> CTOjobs.co
← Job board
privacy_policysite_termsrecruiting_terms
trust/privacy

Privacy policy

How we collect, use, share and protect personal data across job alerts, employer submissions and candidate introductions.

Effective 1 September 2026Version 1.0

1. Who is responsible for your data

TOPUS SOFTWARE SL is the data controller for CTOjobs.co. Our tax identification number is B13660576 and our registered address is Carrer de la Creu Roja, 26, L'Hospitalet de Llobregat, Barcelona, Spain. You can contact us about privacy or exercise your rights at hello@ctojobs.co.

2. Personal data we collect

  • Job alerts: email address, role and location preferences, subscription status and consent records.
  • Candidate introductions: name, contact details, CV or professional profile, work history, preferences, compensation expectations, communications and employer-specific sharing choices.
  • Employer submissions: business contact details, company and vacancy information, hiring requirements, order-form details and correspondence.
  • Site and security data: request, device, browser, approximate location derived from IP address, error and security records where generated by our infrastructure.
  • Messages: the content of enquiries and any information a person chooses to provide.

Please do not send special-category data, government identifiers or other information that is not necessary for the relevant hiring process.

3. Why we use data and our legal bases

ActivityPurposeLegal basis
Job alertsSend requested alerts and manage preferences or unsubscribe requestsConsent
Candidate introductionsAssess a request, identify relevant opportunities and coordinate an authorised introductionConsent and steps requested before providing the service
Employer submissionsVerify and publish roles, manage the recruiting relationship and administer an order formContract, pre-contract steps and legitimate interests
Site operationsDeliver, secure, debug and improve CTOjobs.co; prevent fraud and misuseLegitimate interests
Business recordsAccounting, compliance, disputes and enforcementLegal obligation and legitimate interests

Where we rely on consent, it can be withdrawn at any time without affecting processing that was lawful before withdrawal. Where we rely on legitimate interests, we balance those interests against the person's rights and reasonable expectations.

4. Candidate control and introductions

Subscribing to alerts does not authorise candidate representation. Requesting an introduction does not permit open-ended sharing. Before sending identifiable candidate information to an employer, we identify that employer and opportunity and obtain the candidate's specific permission.

A candidate can decline an introduction or withdraw permission before sharing without losing access to public listings. After data has been shared, the employer acts as an independent controller for its hiring process and may retain information where it has its own lawful basis. We will pass on a withdrawal or deletion request where appropriate, but cannot erase records controlled independently by another organisation.

5. Where data comes from

Most personal data comes directly from the candidate, subscriber, employer or authorised representative. We may also use professional information made public by the individual, referrals made with authority, and vacancy information supplied by employers or obtained from public job sources. When data comes from another source, we provide any notice required by law.

6. Who receives data

  • Employers receive candidate information only for an identified opportunity and with candidate permission.
  • Candidates may receive employer and vacancy information needed to evaluate an opportunity.
  • Service providers may process limited data for hosting, email delivery, security, analytics, storage, communications, accounting or professional support under contractual confidentiality and data-protection obligations.
  • Authorities, advisers or counterparties may receive data where required by law, needed to protect rights and safety, or necessary for a corporate transaction subject to appropriate safeguards.

We do not sell personal data or share candidate profiles with employers for unrelated roles without a separate lawful basis.

7. International transfers

Some service providers may process data outside the European Economic Area. Where that happens, we use a lawful transfer mechanism, such as an adequacy decision or the European Commission's standard contractual clauses, together with supplementary safeguards where required. Details of the relevant safeguard are available on request.

8. How long we keep data

  • Job-alert data is kept while the subscription is active and removed after unsubscribe or 24 months without meaningful activity. A minimal suppression and consent record may be kept for three years.
  • Candidate introduction files are kept during the active process and for up to 24 months after the last substantive interaction, unless the candidate asks for earlier deletion or separately agrees to a longer talent-pool relationship.
  • Employer leads and unpublished submissions are kept for up to 24 months after the last substantive contact.
  • Order forms, invoices and records needed for accounting, contractual claims or legal compliance are kept for six years, or longer where a specific legal hold applies.
  • Routine security and request logs are kept for up to 12 months unless an incident requires longer preservation.

At the end of the relevant period, data is deleted, anonymised or restricted so that it is used only for the remaining legal purpose.

9. Your data-protection rights

Subject to applicable law, a person may request access, correction, deletion, restriction or portability of personal data; object to processing based on legitimate interests; and withdraw consent at any time. Send a request to hello@ctojobs.co. We may request proportionate information to verify identity and normally respond within one month.

You may also complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority. CTOjobs.co does not make solely automated decisions that produce legal or similarly significant effects.

10. Security, local storage and children

We use technical and organisational measures appropriate to the risk, including access controls, restricted sharing and service-provider review. No online service can guarantee absolute security.

CTOjobs.co currently uses browser local storage to remember the selected visual theme. If optional analytics or cookie-based features are introduced, we will provide any consent controls required by law before using them. The service is intended for adults acting in a professional context and is not directed to children.

11. Changes to this policy

We may update this policy to reflect changes to the service or law. The effective date and version at the top identify the current policy. Material changes will be communicated through the site or directly where required.

CTOjobs.co © 2026
privacysite_termsrecruiting_terms
hello@ctojobs.co