Privacy Policy

1. Introduction

This Privacy Policy explains how personal data is collected, used, stored, and shared when you use the EmploRef Telegram bot (“EmploRef” or the “Bot”).

EmploRef connects Candidates seeking employee referrals with Referrers who work at the relevant companies and are willing to review Candidates for a potential referral.

For the purposes of the General Data Protection Regulation (“GDPR”), the data controller responsible for the processing of personal data by EmploRef is:

Mark Bulgakov
Germany
Email: [email protected]

EmploRef operates through Telegram. Telegram processes certain information relating to your Telegram account and your use of Telegram independently in accordance with its own privacy policy.

EmploRef processes personal data only where there is a legal basis for doing so.

2.1. Providing EmploRef

Personal data necessary to provide the functionality requested by you is processed under Article 6(1)(b) GDPR, where processing is necessary to provide the Service at your request.

For Candidates, this includes processing the selected company, professional area, CV, Telegram account information necessary to operate the Bot, and the Candidate request itself in order to create the request, identify suitable Referrers, and allow Referrers to review it.

For Referrers, this includes processing the selected company, professional area, corporate email address, Telegram account information necessary to operate the Bot, and responses to Candidate requests in order to verify the Referrer, identify relevant Candidates, and operate the referral workflow.

2.2. Security and Prevention of Abuse

Where necessary, personal data may also be processed under Article 6(1)(f) GDPR for the legitimate interests of protecting EmploRef and its users, preventing spam, fraud and abuse, maintaining the security and reliability of the Service, and investigating technical or security incidents.

When relying on legitimate interests, EmploRef considers whether those interests are overridden by the rights and freedoms of affected users.

3. Personal Data We Process

3.1. Telegram Data

When you interact with the Bot, EmploRef may receive information made available through Telegram, including:

This information is used to identify you within EmploRef and provide the Bot’s functionality.

3.2. Candidate Data

If you use EmploRef as a Candidate, we process:

A CV is required to submit a Candidate request. Without providing a CV, you cannot create a Candidate request through EmploRef.

Your CV may contain additional personal data that you choose to provide, such as your name, contact details, employment history, education, qualifications, and skills.

You should not include personal data in your CV that is unnecessary for the referral process.

3.3. Referrer Data

If you use EmploRef as a Referrer, we process:

A verified corporate email address is required to receive Candidates through EmploRef.

A verification code is sent to the corporate email address provided by the Referrer. After successful verification, EmploRef checks whether the email domain corresponds to the company selected by the Referrer.

Without providing and verifying a corporate email address, you cannot use the Candidate review functionality as a Referrer.

3.4. Matching

EmploRef automatically uses the company and professional area selected by users to identify suitable Referrers for Candidate requests.

Matching is based on the company, with priority given to Referrers whose professional area matches that of the Candidate. If several suitable Referrers are available, the request may be presented to them sequentially.

The matching process does not itself determine whether a Candidate will receive a referral. The decision to accept or reject a Candidate is made by a Referrer.

4. Storage, Retention and Security

EmploRef takes appropriate technical and organizational measures designed to protect personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction.

Personal data is retained only for as long as necessary for the purposes described in this Privacy Policy and, where applicable, for the establishment, exercise, or defense of legal claims or compliance with legal obligations.

The retention period depends on the category of data and the purpose for which it is processed. Where possible, specific retention periods will be established based on the period during which the relevant account, verification, or referral request remains necessary for operation of the Service.

When personal data is no longer required for the relevant purpose and there is no legal basis requiring or permitting its continued retention, it will be deleted or anonymized.

5. Sharing and Recipients of Personal Data

5.1. Candidate Data Shared with Referrers

The core functionality of EmploRef requires Candidate information to be disclosed to Referrers.

When a Candidate request is presented to a suitable Referrer, the Referrer receives the Candidate and their CV for the purpose of deciding whether to make a referral.

If a Referrer rejects the Candidate, the request may be presented to another suitable Referrer. If a Referrer accepts the Candidate, EmploRef informs the Candidate that a Referrer willing to make a referral has been found.

Candidates should therefore understand that submitting a referral request necessarily involves disclosure of their CV to selected Referrers.

If, after accepting a Candidate, a Referrer submits Candidate information to an employer’s internal referral or recruitment system, additional processing may occur outside EmploRef. Such processing may be subject to the privacy practices of the relevant employer or recruitment provider.

5.2. Technical Service Providers

Personal data may be processed by third-party technical service providers where this is necessary to operate EmploRef, for example providers used to host or deliver components of the Service.

Where a provider processes personal data on behalf of EmploRef, appropriate data-protection arrangements will be used where required by applicable law.

Information about applicable international transfers and safeguards will be provided where EmploRef’s use of a service provider results in a transfer of personal data outside the European Economic Area that is subject to the GDPR’s international-transfer requirements.

Personal data may also be disclosed where required by law or where necessary for the establishment, exercise, or defense of legal claims.

6. Your Data Protection Rights

Subject to the conditions provided by applicable law, you may have the right to:

These rights and the requirement to inform users about them are addressed by Articles 13 and 15–21 GDPR.

To exercise your rights, request deletion of your EmploRef data, or ask a privacy-related question, contact:

Mark Bulgakov
Email: [email protected]

Additional information may be requested where reasonably necessary to verify the identity of the person making a request.

A request to delete data from EmploRef does not by itself delete personal data that has already been independently submitted to or processed by a third party, such as an employer’s recruitment system.

7. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to EmploRef, its processing of personal data, or applicable legal requirements.

The “Last updated” date at the top of this Privacy Policy indicates when it was last revised.

If changes materially affect how personal data is collected, used, stored, or shared, affected users will be informed through the Bot or another appropriate communication method. Where appropriate, such notice will be provided before the relevant change takes effect.

Changes that introduce a new purpose for processing personal data will be communicated before personal data is processed for that new purpose, as required by applicable law.

Minor changes that do not materially affect the processing of personal data, such as corrections of typographical or grammatical errors, may be made without individual notification.

This distinction follows the EDPB transparency guidance: material changes such as a new processing purpose, a change of controller, or a change in how rights are exercised should be actively communicated, while purely stylistic or grammatical corrections need not be. The guidance also says that telling users merely to check the policy periodically is insufficient for material changes.