Privacy Policy
Version 2026-10-01 · Effective 2026-10-01
This Privacy Policy describes how JobMistr s.r.o. ("JobMistr", "we", "us") processes personal data when you use the JobMistr service (the "Service"). Read it together with our GDPR notice, the Security page, and — if you upload personal data of your own clients — the Data Processing Agreement.
1. Controller and contact
The data controller for personal data of users who register directly with JobMistr (and for limited operational data we determine the purpose of) is:
JobMistr s.r.o.
Korunní 2569/108, Vinohrady, 101 00 Praha 10
Company ID (IČO): 29698774
Czech Republic
Email: privacy@jobmistr.com
For personal data that you upload to your workspace about your own clients, contacts, suppliers or staff, you are the controller and JobMistr acts as a processor on your behalf. The terms of that processing are set out in our DPA.
2. Categories of personal data we process
We process the following categories of personal data:
- Account data — name, email address, password hash, role, preferred language, optional phone number, and audit information (consent timestamps and versions, login history).
- Business profile data — for service-provider accounts: business name, registration number (IČO), VAT number (DIČ), address, geographic coordinates of the service area, opening hours, service categories, bank account details shown on invoices, and an optional saved signature image.
- Workspace content — anything you create or upload: clients, jobs, quotes, invoices, contracts, calendar entries, documents, photographs, time entries, expenses, messages, and notes.
- Communication data — the content of in-app messages, support correspondence, and — if you connect a mailbox or WhatsApp number — the messages synchronised from those accounts. Connected-account credentials are stored encrypted and used solely to operate the inbox features.
- Signing data — for electronically signed documents: the signature image, signer name, timestamp, and the signer's IP address (kept as evidence of the signature).
- Financial data — subscription plan, billing history, invoice metadata, payment-link and gateway transaction references, and — if you connect a bank feed — transaction data received from your bank. Payment-card numbers are never stored on JobMistr systems — only the last four digits and a tokenised reference returned by the payment processor.
- Technical data — IP address, browser and device identifiers (including device fingerprints used for trusted-device verification), request logs, security events, and audit-log entries about sensitive operations.
- Marketing data — opt-in status and version, opt-out timestamps, email engagement metadata (opens / clicks via Resend) for users who have consented to marketing emails.
- Waitlist data — if you join the waitlist before JobMistr opens: your email address and, if you choose to give them, your trade, the size of your team and the plan you were interested in; the page and language you joined from; when you confirmed your address and the version of the notice shown to you; when we emailed you and whether delivery failed (with the email provider's error message, without your address); and your personal early-access link — if you use it to open an account, your waitlist entry is linked to that account. To enforce the sending limits described below we also keep, for a short time, coded (keyed-hash) values derived from your address and from the internet connection that asked for an email — never the address or the connection itself in readable form; they are deleted within a few days, or with your entry.
- Referral data — if you take part in the referral programme: your referral code or link, the link between a referrer and the users who sign up through them, and reward / credit status.
3. Purposes and legal bases (GDPR Art. 6)
We process personal data for the following purposes:
- To provide the Service to you — performance of a contract (Art. 6(1)(b)). Includes authentication, workspace operations, document generation and signing, sending transactional emails and SMS you initiate, synchronising integrations you connect, and providing customer support.
- To meet legal obligations — Art. 6(1)(c). Includes retaining accounting records under Czech Act No. 563/1991 Coll., the Accounting Act (§31 — five (5) years for accounting documents and books and ten (10) years for financial statements, from the end of the accounting period, and longer where the records remain needed for tax proceedings), responding to lawful orders from authorities, and complying with anti-fraud obligations of our payment processor.
- Legitimate interests — Art. 6(1)(f). Includes securing the Service (rate-limiting, abuse detection, trusted devices, audit logging), preventing fraud, debugging and improving the product (aggregated, non-identifying), pursuing or defending legal claims, and — for an address entered on our waitlist form but not yet confirmed — sending confirmation emails (no more than three a week to an address typed into the form and no more than three a day to one mailbox through other forms of its address, such as name+tag@, plus a new link if the owner of the address asks for one) and keeping the address, and any details given with it, for up to thirty (30) days, so that we can check the request came from the owner of the address and stop the form being misused. We have weighed these interests against your rights and freedoms and consider them not to be overridden in these contexts.
- Consent — Art. 6(1)(a). Strictly applies to marketing communications (including the pre-launch waitlist once you have confirmed your address: we use your email address only to send you, when it is your turn, a personal link to create your account before JobMistr opens to everyone, with the founding prices offered to people on the list; and the trade, team size, plan and page you joined from, if given, only to understand who is waiting for JobMistr) and to optional integrations (such as connecting your Google or Microsoft calendar, a mailbox, a bank feed, or WhatsApp). You can withdraw consent at any time without affecting prior lawful processing — see "Your rights" below.
We do not knowingly process special categories of personal data (Art. 9) and ask that you do not upload such data into your workspace unless you have established a separate legal basis.
4. Recipients and sub-processors
Personal data is shared in the ways listed below, only to the extent necessary to deliver the Service.
4.1 Core infrastructure sub-processors
These parties process personal data on our behalf under a data processing agreement. They are present for every JobMistr workspace.
- Convex — authentication and real-time database. Region: EU. Used for: user account, session, sign-in.
- Vercel — application hosting and edge delivery. Region: EU (Frankfurt). Used for: serving the Service, including branded pages on any custom domain you connect.
- Neon — managed (serverless) PostgreSQL, our primary application database. Region: EU (Frankfurt); provider US-incorporated, SCCs apply.
- Cloudflare R2 — object storage for files, attachments, and PDFs. Region: EU.
- Cloudflare Turnstile — the automated-abuse check on the sign-up, email-verification and waitlist forms; it receives your IP address and browser signals when you use those forms. Region: global (SCCs).
- Resend — transactional and marketing email delivery. Region: EU/US (SCCs).
- Sentry — error and performance monitoring (production errors with request context). Region: EU/US (SCCs).
- SMSbrana.cz — outgoing SMS notifications if enabled by you. Only the phone number and message text are shared.
4.2 Platform billing (JobMistr subscriptions)
For JobMistr subscriptions (the plans you pay to use JobMistr), payments are processed by Stripe Payments Europe, Ltd. (Ireland). JobMistr is the seller; Stripe processes the payment and acts as an independent controller for fraud screening and its own regulatory compliance, and as our processor for the payment transaction. Card numbers never touch JobMistr systems. See stripe.com/privacy.
4.3 Provider-elected payment gateways
Each JobMistr provider may connect one or more of the following gateways to accept payments from their own end clients. These are activated only by your express configuration in Settings → Integrations and process personal data only when you have connected them. The provider is the controller for those flows; the gateway is the controller for fraud/AML/screening purposes and a processor for the payment itself.
- Stripe Payments Europe, Ltd. — Ireland. Cards, SEPA, Apple/Google Pay.
- GoPay s.r.o. — Czech Republic. Czech market gateway covering cards, Apple/Google Pay, bank buttons.
- ComGate Payments, a.s. — Czech Republic. Cards and online banking.
- Twisto payments a.s. — Czech Republic. Buy now, pay later.
- Revolut Payments UAB — Lithuania. Multi-currency checkout. SCCs apply where applicable.
- PayPal (Europe) S.à r.l. et Cie, S.C.A. — Luxembourg. Cards + PayPal balance.
- Direct bank transfer — no third-party processor; only your IBAN is shown on the invoice + QR code.
4.4 Other elective integrations
- Google LLC (Calendar / Sign-in with Google) — only when you explicitly enable a Google integration. Tokens held encrypted with restricted scopes. SCCs apply.
- Microsoft Corporation (Outlook / Entra ID) — only when you enable the integration. SCCs apply.
- Apple Inc. (Sign-in with Apple, ICS calendar sync) — only when you enable the integration.
- Meta Platforms (WhatsApp Business / Cloud API) — only when you connect a WhatsApp number; message content and phone numbers are exchanged with Meta to deliver messages. SCCs apply.
- Enable Banking Oy — Finland. Open-banking (PSD2) access to bank account transaction data, only when you connect a bank account through your bank's own consent flow. [REMOVE — aggregator no longer used]
- [ADD] Email bank feed — when you enable it, you configure your bank, or a forwarding rule in your own mailbox, to send transaction-notification emails to a unique address we generate for you. We receive and parse those emails to record your transactions and match them to your invoices and expenses. This is not an open-banking (PSD2) account-information service and involves no third-party account-access provider; we do not access your bank account. The emails are received on our email infrastructure (see 4.1) and stored encrypted at rest.
- [ADD — belongs in §4.1 core sub-processors] Fastmail Pty Ltd — inbound email hosting (our support mailbox and the bank-feed mailbox that receives your bank's transaction-notification emails). Australia-incorporated, data hosted in the US; SCCs apply.
- Your own email provider (IMAP/SMTP) — only when you connect a mailbox; messages are exchanged directly with the provider you choose.
- Webhook endpoints you configure — if you enable the API and webhooks, data about the events you subscribe to is sent to the URL you specify. You control that destination and are responsible for its security.
- ISDS (datová schránka) — the Czech state data-box system, operated by the Czech state. When you connect your data box and initiate a filing, the content is transmitted to ISDS. The state is an independent recipient, not our sub-processor.
We may also disclose personal data to professional advisers (lawyers, accountants, auditors) bound by duties of confidentiality, to acquirers in connection with a merger or sale of the business (with appropriate notice), and to public authorities where required by law.
5. International transfers
Where a sub-processor processes personal data outside the European Economic Area, the transfer is governed by the European Commission's Standard Contractual Clauses (SCCs) or another legally recognised transfer mechanism. We assess each transfer in line with the EDPB's recommendations following Schrems II.
6. Retention
- Active accounts — for as long as you use the Service.
- Deleted workspaces — when you initiate workspace deletion, data is retained for thirty (30) days for recovery, then hard-deleted from our active systems.
- Individually deleted records — records you delete inside the Service (for example an invoice or client) can be restored for sixty (60) days, after which the snapshot is permanently erased.
- Invoices and accounting records — accounting documents and books are retained for five (5) years and financial statements for ten (10) years from the end of the accounting period under Czech Act No. 563/1991 Coll. (§31), and longer where the records remain necessary for tax proceedings (up to the ten-year tax-assessment limit under Act No. 280/2009 Coll., §148).
- Audit log — seven hundred and thirty (730) days by default; longer where needed for legal-defence purposes.
- Server / security logs — typically 90 days rolling.
- Marketing engagement data — for as long as you have an active marketing opt-in plus thirty (30) days after withdrawal. The consent ledger itself (when you opted in or out, and which version) is kept as proof of compliance.
- Waitlist data — a sign-up you never confirm is deleted after thirty (30) days. A confirmed sign-up is kept until six (6) months after we send you your early-access email (or, if that email cannot be delivered, six months after our last attempt), and in any case no longer than six (6) months after JobMistr first opens to everyone, or until you leave the list, whichever comes first — leaving deletes it. So that our waitlist form does not email you again for twelve (12) months after you leave (even if someone else types your address into it), we keep for that time only a coded one-way value derived from your address, from which the address cannot be read; write to us if you want to join again sooner. Every email we send has a link to leave the list; you can also write to privacy@jobmistr.com. Opening an account does not change this: your waitlist entry follows these periods, and your account data follows the account retention above.
- Backups — retained on a rolling 30-day basis; erasure requests applied to live systems immediately and to backups on the next restore cycle.
- Per-category retention settings — you can configure automatic deletion windows for synchronised emails, documents, forms, and job images in Settings; a nightly job enforces them.
7. Your rights
Under GDPR (and equivalent provisions of Czech Act No. 110/2019 Coll.) you have the following rights, exercisable free of charge:
- Access (Art. 15) — confirm whether we process your data and obtain a copy. Self-service: Settings → Data & export (a ZIP archive of JSON files).
- Rectification (Art. 16) — correct inaccurate or incomplete data. Self-service: Settings → Profile / Business.
- Erasure (Art. 17) — request deletion where one of the grounds applies. Self-service: Settings → Data & export → Delete workspace.
- Restriction (Art. 18) — request that we limit how we use your data while a dispute is resolved. Email privacy@jobmistr.com.
- Portability (Art. 20) — receive your data in a machine-readable format (the export above is JSON).
- Object (Art. 21) — object to processing based on legitimate interests, or to direct marketing at any time (one-click unsubscribe in every marketing email per RFC 8058).
- Withdraw consent (Art. 7(3)) — for any processing based on consent, withdraw at any time without affecting prior lawful processing.
- Waitlist — to see or delete your waitlist entry, email privacy@jobmistr.com from the address you joined with, or use the leave link in any waitlist email. Deleting your account in Settings does not remove a waitlist entry.
- Lodge a complaint (Art. 77) — with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic, or with your local supervisory authority.
We respond to verified data-subject requests within one (1) month and may extend by two further months for complex requests under Art. 12(3).
8. Automated decision-making
We do not make decisions producing legal or similarly significant effects based solely on automated processing (Art. 22). The Service's job-matching feature is an information aid — the decision to accept an offer always rests with you.
9. Children
The Service is not directed at children under sixteen (16) and we do not knowingly collect personal data from them. If you believe a child has registered, email privacy@jobmistr.com and we will delete the account.
10. Cookies and similar technologies
We currently use only strictly necessary cookies (session authentication, anti-CSRF, locale preference) — these do not require consent under ePrivacy. If we introduce analytics or marketing cookies, we will present a consent banner before any non-essential cookie is set, in line with the Czech Electronic Communications Act (Act No. 127/2005 Coll. §89) and ePrivacy Directive.
11. Security
We apply the technical and organisational measures described on our Security page, including field-level AES-256-GCM encryption at rest for sensitive personal data (such as emails, phone numbers, addresses, bank details, message content, and integration credentials). No system is perfectly secure; we will notify you of personal-data breaches in line with Art. 33-34 GDPR.
12. Changes to this Policy
Material changes will be notified by email and in-app banner at least thirty (30) days in advance. The version and effective date at the top of this page reflect the current revision. Earlier versions are available on request.
13. Contact
Email: privacy@jobmistr.com. Postal address: Korunní 2569/108, Vinohrady, 101 00 Praha 10. JobMistr has not yet appointed a Data Protection Officer; we will publish contact details here when one is appointed. This Policy is published in Czech and English; in case of conflict the Czech version prevails.