Privacy Policy

Last updated: February 12, 2026

1. Introduction

DataToday NV ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our platform (the "Service").

We are the data processor for candidate data uploaded by our customers (who are the data controllers). For our own customers' account data, we act as the data controller.

2. Data We Collect

2.1 Account Data (Controller)

2.2 Candidate Data (Processor)

2.3 Technical Data

3. Legal Basis for Processing

PurposeLegal Basis (GDPR Art. 6)
Providing the ServiceContract performance (Art. 6(1)(b))
Account managementContract performance (Art. 6(1)(b))
Candidate data processingLegitimate interest of the controller (Art. 6(1)(f)) or consent
Security and fraud preventionLegitimate interest (Art. 6(1)(f))
Service improvementLegitimate interest (Art. 6(1)(f))
Marketing communicationsConsent (Art. 6(1)(a))
Legal obligationsLegal obligation (Art. 6(1)(c))

4. Data Retention

Data TypeRetention Period
Account dataDuration of account + 12 months
Candidate dataAs configured by the data controller (default: 24 months)
CV filesAs configured by the data controller (default: 24 months)
Audit logs36 months (regulatory minimum)
Technical logs90 days
Billing records7 years (legal requirement)

5. Your Rights (Data Subject Rights)

Under the GDPR, you have the right to:

To exercise these rights, contact us at dpo@askbob.be. We will respond within 30 days.

6. Data Transfers

Your data is stored in the European Union (GCP europe-west1 region, Belgium). We do not transfer personal data outside the EU/EEA unless required and protected by Standard Contractual Clauses or an adequacy decision.

7. Sub-processors

We use the following sub-processors:

Sub-processorPurposeLocation
Google Cloud PlatformInfrastructure hosting and storageEU (Belgium)
OpenAIAI text processing and embeddingsUS (SCCs in place)
Mistral AIAI document parsing and embeddingsEU (France)
ConvertAPIDocument format conversionEU
SMTP email relayTransactional email deliveryEU

8. Security Measures

We implement appropriate technical and organizational measures including:

9. Cookies

We use the following cookies:

CookiePurposeDuration
session_tokenAuthentication (essential)Session
refresh_tokenToken refresh (essential)7 days
preferencesUI preferences (functional)1 year

We do not use third-party tracking or advertising cookies.

10. Data Breach Notification

In the event of a personal data breach, we will notify affected data controllers within 72 hours as required by GDPR Article 33.

11. Data Protection Officer

Our Data Protection Officer can be reached at:
Email: dpo@askbob.be
DataToday NV, Veldkant 33 A, 2550 Kontich, Belgium

12. Supervisory Authority

You have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, gegevensbeschermingsautoriteit.be) or your local supervisory authority.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before they take effect.

14. Contact Us

Privacy / data-subject requests: dpo@askbob.be
General enquiries: hello@askbob.be
DataToday NV
Veldkant 33 A, 2550 Kontich, Belgium
Enterprise / VAT number: BE 0669.633.758