Skip to content
LazyHead
AboutPricing
  • DE Deutsch
  • EN English
  • UA Українська

Information

About Pricing Support & Contact

Privacy

Privacy Policy

Contents

  1. 1. Controller
  2. 2. Scope
  3. 3. Website data (server logs)
  4. 4. Cookies, storage and consent
  5. 5. Support and contact requests
  6. 6. Registration and sign-in
  7. 7. Candidate profiles
  8. 8. Employer profiles and vacancies
  9. 8a. Trust level of the employer account
  10. 8b. Subscriptions and payment data
  11. 9. Chat and attachments
  12. 10. Message translation
  13. 11. Maps and location
  14. 12. Interview planner
  15. 12b. Company verification and AI pre-check
  16. 13. Notifications
  17. 14. Account deletion
  18. 15. Your rights
  19. 16. Processors
  20. 17. International transfers
  21. 18. Retention
  22. 19. Security
  23. 20. Automated decisions
  24. 21. Minors
  25. 22. Supervisory authority
  26. 23. Version

This privacy policy describes how personal data is processed in connection with the website lazyhead.at, the LazyHead app (web, iOS, Android, desktop) and support. It deliberately distinguishes between the information website and the application.

1. Controller

The controller under the GDPR is LazyHead e.U., sole proprietor Andrii Snikhovskyi, Morizgasse 2/2/14, 1060 Wien, Österreich.

Email for privacy matters: privacy@lazyhead.at.

2. Scope

This policy covers the website lazyhead.at, the web app, the mobile apps (iOS, Android), the desktop app and support requests.

3. Website data (server logs)

When you visit the website, technically necessary data is processed: IP address, timestamp, requested URL, HTTP status code, data volume, user agent and referrer. Security logs are also generated.

The legal basis is our legitimate interest in secure, stable operation (Art. 6(1)(f) GDPR). This data is not analysed for marketing.

4. Cookies, storage and consent

Necessary technologies (e.g. Cloudflare security cookies, the record of your cookie decision, and Cloudflare Turnstile when you submit a form) are required for secure operation and the features you request, and are always active. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR) and/or performing the feature you requested.

Optional technologies are used only with your consent (§ 165(3) Austrian TKG 2021, Art. 6(1)(a) GDPR). Currently this concerns only remembering your light/dark theme across visits. Without consent your theme choice applies to the current session only. There is no analytics, marketing or tracking.

You can give, change or just as easily withdraw your consent at any time via “Cookie settings” in the footer. Details of every technology are in the Cookie Policy.

5. Support and contact requests

When you use the contact form or one of our email addresses, we process your email address, optionally your name, subject, category, message text and anti-abuse metadata.

Legal bases: Art. 6(1)(b) (handling your request), (f) (secure operation) and (c) where legal retention applies.

Support requests are retained by default for 6 months after closure.

For an Enterprise request we additionally process the company details you provide: company name, contact person, optionally phone number and website, number of locations, expected number of users and preferred payment method. The purpose is to handle the request, prepare an offer and conduct pre-contractual communication. No bank or payment data (e.g. IBAN, SEPA mandate), invoices or payment history are processed at this stage.

When the contact form is active, we use Cloudflare Turnstile to prevent abuse and Resend (Resend, Inc.) to deliver the request by email. The website is served via Cloudflare Pages, which produces technical server logs. These providers act as processors.

The app additionally offers a built-in support chat. There we process your message text, timestamps, your basic account data (role, email, language) and any files you attach (images or PDF, e.g. screenshots). The history stays linked to your account so you can revisit earlier answers; the same retention rules as for support requests apply.

In the support chat, an AI assistant (“LazyHead Assistant”) may answer typical questions about how the app works. It is clearly labelled as AI (Art. 50 EU AI Act); a human can take over at any time — just say you want a person. To answer, the message text of the current request, your first name, account language, role and non-sensitive account facts (e.g. subscription status, vacancy limits) are transmitted automatically to Google (Gemini API, Google Ireland Limited); a transfer to third countries may occur on the basis of Standard Contractual Clauses. The assistant makes no decisions about verification, hiring or your account.

6. Registration and sign-in

For an account we process your email address, the chosen role (candidate or employer), one-time-code (OTP) sign-in metadata, login timestamps and account status.

If sign-in via Apple or Google is enabled, we process the identifier and email address supplied by the provider. There is no phone-number/SMS sign-in.

7. Candidate profiles

As a candidate you may provide name, photo, experience, skills, languages, location, CV, preferences and your own files.

We distinguish between publicly visible fields, fields visible only to employers you engage with, and private fields. You decide what you share.

We process job seekers' data exclusively for the purpose of job placement and to meet legal requirements (§ 6(1) AMFG). It is not used for advertising, product analytics or training AI models, and we only collect data that has a direct factual connection to the intended occupation.

8. Employer profiles and vacancies

As an employer we process company name, contact person, company details, role content, location, working hours, salary information, requirements and the status (active/archived) of a vacancy.

8a. Trust level of the employer account

To protect job seekers from abuse, every employer account has a trust level (0–3). It is derived solely from verifiable facts: a confirmed phone number, a match with the Firmenbuch or GISA register, a confirmed work email address on the company domain, an active payment made on the website. We do not process copies of identity documents or biometric data for this.

To confirm the phone number we process the number and the delivery of a one-time code by SMS; to confirm the work email address, the address and a one-time code. The legal basis is our legitimate interest in preventing fraud and protecting job seekers (Art. 6(1)(f) GDPR) in connection with our responsibility as a job placement service (§ 4(6) AMFG).

The trust level determines which actions an employer account can perform (see Terms, section 8a). When a job seeker discloses data to a company (identity, CV, phone number), we log the time, the type of disclosure and the company's trust level at that moment — without content. These logs are kept as long as the security logs (see Retention).

The first messages an employer sends to a job seeker are checked automatically for patterns that suggest moving the conversation outside LazyHead (e.g. phone numbers or names of external messengers). There is no evaluation of the content; the result is solely a notice to the job seeker and to our moderation team. Decisions restricting an account are always taken by a human.

Confirmed violations (after a report and review by our moderation team) are attributed to the company account and may temporarily lower its trust level (Art. 23 DSA). They are kept together with the related report.

8b. Subscriptions and payment data

When an employer account takes out a subscription or a TOP placement, we process the contract and billing data required for it: plan, term and status of the subscription, payment transactions (amount, currency, VAT rate and invoice country, the payment provider's transaction reference), issued invoices, and the e-mail address for payment receipts and the reminder we send at least 7 days before each automatic renewal.

Card and bank details never reach our servers: payment is handled entirely by Stripe Payments Europe, Ltd. (Ireland); we only receive a confirmation or transaction reference. Stripe processes payment data partly as our processor and partly under its own responsibility (e.g. fraud prevention under its own rules); see https://stripe.com/privacy.

Legal bases: Art. 6(1)(b) GDPR (performance of the contract and billing), (c) (statutory retention duties, in particular § 132 BAO and § 11 UStG) and (f) (abuse and fraud prevention). During the free trial, payment data is only collected if you voluntarily add a payment card to confirm your business: Stripe performs a €0 check (nothing is charged), the card is stored with Stripe for a later subscription, and we only receive the time of confirmation.

We retain invoicing and accounting data for 7 years from the end of the calendar year of the invoice (§ 132 BAO); after that it is deleted. Deleting the account does not affect this statutory retention (see Retention).

9. Chat and attachments

For direct communication we process message text, timestamps, sender and recipient, delivery and read metadata, shared files (e.g. CVs) and moderation/security metadata.

We do not claim end-to-end encryption while it is not implemented.

10. Message translation

Tap-to-translate is active. When you trigger it, only the selected text (a message, a job description or a profile text) is transmitted to Google (Gemini API, Google Ireland Limited) and returned translated. Translation happens only on your action — never automatically and never in the background.

The legal basis is performing the feature you requested (Art. 6(1)(b) GDPR). Only the text itself is transmitted — no account, no name, no identifier. We do not store translated texts.

A transfer to third countries may occur and takes place on the basis of Standard Contractual Clauses. Machine translation can be inaccurate and does not replace a verified translation.

11. Maps and location

Map search is active. We distinguish between an approximate job/search location and a precise device location; a precise location is used only with your permission and only when necessary.

In the web app, map tiles are loaded by your device directly from CARTO and the OpenStreetMap Foundation; these providers receive your IP address and technical request metadata. In the mobile apps (iOS and Android) the map is rendered through the Google Maps SDK: the map section you are viewing, your IP address and — if you have granted the permission — your device location are transmitted to Google (Google Ireland Limited). Converting addresses into coordinates (geocoding, Nominatim/OpenStreetMap) runs through our server: only the address text is transmitted, not your IP address.

Distance figures are approximations.

12. Interview planner

For scheduling we process date, time, participants, format, status and notification metadata. An external video provider is named only once connected.

12b. Company verification and AI pre-check

Employers can upload documents to verify their company (e.g. register extracts) — as a fallback when the check against the Firmenbuch or GISA register is not possible. The files are accessible only for the review and are deleted immediately after the decision; we keep only the outcome of the review plus type, file name and time of the submitted documents (§ 5(5) AMFG). Identity documents are not requested.

For a pre-check, the document content may be transmitted automatically to Google (Gemini API, Google Ireland Limited); the result is a hint for the human review — the verification decision is always taken by a person. A transfer to third countries may occur and takes place on the basis of Standard Contractual Clauses.

13. Notifications

Push notifications are available and strictly opt-in: we process push tokens and notification preferences only once you enable notifications.

In the browser, delivery runs via your browser’s push service (Web Push); in the mobile apps via Expo (650 Industries, Inc.) plus Apple APNs / Google FCM. Only the push token is transmitted; notification content is deliberately minimal (e.g. “New message”) and contains no chat text.

14. Account deletion

You can delete your account in the app or by request via the website. Your profile, vacancy and communication data is removed unless a legal retention obligation applies.

Data is removed from backups within the usual backup cycles. See the “Account deletion” page for details.

15. Your rights

You have the right to access, rectification, erasure, restriction, data portability and objection and — where applicable — to withdraw consent and to lodge a complaint with a supervisory authority.

You can make requests via the “Data request” page or at privacy@lazyhead.at.

16. Processors

We use service providers only on instruction under data-processing agreements. Only providers actually in use are published.

For transparency the overview also lists providers that, in data-protection terms, are recipients rather than processors in the strict sense — in particular the map services (Google Maps SDK in the mobile apps, CARTO and the OpenStreetMap Foundation).

Provider Service Purpose Region Third country
Hetzner Online GmbH Backend-Hosting, Datenbank & Datei-Speicher Betrieb der Anwendung, Speicherung von Anwendungsdaten und Nutzer-Dateien (inkl. Backups) EU (Deutschland/Finnland) –
Cloudflare, Inc. Website-Hosting / CDN / DNS / Bot-Schutz (Turnstile) Auslieferung und Absicherung der Website lazyhead.at EU/US ✓
Resend, Inc. Transaktionale E-Mail Versand von Anmelde-Codes (OTP), System-E-Mails und Kontaktformular-E-Mails EU/US ✓
Google Ireland Limited (Gemini API) Maschinelle Übersetzung & KI-Funktionen Übersetzung auf Klick (Chat, Vakanz-, Profiltexte), KI-gestützte Strukturierung von Profilen sowie KI-Vorprüfung hochgeladener Verifizierungsdokumente von Unternehmen EU/US ✓
Apple Inc. Anmeldung mit Apple Social Login (Sign in with Apple) EU/US ✓
Google Ireland Limited Anmeldung mit Google Social Login (Google Sign-In) EU/US ✓
LINK Mobility Austria GmbH (websms) SMS-Versand (Einmalcodes) Zustellung von Einmalcodes per SMS zur Bestätigung der Telefonnummer von Arbeitgeberkonten (Vertrauensstufe) EU –
Expo (650 Industries, Inc.) / Apple APNs / Google FCM Push-Benachrichtigungen Zustellung von Benachrichtigungen in den mobilen Apps und im Browser (nur bei aktivierten Benachrichtigungen) EU/US ✓
Stripe Payments Europe, Ltd. Zahlungsabwicklung Abwicklung kostenpflichtiger Arbeitgeber-Abos (sobald die Bezahlung aktiviert ist); Zahlungsdaten liegen ausschließlich bei Stripe EU/US ✓
Google Ireland Limited (Google Maps SDK) Kartendarstellung in den mobilen Apps Anzeige und Bedienung der Karte in den Apps für iOS und Android (Google Maps SDK); geladen werden die jeweils sichtbaren Kartenausschnitte EU/US ✓
CARTO (CARTO DB, Inc.) Kartenkacheln in der Web-App Auslieferung der hellen und dunklen Kartenkacheln; die Kacheln werden direkt von deinem Gerät geladen EU/US ✓
OpenStreetMap Foundation Geocoding (Nominatim) und OpenStreetMap-Kartenkacheln Umwandlung von Adresstexten in Koordinaten über unseren Server — übermittelt wird nur der Adresstext, nicht deine IP-Adresse — sowie Auslieferung von OpenStreetMap-Kartenkacheln direkt an dein Gerät EU/Vereinigtes Königreich ✓
Google Ireland Limited AI-Support (Gemini API) KI-Assistent im Support-Chat: automatische Antworten auf Funktionsfragen; Übergabe an einen Menschen jederzeit möglich EU/US ✓

17. International transfers

Any transfer outside the EEA happens only with providers actually in use and only with appropriate safeguards (e.g. an adequacy decision or Standard Contractual Clauses).

18. Retention

We store data only as long as necessary for the respective purpose or legal obligations. The overview below states the default periods.

Data Retention Trigger
Security logs 90 days creation
Support requests 6 months closure
Account data until deletion + legal exceptions deletion
Inactive account 7 years last activity
Messages per configured policy deletion
Vacancies active + limited archive removal
Interview data 12 months interview
Invoicing and accounting data 7 years (§ 132 BAO) invoice year
Legal records statutory period transaction

19. Security

We treat security as an ongoing task: considered access controls, transport encryption (HTTPS), data minimisation, backups, logging, patching and an incident-response process.

No one can guarantee absolute security. You can report possible vulnerabilities responsibly to developer@lazyhead.at. We never ask for your password by email.

20. Automated decisions

There is no solely automated decision-making producing legal effects concerning you.

21. Minors

You can create a candidate account from the age of 14: in Austria consent under data-protection law is possible from that age (§ 4(4) DSG), and someone looking for an apprenticeship or an internship should be able to browse employers and message them.

An employer account requires you to be at least 18, because it involves commercial acts: a subscription, payments and publishing vacancies on behalf of a company.

These age limits concern the account only, not the work itself. Whether and in what form a minor may actually be employed follows the Austrian employment rules — in particular the Children and Young Persons Employment Act (KJBG), compulsory schooling (Schulpflicht) and the type and format of the work (Lehre, Praktikum, Ferialjob). LazyHead does not check or confirm this; the employer is responsible for it.

In addition, the necessary legal capacity or the consent of a legal guardian is required. If we learn that an account is held contrary to these limits, we block and delete it. Please report such cases to privacy@lazyhead.at.

22. Supervisory authority

Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, Austria. Email: dsb@dsb.gv.at.

23. Version

Last updated: 2026-08-31. Version 1.6.

LazyHead
  • About
  • Pricing
  • Support & contact
  • Imprint
  • Privacy
  • Terms of Use
  • Cookie Policy
  • Report content
  • Data request
  • Delete account

© 2026 LazyHead e.U.

· Wien, Österreich

Support & contact

Please enter a valid email address.

Company details

For Enterprise requests only. Please do not send any bank or payment details.

The subject must be 3–160 characters.

The message must be 10–5000 characters.

* Required field

The message could not be sent. Try again or email office@lazyhead.at.

The spam check failed. Please reload the page and try again.

The message could not be delivered. Please try again later or email office@lazyhead.at.

The spam protection could not load. Please disable blockers and reload the page.

We use the information you provide only to process your request. More information is available in our . Privacy Policy.

Prefer to email us directly? office@lazyhead.at

Thank you! Message sent. We will reply to the email address provided.

Privacy settings

We use necessary technologies to keep this website secure and reliable. With your consent, we also use optional technologies for preferences, analytics and marketing. You can choose freely and change or withdraw your decision at any time through “Cookie settings”.

Privacy settings

Choose which optional technologies we may use. Necessary technologies are required for secure operation and are always active.

Necessary

For security, abuse prevention and the features you request (e.g. sending a form). Cannot be disabled.

Always active
  • Consent record Provider: LazyHead

    Stores your cookie decision so we don't ask you again.

    Cookies / storage: lh_consent_v1

  • Cloudflare security Provider: Cloudflare, Inc. Privacy

    Security cookies set by Cloudflare at the edge for secure operation and abuse prevention.

    Cookies / storage: __cf_bm (~30 min), cf_clearance (≤ 1 Jahr / year / рік)

  • Cloudflare Turnstile Provider: Cloudflare, Inc. Privacy

    Privacy-friendly spam/bot protection — active only when you use a contact form, so your message can be delivered securely.

Preferences

Remembers settings such as the light/dark theme across visits.

  • Theme preference Provider: LazyHead

    Remembers your light/dark theme across visits. Without consent it applies to the current session only.

    Cookies / storage: lh-color-theme

Analytics

Anonymous usage measurement to improve the site. Not currently in use.

Marketing

Advertising and reach measurement. Not currently in use.