Privacy
1. Controller
The controller is the natural person operating Klinnova as a sole trader (nicht eingetragenes Einzelunternehmen), as identified in the Impressum. For privacy and data-subject requests during Cohort A, contact support@klinnova.com. No data protection officer is appointed for this private beta unless later required.
2. Scope
This notice describes personal-data processing for the Klinnova private beta (Cohort A). It may change as the product and later legal review progress. It is not a claim of full GDPR certification.
3. What we process
Depending on how you use Klinnova, we may process:
- Candidate account and profile data you provide (name, Berlin locality/travel preferences, languages, German comfort, work-authorisation self-declaration, availability, job preferences); applications and submission snapshots; optional CV or candidate documents only if that feature is enabled and you upload them.
- Employer account and profile data (display name, locality, contact details, organisation name where applicable); verification attestation data; vacancies; applicant information made available through the product for review.
- Operator moderation and audit records created when an operator reviews, suspends, restores, or otherwise moderates an account or vacancy.
- Technical data needed to run and secure the service (authentication session cookies, security logs, and — where monitoring is enabled — scrubbed error events).
Klinnova does not collect identity or residence-title documents in the MVP. Work authorisation is a self-declaration. Exact private residential workplace addresses are not collected for public job surfaces; public locality remains privacy-safe.
4. Why we process data (legal bases)
- Providing accounts, profiles, vacancies, matching, and applications: Art. 6(1)(b) GDPR (contract / steps at your request).
- Security, abuse prevention, and service integrity: Art. 6(1)(f) GDPR (legitimate interests), and Art. 6(1)(b) where needed to operate your account.
- Moderation and the operator audit ledger: Art. 6(1)(f) GDPR, and Art. 6(1)(c) where a legal obligation applies.
- Support and data-subject requests via support@klinnova.com: Art. 6(1)(b)/(f)/(c) GDPR as applicable.
- Transactional product email: Art. 6(1)(b) GDPR.
- Error monitoring (Sentry), where enabled: Art. 6(1)(f) GDPR — keeping the service reliable and secure.
Cohort A does not use separate marketing email. If marketing is added later, it will require a distinct legal basis (typically consent).
5. Processors and service providers
- Supabase — authentication, application database, and private document storage where used.
- Vercel — web application hosting and delivery.
- Zoho — hosting of the support@klinnova.com mailbox.
- Resend — transactional product email provider for configured Production mail flows.
- Sentry — error monitoring under the boundary below.
We do not sell personal data and do not use advertising networks or third-party product analytics (for example PostHog) in Cohort A.
6. Monitoring (Sentry)
Klinnova uses Sentry for error monitoring only, with a privacy-conscious configuration: no session replay; no request-body or application/vacancy payload capture; default PII sending disabled; additional scrubbing of sensitive fields; EU region preferred where available on the selected plan; retention target of 30 days or less where supported.
- Preview: Sentry is active for hosted Preview under the boundary above.
- Production: Sentry is intentionally not enabled for Cohort A unless the founder later authorizes Production activation. If that changes, this notice will be updated.
7. International transfers
Some providers may process data outside the EEA. Where required, we rely on appropriate transfer mechanisms offered by those providers (such as Standard Contractual Clauses) and prefer EU-region options where we have configured them.
8. Cookies and similar technologies
Klinnova uses essential cookies and similar technologies required for authentication sessions and secure operation of the site. Cohort A does not add non-essential advertising or analytics cookies.
9. Retention
- Account and profile data: for the life of the account, then handled under the account-deletion process (anonymization/tombstones as implemented in the product).
- Support mailbox correspondence: only as long as needed to resolve the request, plus an operational buffer of up to 24 months, unless a longer hold is required for a dispute or legal obligation.
- Sentry error events: 30 days or less where supported.
- Moderation/audit taxonomy records may be retained in anonymized or redacted form as required for integrity of the audit trail.
10. Your rights
Subject to applicable law, you may request access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests. You can use in-product account export and deletion where available, or email support@klinnova.com. You may lodge a complaint with the Berliner Beauftragte für Datenschutz und Informationsfreiheit (or another competent supervisory authority).
11. Age
Klinnova is not directed at children under 16. Accounts should only be created by users who are at least 16 years old (or older if required for the work they seek).
12. Changes
We may update this notice as the beta and later legal review progress. Material changes will be reflected on this page.