Privacy policy
Last updated: 8 September 2026 · Version 2026-09-08
This notice explains, in plain language, how Farol uses your account, CV, profile, preferences, and match activity. It applies when TODO legal company or sole-trader name acts as controller.
Controller and contact
TODO legal company or sole-trader name, TODO full geographic address, tax id TODO Portuguese NIF/NIPC, registration TODO commercial register and number, or Not applicable, is the controller for Farol. Privacy questions and rights requests: privacy@faroljobs.com. General contact: hello@faroljobs.com.
Data we collect
Account and security data: email address, password hash, language, login IP address, browser or device details, and timestamps. Candidate data: your uploaded CV and its extracted text, anything you write about yourself, a photograph if you choose to add one, name, work history, education, skills, certifications, languages, approximate location, work eligibility, preferences, and the contact details you give us for a tailored CV (email, phone, links, and — only for the European format, and only if you choose to give them — date of birth and nationality). Service data: generated matches, explanations, email preferences, and your feedback. Billing data is added only if you buy a paid plan; complete card details stay with the payment provider shown at checkout.
Some fields are optional. Without an email and a minimum candidate profile we cannot create the account or provide matching. Uploading a CV is optional because you can complete the profile manually.
Purposes and legal bases
Contract necessity (GDPR Article 6(1)(b)): create and administer your account; store the ordinary data in your CV or manual profile; extract a reviewable profile; compare it with job postings; show and email the shortlist you requested; provide exports, support, and paid features.
Legitimate interests (Article 6(1)(f)): secure and troubleshoot Farol, prevent abuse, keep minimal technical logs, and understand service reliability. We balance these interests against your rights. Legal obligation (Article 6(1)(c)): tax, accounting, regulatory, and lawful authority requests. Consent (Article 6(1)(a)): optional marketing or optional device storage if introduced; you may withdraw it at any time.
Your CV, sensitive data, and AI
When you upload a CV, Farol extracts its text and sends that text to Anthropic's commercial API to turn it into structured candidate fields. You see and can correct those fields. Anthropic states that commercial API inputs and outputs are not used to train its models by default and are normally deleted from its backend within 30 days, subject to limited safety or legal exceptions.
Please remove special-category data—such as ethnicity, politics, religion, trade-union membership, genetics, biometrics used for identification, health, sex life, or sexual orientation. Farol instructs the extraction system not to extract or infer it and does not use it to rank jobs. If any remains in the file, we rely on the explicit, limited consent you give at upload under GDPR Article 9(2)(a). You can avoid this processing by entering your profile manually and can withdraw consent by deleting the CV; this does not affect processing already carried out lawfully.
Automated matching
Farol automatically compares profile facts and preferences with job-posting requirements and produces a score and plain-language reasons. This decides only what Farol recommends to you. It does not apply for you, share your CV, or make an employer's hiring decision, and therefore is not intended to produce a legal or similarly significant effect. You can correct your profile, change preferences, ignore any result, and contact us for an explanation.
Processors, recipients, and transfers
Farol uses Hetzner Online GmbH and Cloudflare, Inc. (backup storage) for hosting in EU (Falkenstein, Germany), Anthropic for CV extraction and matching assistance, and Resend for transactional email. Stripe runs the checkout page and processes payments; card and MB WAY details go to Stripe and never to Farol. These providers process data under contract and only for the service. We may also disclose the minimum required by law or to professional advisers bound by confidentiality. We never sell personal data and never send your CV to employers.
Where a provider processes data outside the EEA, Farol uses an applicable adequacy decision or the European Commission's Standard Contractual Clauses and assesses supplementary safeguards. Ask privacy@faroljobs.com for information about the relevant safeguard or a copy with confidential terms removed.
Retention and deletion
Account, profile, preferences, CV, extracted CV text, and personalised matches are kept while your active account needs them. You can delete the original CV and extracted text at any time; the profile you already reviewed remains until you edit or delete it. Account deletion removes the CV, photograph, profile, preferences, sessions, email, and personalised match explanations from active systems immediately. Anonymous match and feedback statistics may remain because they no longer identify you.
Anthropic's standard API retention is up to 30 days. Login sessions expire after 30 days. Security logs are normally kept up to 30 days and may be isolated longer when needed to investigate an incident or comply with law. Deleted data may remain in encrypted, access-restricted backups for up to 30 days. Tax and invoice records are retained for the Portuguese legal period, normally 10 years.
Your rights
You may request access, correction, erasure, restriction, and portability, and object to legitimate-interest processing. Where processing relies on consent, you may withdraw it at any time. Use the account export and deletion controls or write to privacy@faroljobs.com. We normally respond within one month; complex requests may take up to two additional months after notice. We may need proportionate identity verification.
You may complain to the Comissão Nacional de Proteção de Dados (CNPD) at cnpd.pt or to the supervisory authority where you live or work.
Security, children, and changes
We use access controls, password hashing, TLS in production, restricted processor access, and data minimisation. No online service is risk-free; if a breach is likely to risk your rights, we will follow GDPR notification duties.
Farol is for people aged 16 or over. A user under 18 should involve a parent or legal representative before buying a plan. We will post material policy changes here and, when they significantly affect existing processing, notify account holders by email or in the product.