receives your business email, an opaque tenant identifier and billing-country. Card data is collected directly by Stripe. Privacy notice: stripe.com/ie/privacy.
- Resend (Resend, Inc., United States) — transactional email delivery. Receives recipient email address, subject line and rendered HTML body of each email we send on your behalf. Transfers rely on Standard Contractual Clauses (SCCs, EU Commission Decision 2021/914).
- Google LLC — Maps & Places APIs — address auto-complete and map rendering. Only the address or coordinates you look up are transmitted. See policies.google.com/privacy.
- HeiGIT gGmbH — OpenRouteService (Germany) — driving distance/time calculations. Only postcodes / lat-lng coordinates are transmitted; no personal identifiers.
- MongoDB Atlas (MongoDB Ireland Ltd.) — primary database hosting in an EU region. Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
- OpenAI (via Emergent LLM key gateway) — optional AI helpers (e.g. duplicate-customer detection). Only prompts constructed from anonymised or pseudonymised business data are sent. If your account has AI features disabled, no data is sent to OpenAI. See openai.com/policies/privacy-policy.
We never sell personal data and we never share it for third-party advertising. A current list of sub-processors is available on request via info@yourdataapp.com.
5. International data transfers
Where a sub-processor is located outside the European Economic Area (EEA) — primarily the United States (Resend, OpenAI) — the transfer is protected by the European Commission's Standard Contractual Clauses (SCCs) Module 2 (controller-to-processor) or Module 3 (processor-to-processor), supplemented by technical measures (encryption in transit, minimum-necessary payloads). Where a sub-processor is certified under the EU-US Data Privacy Framework we also rely on that adequacy decision.
6. How long we keep your data (retention)
- Active account: retained while your subscription is active.
- Trial that does not upgrade: read-only for 30 days after the trial ends, then permanently deleted.
- Cancelled paid account: retained for 30 days in a soft-locked state for billing-dispute resolution, then permanently deleted (see Section 8 — you can request earlier deletion at any time).
- Invoicing & ledger records: retained for 7 years to comply with Irish Revenue record-keeping obligations (Taxes Consolidation Act 1997 s.886 and the VAT Consolidation Act 2010 s.84). On deletion of your account these records are anonymised (personal identifiers stripped) but the numeric tax data is kept.
- Failed-login records: IP-truncated logs are kept for 90 days for brute-force protection.
- Backup snapshots: encrypted rolling backups are retained for a maximum of 30 days.
7. Security measures
- TLS 1.2+ for every HTTP request; HSTS enforced on the production domain.
- Passwords and staff PINs hashed with bcrypt (cost ≥ 12).
- Database encryption at rest (AES-256, provider-managed keys).
- Tenant isolation enforced at the database driver level (every query is scoped by tenant id).
- Short-lived JWTs (24 hours) with server-side revocation on password / PIN change.
- Audit log of privileged actions (data exports, deletions, tenant merges).
- Principle of least privilege — production database access limited to on-call engineers with MFA.
- Regular dependency scanning and prompt patching of critical vulnerabilities.
8. Your rights under GDPR
You have the following rights, exercisable free of charge:
- Right of access (Art. 15) — obtain a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — correct inaccurate data. Managers can edit their profile in Settings.
- Right to erasure (Art. 17, "right to be forgotten") — request deletion, subject to legal-retention exceptions in Section 6.
- Right to data portability (Art. 20) — receive your data in a structured, commonly-used, machine-readable format (JSON). Available in Settings → Privacy & data → Export my data.
- Right to restriction of processing (Art. 18).
- Right to object (Art. 21) — including a right to opt out of legitimate-interest processing at any time.
- Right to withdraw consent (Art. 7(3)) — where processing is based on consent (marketing emails), you can withdraw at any time without affecting prior lawful processing.
Most rights are self-serve via Settings → Privacy & data. For anything else, email info@yourdataapp.com. We will respond within 30 days (extendable by up to 60 further days for complex requests, per Art. 12(3) GDPR).
9. Cookies and similar technologies
JobsBook.app uses only strictly-necessary cookies and browser storage — no analytics, no advertising, no cross-site tracking. Full details are in our Cookie Policy.
10. Data-breach notification
If a personal-data breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify the Irish Data Protection Commission within 72 hours of becoming aware of it, as required by Art. 33 GDPR. Where the breach is likely to result in a high risk to you, we will also notify you directly and without undue delay (Art. 34 GDPR), with a description of the nature of the breach, likely consequences and mitigation measures.
11. Complaints
You have the right to lodge a complaint with a supervisory authority, in particular the Irish Data Protection Commission (DPC):
Data Protection Commission21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Web: https://www.dataprotection.ie
12. Children
JobsBook.app is a B2B tool and is not directed at children under the age of 16. We do not knowingly collect personal data from children.
13. Changes to this policy
If we make material changes to this policy we will notify you by email and re-request your acknowledgement on next login. The version number and effective date at the top of this page always reflect the current policy.