Privacy

Privacy Policy

This policy explains what personal data Nexorgo processes, why we process it and what rights you have under GDPR.

This page explains how the Nexorgo marketplace handles platform data, processors and commercial terms.

Controller: Nexorgo, Amsterdam, Netherlands. Legal entity details are provided in the platform operator records.

Contact: privacy@nexorgo.com

Last updated: July 21, 2026

Who we are

Nexorgo is a recruitment marketplace for agencies, companies and job seekers. The platform helps users create accounts, compare agencies, publish jobs, apply to jobs and manage candidate CVs.

For most platform processing Nexorgo acts as controller. Agencies and companies may also act as independent controllers for their own hiring decisions.

Data we collect

Account data: name, email address, password hash, role, verification status and authentication tokens.

Agency data: business profile, branches, logo, contact details, KYB information, verification status and job listings.

Job seeker data: saved agencies, followed jobs, applications, CV files, messages and deletion requests.

Technical data: IP address, browser/device information, security logs, cookie preferences and server logs.

Why we use data

To provide the service, authenticate users, display agencies and jobs, process applications and route hiring requests.

To keep the platform secure, prevent abuse, debug errors and comply with legal obligations.

With consent, to use optional analytics or marketing cookies. You can withdraw consent at any time.

Legal bases

Contract: to create and operate your account, dashboard, applications and agency profile.

Legitimate interests: platform security, fraud prevention, service improvement and business communication, balanced against user rights.

Legal obligation: accounting, compliance, dispute handling and regulatory requests where applicable.

Consent: optional cookies, marketing emails and other consent-based processing.

Sharing and processors

We share application data with the agency or company related to the job or request. CVs are only made available where needed for recruitment workflows.

We may use hosting, database, email, analytics, file storage and security providers as processors. Add your exact provider list before launch, including Vercel, Render, database hosting, email providers and any analytics tools you enable.

Retention

We keep account data while the account is active. Authentication logs and security records are kept only as long as needed for security and compliance.

Users can delete CVs and request permanent account deletion. Some records may be retained where required for legal claims, accounting or abuse prevention.

Your rights

Depending on your situation, you may request access, correction, deletion, restriction, portability, objection and withdrawal of consent.

You can manage cookies from the footer link. You can delete CVs and request account deletion from your dashboard.

International transfers and security

Where providers process data outside the EEA, appropriate safeguards such as standard contractual clauses should be used.

We use HTTPS, hashed passwords, httpOnly authentication cookies, role-based access and restricted CV download routes.