Privacy
Privacy Policy
This privacy policy describes how personal data is processed in connection with the website lazyhead.at, the LazyHead app (web, iOS, Android, desktop) and support. It deliberately distinguishes between the information website and the application.
1. Controller
The controller under the GDPR is LazyHead e.U., sole proprietor Andrii Snikhovskyi, Morizgasse 2/2/14, 1060 Wien, Österreich.
Email for privacy matters: privacy@lazyhead.at.
2. Scope
This policy covers the website lazyhead.at, the web app, the mobile apps (iOS, Android), the desktop app and support requests.
3. Website data (server logs)
When you visit the website, technically necessary data is processed: IP address, timestamp, requested URL, HTTP status code, data volume, user agent and referrer. Security logs are also generated.
The legal basis is our legitimate interest in secure, stable operation (Art. 6(1)(f) GDPR). This data is not analysed for marketing.
4. Cookies, storage and consent
Necessary technologies (e.g. Cloudflare security cookies, the record of your cookie decision, and Cloudflare Turnstile when you submit a form) are required for secure operation and the features you request, and are always active. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR) and/or performing the feature you requested.
Optional technologies are used only with your consent (§ 165(3) Austrian TKG 2021, Art. 6(1)(a) GDPR). Currently this concerns only remembering your light/dark theme across visits. Without consent your theme choice applies to the current session only. There is no analytics, marketing or tracking.
You can give, change or just as easily withdraw your consent at any time via “Cookie settings” in the footer. Details of every technology are in the Cookie Policy.
5. Support and contact requests
When you use the contact form or one of our email addresses, we process your email address, optionally your name, subject, category, message text and anti-abuse metadata.
Legal bases: Art. 6(1)(b) (handling your request), (f) (secure operation) and (c) where legal retention applies.
Support requests are retained by default for 6 months after closure.
For an Enterprise request we additionally process the company details you provide: company name, contact person, optionally phone number and website, number of locations, expected number of users and preferred payment method. The purpose is to handle the request, prepare an offer and conduct pre-contractual communication. No bank or payment data (e.g. IBAN, SEPA mandate), invoices or payment history are processed at this stage.
When the contact form is active, we use Cloudflare Turnstile to prevent abuse and Resend (Resend, Inc.) to deliver the request by email. The website is served via Cloudflare Pages, which produces technical server logs. These providers act as processors.
The app additionally offers a built-in support chat. There we process your message text, timestamps, your basic account data (role, email, language) and any files you attach (images or PDF, e.g. screenshots). The history stays linked to your account so you can revisit earlier answers; the same retention rules as for support requests apply.
In the support chat, an AI assistant (“LazyHead Assistant”) may answer typical questions about how the app works. It is clearly labelled as AI (Art. 50 EU AI Act); a human can take over at any time — just say you want a person. To answer, the message text of the current request, your first name, account language, role and non-sensitive account facts (e.g. subscription status, vacancy limits) are transmitted automatically to Google (Gemini API, Google Ireland Limited); a transfer to third countries may occur on the basis of Standard Contractual Clauses. The assistant makes no decisions about verification, hiring or your account.
6. Registration and sign-in
For an account we process your email address, the chosen role (candidate or employer), one-time-code (OTP) sign-in metadata, login timestamps and account status.
If sign-in via Apple or Google is enabled, we process the identifier and email address supplied by the provider. There is no phone-number/SMS sign-in.
7. Candidate profiles
As a candidate you may provide name, photo, experience, skills, languages, location, CV, preferences and your own files.
We distinguish between publicly visible fields, fields visible only to employers you engage with, and private fields. You decide what you share.
We process job seekers' data exclusively for the purpose of job placement and to meet legal requirements (§ 6(1) AMFG). It is not used for advertising, product analytics or training AI models, and we only collect data that has a direct factual connection to the intended occupation.
8. Employer profiles and vacancies
As an employer we process company name, contact person, company details, role content, location, working hours, salary information, requirements and the status (active/archived) of a vacancy.
8a. Trust level of the employer account
To protect job seekers from abuse, every employer account has a trust level (0–3). It is derived solely from verifiable facts: a confirmed phone number, a match with the Firmenbuch or GISA register, a confirmed work email address on the company domain, an active payment made on the website. We do not process copies of identity documents or biometric data for this.
To confirm the phone number we process the number and the delivery of a one-time code by SMS; to confirm the work email address, the address and a one-time code. The legal basis is our legitimate interest in preventing fraud and protecting job seekers (Art. 6(1)(f) GDPR) in connection with our responsibility as a job placement service (§ 4(6) AMFG).
The trust level determines which actions an employer account can perform (see Terms, section 8a). When a job seeker discloses data to a company (identity, CV, phone number), we log the time, the type of disclosure and the company's trust level at that moment — without content. These logs are kept as long as the security logs (see Retention).
The first messages an employer sends to a job seeker are checked automatically for patterns that suggest moving the conversation outside LazyHead (e.g. phone numbers or names of external messengers). There is no evaluation of the content; the result is solely a notice to the job seeker and to our moderation team. Decisions restricting an account are always taken by a human.
Confirmed violations (after a report and review by our moderation team) are attributed to the company account and may temporarily lower its trust level (Art. 23 DSA). They are kept together with the related report.
8b. Subscriptions and payment data
When an employer account takes out a subscription or a TOP placement, we process the contract and billing data required for it: plan, term and status of the subscription, payment transactions (amount, currency, VAT rate and invoice country, the payment provider's transaction reference), issued invoices, and the e-mail address for payment receipts and the reminder we send at least 7 days before each automatic renewal.
Card and bank details never reach our servers: payment is handled entirely by Stripe Payments Europe, Ltd. (Ireland); we only receive a confirmation or transaction reference. Stripe processes payment data partly as our processor and partly under its own responsibility (e.g. fraud prevention under its own rules); see https://stripe.com/privacy.
Legal bases: Art. 6(1)(b) GDPR (performance of the contract and billing), (c) (statutory retention duties, in particular § 132 BAO and § 11 UStG) and (f) (abuse and fraud prevention). During the free trial, payment data is only collected if you voluntarily add a payment card to confirm your business: Stripe performs a €0 check (nothing is charged), the card is stored with Stripe for a later subscription, and we only receive the time of confirmation.
We retain invoicing and accounting data for 7 years from the end of the calendar year of the invoice (§ 132 BAO); after that it is deleted. Deleting the account does not affect this statutory retention (see Retention).
9. Chat and attachments
For direct communication we process message text, timestamps, sender and recipient, delivery and read metadata, shared files (e.g. CVs) and moderation/security metadata.
We do not claim end-to-end encryption while it is not implemented.
10. Message translation
Tap-to-translate is active. When you trigger it, only the selected text (a message, a job description or a profile text) is transmitted to Google (Gemini API, Google Ireland Limited) and returned translated. Translation happens only on your action — never automatically and never in the background.
The legal basis is performing the feature you requested (Art. 6(1)(b) GDPR). Only the text itself is transmitted — no account, no name, no identifier. We do not store translated texts.
A transfer to third countries may occur and takes place on the basis of Standard Contractual Clauses. Machine translation can be inaccurate and does not replace a verified translation.
11. Maps and location
Map search is active. We distinguish between an approximate job/search location and a precise device location; a precise location is used only with your permission and only when necessary.
In the web app, map tiles are loaded by your device directly from CARTO and the OpenStreetMap Foundation; these providers receive your IP address and technical request metadata. In the mobile apps (iOS and Android) the map is rendered through the Google Maps SDK: the map section you are viewing, your IP address and — if you have granted the permission — your device location are transmitted to Google (Google Ireland Limited). Converting addresses into coordinates (geocoding, Nominatim/OpenStreetMap) runs through our server: only the address text is transmitted, not your IP address.
Distance figures are approximations.
12. Interview planner
For scheduling we process date, time, participants, format, status and notification metadata. An external video provider is named only once connected.
12b. Company verification and AI pre-check
Employers can upload documents to verify their company (e.g. register extracts) — as a fallback when the check against the Firmenbuch or GISA register is not possible. The files are accessible only for the review and are deleted immediately after the decision; we keep only the outcome of the review plus type, file name and time of the submitted documents (§ 5(5) AMFG). Identity documents are not requested.
For a pre-check, the document content may be transmitted automatically to Google (Gemini API, Google Ireland Limited); the result is a hint for the human review — the verification decision is always taken by a person. A transfer to third countries may occur and takes place on the basis of Standard Contractual Clauses.
13. Notifications
Push notifications are available and strictly opt-in: we process push tokens and notification preferences only once you enable notifications.
In the browser, delivery runs via your browser’s push service (Web Push); in the mobile apps via Expo (650 Industries, Inc.) plus Apple APNs / Google FCM. Only the push token is transmitted; notification content is deliberately minimal (e.g. “New message”) and contains no chat text.
14. Account deletion
You can delete your account in the app or by request via the website. Your profile, vacancy and communication data is removed unless a legal retention obligation applies.
Data is removed from backups within the usual backup cycles. See the “Account deletion” page for details.
15. Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection and — where applicable — to withdraw consent and to lodge a complaint with a supervisory authority.
You can make requests via the “Data request” page or at privacy@lazyhead.at.
16. Processors
We use service providers only on instruction under data-processing agreements. Only providers actually in use are published.
For transparency the overview also lists providers that, in data-protection terms, are recipients rather than processors in the strict sense — in particular the map services (Google Maps SDK in the mobile apps, CARTO and the OpenStreetMap Foundation).
| Provider | Service | Purpose | Region | Third country |
|---|---|---|---|---|
| Hetzner Online GmbH | Backend-Hosting, Datenbank & Datei-Speicher | Betrieb der Anwendung, Speicherung von Anwendungsdaten und Nutzer-Dateien (inkl. Backups) | EU (Deutschland/Finnland) | – |
| Cloudflare, Inc. | Website-Hosting / CDN / DNS / Bot-Schutz (Turnstile) | Auslieferung und Absicherung der Website lazyhead.at | EU/US | ✓ |
| Resend, Inc. | Transaktionale E-Mail | Versand von Anmelde-Codes (OTP), System-E-Mails und Kontaktformular-E-Mails | EU/US | ✓ |
| Google Ireland Limited (Gemini API) | Maschinelle Übersetzung & KI-Funktionen | Übersetzung auf Klick (Chat, Vakanz-, Profiltexte), KI-gestützte Strukturierung von Profilen sowie KI-Vorprüfung hochgeladener Verifizierungsdokumente von Unternehmen | EU/US | ✓ |
| Apple Inc. | Anmeldung mit Apple | Social Login (Sign in with Apple) | EU/US | ✓ |
| Google Ireland Limited | Anmeldung mit Google | Social Login (Google Sign-In) | EU/US | ✓ |
| LINK Mobility Austria GmbH (websms) | SMS-Versand (Einmalcodes) | Zustellung von Einmalcodes per SMS zur Bestätigung der Telefonnummer von Arbeitgeberkonten (Vertrauensstufe) | EU | – |
| Expo (650 Industries, Inc.) / Apple APNs / Google FCM | Push-Benachrichtigungen | Zustellung von Benachrichtigungen in den mobilen Apps und im Browser (nur bei aktivierten Benachrichtigungen) | EU/US | ✓ |
| Stripe Payments Europe, Ltd. | Zahlungsabwicklung | Abwicklung kostenpflichtiger Arbeitgeber-Abos (sobald die Bezahlung aktiviert ist); Zahlungsdaten liegen ausschließlich bei Stripe | EU/US | ✓ |
| Google Ireland Limited (Google Maps SDK) | Kartendarstellung in den mobilen Apps | Anzeige und Bedienung der Karte in den Apps für iOS und Android (Google Maps SDK); geladen werden die jeweils sichtbaren Kartenausschnitte | EU/US | ✓ |
| CARTO (CARTO DB, Inc.) | Kartenkacheln in der Web-App | Auslieferung der hellen und dunklen Kartenkacheln; die Kacheln werden direkt von deinem Gerät geladen | EU/US | ✓ |
| OpenStreetMap Foundation | Geocoding (Nominatim) und OpenStreetMap-Kartenkacheln | Umwandlung von Adresstexten in Koordinaten über unseren Server — übermittelt wird nur der Adresstext, nicht deine IP-Adresse — sowie Auslieferung von OpenStreetMap-Kartenkacheln direkt an dein Gerät | EU/Vereinigtes Königreich | ✓ |
| Google Ireland Limited | AI-Support (Gemini API) | KI-Assistent im Support-Chat: automatische Antworten auf Funktionsfragen; Übergabe an einen Menschen jederzeit möglich | EU/US | ✓ |
17. International transfers
Any transfer outside the EEA happens only with providers actually in use and only with appropriate safeguards (e.g. an adequacy decision or Standard Contractual Clauses).
18. Retention
We store data only as long as necessary for the respective purpose or legal obligations. The overview below states the default periods.
| Data | Retention | Trigger |
|---|---|---|
| Security logs | 90 days | creation |
| Support requests | 6 months | closure |
| Account data | until deletion + legal exceptions | deletion |
| Inactive account | 7 years | last activity |
| Messages | per configured policy | deletion |
| Vacancies | active + limited archive | removal |
| Interview data | 12 months | interview |
| Invoicing and accounting data | 7 years (§ 132 BAO) | invoice year |
| Legal records | statutory period | transaction |
19. Security
We treat security as an ongoing task: considered access controls, transport encryption (HTTPS), data minimisation, backups, logging, patching and an incident-response process.
No one can guarantee absolute security. You can report possible vulnerabilities responsibly to developer@lazyhead.at. We never ask for your password by email.
20. Automated decisions
There is no solely automated decision-making producing legal effects concerning you.
21. Minors
You can create a candidate account from the age of 14: in Austria consent under data-protection law is possible from that age (§ 4(4) DSG), and someone looking for an apprenticeship or an internship should be able to browse employers and message them.
An employer account requires you to be at least 18, because it involves commercial acts: a subscription, payments and publishing vacancies on behalf of a company.
These age limits concern the account only, not the work itself. Whether and in what form a minor may actually be employed follows the Austrian employment rules — in particular the Children and Young Persons Employment Act (KJBG), compulsory schooling (Schulpflicht) and the type and format of the work (Lehre, Praktikum, Ferialjob). LazyHead does not check or confirm this; the employer is responsible for it.
In addition, the necessary legal capacity or the consent of a legal guardian is required. If we learn that an account is held contrary to these limits, we block and delete it. Please report such cases to privacy@lazyhead.at.
23. Version
Last updated: 2026-08-31. Version 1.6.