Jemmo's Commitment Regarding Confidentiality
Jemmo complies with regulations relating to the protection of personal data, in particular Regulation 2016/679 of April 27, 2016 regarding the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation (GDPR)) as well as the Data Protection and Liberties Act.
In this context, Jemmo has designated a data protection officer responsible for ensuring compliance with regulations and responding to all information and/or advice requests relating to personal data.
More specifically, Jemmo undertakes to ensure the confidentiality, security, integrity, availability, and preservation of personal data processed and/or hosted in compliance with applicable laws and regulations, and to make, where appropriate, any procedures or obtain any authorizations incumbent upon it under data processing regulations.
Data collected
Data is collected and used by Jemmo to manage Clients' access and actions on the Services, to improve and personalize the Services, and to maintain the customer relationship. This data also allows Jemmo and its partners to comply with legal and regulatory obligations and to produce statistics, audience measurements and market research.
Creating an Account and subscribing to the Services implies the collection and automated processing by Jemmo of the information necessary to provide the Services and operate the Site.
Data from client users (HR / Recruiters)
| Category | Data collected |
|---|---|
| Identity | Email, first name, last name |
| Authentication | Password (hashed by Supabase Auth), CGV acceptance (cgv_accepted_at) |
| Organization | Organization name, role (ADMIN / MEMBER), join date |
| Navigation | Pages visited, searches performed, interactions with talents |
| Technical | IP address, user-agent, session cookies (sb-*) |
Client Users (HR / Recruiters)
| Category | Data collected |
|---|---|
| Identity | Email, first name, last name |
| Authentication | Password (hashed by Supabase Auth), terms acceptance date (cgv_accepted_at) |
| Organisation | Organisation name, role (ADMIN / MEMBER), membership date |
| Navigation | Pages visited, searches performed, interactions with talent profiles |
| Technical | IP address, user-agent, session cookies (sb-*) |
Candidates / Talent
| Category | Data collected |
|---|---|
| Identity | First name, last name, email, phone, photo (URL) |
| Professional profile | Title / position, description, LinkedIn public ID, years of experience |
| Address | City, region, country, full address |
| Skills | Skills list, tags |
| Experience | Position, company, dates, description |
| Education | Degree, school, dates |
| Compensation | Type, min / max range, currency, frequency |
| CV / Resume | PDF or DOCX file stored in Supabase Storage |
| Metadata | Import source (LinkedIn, ATS, manual upload), internal ATS identifier |
| Enrichment | Data enriched via LinkedIn (linkedin_enrichment) |
Technical and Analytics Data
- Wide Events: structured logs containing
user_id,org_id,operation,duration_ms,outcome— used for monitoring and debugging. - PostHog: usage events (searches, job creations, matching sessions) — product analytics.
- Cookies: Supabase session (
sb-*), language preferences, analytics cookie consent.
Processing Purposes
| Purpose | Technical description |
|---|---|
| Access management | Authentication via Supabase Auth; multi-tenant isolation via RLS (Row Level Security) |
| AI matching | Talent data is sent to Supabase edge functions for AI-based scoring |
| ATS synchronisation | Bidirectional sync with Jarvi, Spott, and Teamtailor (jobs and candidates) |
| Analytics | PostHog for user behaviour analysis |
| Logging | Wide events for monitoring and debugging |
Recipients of Data
Internal Access
| Role | Access scope |
|---|---|
| MEMBER (logged-in user) | Own organisation data only (Supabase RLS) |
| ADMIN (organisation) | Member management, invitations, talent deletion |
| Service Role (technical) | Restricted access for workers and edge functions |
Sub-processors and Third-Party Services
| Service | Data shared | Purpose | Location |
|---|---|---|---|
| Supabase | All application data | Database hosting | Germany (EU) |
| Supabase Auth | Email, password hash | Authentication | Germany (EU) |
| PostHog | Anonymised events, user_id, org_id, user actions | Analytics | EU (eu.posthog.com) |
| Jarvi ATS | Candidate data, job listings | ATS synchronisation | External API |
| Spott ATS | Candidate data, job listings | ATS synchronisation | External API |
| Teamtailor ATS | Candidate data, job listings | ATS synchronisation | External API |
Client API keys (ATS) are stored encrypted in the database.
Jemmo's Commitment Regarding Data Security
Technical and analytics data
- Structured logs: application events with
user_id,org_id, operation, duration, outcome. - PostHog analytics: usage events (searches, job creations, matching) hosted on
eu.posthog.com. - Cookies: session, language preferences, consent.
Subject to prior information and in the absence of opposition, a Client may receive solicitations, offers and promotional messages from Jemmo's partners at their email address.
Recipients of data
| Legal basis | Purpose covered |
|---|---|
| Contract performance | Provision of the matching service, access management |
| Legal obligations | Anti-money laundering compliance, invoicing |
| Legitimate interest | Service improvement, statistics, analytics |
| Consent | Analytics cookies (PostHog), partner solicitations |
The data collected by Jemmo is processed and stored at the Site's host and that of the Platform in conditions aimed at ensuring their security and are retained for a period of one year beyond the duration necessary for achieving the purposes mentioned above. Beyond this period, they are retained for exclusively statistical purposes and do not give rise to any exploitation of any nature whatsoever.
| Data type | Retention period | Notes |
|---|---|---|
| Active data | Contract duration + 1 year | — |
| Statistical data | Beyond 1 year (anonymised) | No personal identifiers |
| Essential cookies | Session / 1 year | — |
| PostHog cookies | 1 year | — |
| Cookie consent | 6 months | — |
Access, Correction, and Deletion by the Client or User of Their Information
Withdrawal. If you no longer wish for us to collect, store, or use your information, you must cease using the Site and the Platform, cancel your Account and/or send us a message at the address contact@jemmo.io to request us to delete your information from our database. Withdrawal of your consent does not affect the lawfulness of the processing prior to the withdrawal.
Your Rights. Personal data is any information relating to a natural person likely to be identified, directly or indirectly. (for more information)
Personal data is any information relating to a natural person likely to be identified, directly or indirectly.
Under the data protection legislation in force, you have the following rights (following rights):
Right of Access. You can obtain confirmation of the processing of your data collected by Jemmo, access to your data, as well as for example the purposes of the processing, or the categories of data concerned.
Right of Rectification. You can request the rectification of your data when they are inaccurate.
Right to Erasure. You can request the deletion of your data in particular when these data have been the subject of unlawful processing, or when the purpose for which they were collected is no longer current.
Right to Restriction of Processing. You have the right to restrict the processing of your personal data in certain circumstances.
Right to Data Portability. You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transfer it to another structure if this is technically possible.
Right to Object. You may object at any time to the processing of your personal data for reasons relating to your particular situation or for example if your data is used for protection purposes
The Client may make a request concerning these aforementioned rights directly to Jemmo at the following address: contact@jemmo.io.
Where applicable, a complaint may be introduced to the National Commission for Informatics and Liberties, www.cnil.fr.
Modifications
Jemmo reserves the right to modify this privacy policy at any time. These modifications may be made necessary to comply with legal developments, or for strategic or technical reasons.
The new version of this privacy policy will come into force on the date of its publication.
Jemmo undertakes to make its best efforts to directly inform the Client or the User of any substantial modification made to this privacy policy.
Need a PDF version?
All our legal documents are available as a timestamped PDF for your records and your legal department.