Privacy policy
Last updated: 23 August 2026
This policy explains which personal data we process on Gratis Stelleninserate, for what purpose, and for how long. It follows the revised Swiss Data Protection Act (revFADP) and, where applicable, the European General Data Protection Regulation (GDPR).
The most important point first: you never need an account to apply. In the vast majority of cases your application also goes directly to the company that posted the listing, and we never see your documents. Only when a company specifically chooses to receive applications through this portal is it different – section 2 explains both cases.
1. Controller
The controller for the processing of personal data on this portal is:
Livo Holding AG, Neugasse 4, 6300 Zug, Switzerland · company ID CHE-409.268.189 · kontakt@gratisstelleninserate.ch
We have not appointed a data protection advisor within the meaning of Art. 10 revFADP and are not required to. For any question about this policy, please contact us at the address above.
2. Applying without an account
There is no candidate account, and one will never be required in order to apply. How your application works in detail depends on which method the posting company chose for that listing – this is shown on every listing page.
a) Default case – applying directly with the company. Anyone applying for a listing does so through the link, email address or phone number stated in the listing. We are not involved in that step, keep no application files, and store no CVs, references or details about you. When you click an application link, you leave this portal – from that moment the privacy policy of the company or applicant tracking system you land on applies, not this one.
b) Exception – applying through this portal. Some companies choose to receive applications directly through this portal instead of stating their own method. In that case you fill in a form on our site (name, email address, optionally a phone number and a message) and upload your application documents. We store these details temporarily, solely to forward them to the company – see section 3(e) and section 9 for the retention period.
In that case, the company you are applying to is the controller responsible for processing your application data – we process the data only on its behalf and instructions (data processing). Please direct questions about your specific application to the company; for the processing itself you can reach us as described in section 1.
3. What data we process
a) Company accounts. Posting or managing listings requires an account. For that we store: email address, optionally a name, the role (company or administration), the link to one or more companies, and technical details of active sign-ins.
We do not issue passwords. Signing in works through a one-time link sent by email that is valid for 15 minutes. There are therefore no passwords that could be stolen from us.
b) Company details. Company name, contact email address and, where provided, website, logo and company description.
c) Listing content. Everything the company enters: job title, description, location, workload, employment type, optionally a salary range, and how to apply. If the application details include the name, direct line or personal email address of a contact person, those are that person’s personal data – see section 5.
d) Server logs. Our hosting provider logs technical details of every request, including IP address, timestamp, requested address and browser identifier. These logs serve operation and security; we do not analyse them at an individual level and do not combine them with other data.
e) Application data – only for listings that accept applications through the portal (see section 2(b)). In that case: name, email address, optionally a phone number and a message, plus the uploaded application documents (file, original file name, file size). We process this data solely on behalf of the respective company and forward it to them.
4. Cookies and analytics
Without signing in and without your consent to analytics, we set no cookies at all. You can use the entire portal – home page, job search, every listing – without cookies.
Only during and after signing in do we set three strictly necessary cookies: "authjs.session-token" keeps you signed in (until sign-out, or after 8 hours without use), "authjs.csrf-token" protects your account when submitting forms (for the duration of the session only), and "authjs.callback-url" remembers where to return you after signing in (also for the session only).
All three are necessary for operation and cannot be declined – without them signing in is impossible. They are not used for advertising and not shared with third parties.
On your first visit, a consent banner asks whether we may use Google Analytics to measure how the site is used. If you decline or make no choice, we set no analytics cookie and no data is sent to Google. If you consent, Google Analytics collects anonymised usage data – pages visited, approximate location, device type – but no name and no contact details. The legal basis is your consent; without it, no collection takes place. You can change your choice at any time via "Cookie settings" in the footer.
Even without consent to Google Analytics, the typeface is served from our own server rather than loaded from a third party.
5. Listings are public – including contact details
An approved listing is publicly accessible. It is indexed by search engines and marked up with structured data for Google for Jobs so that it appears in Google’s job search. That is the purpose of the portal.
Companies should therefore be aware: whatever the listing says is public and gets indexed. That applies in particular to contact details. Anyone stating an employee’s personal email address or direct line is publishing that person’s personal data and must ensure this is permitted. A general address such as “jobs@company.ch” is the more data-minimising choice.
Some listings do not come from the company itself but from its publicly accessible careers page. Such listings are marked and link to the original. Section 8 explains how this works and how an employer can opt out.
6. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Maintaining accounts, enabling sign-in, managing listings | Performance of the terms of use (Art. 6(1)(b) GDPR); under the revFADP no justification is required |
| Reviewing listings before they appear | Legitimate interest in a portal free of misuse (Art. 6(1)(f) GDPR) |
| Emails about approval, rejection and expiry of a listing | Performance of the terms of use |
| Operation, security, prevention of misuse | Legitimate interest |
We process no sensitive personal data and make no automated individual decisions with legal consequences for you. Whether a listing is approved is decided by a person.
7. Who else sees the data
We do not sell data and do not pass it on for advertising. We work with the following providers, which process data solely on our behalf and on our instructions:
| Category | Purpose | Where the data is held |
|---|---|---|
| Database hosting | Storage of all account and listing data | Europe (EU) |
| Email delivery service | Delivery of sign-in and notification emails | Europe (EU) |
| Application hosting | Running the application, server logs | Europe (EU) |
| File storage | Storage of application documents, only for listings that accept applications through the portal (section 2(b)) | Europe (EU) |
| Web analytics | Traffic measurement, only if you consented in the consent banner (section 4) | Europe/USA (standard contractual clauses) |
All account and listing data is held in the European Union. We deliberately use no provider-specific database features, so that a change of provider or region remains possible at any time.
Where a provider processes data in a country without an adequate level of data protection, we base the transfer on the European Commission’s standard contractual clauses in the version recognised by the Swiss FDPIC.
Authorities receive data only where we are legally required to provide it.
8. Listings taken from employers’ careers pages
Not every listing on this portal was submitted by the company itself. We also take job listings from the publicly accessible careers pages of employers. Such listings are marked as taken on their detail page and link visibly to the original; applications go to the employer only.
We take listings solely from employers’ own careers pages, never from other job boards. We follow these rules:
- Our crawler identifies itself in every request: GratisStelleninserateBot/1.0 (+https://gratisstelleninserate.ch/bot).
- A site’s robots.txt is obeyed. If it forbids access, the page is not fetched.
- At most one request per second per domain, and a source is not fetched more often than every two days.
- Only publicly accessible pages are fetched. We do not circumvent any login or technical barrier.
- Every taken listing is reviewed by a person before it becomes visible.
A job listing is usually not personal data. It may contain some, however – such as the name and direct line of the person responsible for applications. We take such details only where the employer published them in the listing itself, and only for the purpose for which they were published there: so that interested people can get in touch.
The legal basis is our legitimate interest in offering a complete picture of the job market, together with employers’ interest in the visibility of their vacancies. We have weighed these interests and kept the interference as small as possible: public sources, clear marking, a link to the original, and the option to opt out at any time.
Automated listings taken from careers pages without their own structured data are processed using a language model. Only the publicly accessible page text is transmitted – no applicant data and no account or listing data. The language model we use is based outside Switzerland/the EU; we base this transfer on standard contractual clauses.
Everything else on the portal – your account, an application, your own listing – continues to be processed within Switzerland/the EU. Only this one automated step, when taking over a third-party careers page, uses the language model mentioned above, outside Switzerland/the EU.
Any employer can stop this at any time and without giving reasons – an email to kontakt@gratisstelleninserate.ch is enough. We then delete all taken listings of that company and permanently stop fetching the domain. Details are set out at /bot.
If a listing disappears from the careers page, we deactivate it after three days. It is not deleted immediately, so that a brief outage of the careers page does not destroy data.
9. Retention
Sign-in links expire after 15 minutes and can be used once. A signed-in session ends immediately when you sign out, and otherwise 8 hours after its last use.
A published listing expires 30 days after approval and is no longer publicly visible after that. Seven days before expiry we remind the company by email; they can extend the period by another 30 days. For staffing agencies’ standing offers the extension can happen automatically – such listings are worded accordingly.
Expired listings remain stored in the company’s account so they can republish rather than enter everything again. Company data is retained for as long as the account exists. We delete listings or the entire account on request.
A rejected listing is retained together with its reason so the company can revise it without entering everything again.
Application data and documents submitted through the portal (section 2(b)) are automatically deleted 90 days after the application is received – regardless of whether the company has already viewed it. This period cannot be extended.
If you have consented to analytics (section 4), Google retains the usage and event data collected on our behalf for at most 14 months and deletes it afterwards. This period does not restart with each further visit. If you withdraw your consent via "Cookie settings" in the footer, no further data is collected from that point on.
10. Your rights
You have the right to obtain information about the data we process about you. You may also request that we correct inaccurate data, delete data or restrict its processing, and you may object to processing. Where the GDPR applies, you additionally have the right to receive your data in a common format.
Proof of identity may be necessary so that we do not hand data to the wrong person. An email to kontakt@gratisstelleninserate.ch is enough for any request.
You may also lodge a complaint: in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC), in the EU with the supervisory authority of your country of residence.
11. Security
The connection to this portal is encrypted (TLS). The connection between application and database is encrypted as well, with the certificate of the other end verified. Only a small number of named individuals have access to the database.
An account only ever sees the listings of the companies it is linked to. Adding further people to a company gives them access to all of that company’s listings – please only invite people who should have that access.
12. Changes
We update this policy when our processing changes – for instance when new features are added. The version published on this page applies. The date above shows its status.