Privacy notice
Provided under art. 13 of Regulation (EU) 2016/679 ("GDPR") to users of the Faro Jobs service.
1. Data controller
Francesco Milani, email: support@farojobs.app.
2. Scope of the service
Faro Jobs collects job postings from public sources (employers' career sites and ATSs), matches them against the user's CV and preferences, and produces a reasoned compatibility score, together with tools for CV tailoring and application tracking.
3. Categories of data processed
- Data provided by the user: email; password (stored exclusively as a salted hash); phone number (optional); CV as text; search preferences; application data (status, notes, reminders); generated documents; language and theme settings.
- Data generated by use: compatibility scores and their reasons; the vector representation of the CV (embedding), treated as personal data as it derives from the CV; preference signals; AI feature usage counters for plan limits.
- Technical data: IP address, used for rate limiting and anti-bot verification (Cloudflare Turnstile) and not stored in the service's records; session identifiers and OTP codes, stored as hashes; Cloudflare platform logs, per the provider's retention terms.
4. Purposes and legal bases
- Provision of the service and operational communications: performance of the contract (art. 6.1.b)
- Security, abuse prevention, rate limiting: legitimate interest (art. 6.1.f)
- Aggregate statistics: legitimate interest (art. 6.1.f)
- Payments and tax obligations: contract and legal obligation (art. 6.1.c)
The service performs no advertising profiling: no profiling cookies or third-party pixels, no transfer of data to third parties for commercial purposes. The only cookies used are technical (session and theme).
5. Special categories of data
The service does not request data under art. 9 GDPR (health, trade-union membership, religious or political beliefs, ethnic origin) or criminal-record data. The Terms of service require the user not to include in the CV data unnecessary for professional evaluation. Any such data present in the uploaded text is processed solely as part of the document and is not used as an evaluation criterion. Any processing of data of this nature within the optional AI functions is carried out on the basis of the user's explicit consent (art. 9(2)(a); see § 8).
6. Automated decision-making
The service assigns each posting a compatibility score that determines its ordering. The score produces no legal effects and does not significantly affect the person (art. 22 GDPR does not apply); its reasons can be reviewed for each posting. The optional "AI second opinion" feature provides an assessment and does not alter the ordering. When the user activates it, an extract of the CV is sent to an external AI provider (§§ 7-8) on the basis of the user's explicit consent.
7. Recipients of the data
- Cloudflare, Inc.: hosting, database, semantic search, AI processing (Workers AI), anti-bot protection; DPA with standard contractual clauses.
- Resend: delivery of operational emails.
- Amazon Web Services (SES): backup email channel, currently inactive.
- Polar Software, Inc.: payment handling as merchant of record and independent data controller: it concludes the transaction, applies VAT and issues the receipt. Payment data does not pass through the service's systems. Privacy policy: polar.sh/legal/privacy.
- Moonshot AI (Kimi,
api.moonshot.ai): receives an extract of the CV (~900 characters) and the job data to provide the "AI second opinion", prepare or generate application materials, and identify matching roles (distillation); it does not use the data to train its models. Non-EU provider (China) without an adequacy decision; see § 8.
AI processing of the CV takes place mainly on Cloudflare Workers AI, with the same provider that hosts the service; Moonshot is used for the AI functions described above. No data is sold or transferred for third-party purposes.
8. Transfers outside the EU
Transfers to US providers rely on standard contractual clauses and, where the provider participates, on the Data Privacy Framework.
The AI functions described in § 7 involve transferring an extract of the CV to Moonshot AI (China), a country without an EU adequacy decision: the transfer occurs solely on the user's explicit consent, collected once at first access or login, recorded and versioned (art. 49(1)(a) GDPR), after notice of the absence of adequacy. Consent may be withdrawn at any time in the "You → Your data" section.
The consent covers recurring uses of the AI functions: on each activation an extract of the CV is transferred to Moonshot AI (China). The user is informed that these are repeated transfers to a country without an adequacy decision and without equivalent safeguards, and may withdraw consent at any time, with effect on subsequent uses.
Where the CV extract incidentally contains special-category data (art. 9 GDPR), that same explicit consent constitutes the condition for lawfulness under art. 9(2)(a) GDPR for processing such data within the AI functions described; such data is not used as an evaluation criterion (see § 5).
9. Retention periods
- Account, profile, CV, applications: for the life of the account; immediate removal upon deletion.
- Sessions: 30 days. OTP codes: a few minutes.
- Scores: periodically recomputed; obsolete ones are removed.
- Aggregate technical statistics: approximately 120 days.
- Payout records: 10 years (legal obligation). Sale receipts are issued and kept by Polar.
10. Rights of the data subject
Access and portability (art. 15 and 20) and erasure (art. 17) can be exercised directly in the application, under You → Your data; deletion is final and immediate. Rectification (art. 16) is performed by editing profile and preferences. For objection and restriction (art. 18 and 21) or any other request: support@farojobs.app, response within one month. The right to lodge a complaint with the Italian supervisory authority (gpdp.it) remains unaffected.
11. Security measures
Passwords and session tokens stored exclusively as hashes; encrypted connections (HTTPS); anti-bot verification at sign-up; rate limits on authentication. In the event of a breach entailing a high risk, the user will be informed under art. 34.
12. Changes
Substantial changes are communicated by email or in the application before taking effect.
Last updated: 29 August 2026 (v3)