DOP Team — Privacy Policy
1. Introduction
This Privacy Policy (the "Policy") explains how >>> FILL IN: full legal entity name <<< ("DOP Team", "Company", "we", "us" or "our") collects, uses, discloses, stores and protects your personal data when you access or use our websites, web applications and related services (together, the "Platform"), and the rights you have over your personal data.
The Platform is operated by the Company, which intends to be incorporated in >>> FILL IN: country of incorporation (currently stated as Bulgaria — confirm) <<<. We act as the controller of the personal data described in this Policy.
This Policy is written to comply with Regulation (EU) 2016/679 (the "GDPR"), the EU ePrivacy rules, and other applicable data-protection laws. Where you are located outside the European Economic Area ("EEA"), additional local rules may apply.
Protecting your personal data and respecting your privacy are a priority for us. We are committed to processing your data lawfully, fairly and transparently, to collecting only what we need, and to keeping it secure (see Section 10).
Please read this Policy together with our Terms of Service and our Cookie Policy. By creating an account or otherwise using the Platform, you confirm that you have read and understood this Policy. If you do not agree with it, please do not use the Platform.
Public website: https://dopteam.io
Web application: https://app-dopteam.io
All related services, features, APIs and applications offered under the DOP Team brand
2. Who we are (Data Controller)
The data controller responsible for your personal data is:
Legal entity: >>> FILL IN: registered company name <<<
Company registration number: >>> FILL IN: registration / VAT number <<<
Registered address: >>> FILL IN: full registered address <<<
Privacy contact e-mail: >>> FILL IN: privacy@dopteam.io or equivalent <<<
Data Protection Officer (if appointed): >>> FILL IN: DPO name and contact, or state "not appointed" <<<
IMPORTANT NOTICE — the operating legal entity is in the process of being registered. Until registration is complete, the placeholders above must be filled in and this Policy must not be relied upon as final. Operating a data-processing platform before a controlling legal entity exists carries legal and liability risk; we recommend completing incorporation and appointing a clear controller before public launch.
3. What personal data we collect
We collect the categories of personal data set out below. Some data is required to provide the Platform; other data is optional and you choose whether to provide it.
3.1 Account and identity data
E-mail address and password (your password is never stored in plain text — it is stored only as a salted cryptographic hash)
First name and last name
Profile photo (avatar)
Date of birth
Nationality / citizenship
Country and city of current location
A unique public profile identifier (slug) and account role(s)
Records of your acceptance of our Terms of Service and Privacy Policy, including the version and date accepted
3.2 Professional and profile data
Current position / job title and total work experience
Work experience entries, education, courses and trainings (including certificate names, files and links you upload)
Skills, technologies and tools
Languages and proficiency levels
"About me" description and current job-search status
A CV/résumé generated by the Platform in PDF form on your request, based on your profile
Your participation in projects and teams, applications you submit, job postings you create, and investment requests
3.3 Contact and social data
Phone number and country dialling code (optional)
Preferred contact methods
Links to your external profiles that you choose to add (for example LinkedIn, GitHub, Facebook, Telegram)
3.4 Communications data
Messages you send and receive through the Platform's chat and project-communication features, and message read receipts
Cover letters and notes submitted with applications
Messages you send through our public "Contact us" form
Notifications generated for you
The content of chat messages is encrypted at rest in our database. Please note that other participants in a conversation can read the messages you send to them, and the Company may access message content where strictly necessary for security, abuse-prevention, legal compliance, or to provide support.
3.5 Technical, log and security data
To operate the Platform securely and to keep an audit trail, we automatically collect and log technical data for requests you make, including:
Internet Protocol (IP) address
Browser type and User-Agent string
Device and operating-system information
Date, time, the action performed, the resource accessed and the response status
Session and authentication identifiers (see our Cookie Policy)
We maintain an audit log that records, for security and accountability purposes, the actor, action, IP address, User-Agent and related metadata of activity on the Platform.
3.6 Analytics data
Where you consent to analytics cookies, we collect usage statistics through Google Analytics (such as pages viewed, features used, approximate location and session duration). See our Cookie Policy for details and for how to give or withdraw consent.
3.7 Data from third-party sign-in
If you register or log in using Google, GitHub or LinkedIn, we receive basic profile information from that provider (such as your name and e-mail address) in accordance with the permissions you grant and that provider's own privacy policy. We use this data to create or access your account.
3.8 Planned features (not yet active)
Some features described in our roadmap — such as AI-assisted interviews and paid/subscription services — are not yet live and we do not currently collect AI-interview responses or payment-card data. If and when these features are launched, we will update this Policy before processing such data. We never store full payment-card numbers; any future payments will be handled by a regulated third-party payment provider.
4. How and why we use your data, and our legal bases
Under the GDPR we must have a lawful basis for each use of your personal data. The table below summarises why we process data and the legal basis we rely on.
Purpose | Examples | Legal basis (GDPR Art. 6) |
|---|---|---|
Create and manage your account | Registration, login, sessions, profile display, account recovery and deletion | Performance of a contract (Art. 6(1)(b)) |
Provide core Platform features | Networking, projects and teams, job postings and applications, mentorship, investment requests, chat and notifications | Performance of a contract (Art. 6(1)(b)) |
Matching and recommendations | Connecting you with projects, jobs, mentors and other users | Performance of a contract; or legitimate interests (Art. 6(1)(f)) |
Security, fraud and abuse prevention | Authentication, audit logging (incl. IP and User-Agent), blocking and moderation | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
Service e-mails and in-app notifications | OTP/verification codes, account and transactional notices, support replies | Performance of a contract; legitimate interests |
Analytics and product improvement | Understanding how the Platform is used (Google Analytics) | Consent (Art. 6(1)(a)) |
Marketing communications (if any) | Optional newsletters or promotional messages | Consent (Art. 6(1)(a)) |
Comply with legal obligations | Responding to lawful requests, record-keeping, dispute resolution | Legal obligation (Art. 6(1)(c)); legitimate interests |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.
5. Who we share your data with
We do not sell your personal data. We share it only as described below.
5.1 Other users
Information in your public profile, your project and team participation, job postings, and the messages you send are visible to the users you interact with or, where you make a profile public, to other Platform users and visitors. You control much of this through your profile and visibility settings.
5.2 Service providers (processors)
We use carefully selected providers who process personal data on our behalf under data-processing agreements. They may only use the data to provide their service to us. Our main providers are:
Provider | Purpose | Data involved | Location / transfer |
|---|---|---|---|
Amazon Web Services (AWS S3) | Storage of uploaded files (avatars, logos, certificates, event images) | Files you upload and related metadata | >>> FILL IN: AWS region <<< — may involve transfer to the USA |
MailerSend (and SMTP e-mail delivery) | Sending transactional and verification e-mails | E-mail address, name, message content | USA — transfer outside the EEA |
Google (Google Analytics) | Usage analytics (only with your consent) | Online identifiers, usage and device data | USA — transfer outside the EEA |
Google, GitHub, LinkedIn (OAuth sign-in) | Optional social login | Basic profile data you authorise | USA — transfer outside the EEA |
Hosting / infrastructure provider | Servers, database and caching | All Platform data | >>> FILL IN: hosting provider name and country <<< |
5.3 Legal and protective disclosures
We may disclose personal data where required by law, court order or a competent authority, or where necessary to establish, exercise or defend legal claims, to enforce our Terms, or to protect the rights, safety and security of our users, the public or the Company.
5.4 Business transfers
If the Company is involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy and applicable law.
6. International data transfers
Some of our providers (including AWS, MailerSend and Google) are located in or transfer data to the United States or other countries outside the EEA. Where we transfer personal data outside the EEA, we rely on appropriate safeguards required by the GDPR, such as European Commission adequacy decisions or Standard Contractual Clauses (SCCs), together with supplementary measures where needed.
You can request a copy of the relevant safeguards by contacting us using the details in Section 2.
7. How long we keep your data
We keep personal data only for as long as necessary for the purposes described in this Policy, or as required by law.
Data | Retention |
|---|---|
Account and profile data | For as long as your account is active |
Deleted accounts | When you delete your account, your live profile is anonymised immediately; a snapshot is kept for a short grace period to allow you to restore the account, after which it is permanently deleted and associated stored files are purged (see Section 8 and our Terms). Current grace period: >>> FILL IN: confirm grace period (the Platform uses a short restore window followed by automated purge) <<< |
Chat messages | Until the conversation, project or account is deleted, subject to the other participant's copy |
Security and audit logs (incl. IP, User-Agent) | >>> FILL IN: retention period for audit logs (recommended: a defined period such as 12 months unless needed longer for security or legal reasons) <<< |
Analytics data | As configured in Google Analytics (subject to your consent) |
Backups | Until rotated out of our backup cycle |
8. Your rights
Subject to applicable law, you have the following rights over your personal data:
Access — obtain confirmation of whether we process your data and a copy of it
Rectification — correct inaccurate or incomplete data (you can edit most data directly in your profile)
Erasure — request deletion of your data ("right to be forgotten"); you can delete your account from your settings
Restriction — ask us to limit how we use your data in certain circumstances
Portability — receive certain data in a structured, machine-readable format (you can also export your CV/profile as a PDF)
Objection — object to processing based on our legitimate interests, including profiling, and to direct marketing
Withdraw consent — at any time, where we rely on consent (for example analytics cookies or marketing)
Lodge a complaint — with a data-protection supervisory authority
To exercise your rights, contact us at >>> FILL IN: privacy contact e-mail <<<. We will respond within one month, as required by the GDPR, and may extend this by two further months for complex requests. We may need to verify your identity before acting on a request.
You also have the right to complain to your local supervisory authority. The authority in our place of establishment is the Bulgarian Commission for Personal Data Protection (CPDP); if you are in another EEA country, you may contact your national authority. >>> FILL IN: confirm lead supervisory authority once incorporation is finalised <<<
9. Automated decision-making and AI
We do not currently make decisions that produce legal or similarly significant effects about you based solely on automated processing. Matching and recommendation features may rank or suggest content, but they do not, by themselves, make binding decisions about you.
If we introduce AI-assisted interviews or similar automated tools in future, we will provide clear information beforehand, identify the logic involved, offer the ability to request human review and to contest a decision, and comply with GDPR Article 22 and applicable AI-transparency rules.
10. How we protect your data
We implement technical and organisational measures appropriate to the risk, including:
Encryption of data in transit (HTTPS/TLS) and encryption of chat-message content at rest
Storing passwords only as salted cryptographic hashes (bcrypt)
Access controls, role-based permissions and session management
Security and audit logging, and monitoring for abuse
Use of reputable infrastructure and service providers
No method of transmission or storage is completely secure. You are responsible for keeping your login credentials confidential. If we become aware of a personal-data breach that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours where required, and affected users where the law requires it.
11. Children and age
The Platform is intended for, and restricted to, users aged 18 and over. We do not target the Platform at children and do not knowingly allow them to register. During registration you are clearly informed that by continuing you confirm you are at least 18 years old, and the Platform does not allow a date of birth indicating an age under 18 to be saved to a profile.
Minimum ages for using online services and for valid consent to the processing of personal data differ from country to country. For example, the GDPR sets the age of digital consent at 16, and individual EEA countries may lower it to as low as 13; other countries set different thresholds. It is your responsibility — and, for anyone below the age of majority or the applicable age of digital consent in their country, the responsibility of their parent or legal guardian — to ensure that using the Platform and providing personal data is permitted and properly authorised under the laws that apply to you.
If, despite these measures, a person under 18 accesses the Platform (for example by providing false information), they must stop using it immediately. By using the Platform or providing personal data, you confirm that you meet the applicable minimum age of 18.
We do not knowingly collect personal data from a child below the applicable age of digital consent without the consent of a parent or guardian. If we become aware that we hold such data without the consent required by law, we will delete it without undue delay. If you are a parent or guardian and believe a child has provided us with personal data, please contact us at >>> FILL IN: privacy contact e-mail <<< and we will take steps to delete it.
To the maximum extent permitted by applicable law, we are not responsible for personal data provided by a user who has misrepresented their age in order to bypass these measures. Nothing in this Policy removes or limits protections that the law grants to children and that cannot be waived.
12. Third-party links and services
The Platform may contain links to, or integrations with, third-party websites and services (for example external project links, social profiles, or OAuth providers). We are not responsible for the privacy practices or content of those third parties. We encourage you to review their privacy policies.
13. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the "Last Updated" date and, where required, notify you (for example by e-mail or an in-app notice) and, where the law requires, ask for renewed consent. Your continued use of the Platform after an update means you accept the revised Policy.
14. Language and contact
This Policy is provided in several languages. The English version is the controlling version; translations are provided for convenience only.
For any privacy-related question or to exercise your rights, contact us at >>> FILL IN: privacy contact e-mail <<< or by post at >>> FILL IN: registered address <<<.
If any provision of this Policy is found invalid or unenforceable, the remaining provisions continue in full force and effect.