Privacy notice
Effective 18 July 2026JOBE Recruit is operated by Christopher John Howitt, a sole trader trading as JOBE Recruit. He is the controller for account, billing, support and product-usage information and for corporate prospect research that JOBE sources or creates for the lead marketplace. A recruiter or recruitment business using JOBE is normally the controller for candidate, client and outreach information placed in its workspace; JOBE processes that workspace information on the customer’s instructions to provide the service.
Postal address awaiting completion
The operator is Christopher John Howitt, a sole trader trading as JOBE Recruit. A valid postal or service address has not yet been supplied and must be added before commercial launch. Until the notice is completed, contact chrisjhowitt@gmail.com for privacy and data-protection requests.
Information we process
- Account information: name, email address, account identifier, authentication events, invited team membership and role.
- Recruitment workspace information: candidate CVs and contact details, assessments, employment information, jobs, clients, call notes and transcripts, shortlists, feedback, tasks and commercial records entered by an authorised user.
- AI requests and results: the advert, screenshot, CV, transcript or other text submitted for a requested AI function, the resulting structured output and limited request metadata.
- Billing and entitlement information: plan, subscription status, transaction references and lead-credit activity received from Stripe. JOBE does not receive or store full card details.
- Business prospect information: public corporate identity, company number, status, company type, sector, registered-office locality, website or other public corporate contact route, source and retrieval details, recruitment-fit scoring, and recruiter-prepared outreach notes used in the lead marketplace. A company’s identity and active status may be verified against Companies House; employee bands, recruitment-fit scores, likely hiring needs, “why now” signals, suggested decision-maker roles and outreach wording are estimates or AI-assisted inferences unless a specific dated source is shown. JOBE does not sell private personal contact details or infer an individual’s email address or phone number.
- Support and feedback: contact details, messages, bug reports, account-deletion requests, ratings and any diagnostic context the user chooses to send.
- Technical information: security events, request timing and basic network or device information needed to operate, protect and troubleshoot the service.
- Optional analytics: approved JOBE screen names and page counts after the visitor allows analytics. Candidate names, client names, record identifiers and route parameters are not deliberately added to analytics events.
Information comes from customers and their authorised users, from people whose information a customer enters, from authentication, payment and hosting providers used to deliver the service, and for marketplace research from Companies House and public pages operated by the relevant business, such as its website, contact page or careers page. JOBE does not treat professional-networking profiles or the mere public availability of personal information as permission to collect or market to an individual.
Why information is used
| Purpose | Basis where JOBE is controller |
|---|---|
| Open and secure an account, provide subscribed functions and administer billing | Performance of the customer contract and legitimate interests in delivering a secure service |
| Research, score, maintain and provide corporate prospect records through the lead marketplace | Performance of the service requested by the customer for non-personal corporate information. If a record contains personal information, JOBE relies on legitimate interests in providing proportionate business-to-business research, subject to a documented purpose, necessity and balancing assessment and the safeguards below. |
| Respond to support, investigate faults, prevent abuse and keep necessary records | Contract, legitimate interests and legal obligations where applicable |
| Send service notices about access, billing, security or material product changes | Contract and legitimate interests; these are not promotional messages |
| Count approved page and screen visits | Consent, which can be withdrawn at any time |
When JOBE processes a customer’s recruitment workspace, it acts on that customer’s instructions. The customer decides its lawful basis and is responsible for telling candidates, clients, prospects and call participants how their information is used. JOBE does not sell customer, candidate or client information and does not use workspace records for advertising. Lead credits purchase access to JOBE’s separately controlled corporate-prospect research and public corporate contact routes; they do not purchase ownership of a person’s data or permission to market unlawfully.
Corporate prospect research and direct marketing
- Corporate focus: the marketplace is intended for incorporated companies and other corporate subscribers. JOBE does not present a sole trader, an unincorporated partnership or an organisation whose subscriber type is uncertain as automatically eligible for unsolicited electronic marketing.
- Contact boundary: JOBE limits marketplace-sourced routes to public corporate channels, such as a company switchboard, company-owned contact or careers page, or a generic role mailbox. It does not sell named individuals, personal or direct email addresses, mobile numbers, inferred email patterns, or Companies House officer or person-with-significant-control details.
- Verification: “verified” refers only to the corporate fact and source expressly identified. AI-assisted estimates and suggested sales wording remain hypotheses for the recruiter to check and are not evidence that a business is hiring or will respond.
- Transparency: if JOBE obtains personal information indirectly and no legal exception applies, JOBE will provide the affected person with the required privacy information within a reasonable period and no later than one month, at the first communication if earlier, or before the information is disclosed if that happens first. If JOBE cannot use or disclose the information fairly and lawfully, it will not offer it as a marketplace contact.
- Objections and suppression: an individual may object at any time to use of their personal information for direct marketing. JOBE will stop that use and may retain the minimum identifier needed on a suppression list so the information is not added again. To help prevent an accidental paid unlock, JOBE also keeps one-way hashes derived from normalised company identifiers in the customer or team suppression list; these hashes are checked before marketplace credits are charged. A customer must still maintain and apply its own suppression records for outreach it controls.
The customer becomes a separate controller for the outreach it chooses to make and for any named contact it adds to its workspace. Before contacting a prospect, the customer must establish a lawful basis, distinguish corporate subscribers from sole traders and relevant partnerships, give required privacy information, screen applicable TPS, CTPS and internal suppression lists, identify itself, provide a working opt-out and honour objections promptly.
AI, audio and automated assistance
- Requested CV, screenshot, job-advert, candidate, client and recruitment-text analysis may be sent to OpenAI.
- Requested audio transcription may be sent to OpenAI. If browser speech recognition is chosen, speech may instead be processed by the browser or operating-system provider.
- JOBE’s server sends only the content needed for the selected function. Provider API keys stay server-side.
- JOBE does not persist uploaded call-audio bytes. They are held for the transcription request and discarded after it completes. The resulting transcript is stored only when the user saves or retains it.
- AI output can be wrong or incomplete. A recruiter must review it before relying on it, sharing it or using it in a hiring process. JOBE should not be used to infer protected characteristics or make solely automated employment decisions.
Customers must minimise what they submit, have a lawful basis for candidate information, and obtain any consent or give any notice required before recording or transcribing a conversation.
Providers and international processing
JOBE currently uses Supabase for authentication, individual cloud workspace storage and synchronisation; Railway for application and API hosting and shared Business workspace storage; Stripe for checkout and subscription management; OpenAI for requested AI analysis, transcription and some support assistance; Google for sign-in and optional Google Analytics; and Resend for support and team-invitation email delivery.
These providers may process information in the UK, EEA, United States or another location used by their services. Where restricted transfers apply, JOBE relies on the provider’s applicable contractual safeguards and the customer should assess whether additional measures are required for its use. The current processing summary and subprocessor roles are set out on the Security and data processing page.
Storage and retention
- Workspace: an individual workspace is synchronised to the customer’s authenticated Supabase workspace. A shared Business workspace is stored in JOBE’s protected Railway application database and made available only after server-side account, plan and team-membership checks. An authorised user’s browser may also hold a local copy. Workspace information remains until the customer deletes records or asks for account deletion, subject to necessary backup, dispute and legal retention.
- Browser data: account-scoped workspace data is cleared from that browser when the user signs out. Clearing browser site data can also remove local information that has not finished synchronising.
- Transcripts: a customer can select 30, 90, 180 or 365 days and apply that policy. When it runs, expired transcript text is removed from the active workspace; a summary and audit marker may remain.
- AI cache: JOBE may retain the AI result, an input hash and limited request metadata for up to 30 days to avoid repeating identical processing. The cache does not store the original prompt as a separate readable field, although the output itself may contain personal information.
- Client shortlist links: links stop working after 30 days and may be revoked earlier. Expiry prevents public access but is not, by itself, immediate deletion of the underlying shortlist record.
- Team recycle bin: a recoverable copy of a deleted shared record is kept for up to 30 days unless the Business owner restores or permanently deletes it earlier. The recoverable copy is automatically purged when that period ends; a minimal deletion or activity marker may remain where needed to prevent an older device from restoring the record or to maintain a proportionate security audit.
- Marketplace research: an unlocked corporate prospect remains available in the customer workspace until it is deleted or account access ends. Source verification and premium AI insight display their retrieval time and should be refreshed or rechecked after 14 days because public information and business circumstances change. JOBE keeps the supporting source snapshot and unlock audit only while needed to deliver and evidence the unlock, investigate accuracy or charge complaints, prevent abuse and meet legal obligations, and reviews them for deletion or anonymisation when those purposes end. A minimal suppression entry may be retained for longer where necessary to respect an objection.
- Billing, credits, support, feedback and security: these records are retained for service operation and then only as long as reasonably needed for support, fraud prevention, accounting, disputes and legal obligations.
An in-product account-deletion request creates a support request; it does not cancel an active Stripe subscription. The customer must separately cancel the subscription in the billing portal.
Security and team access
JOBE uses HTTPS, authenticated sessions, server-side provider secrets, request limits and workspace access controls. Supabase row-level policies restrict each individual workspace to its authorised account. Requests for a shared Business workspace are checked by JOBE’s server against the owner’s active plan and the authenticated user’s team membership and role. Shared records are visible to the owner and members the owner invites, so the owner must remove access promptly when it is no longer required. The owner can pause member credit spending, set a member monthly cap and control whether members may move shared records to an owner-managed recycle bin; permanent deletion is owner-only. A redacted activity history records team-level changes without copying CV, transcript or contact-field contents into the activity entry. Public shortlist access is limited to a specific link, expires after 30 days and can use a hashed access PIN.
No online service can promise absolute security. Current controls, limitations and a security-reporting route are described at Security and data processing.
Your choices and rights
Depending on the circumstances, a person may request access, correction, erasure, restriction, portability or objection, and may withdraw consent. An individual has an absolute right to object to processing of their personal information for direct marketing; JOBE will stop that processing while retaining only what is necessary to honour the suppression. Customers can export workspace information, change analytics consent, apply transcript retention and request account deletion inside JOBE. Candidate, client or customer-added prospect requests should normally go first to the recruiter or recruitment business that collected the information, because it controls that workspace. A request about prospect research sourced by JOBE may be sent directly to JOBE.
For information controlled directly by JOBE, email chrisjhowitt@gmail.com with the account email and “privacy request” in the subject. Identity may need to be verified. You may also complain to the UK Information Commissioner’s Office.
Contact
Signed-in users can use Help → Contact support. Anyone can email chrisjhowitt@gmail.com. Do not send a CV, identity document or other unnecessary personal information in an initial support email.