Nobl.ai

Website Privacy Policy

This document summarizes how the EU General Data Protection Regulation (GDPR) applies to the data Nobl.ai handles regarding our website. It also describes how and under which conditions we collect, use, store and share personal information. This document applies exclusively to the data we collect and manage from our website, where we act as a data controller. You can find the privacy policy that applies to our SaaS services, where we act as a data processor, here: Services Privacy Policy. Our commitment to data security can be found in our Security Policy.

What GDPR is

The GDPR (Regulation EU 2016/679, in force since 25 May 2018) is the European law that protects people’s personal data. It gives individuals rights over their data and sets clear obligations for the organisations that handle it. Nobl.ai has been built around these rules from the start.

We take your privacy seriously

Nobl.ai (Nobl.ai BV, Ghent, Belgium) provides AI software (candidate–vacancy matching, ESCO occupation tagging, CV parsing, career guidance and related agents) as a service to HR customers such as job boards, staffing agencies and public employment services. When you use our website to explore our products, request demos or use our self-service solutions, we may collect personal data. This data is treated according to the highest standards of data privacy and security, in full compliance with the GDPR.

Our role: we are a data controller

Nobl.ai handles personal data from the nobl.ai website, including for the creation of accounts and subscription to our self-service ESCO tagger. For the website and these accounts, Nobl.ai is the data controller. The processing of the (vacancy) data you submit into the ESCO tagger itself is covered by our Services Privacy Policy; in short, we process it to predict the best-matching ESCO occupation codes and then delete it. We do not retain the plain (job vacancy) text you upload to our tagger.

What we collect, and how

  • Information you give us. When you use our contact form to get in touch or request a demo, we collect your name, email, company and any message you send.
  • Account data. If you create an account to use our ESCO tagger, we collect your name, email, a password (stored securely, never in plain text) and your organisation. The ESCO tagger has a free tier and paid subscription tiers.
  • Subscription & payment data. If you select any plan, we keep a record of the selection, number of queries used, your invoices and payment status. Card payments are handled by Stripe, which processes your card details on our behalf; we do not store your credit card information ourselves.
  • Information collected automatically. Standard technical and usage data such as IP address, approximate location, browser/device type, pages viewed and referring page. We use Google Analytics to understand how the site is used.

Cookies

Essential cookies are always on, including the session/login cookies needed to keep you signed in to your account; non-essential cookies (including Google Analytics) only load after you consent. You can change your choice at any time via “Cookie settings”. See our Cookie Policy for the full list.

How we use it

  • To respond to your enquiries and provide the information or demo you asked for.
  • To create and manage your account, provide the ESCO tagger service, handle your subscription and process payments.
  • To run, secure and improve the website (including filtering spam submissions).
  • To send account and service messages (e.g. billing, security and account notices).
  • With your consent, to measure and improve our content.

Legal bases (GDPR): performing our contract with you (account, subscription and payments), a legal obligation (keeping invoices and accounting records), your consent (for analytics cookies), our legitimate interest (running and securing the site), and taking steps at your request (answering enquiries).

How long we keep it

We keep enquiry and contact data only as long as needed to handle your request. We keep account data while your account is active, and billing and invoice records for as long as tax and accounting law requires. Analytics data is retained according to our provider’s settings. We delete or anonymise data when it is no longer needed.

When we share it

We do not sell your data. We share it only with service providers (processors) that help us run the website, under agreements requiring appropriate protection:

  • Amazon Web Services (AWS): hosting, in our own protected AWS environment (EU region);
  • SendLayer: delivery of emails such as contact-form submissions and account/service messages;
  • Stripe: payment processing for paid subscriptions;
  • Google: reCAPTCHA (to protect our contact form from spam) and, where you have consented, Google Analytics.

We may also disclose data if legally required, or in the context of a merger/acquisition, with appropriate safeguards.

How we protect it

We apply strong technical and organisational measures such as encryption in transit and at rest, access controls, logging, backups and monitoring. See our Security Policy (security-policy.md) for more details. No system is ever 100% secure, but we work hard to keep data safe and to respond quickly to any incident.

International transfers

The site is hosted on AWS in the EU. Some providers (e.g. Google Analytics, Google reCAPTCHA, our email-delivery provider SendLayer, and Stripe) may process data outside the EEA under appropriate safeguards (such as the EU–US Data Privacy Framework or standard contractual clauses).

Your rights

You can access (including an export of your data), correctdelete/eraserestrictport or object to the processing of your personal data, and withdraw consent at any time. If you have an account, you can view and update much of this directly in your account settings. This does not cover data we must keep for administrative, legal or security reasons (such as invoices). To exercise these rights, contact dpo@nobl.ai. Complaints can also be lodged with your national data protection authority.

Changes & contact

We may update this policy as our website or the law evolves; material changes will be made clear. Questions or requests: Data Protection Officer, Alex Mara (dpo@nobl.ai).

Scroll to Top