Privacy Policy
Last updated: March 2026
1. Data Controller
The data controller responsible for the processing of your personal data on this platform is:
BOTFORCE Technology GmbH
Wienerbergstraße 11/12A
A-1100 Wien, Österreich
Geschäftsführer: Robert Aksan
FN 123456a, Handelsgericht Wien
UID: ATU12345678
Email: datenschutz@botforce.at
ProjexMaster is a brand and product of BOTFORCE Technology GmbH, registered in Austria. All references to “we,” “us,” or “our” in this policy refer to BOTFORCE Technology GmbH.
2. What Data We Collect
We collect the following categories of personal data:
- Account Data: Name, email address, password (hashed), and account type (freelancer or company) provided during registration.
- Profile Data: Professional information such as skills, experience, rates, availability, CV/resume content, company name, and industry sector.
- Mandate & Matching Data: Mandate postings, applications, matching scores, pipeline health metrics, and briefing analysis results.
- Usage Data: Information about how you interact with the platform, including pages visited, features used, search queries, application activity, and timestamps.
- Cookies and Technical Data: Browser type, device information, IP address, and cookies as described in our Cookie Policy.
3. How We Use Your Data
We process your personal data for the following purposes:
- Service Provision: To create and manage your account, facilitate mandate browsing, and enable applications.
- Profile & Mandate Management: To maintain freelancer profiles, company mandates, and enable matching between the two.
- AI-Powered Matching: To match freelancer profiles with company mandates using AI-driven analysis of skills, experience, and project requirements.
- Pipeline Monitoring: To calculate and maintain your Pipeline Health Score, provide seasonal risk alerts, and send proactive notifications about your contract runway.
- Analytics: To understand platform usage, improve our services, and generate aggregated, non-identifying insights.
- Communications: To send transactional emails (e.g., application confirmations, status updates, pipeline alerts) and, where you have opted in, marketing communications.
4. Legal Basis for Processing
We process your personal data on the following legal bases under the DSGVO (GDPR):
- Consent (Art. 6(1)(a) DSGVO): Where you have given explicit consent, such as for marketing communications or optional analytics cookies.
- Contract Performance (Art. 6(1)(b) DSGVO): Processing necessary to provide you with the ProjexMaster platform services, including account management, matching, pipeline monitoring, and application processing.
- Legitimate Interest (Art. 6(1)(f) DSGVO): Processing necessary for our legitimate interests, such as platform security, fraud prevention, and service improvement, provided these interests are not overridden by your rights.
5. Data Sharing and Third-Party Processors
We share your data with the following third-party service providers who act as data processors on our behalf:
- Supabase (Supabase Inc.): Database hosting, authentication, and file storage. Data is stored in EU-based infrastructure.
- Anthropic (Anthropic PBC): AI-powered features including mandate matching, briefing analysis, and interview preparation using Claude.
- OpenAI (OpenAI LLC): Embedding generation for semantic search and matching capabilities.
- Resend (Resend Inc.): Transactional and marketing email delivery.
- Vercel (Vercel Inc.): Application hosting, edge network delivery, and optional analytics.
All processors are bound by data processing agreements (Auftragsverarbeitungsverträge) in accordance with Art. 28 DSGVO.
6. AI Services
ProjexMaster uses artificial intelligence services to provide core platform features:
- Claude (Anthropic):Used for AI-powered mandate matching, briefing analysis, interview preparation guidance, and pipeline recommendations. Profile and mandate data may be sent to Anthropic's API for processing.
- OpenAI Embeddings:Used to generate semantic vector embeddings of profiles and mandates for similarity-based matching. Text data is sent to OpenAI's API for embedding generation.
Both providers process data under strict data processing agreements. Data sent to these services is not used to train their models. We minimize the data sent to only what is necessary for the specific feature.
7. Cookies
We use the following types of cookies:
- Essential Cookies: Required for authentication (session tokens) and locale preferences. These cannot be disabled.
- Analytics Cookies (future): We may introduce analytics cookies in the future to understand platform usage. These will require your explicit consent.
- Preference Cookies: Store your display preferences such as language and theme settings.
For more details, see our Cookie Policy.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy.
| Data Category | Retention Period |
|---|---|
| Account data | Duration of active account + 30 days after deletion |
| Profile & mandate data | Duration of active account + 30 days after deletion |
| Application & matching data | Duration of active account + 30 days after deletion |
| Usage & analytics data | 26 months (anonymized or deleted) |
| Financial / billing records | Up to 7 years (Austrian tax law, BAO § 132) |
| Email communication logs | 12 months |
9. Your Rights Under the DSGVO
Under the General Data Protection Regulation (DSGVO), you have the following rights:
- Right of Access (Art. 15): You may request a copy of your personal data held by us.
- Right to Rectification (Art. 16): You may request correction of inaccurate personal data.
- Right to Erasure (Art. 17):You may request deletion of your personal data (“right to be forgotten”).
- Right to Restriction (Art. 18): You may request restriction of processing in certain circumstances.
- Right to Data Portability (Art. 20): You may request your data in a structured, machine-readable format.
- Right to Object (Art. 21): You may object to processing based on legitimate interest.
- Right to Withdraw Consent (Art. 7(3)): You may withdraw previously given consent at any time.
To exercise any of these rights, please contact us at datenschutz@botforce.at.
You also have the right to lodge a complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde): dsb@dsb.gv.at / www.dsb.gv.at.
10. International Data Transfers
Some of our third-party processors (Anthropic, OpenAI, Resend, Vercel) are based in the United States. Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs) as per Art. 46(2)(c) DSGVO, or reliance on an adequacy decision by the European Commission (such as the EU-U.S. Data Privacy Framework where applicable).
11. Contact for Data Protection Inquiries
For any questions regarding the processing of your personal data or to exercise your rights under the DSGVO, please contact:
BOTFORCE Technology GmbH — Datenschutz
Wienerbergstraße 11/12A, A-1100 Wien, Österreich
Email: datenschutz@botforce.at
12. Updates to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last updated” date. If we make material changes that affect how we process your personal data, we will notify you via email or an in-platform notification before the changes take effect.
We encourage you to review this page periodically to stay informed about our data practices.