DOP Team — Privacy Policy

Last Updated: >>> FILL IN: date of publication <<<

Effective Date: >>> FILL IN: effective date <<< · Version 2.0

1. Introduction

This Privacy Policy (the "Policy") explains how >>> FILL IN: full legal entity name <<< ("DOP Team", "Company", "we", "us" or "our") collects, uses, discloses, stores and protects your personal data when you access or use our websites, web applications and related services (together, the "Platform"), and the rights you have over your personal data.

The Platform is operated by the Company, which intends to be incorporated in >>> FILL IN: country of incorporation (currently stated as Bulgaria — confirm) <<<. We act as the controller of the personal data described in this Policy.

This Policy is written to comply with Regulation (EU) 2016/679 (the "GDPR"), the EU ePrivacy rules, and other applicable data-protection laws. Where you are located outside the European Economic Area ("EEA"), additional local rules may apply.

Protecting your personal data and respecting your privacy are a priority for us. We are committed to processing your data lawfully, fairly and transparently, to collecting only what we need, and to keeping it secure (see Section 10).

Please read this Policy together with our Terms of Service and our Cookie Policy. By creating an account or otherwise using the Platform, you confirm that you have read and understood this Policy. If you do not agree with it, please do not use the Platform.

  • Public website: https://dopteam.io

  • Web application: https://app-dopteam.io

  • All related services, features, APIs and applications offered under the DOP Team brand

2. Who we are (Data Controller)

The data controller responsible for your personal data is:

  • Legal entity: >>> FILL IN: registered company name <<<

  • Company registration number: >>> FILL IN: registration / VAT number <<<

  • Registered address: >>> FILL IN: full registered address <<<

  • Privacy contact e-mail: >>> FILL IN: privacy@dopteam.io or equivalent <<<

  • Data Protection Officer (if appointed): >>> FILL IN: DPO name and contact, or state "not appointed" <<<

IMPORTANT NOTICE — the operating legal entity is in the process of being registered. Until registration is complete, the placeholders above must be filled in and this Policy must not be relied upon as final. Operating a data-processing platform before a controlling legal entity exists carries legal and liability risk; we recommend completing incorporation and appointing a clear controller before public launch.

3. What personal data we collect

We collect the categories of personal data set out below. Some data is required to provide the Platform; other data is optional and you choose whether to provide it.

3.1 Account and identity data

  • E-mail address and password (your password is never stored in plain text — it is stored only as a salted cryptographic hash)

  • First name and last name

  • Profile photo (avatar)

  • Date of birth

  • Nationality / citizenship

  • Country and city of current location

  • A unique public profile identifier (slug) and account role(s)

  • Records of your acceptance of our Terms of Service and Privacy Policy, including the version and date accepted

3.2 Professional and profile data

  • Current position / job title and total work experience

  • Work experience entries, education, courses and trainings (including certificate names, files and links you upload)

  • Skills, technologies and tools

  • Languages and proficiency levels

  • "About me" description and current job-search status

  • A CV/résumé generated by the Platform in PDF form on your request, based on your profile

  • Your participation in projects and teams, applications you submit, job postings you create, and investment requests

3.3 Contact and social data

  • Phone number and country dialling code (optional)

  • Preferred contact methods

  • Links to your external profiles that you choose to add (for example LinkedIn, GitHub, Facebook, Telegram)

3.4 Communications data

  • Messages you send and receive through the Platform's chat and project-communication features, and message read receipts

  • Cover letters and notes submitted with applications

  • Messages you send through our public "Contact us" form

  • Notifications generated for you

The content of chat messages is encrypted at rest in our database. Please note that other participants in a conversation can read the messages you send to them, and the Company may access message content where strictly necessary for security, abuse-prevention, legal compliance, or to provide support.

3.5 Technical, log and security data

To operate the Platform securely and to keep an audit trail, we automatically collect and log technical data for requests you make, including:

  • Internet Protocol (IP) address

  • Browser type and User-Agent string

  • Device and operating-system information

  • Date, time, the action performed, the resource accessed and the response status

  • Session and authentication identifiers (see our Cookie Policy)

We maintain an audit log that records, for security and accountability purposes, the actor, action, IP address, User-Agent and related metadata of activity on the Platform.

3.6 Analytics data

Where you consent to analytics cookies, we collect usage statistics through Google Analytics (such as pages viewed, features used, approximate location and session duration). See our Cookie Policy for details and for how to give or withdraw consent.

3.7 Data from third-party sign-in

If you register or log in using Google, GitHub or LinkedIn, we receive basic profile information from that provider (such as your name and e-mail address) in accordance with the permissions you grant and that provider's own privacy policy. We use this data to create or access your account.

3.8 Planned features (not yet active)

Some features described in our roadmap — such as AI-assisted interviews and paid/subscription services — are not yet live and we do not currently collect AI-interview responses or payment-card data. If and when these features are launched, we will update this Policy before processing such data. We never store full payment-card numbers; any future payments will be handled by a regulated third-party payment provider.

4. How and why we use your data, and our legal bases

Under the GDPR we must have a lawful basis for each use of your personal data. The table below summarises why we process data and the legal basis we rely on.

Purpose

Examples

Legal basis (GDPR Art. 6)

Create and manage your account

Registration, login, sessions, profile display, account recovery and deletion

Performance of a contract (Art. 6(1)(b))

Provide core Platform features

Networking, projects and teams, job postings and applications, mentorship, investment requests, chat and notifications

Performance of a contract (Art. 6(1)(b))

Matching and recommendations

Connecting you with projects, jobs, mentors and other users

Performance of a contract; or legitimate interests (Art. 6(1)(f))

Security, fraud and abuse prevention

Authentication, audit logging (incl. IP and User-Agent), blocking and moderation

Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c))

Service e-mails and in-app notifications

OTP/verification codes, account and transactional notices, support replies

Performance of a contract; legitimate interests

Analytics and product improvement

Understanding how the Platform is used (Google Analytics)

Consent (Art. 6(1)(a))

Marketing communications (if any)

Optional newsletters or promotional messages

Consent (Art. 6(1)(a))

Comply with legal obligations

Responding to lawful requests, record-keeping, dispute resolution

Legal obligation (Art. 6(1)(c)); legitimate interests

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.

5. Who we share your data with

We do not sell your personal data. We share it only as described below.

5.1 Other users

Information in your public profile, your project and team participation, job postings, and the messages you send are visible to the users you interact with or, where you make a profile public, to other Platform users and visitors. You control much of this through your profile and visibility settings.

5.2 Service providers (processors)

We use carefully selected providers who process personal data on our behalf under data-processing agreements. They may only use the data to provide their service to us. Our main providers are:

Provider

Purpose

Data involved

Location / transfer

Amazon Web Services (AWS S3)

Storage of uploaded files (avatars, logos, certificates, event images)

Files you upload and related metadata

>>> FILL IN: AWS region <<< — may involve transfer to the USA

MailerSend (and SMTP e-mail delivery)

Sending transactional and verification e-mails

E-mail address, name, message content

USA — transfer outside the EEA

Google (Google Analytics)

Usage analytics (only with your consent)

Online identifiers, usage and device data

USA — transfer outside the EEA

Google, GitHub, LinkedIn (OAuth sign-in)

Optional social login

Basic profile data you authorise

USA — transfer outside the EEA

Hosting / infrastructure provider

Servers, database and caching

All Platform data

>>> FILL IN: hosting provider name and country <<<

5.3 Legal and protective disclosures

We may disclose personal data where required by law, court order or a competent authority, or where necessary to establish, exercise or defend legal claims, to enforce our Terms, or to protect the rights, safety and security of our users, the public or the Company.

5.4 Business transfers

If the Company is involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy and applicable law.

6. International data transfers

Some of our providers (including AWS, MailerSend and Google) are located in or transfer data to the United States or other countries outside the EEA. Where we transfer personal data outside the EEA, we rely on appropriate safeguards required by the GDPR, such as European Commission adequacy decisions or Standard Contractual Clauses (SCCs), together with supplementary measures where needed.

You can request a copy of the relevant safeguards by contacting us using the details in Section 2.

7. How long we keep your data

We keep personal data only for as long as necessary for the purposes described in this Policy, or as required by law.

Data

Retention

Account and profile data

For as long as your account is active

Deleted accounts

When you delete your account, your live profile is anonymised immediately; a snapshot is kept for a short grace period to allow you to restore the account, after which it is permanently deleted and associated stored files are purged (see Section 8 and our Terms). Current grace period: >>> FILL IN: confirm grace period (the Platform uses a short restore window followed by automated purge) <<<

Chat messages

Until the conversation, project or account is deleted, subject to the other participant's copy

Security and audit logs (incl. IP, User-Agent)

>>> FILL IN: retention period for audit logs (recommended: a defined period such as 12 months unless needed longer for security or legal reasons) <<<

Analytics data

As configured in Google Analytics (subject to your consent)

Backups

Until rotated out of our backup cycle

8. Your rights

Subject to applicable law, you have the following rights over your personal data:

  • Access — obtain confirmation of whether we process your data and a copy of it

  • Rectification — correct inaccurate or incomplete data (you can edit most data directly in your profile)

  • Erasure — request deletion of your data ("right to be forgotten"); you can delete your account from your settings

  • Restriction — ask us to limit how we use your data in certain circumstances

  • Portability — receive certain data in a structured, machine-readable format (you can also export your CV/profile as a PDF)

  • Objection — object to processing based on our legitimate interests, including profiling, and to direct marketing

  • Withdraw consent — at any time, where we rely on consent (for example analytics cookies or marketing)

  • Lodge a complaint — with a data-protection supervisory authority

To exercise your rights, contact us at >>> FILL IN: privacy contact e-mail <<<. We will respond within one month, as required by the GDPR, and may extend this by two further months for complex requests. We may need to verify your identity before acting on a request.

You also have the right to complain to your local supervisory authority. The authority in our place of establishment is the Bulgarian Commission for Personal Data Protection (CPDP); if you are in another EEA country, you may contact your national authority. >>> FILL IN: confirm lead supervisory authority once incorporation is finalised <<<

9. Automated decision-making and AI

We do not currently make decisions that produce legal or similarly significant effects about you based solely on automated processing. Matching and recommendation features may rank or suggest content, but they do not, by themselves, make binding decisions about you.

If we introduce AI-assisted interviews or similar automated tools in future, we will provide clear information beforehand, identify the logic involved, offer the ability to request human review and to contest a decision, and comply with GDPR Article 22 and applicable AI-transparency rules.

10. How we protect your data

We implement technical and organisational measures appropriate to the risk, including:

  • Encryption of data in transit (HTTPS/TLS) and encryption of chat-message content at rest

  • Storing passwords only as salted cryptographic hashes (bcrypt)

  • Access controls, role-based permissions and session management

  • Security and audit logging, and monitoring for abuse

  • Use of reputable infrastructure and service providers

No method of transmission or storage is completely secure. You are responsible for keeping your login credentials confidential. If we become aware of a personal-data breach that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours where required, and affected users where the law requires it.

11. Children and age

The Platform is intended for, and restricted to, users aged 18 and over. We do not target the Platform at children and do not knowingly allow them to register. During registration you are clearly informed that by continuing you confirm you are at least 18 years old, and the Platform does not allow a date of birth indicating an age under 18 to be saved to a profile.

Minimum ages for using online services and for valid consent to the processing of personal data differ from country to country. For example, the GDPR sets the age of digital consent at 16, and individual EEA countries may lower it to as low as 13; other countries set different thresholds. It is your responsibility — and, for anyone below the age of majority or the applicable age of digital consent in their country, the responsibility of their parent or legal guardian — to ensure that using the Platform and providing personal data is permitted and properly authorised under the laws that apply to you.

If, despite these measures, a person under 18 accesses the Platform (for example by providing false information), they must stop using it immediately. By using the Platform or providing personal data, you confirm that you meet the applicable minimum age of 18.

We do not knowingly collect personal data from a child below the applicable age of digital consent without the consent of a parent or guardian. If we become aware that we hold such data without the consent required by law, we will delete it without undue delay. If you are a parent or guardian and believe a child has provided us with personal data, please contact us at >>> FILL IN: privacy contact e-mail <<< and we will take steps to delete it.

To the maximum extent permitted by applicable law, we are not responsible for personal data provided by a user who has misrepresented their age in order to bypass these measures. Nothing in this Policy removes or limits protections that the law grants to children and that cannot be waived.

12. Third-party links and services

The Platform may contain links to, or integrations with, third-party websites and services (for example external project links, social profiles, or OAuth providers). We are not responsible for the privacy practices or content of those third parties. We encourage you to review their privacy policies.

13. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last Updated" date and, where required, notify you (for example by e-mail or an in-app notice) and, where the law requires, ask for renewed consent. Your continued use of the Platform after an update means you accept the revised Policy.

14. Language and contact

This Policy is provided in several languages. The English version is the controlling version; translations are provided for convenience only.

For any privacy-related question or to exercise your rights, contact us at >>> FILL IN: privacy contact e-mail <<< or by post at >>> FILL IN: registered address <<<.

If any provision of this Policy is found invalid or unenforceable, the remaining provisions continue in full force and effect.