プライバシーポリシー

このポリシーは、BlockJobsが収集する個人データ、その使用方法、共有相手、およびお客様が持つ選択肢について説明します。シンガポールの個人情報保護法(PDPA)の要件を満たすように作成されており、BlockJobsのウェブサイトおよびサービス(以下「本サービス」)のすべてのユーザーに適用されます。

1. Data Protection Officer

BlockJobs has designated a Data Protection Officer (DPO) who is responsible for our compliance with the PDPA and for responding to data-related requests. You can reach the DPO at:

2. What we collect

  • Account info: name, email address, and a hashed password when you sign up.
  • Profile data: avatar, job preferences, experience level, current/expected salary, links, and any other fields you choose to fill in.
  • Resume: the file you upload, stored on Cloudflare R2. We also extract structured fields (headline, work history, education, skills) via AI to populate your profile.
  • Company data (employers): company name, website, industry, size, description, logo, and team members.
  • Job applications: when you apply to a role we record a snapshot of your name, email, headline and resume at the moment of application, plus any cover note you include.
  • Usage: standard server logs (IP address, user agent, timestamp, URL) retained for up to 30 days for security and debugging.

3. Purposes for which we collect, use and disclose data

We only use your personal data for the purposes you would reasonably expect from a job board, namely:

  • Operating your account and authenticating you
  • Showing you relevant job listings and recommendations
  • Letting employers whose roles you apply to view your profile and resume
  • Letting candidates view employer / company profiles
  • Sending account-related emails (verification, password reset, application updates)
  • Improving the Service, including AI-assisted features such as resume parsing and content rewriting
  • Detecting and preventing abuse, fraud, or security issues
  • Complying with applicable law and lawful requests

We do not sell your personal data to third parties, and we do not use it for advertising or unrelated marketing.

4. Consent

By creating an account you consent to the collection, use and disclosure of your personal data for the purposes listed above and as further described in this policy. You may withdraw your consent at any time by deleting your account or by contacting the DPO. If you withdraw consent for a use that is necessary to provide the Service, we may not be able to continue providing the Service.

5. Third parties who process your data on our behalf

We use a small set of third-party service providers (data intermediaries) to operate the Service. Each is bound by their terms to process your data only on our instructions and to apply comparable protections. Your data may be processed in countries outside Singapore, including the United States, the European Union, and China (in DeepSeek's case).

  • Cloudflare (US / global edge) — hosting, the D1 database where your account and profile rows live, the R2 bucket where your resume and uploaded images live, and the Workers AI document conversion used by the resume parser.
  • Google (Generative Language API / Gemini) (US) — parses uploaded job descriptions and resumes into structured fields. The file is sent directly to the API; Google's published policy states that data sent via the paid API is not used to train their models.
  • DeepSeek (China) — used by the "Improve with AI" rewrite tool to refine free-text descriptions you compose. The text you type is sent to DeepSeek; nothing about your account is sent. If you would prefer to opt out of the DeepSeek processor, do not use the "Improve with AI" feature.
  • Resend (US / EU) — delivers transactional email (verification, password reset). Your name and email address are sent to Resend for each message.
  • Telegram (global) — when an employer opts in, we post a notification about a new public job listing to a BlockJobs Telegram channel. The notification contains the listing's public information only.

We notify the DPO of any change to this list. By using the Service you consent to the overseas transfers described above on the basis that BlockJobs has taken steps to ensure each recipient is bound to a comparable standard of protection.

6. Sharing with employers

When you apply to a role, the employer who posted that role can see the snapshot of your name, email, headline and resume that was created at the moment of application. We do not share your information with employers you have not actively engaged with.

7. Cookies

We use only first-party cookies necessary to keep you signed in and to protect the Service from cross-site request forgery. The session cookies are issued by our authentication library and are HttpOnly, SameSite=Lax, and (in production) Secure. We do not use third-party advertising, analytics, or tracking cookies.

8. Your rights under the PDPA

  • Access: you may view the information we hold about you from your dashboard. To request a structured export (a copy of all data we hold on you) email the DPO; we will respond within 30 days.
  • Correction: edit your profile, preferences and resume at any time. For data you cannot edit yourself (e.g. job applications already submitted), email the DPO.
  • Withdrawal of consent / deletion: close your account from your dashboard, or email the DPO. We delete your personal data within 30 days of the request, except where we are required to retain limited records for legal, accounting, or fraud-prevention reasons.
  • Complaint: if you are not satisfied with our response you may lodge a complaint with Singapore's Personal Data Protection Commission (PDPC) at pdpc.gov.sg.

9. Data retention

We keep your account and profile data for as long as your account is active. If you close your account or ask us to delete your data, we remove personal data within 30 days, except:

  • Server logs are retained for up to 30 days regardless
  • Job application snapshots already sent to an employer may be retained by that employer; please contact the relevant employer for those records
  • We may retain limited records (e.g. transaction logs) for as long as required by law

Inactive accounts: if you have not signed in for 24 consecutive months, we will treat your account as abandoned and delete it (along with your profile, resume, applications, and other linked data). Log in periodically to keep your account.

10. Security

Passwords are hashed using industry-standard algorithms. Connections to the Service are encrypted in transit (HTTPS / TLS 1.2+). Resumes and uploaded images are stored privately in Cloudflare R2 and served only via authenticated, signed URLs. Access to production systems is restricted to authorised BlockJobs personnel.

11. Data-breach notification

If we become aware of a personal-data breach that is likely to result in significant harm to affected individuals, or that affects 500 or more individuals, we will notify the PDPC and the affected individuals as soon as practicable, and in any case within 72 hours of becoming aware (in line with PDPA s.26D).

12. Children

BlockJobs is not intended for anyone under 18. If we learn that someone under 18 has signed up, we will delete the account.

13. Changes to this policy

We may update this policy from time to time. Material changes will be announced via email or a banner on the site. The "Last updated" date at the top of this page reflects the most recent revision.

14. Contact

Privacy questions or PDPA requests should be sent to the DPO at dpo@blockjobs.work.