1. Who we are and what this policy covers
Jobara in Syria is responsible for the personal information it processes to operate its website, available applications, recruitment tools, CV services and support channels. In this policy, “we” means Jobara. Personal information means information that identifies a person or can reasonably be linked to them. You can contact us about privacy through the website’s contact or support page.
This policy covers visitors, job seekers, employer representatives and people who contact us or whose information is provided through these services. Employers are separately responsible for their recruitment decisions and their own use of candidate information. External websites and sign-in providers also have their own privacy notices. The Cookie Policy and Job Seeker and CV Policy provide additional detail about the activities they cover.
2. Information you provide
Account and identity information: your name, email address, phone number where provided, account type, language, sign-in methods, verification status and account preferences. If you use an external sign-in or verification service, we receive the profile, identifier or verified contact information that service shares through the permissions you grant.
Career and application information: profile descriptions, experience, education, skills, languages, location, work preferences, photographs, CVs and attachments, screening answers, application history and messages. Provide only information relevant to the service. Avoid including identity documents, health information or other sensitive details in public profiles or ordinary messages unless there is a clear, lawful need.
Employer and company information: business and representative details, registration or verification documents, addresses, logos, public vacancies, team memberships and permissions, candidate lists, internal notes, interview assessments and recruitment activity. Company information can also be personal information when it identifies an individual.
Purchases and enquiries: orders, payment references, amounts, currency, status, receipts or evidence you submit, credit use, refund requests, support correspondence, reports and bug submissions. Do not send passwords, sign-in codes or full payment credentials through support. Any payment provider or bank also handles information under its own terms and privacy notice.
Optional contributions: survey responses, salary and currency information, related role, experience and location details, and text you submit to writing or translation tools. Salary responses are linked to your account internally to manage participation and data quality; they are not anonymous merely because published insights use grouped statistics.
3. Information generated or received through the service
We process technical information such as IP address, browser and device details, request times, session identifiers, security events and diagnostic information to operate and protect the service. Cookies and similar storage also remember sign-in state, preferences and consent choices. Optional browser analytics are described in section 7.
We record service activity such as applications, status changes, CV access and downloads, messages, invitations, interview scheduling, purchases, notification delivery and policy acceptance. Where relevant, acceptance and audit records include the version, time, account and technical context. Mobile notifications may require a device delivery token, platform details and permission status.
Information may also come from employers and their authorised team members, other users, people submitting reports, and service providers confirming identity, delivery or payment events. For example, an employer may record an interview assessment or a reference contact. Anyone providing another person’s information must have an appropriate lawful basis and any permission required for that use.
4. Why we use information
We use account and technical information to register and authenticate users, manage access and preferences, provide support and keep the service reliable. Missing required information may prevent us from providing the requested feature; optional information can be omitted unless it is needed for a feature you choose.
We use career, company and recruitment information to display profiles and vacancies, support search and relevant results, process applications, enable authorised candidate review, arrange interviews and deliver recruitment communications. We use purchase records to fulfil paid services, maintain credit balances, reconcile payments and resolve billing enquiries.
We use reports, security signals and relevant activity records to investigate fraud, abuse and technical problems, enforce platform rules, protect users and handle disputes. Optional surveys and permitted analytics help us understand salary trends and service performance. We also keep records needed to meet applicable legal duties and demonstrate policy choices and account actions.
Processing must have a basis permitted by applicable law. Depending on the purpose and legal framework, this may be providing a service you request or performing a contract, meeting a legal obligation, pursuing a legitimate and proportionate operational or security interest where permitted, or obtaining consent where required. Acknowledging this policy is not blanket consent to every use. Where consent is the basis, you may withdraw it for future processing without changing the lawfulness of earlier processing.
5. CV visibility and employer access
Creating an account does not, by itself, make every CV public. Access depends on the relevant CV visibility, publication and sharing settings, profile discoverability and recruitment workflow. Employer sourcing access also depends on the candidate-pool settings and eligibility rules. Paid credits do not override these controls or give an employer ownership of candidate information.
Applying for a job gives the relevant employer and its authorised recruitment team access to the information and CV attached to that application. This access is separate from candidate-pool visibility. Making a CV private, leaving the candidate pool, withdrawing an application, or closing a vacancy does not automatically erase the application or revoke that employer’s existing application-based access. Current submissions capture the relevant profile and CV presentation and the screening questions and answers. Later edits to the live CV do not automatically replace the captured application content. Older records or unavailable materials may not provide the same complete presentation.
A person with a valid CV sharing link may be able to open or forward it. Revoking a link or changing visibility can restrict future access through Jobara, but cannot reliably recall downloaded files, screenshots or other copies. Account deletion follows section 11. Contact the relevant employer about information it keeps independently; Jobara can address access and processing within its own service.
Employer tools may hold internal notes, screening answers, interview assessments and decision history. Access is limited by company and team permissions; internal employer records are not ordinarily shown in the candidate interface. This does not remove any access or other right available under applicable law.
6. Public information and other recipients
Published job adverts, public company information and editorial content can be seen by visitors and search engines and may be distributed through Jobara’s official channels. Information you intentionally include in public content may therefore be copied or indexed by others. Private CVs, messages and verification documents are not public advertising material merely because you uploaded them.
Authorised Jobara staff may access information for support, moderation, verification, security or other necessary operational duties. Providers may process relevant information for hosting, file storage and delivery, authentication, email and push delivery, payment processing, diagnostics, security and optional AI features. They receive information relevant to their function; processor arrangements must include applicable confidentiality, security and data-protection requirements.
Examples of integrated services include Cloudflare for infrastructure and anti-bot checks, supported identity providers for sign-in or contact verification, Expo for mobile push delivery, and OpenAI for available AI assistance. The services involved depend on the feature and active configuration. You may ask support for current recipient and processing-location information relevant to your data.
We may disclose information where lawfully required by a competent authority, or where necessary and lawful to address fraud, protect people, establish or defend legal claims, or carry out a business transfer. Such disclosure must be limited to what the purpose requires and subject to applicable safeguards. An employer’s paid access is for authorised recruitment, not permission to resell candidate data or use it for unrelated marketing.
7. Cookies, analytics and salary insights
Essential cookies and similar storage support authentication, security, preferences and consent records. The cookie-preferences control lets you accept or reject optional browser analytics and change your choice. Refusing optional analytics does not stop the operational records needed to submit an application, process an order or protect an account.
With analytics enabled, browser events can measure advert impressions, detail views and the start of an application. Employer reporting also uses recruitment events such as submissions and stage changes. Reports present totals and trends; the reporting design excludes message bodies and direct candidate identifiers and suppresses certain small groups to reduce identification risk. A pseudonymous identifier is not the same as completely anonymous data.
If you allow optional analytics, Google Analytics processes limited website events and browser identifiers for usage, acquisition and successful-action reporting. Our Cookie Policy describes the information sent, cookie lifetimes, Google retention settings and how to withdraw consent. Refusal does not prevent you from using Jobara. Google acts as a service provider for this measurement; processing can take place outside your country under the applicable service terms and safeguards. See how Google uses information from partner sites (https://policies.google.com/technologies/partner-sites). Withdrawing consent stops future optional measurement but is not itself a request to delete previously collected data. Contact us through the routes in this policy for questions or applicable data-rights requests.
Salary surveys are optional. Responses may be combined with role, experience and location information to produce insights. Public statistics should describe groups rather than identify a respondent, and publication depends on the applicable minimum sample requirements. Authorised administrators may access individual responses for survey administration and quality checks. The Cookie Policy explains storage choices in more detail.
8. AI assistance and automated processing
Available AI assistance helps draft a professional bio or CV summary, improve selected wording, suggest experience descriptions, and translate selected text. When you request one of these features, relevant existing profile or CV fields, source text, instructions and language choices are sent to the AI provider to produce suggestions. These are writing tools; Jobara does not provide AI extraction or parsing of uploaded CV files. You can continue editing manually without using AI. Review the information supplied and avoid unnecessary sensitive or confidential material.
Jobara keeps generated results and usage records as needed to return suggestions, prevent duplicate requests, manage limits and investigate problems. Content you accept into your profile or CV becomes part of that saved content. Providers can have separate security and retention requirements; these tools should not be understood as guaranteeing zero retention by every provider.
Jobara may also use AI to translate approved public job-advert text and prepare short descriptions for its official distribution channels. Private candidate files are not the source for that publishing workflow.
Search, filters and automated security checks help organise or protect the service. Employers can configure screening questions and disqualifying answers; matching a disqualifying rule can automatically mark an application as rejected on submission, before human review. This rule-based screening is separate from AI writing assistance and does not involve AI parsing of an uploaded CV. Employers remain responsible for their criteria and recruitment assessments. If a screening result appears mistaken or discriminatory, contact the employer through an available channel and use Jobara support or reporting tools for a platform or policy concern. You may request review and an explanation available under applicable law, including for other automated restrictions; a request does not guarantee a changed hiring outcome.
9. Communications and device choices
We use contact details and delivery information for security alerts, application and order updates, support replies and legal notices. Optional job alerts, newsletters and promotional messages can be managed through the available notification preferences or unsubscribe options. Essential service messages may still be needed while you use the relevant service.
Mobile push delivery depends on device permissions and notification settings. You can change these in the app or device settings. Notification previews may be visible to someone using your device, so adjust lock-screen settings if needed. Signing in through an external provider or changing device permissions does not automatically delete information already held by Jobara.
10. How long we keep information
Retention depends on the type of information, the feature you use, account and application history, unresolved enquiries or disputes, security needs and applicable recordkeeping obligations. We keep identifiable information only for a justified purpose and delete, redact or anonymise it when that purpose ends, subject to necessary legal holds. Information genuinely anonymised so that it no longer identifies you may remain in statistics.
The current employer-analytics schedule removes raw events older than 400 days and daily aggregates older than 730 days through scheduled cleanup. Standard notification inbox records have a 180-day cleanup threshold; required notices have a 395-day threshold. These schedules apply to those records, not to the separate application, transaction or legal-acceptance records from which they may arise.
Account, CV, application and company records remain subject to their operational purpose and the deletion process below. Payment, audit, dispute and security records can require longer limited retention. Backups and technical recovery copies follow their own controlled lifecycle, so deletion from the active service does not mean every backup copy disappears immediately. Ask support for the retention criteria relevant to a particular record.
Google Analytics retention settings are separate from the employer-analytics schedules above. Our Cookie Policy explains Google retention, analytics-cookie lifetimes and withdrawal of consent.
11. Account deletion
Use the deletion process in account settings or the website’s account-deletion page. The process requires authentication and confirmation. A company owner must transfer ownership before deleting their personal account. If cleanup cannot finish, follow the retry or support guidance shown; do not assume completion until the service confirms it. Completed deletion cannot be reversed.
The deletion process removes or redacts identity and profile information, CV content and files, application answers and notes, interview assessments, message content, connected submissions, surveys, notification data, sign-in credentials and related personal material. Some historical links and records remain after identifying content has been removed, including application status history, legal acceptance, company access history and transaction or credit records.
A limited deletion record is retained to document completion and support accountability. Deletion does not automatically remove information independently retained by an employer, bank, external service or someone who received a copy. Their own responsibilities and any applicable legal duties continue to apply. Removing the app from a device is not an account-deletion request.
12. Your choices and privacy requests
You can update available profile and account fields, manage CV visibility and sharing, change optional notification and cookie preferences, and request account deletion. You may also contact Jobara to ask about your information, request access or correction, or raise a privacy concern. Where applicable law provides them, rights may include erasure, restriction, objection, a portable copy and safeguards concerning significant automated decisions.
To make a request, use the website’s contact or support page, describe what you need and identify the relevant account or record. We may request proportionate proof of identity or authority before disclosing or changing information. Do not send passwords or sign-in codes. An authorised representative may need to show permission to act for you.
We will assess the request under applicable law, explain any lawful limitation and respond within the period that law requires. Rights can be limited by another person’s rights, necessary recordkeeping or a valid legal exception; a request does not automatically require disclosure of someone else’s confidential information. You may ask us to review our response and use any complaint or court remedy available through the competent authorities. This policy does not restrict those rights.
13. Security
We use access controls, authentication safeguards and other technical and organisational measures to reduce unauthorised access, loss and misuse. Access to private information should be limited to the people and services that need it. No internet service can promise absolute security. Protect your sign-in methods and sharing links, and report suspected compromise promptly. If a personal-data incident occurs, we will assess it and notify affected people or authorities where applicable law requires.
14. Processing outside Syria
Jobara serves users in Syria, but providers and recipients may process or store information in other countries. The location depends on the service and its configuration; a recipient country may have different privacy protections. International processing must follow applicable legal requirements and any safeguards required for the transfer. Contact support for information about relevant recipients, locations and applicable safeguards. Using Jobara or acknowledging this notice does not waive mandatory transfer protections or replace a separate consent that the law requires.
Processing outside Syria includes Google Analytics data when you allow optional analytics, as described in section 7 and our Cookie Policy.
15. Children and information about others
Jobara is a career and recruitment service. Use must comply with the legal-capacity and working-age requirements described in the Terms of Service and applicable law. Do not submit a child’s information or use the service on their behalf without lawful authority and any required safeguards. If you believe information has been collected from a child improperly, contact support so we can review and address it. References and other third-party information must also be provided lawfully and only when relevant.
16. Policy changes and contact
The published policy shows its version and effective date. We will explain material changes through appropriate website, in-app or email notices and obtain any separate consent required before a new use of information. A policy update does not itself authorise an incompatible new purpose. Contact Jobara through the website’s contact or support page for questions, requests or complaints about privacy. The Arabic and English versions are intended to communicate the same practices and rights; please report any discrepancy.