Legal

GDPR Compliance

Last updated: May 1, 2025  ·  Applies globally with regional supplements

01 Our Commitment to Global Data Protection

InstantJob is operated by YAZAR.DEV under Estonian jurisdiction and is subject to the GDPR. We treat data protection as a core product principle, not a compliance checkbox. Privacy by design is built into every feature of InstantJob.

While this page focuses on GDPR, our data practices meet or exceed the requirements of CCPA, PIPEDA, Australia's Privacy Act, and KVKK. See our Privacy Policy for regional-specific rights.

02 Data Controller

  • Company: YAZAR.DEV (registration pending — Estonia)
  • DPO Contact: dpo@instantjob.app
  • Privacy Contact: privacy@instantjob.app

03 Legal Bases for Processing (Art. 6 GDPR)

  • Consent (6(1)(a)): Location sharing, marketing, non-essential cookies — withdraw anytime
  • Contract (6(1)(b)): Account, matching, payments — necessary to deliver the service
  • Legal obligation (6(1)(c)): Financial record retention (7 years, Estonian Accounting Act)
  • Legitimate interests (6(1)(f)): Fraud detection, security, platform integrity

04 Your GDPR Rights and How to Exercise Them

  • Access (Art. 15): Request full data export — privacy@instantjob.app
  • Rectification (Art. 16): Update in account settings or contact us
  • Erasure (Art. 17): Delete account in settings — data removed within 30 days
  • Portability (Art. 20): Receive data in JSON format on request
  • Restriction (Art. 18): Request limited processing during disputes
  • Objection (Art. 21): Object to legitimate interest processing
  • Withdraw consent (Art. 7(3)): Via account settings — effective immediately

We respond within 30 days. No fee unless requests are manifestly unfounded or excessive.

05 Privacy by Design Measures

  • Location opt-in: GPS disabled by default — you must explicitly enable map visibility
  • Minimal collection: Only data strictly necessary for platform operation
  • Encryption: TLS 1.3 in transit, AES-256 at rest
  • Access controls: Role-based access with audit logging
  • Pseudonymization: Analytics and Government API data anonymized before processing

06 Government API — Data Sovereignty

  • All API data is fully anonymized and aggregated — individuals cannot be identified
  • Each government sees only their own country's data — complete tenant isolation
  • No cross-country data sharing — ever
  • Private companies cannot access this API at any price
  • All government agreements include Standard Contractual Clauses

The Government API does not process personal data under GDPR. All datasets are statistical aggregates with no possibility of re-identification.

07 Data Breach Procedures

  • Notify Estonian AKI within 72 hours for breaches posing risk to individuals
  • Notify affected users without undue delay for high-risk breaches
  • Internal breach register maintained regardless of notification obligations

Report suspected vulnerabilities: security@instantjob.app

08 Supervisory Authorities

  • 🇪🇪 Estonia (Lead SA): Andmekaitse Inspektsioon — aki.ee
  • 🇺🇸 USA: FTC / California AG — oag.ca.gov
  • 🇦🇺 Australia: OAIC — oaic.gov.au
  • 🇨🇦 Canada: OPC — priv.gc.ca
  • 🇹🇷 Türkiye: KVKK Kurumu — kvkk.gov.tr

Questions about this policy?

YAZAR.DEV — Operating company of InstantJob

General: legal@instantjob.app

Privacy / Data: privacy@instantjob.app

Security: security@instantjob.app

Website: instantjob.app