Privacy Policy
Vokaro · Last updated: 2026-09-16 · v1.2
1. Controller
The controller for the processing of personal data on Vokaro is: Melvin Wachholz, Cala Ratjada, Illes Balears, España. Email: service@vokaro.es. Privacy requests: service@vokaro.es.
2. Scope
This statement applies to the vokaro.es website, Early Access, Talent Cards, candidate and employer accounts, company profiles, applications, personal placement, messages, interviews, support, job alerts, the company waiting list and internal admin access.
3. Principles
Vokaro is built on privacy by design: purpose limitation, data minimisation, transparency, storage limitation, integrity and confidentiality. Optional sharing settings are switched off by default (privacy by default).
4. Data categories
Depending on use we process: account and authentication data (email, password hash via Supabase Auth, sign-in method), profile data (name, city, phone, date of birth, profile picture), Talent Card content (role, industry, experience, skills, languages, job preferences, availability, mobility, driving licence, vehicle, accommodation needs, NIE or work-permit status, short introduction), application and message data, company data, consents and visibility settings, support requests, and technical log and security data.
5. Registration with email
To create an account we process your email address, name and a password. The password is stored only as a hash at our authentication provider Supabase; Vokaro never sees it in clear text. We send confirmation and password-reset emails. The legal basis is pre-contractual and contractual necessity.
6. Sign-in with Google
If you sign in with Google, Google acts as identity provider. Vokaro receives only the basic account information Google provides with your consent: a unique Google identifier (subject identifier), your email address, your name and, where available, the URL of your Google profile picture. Your Google password is never transmitted to Vokaro. We request no additional Google permissions (no Gmail, Drive, Calendar, Contacts, location or phone number). Google Sign-In is optional; email registration remains available at all times. A Google profile picture is only added to your Talent Card if you explicitly confirm it. The legal basis is performance of the contract (providing account access).
7. Talent Cards and visibility
Your Talent Card is not publicly accessible via search engines; the relevant pages are set to noindex and access is restricted at database level. You always see all of your own data. Vokaro reviews the card internally once you submit it. Contact details, date of birth, phone number and the storage path of your profile picture are held in a separate table readable only by you and authorised Vokaro roles. Employers only see what your visibility settings release. Age, profile picture, placement and direct contact are controlled individually and are off by default. You can change your details or pause your profile at any time.
8. Employers and companies
For company accounts we process company data, team member details, job postings, applicant management, talent unlocks and quotas. Access to applicant and talent data is limited to the respective company and its permissions.
9. Applications
When you apply for a job we transmit the application data you selected to the specific company. This may include your CV, documents, answers to application questions and the application status. The company is itself responsible for further processing within its own remit. You can withdraw an application.
10. Personal placement
Placement by Vokaro is voluntary and only active if you explicitly allow it in your visibility settings. We review your Talent Card internally, match it against open roles and suggest suitable employers. If you have enabled the option “I want to approve before any full share”, no full disclosure takes place without your approval. You can withdraw or pause placement at any time. The legal basis is your consent.
11. Messages and interviews
Messages between talent and companies are stored for delivery, including content, attachments and read status. Interview appointments are stored for scheduling. Vokaro staff only access them where there is a legitimate reason, such as a report, a support case or suspected misuse.
12. File uploads
Profile pictures and documents are stored in private Supabase storage buckets. Access is limited to your own user folder and authorised Vokaro roles; previews are served through time-limited signed links. Profile pictures are re-encoded during cropping, which removes embedded metadata such as GPS data. Replacing an image overwrites the previous file.
13. Emails and Resend
Security and service emails (registration confirmation, password reset, Talent Card status changes) are necessary to perform the contract and cannot be unsubscribed from. Newsletters and marketing emails are only sent with your explicit, separate consent; they are never tied to account registration and can be unsubscribed from at any time. We use Resend (Resend, Inc.) to send transactional email.
14. Company waiting list
Companies can reserve access before launch. We process the company name, contact person, business email, optionally a phone number, industry, location, roles sought, hiring needs, desired start date and a voluntary message. The purpose is to contact the company at launch. The legal basis is pre-contractual steps at the company's request. Marketing consent is collected separately and is never pre-ticked.
15. Service providers and hosting
We use: Vercel Inc. (hosting and delivery of the website), Supabase Inc. (database, authentication and file storage), Resend, Inc. (transactional email) and Google Ireland Limited or Google LLC where you use Google Sign-In or have consented to advertising (Google AdSense, see the “Advertising” section). These providers process personal data on our behalf or – in the case of Google as identity provider – under their own responsibility for the sign-in process. The specific contractual and transfer bases are being documented before the public launch and will be added here.
17. Advertising (Google AdSense)
Vokaro is partly funded by advertisements from the Google AdSense service. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The advertising script is only loaded if you have consented to the “Marketing” category in the cookie notice; without that consent it is not requested. No advertising is shown on pages where you enter or view personal data (sign-in, applications, Talent Card, dashboard, employer area). Once you have consented, Google may store cookies or similar identifiers on your device and process in particular your IP address, browser and device information and the page visited in order to serve ads, measure their performance, prevent fraud and – depending on your settings with Google – personalise ads. Google acts under its own responsibility. The legal basis is your consent (Art. 6(1)(a) GDPR; Art. 22(2) LSSI-CE). Data may be transferred to Google LLC in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision. You can withdraw your consent at any time with effect for the future via “Cookie settings” in the footer. How Google uses data: https://policies.google.com/technologies/partner-sites – Google's privacy policy: https://policies.google.com/privacy – manage personalised advertising: https://myadcenter.google.com
18. Server logs and security
When you visit the site, technical log data such as IP address, timestamp, requested resource and user agent is generated at our hosting and database providers. We also record security-relevant events and admin actions in an audit log. The purpose is secure, stable operation and abuse prevention; the legal basis is our legitimate interest in protecting the service.
19. Internal access
Vokaro uses role-based permissions. Staff only see the data required for their task (need-to-know). Access to moderation, support and placement functions is checked server-side and logged.
20. Retention periods
We keep personal data for as long as it is necessary for the respective purpose and then delete or anonymise it, unless a statutory retention obligation applies. You can request deletion of your account at any time. A detailed breakdown of retention periods per data category is under review and will be added here before the public launch.
21. Recipients
Recipients may be: the specific company you apply to or have released your data to, its authorised team members, authorised Vokaro roles (placement, moderation, support) our technical service providers and – only after you consent to advertising – Google Ireland Limited (see the “Advertising” section). Disclosure to authorities only occurs where legally required.
22. International transfers
Some of the providers used are based outside the EU or process data partly outside the EU. The specific processing region and the applicable transfer safeguards are currently being documented per provider and will be added here before the public launch. We do not claim safeguards that are not contractually agreed.
23. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection. You can withdraw consent at any time with future effect. Many of these rights can be exercised directly in your account: edit details, change visibility, pause your profile, unsubscribe from marketing, and request a data export or account deletion.
24. Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD). Depending on your residence, another supervisory authority may also be competent.
25. Minors
Vokaro is intended for adults. Accounts for minors are not provided for. If we learn that an account has been created contrary to this rule, we will review the case and delete the account where appropriate.
26. Special categories of personal data
Vokaro does not ask for special categories of personal data such as religion, political opinion, trade union membership, sexual orientation, health data, biometric data or ethnic origin. Please do not enter such details in free-text fields either.
27. Changes to this statement
This privacy statement is version 1.2, dated 2026-09-16. We update it when processing changes. For material changes we will also inform you in the application or by email.

