Skip to content
Pegel Jobs

Privacy Policy

Last updated: September 2026.

This policy explains what personal data Pegel processes, why, on what legal basis, and how to exercise your rights.

1. Controller

The controller (Verantwortlicher) for the personal data processed on this site is:

Maj Labs UG (haftungsbeschränkt)
represented by Elie Majorel
Riehlstraße 9
14057 Berlin
Germany

Register court: Amtsgericht Charlottenburg
Registration number: HRB 290131 B

Email: pegel@mail.pegel.berlin

There is no Data Protection Officer (DPO). Pegel does not meet the criteria in Art. 37 GDPR that would require appointing one.

2. What data we process

2.1 When you browse

  • Server logs (Cloudflare automatic): your IP address, request URL, user agent, timestamp. Cloudflare does not publish a fixed retention period for these logs; they are deleted when the documented processing purposes expire. Lawful basis: Art. 6(1)(f) GDPR (legitimate interest in security and debugging).
  • Cloudflare Web Analytics: aggregate page-view counts and approximate region. Cookieless: no cookies, no client-side state, no device fingerprinting. Kept six months. Lawful basis: Art. 6(1)(f) GDPR (legitimate interest in measuring service usage).

Pegel also records aggregate filtered-search actions. The counter shows reported filter actions from updated web and mobile clients. The server assigns the Europe/Berlin day and Upstash keeps the combined daily integer for seven days. Older app versions do not contribute to this count.

Each reported action has a fresh random event ID and creation time. Upstash retains the event ID for ten minutes to suppress duplicate deliveries. The ID belongs to one action, not a visitor or device. The creation time is checked but not stored in the counter. The web reports filter clicks and changed search submissions, not page loads or reloads. A reported action does not prove that results finished loading.

The counter does not retain search terms, selected filters, IP addresses, visitor identifiers, device identifiers, or a platform breakdown. No analytics cookie or persistent browser identifier is added. Recording is best-effort and coverage is partial. It is not a unique-user measure or verified human usage. It is not joined with Cloudflare Web Analytics, subscriptions, push registrations, or App Store data. Earlier unverified totals remain separate until their existing retention expires.

2.2 When you subscribe to the email digest

When you subscribe to the email digest, the form collects:

  • Your email address (required)
  • Your filter preferences (the URL parameters at the moment you subscribed)
  • Confirmation and last-sent timestamps. A reserved last-clicked field is not written; email click tracking is disabled.
  • A confirmation token
  • Unsubscribe and manage tokens

Lawful basis: Art. 6(1)(a) GDPR (explicit consent). Consent is given by submitting the subscription form and confirming via the confirmation email (double opt-in).

Retention: until you unsubscribe or your subscription expires, plus 30 days for audit. Unconfirmed subscriptions deleted after 7 days. Each subscription runs for 6 months from the day you confirm; after that it expires and we stop emailing you. The 6-month limit keeps the list to people who still want it, which protects deliverability and your inbox. Re-subscribe at any time to start a new 6-month window.

Pegel also keeps daily aggregate counts for three alert milestones: a valid subscription start, confirmation, and the first digest accepted for sending by Resend. Each row contains only the UTC date, milestone name, total count, and update time. It has no email, subscriber ID, filter, IP address, browser data, or visitor identifier. These aggregate counters are not linked to Cloudflare page views.

2.3 When you create a mobile job alert

The Pegel iPhone and Android apps do not require an account. If you create a job alert and allow notifications, the app sends:

  • An Apple Push Notification service (APNs) device token on iPhone, or a Firebase installation ID (FID) registered with Firebase Cloud Messaging (FCM) on Android. Each is a pseudonymous identifier for this app installation.
  • Your selected search term and job filters
  • Whether the alert is enabled

Pegel records creation and last-update timestamps on the server. On Android, Firebase also processes the app version and basic technical metadata in its Firebase user agent to operate the messaging service.

The server encrypts each APNs token or registered FID with AES-256-GCM and stores a provider-scoped keyed hash for deduplication. Each alert receives a random update-and-delete capability. The capability stays in the iPhone Keychain or is encrypted with Android Keystore; the server stores only its SHA-256 hash. Alert names and saved jobs stay on the device and are not uploaded. Salary-calculator inputs also stay on Android and are not uploaded.

Lawful basis: Art. 6(1)(a) GDPR (consent). You initiate the alert, and the operating system separately asks for notification permission. Browsing and saving jobs remain available if you decline.

Retention: until you delete the alert, the push provider reports that the registration identifier is invalid, or the installation has not synced for 180 days. A deletion attempted while offline stays pending on the device and is retried. Notification delivery records are deleted after 30 days. Pegel gives each job notification a six-hour expiry so a time-sensitive alert is not delivered much later.

The notification sent through APNs or FCM contains the public job title, company name, optional job location text, an opaque job identifier, and a Pegel URL. Pegel does not request or send your device location, contacts, name, email address, or advertising identifier for mobile alerts.

2.4 When you submit a form

The "Suggest a company" form (also used to request a company's removal) collects:

  • The form content (company name, website, optional ATS hints, your reason)
  • Your email address if you provided one

No IP address is stored with a submission; abuse is filtered by a honeypot field instead.

Lawful basis: Art. 6(1)(f) GDPR (legitimate interest in curating the company list and maintaining listing quality).

Retention: 90 days, then deleted.

There is no "Report this listing" form. To flag a listing, email pegel@mail.pegel.berlin.

2.5 When you send a partnership inquiry

The partnerships form collects:

  • Your name
  • Your work email address
  • Your company name, if you provide it
  • Your message

The inquiry is delivered to the operator's mailbox (via Resend) and is not stored in the application database. No IP address is stored with a submission; abuse is filtered by a honeypot field and a rate limit that keeps only a short-lived hash.

Lawful basis: Art. 6(1)(f) GDPR (legitimate interest in responding to business inquiries). Where a conversation turns into pre-contractual steps, Art. 6(1)(b) GDPR applies.

Retention: 12 months from the last message of the conversation, then deleted from the mailbox.

2.6 When you email us

When you send email to pegel@mail.pegel.berlin, we store your email address and the content of the message. Lawful basis: Art. 6(1)(f) (legitimate interest in responding to requests).

Retention: 12 months from last reply.

2.6 What we don't collect

  • No cookies for tracking
  • No third-party analytics services (no Google Analytics, no Plausible-as-third-party)
  • No advertising data, no retargeting
  • No profile data beyond what's listed above
  • No special-category data (Art. 9 GDPR: health, ethnicity, sexual orientation, political views, religion, biometric, etc.)
  • No cross-site tracking

3. Sub-processors

The following third-party services process personal data on our behalf, under data processing agreements (Auftragsverarbeitungsverträge) or Standard Contractual Clauses as applicable:

Sub-processorPurposeLocation
Cloudflare Inc.Web hosting, CDN, and Web AnalyticsUS (EU-US Data Privacy Framework certification; EU Standard Contractual Clauses as fallback); compute on Cloudflare's global edge network
Supabase Inc.Postgres database; Auth (admin only)EU (Frankfurt)
Upstash Inc. (via Vercel Marketplace)Redis cache, rate limiting, scheduled job triggers (QStash; fires internal cron endpoints, no subscriber data), and short-lived daily aggregate measurementEU
Resend Inc.Transactional email delivery (digest and admin emails)EU (Ireland)
Apple Inc.Apple Push Notification service for iPhone alertsGlobal infrastructure, including the US; Apple's applicable contractual transfer safeguards apply
Google LLC (Firebase)Firebase Cloud Messaging for Android alerts; processes the registered Firebase installation ID, app version, basic device and app metadata, and the public notification payloadGlobal infrastructure, including the US; Firebase Data Processing and Security Terms and applicable transfer safeguards apply
Third-party AI classifier providerAI classification: reads public job-description text to classify the German-language requirement and other structured fields. Receives only public job-description content, no subscriber data.US (EU Standard Contractual Clauses); the specific provider, recipient analysis, and supplementary measures are documented in our Transfer Impact Assessment, available on request

When new sub-processors are added (for example a future comment-moderation service), this table will be updated and the change will appear in the changelog.

4. International transfers

Cloudflare, Apple, Google, and the AI classifier provider may process data outside the EU. Applicable contractual transfer safeguards apply. Google's Firebase terms provide a data-transfer solution or Standard Contractual Clauses for restricted European transfers. The classifier transfer relies on EU Standard Contractual Clauses plus supplementary measures documented in our Transfer Impact Assessment (Schrems II). The classifier receives only public job description content (no subscriber data, no user-identifying information), which limits the exposure even further: the content is already public on the source employer's careers page. It is a direct inference provider, so there is no intermediary routing gateway in the recipient chain.

5. Your rights

Under GDPR, you have the right to:

  • Access (Art. 15): request a copy of the data we hold about you
  • Rectification (Art. 16): correct inaccurate data
  • Erasure (Art. 17): request deletion ("right to be forgotten")
  • Restriction (Art. 18): pause processing
  • Portability (Art. 20): receive your data in machine-readable format
  • Object (Art. 21): object to processing on a legitimate-interest basis
  • Withdraw consent (Art. 7): for the email digest subscription specifically
  • Complain to a supervisory authority (Art. 77)

To exercise any of these rights, email pegel@mail.pegel.berlin. We respond within 30 days. The first request per year is free.

For email digest subscribers specifically: every digest contains a one-click unsubscribe link (consent withdrawal) and a manage link (rectification, restriction).

For mobile alerts: you can disable or delete each alert in the app. Deleting an alert withdraws consent and removes its server record. If the device is offline, the app retries the deletion later. Because the service has no account and Pegel does not know your identity, the capability stored on your device is what authorizes changes and deletion.

6. Supervisory authority

You may file a complaint about how we process your personal data with the Berlin data protection supervisory authority:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61
10555 Berlin
mailbox@datenschutz-berlin.de
+49 30 13889-0

7. Cookies

The site uses no cookies for tracking or advertising. The only cookies set are technical: an admin session cookie on /admin/* routes (for authentication, which only applies to the site operator), and Next.js framework cookies for routing. Both are strictly necessary and exempt from consent requirements under § 25(2)(2) TTDSG.

8. AI-generated content

Pegel uses classifiers to extract structured fields from job descriptions. Five run in production: the German-language requirement, visa sponsorship, disclosed salary, tech-stack tags, and remote mode. Heuristics decide first. A scheduled AI model fills some language results that the heuristic cannot decide, while low-confidence results stay empty rather than becoming guesses. A one-line summary classifier is built but stays off. Pegel also has a deferred plan for a short observation block under job listings.

The EU AI Act Article 50 rules have applied since 2 August 2026. The European Commission's final guidance treats extracted structured data, single words, and UI labels as outside the synthetic-content marking duty. Pegel's live classifier labels fit that description. Pegel has no AI chat, emotion recognition, or biometric categorisation.

Generated summaries and observation blocks are different because they create prose. Neither is active. I will not activate one until its accuracy review and the applicable machine-readable marking and visible disclosure controls are verified. Any observation block will also carry "Generated by Pegel from the job posting" inline.

Subscriber data and email content are never sent to AI services. Only public job-description content from employer hiring feeds is sent to the scheduled classification service.

9. Photo takedown

Company pages show a company logo and no other imagery. If any image on Pegel shows you and you want it removed, email pegel@mail.pegel.berlin. We honor removal requests within 7 days, no questions asked.

There is no photo submission flow; logos come from the company's public web presence or are curated by hand.

10. Security

We use HTTPS, encrypted storage at sub-processors, 2FA on administrative accounts, encrypted APNs tokens and FCM installation IDs, Keychain or Android Keystore protection for mobile capabilities, and constant-time secret comparison. Vulnerability disclosure: see Security.

If a data breach occurs that risks your rights and freedoms, we will notify the Berlin supervisory authority within 72 hours as required by Art. 33 GDPR. We will also notify affected users directly when feasible.

11. Changes to this policy

We update this policy when our processing changes, when sub-processors change, or when law changes. Material changes are recorded in the changelog.