Privacy policy
What this service stores about you, why, for how long, and what rights you have. Information under Articles 13 and 14 GDPR.
1. Controller
The controller for the processing of your data on jobshub.win is:
- Roman Zhuchenko
- c/o Block Services, Stuttgarter Str. 106
- 70736 Fellbach
- Deutschland
- Email: kontakt@phantom-creator.com
- Telegram: @phantom_kanzler_bot
There is no data protection officer: the service is run by one person and the conditions of Article 37 GDPR are not met.
2. In short
JobsHub is a closed, free service that shows publicly available job offers for Germany in one place. Data processing is deliberately kept as small as possible:
- no advertising, no tracking, no analytics tools such as Google Analytics and no social media buttons;
- no data is sold, rented out or passed on for advertising;
- no profile is built about you and nothing about your behaviour on other sites is recorded;
- the pages load nothing from third-party servers: no fonts, no scripts, no images. The only exception is the bot check on the login page;
- no account is needed. A name, an address, a CV or application documents are never collected here.
Applications do not go through this service. When you apply you leave the site and your data goes straight to the employer or to the source of the offer.
3. Opening the site and hosting
The site runs on Cloudflare infrastructure (Cloudflare Germany GmbH, Rosental 7, 80331 Munich, for Europe; Cloudflare, Inc., 101 Townsend St., San Francisco, USA). Cloudflare provides the server, the database and the protection against attacks.
When a page is opened, Cloudflare processes technically necessary connection data: IP address, date and time, requested address, status code, amount of data transferred, browser identifier and the previously visited page, if your browser sends it.
- Purpose: to deliver the page, find faults and fend off attacks.
- Legal basis: Article 6(1)(f) GDPR. My legitimate interest is a reachable service protected against abuse.
- Storage: the logs stay with Cloudflare and are deleted there after a few days. I keep no access logs with IP addresses of my own.
A data processing agreement under Article 28 GDPR is in place with Cloudflare. The database of this service is located in Western Europe. Cloudflare runs a global network, so a request may also be handled outside the EU. See section 10.
4. Access and login
The service is not public. There are two ways in and you choose which one you take.
Way 1, access with a password. The password is only checked and never stored. After a correct entry the service sets a signed session cookie (see section 5). So that nobody guesses the password, a counter is stored on a failed attempt. Instead of your IP address only an irreversible check value of that address is kept (HMAC-SHA-256 with a secret key). Legal basis is Article 6(1)(f) GDPR, the interest being protection against automated attacks. The counters are deleted at the latest 24 hours after the block ends.
The login page also runs Cloudflare Turnstile, a check whether a human or a program submits the form. Turnstile transmits your IP address and technical details of your browser to Cloudflare. Turnstile sets no advertising cookies and does not follow you across sites. Legal basis is Article 6(1)(f) GDPR.
Way 2, login through Telegram. This way is voluntary: anyone who does not want it can use the password. If you log in through Telegram, the following data is processed:
- your Telegram identifier (a number),
- first name, last name and username as far as you gave them in Telegram, plus the language code of your Telegram account,
- whether you are subscribed to the related Telegram channel and when this was last checked,
- the time of the first and the last contact, and the login itself (request id, state, timestamps).
The only purpose is access control: the service is visible to subscribers of the channel and to people I let in personally. Legal basis is Article 6(1)(b) GDPR for the use of the service and Article 6(1)(a) GDPR for your decision to use this particular way in. You can withdraw that consent at any time with effect for the future by writing to me; I then delete the related data and access runs through the password.
For the login and for the bot, Telegram acts as its own provider (Telegram FZ-LLC, Dubai, United Arab Emirates). What Telegram processes itself is described in its privacy policy at telegram.org/privacy. On the transfer to a third country see section 10.
If you lose access, for example by leaving the channel, the marks of offers you opened are deleted. Your Telegram identifier is kept as long as it is needed for the access check and no longer than your withdrawal.
5. Cookies and browser storage
The service sets only cookies that are necessary for it to work. All of them are first-party, unreadable for scripts in the browser (httpOnly) and valid over HTTPS only.
| Name | Purpose | Lifetime |
|---|---|---|
| jh_session | signed session after the login with a password | 7 days |
| jh_telegram_session | signed session after the login through Telegram | 90 days |
| jh_device | random identifier of this browser for the shortlist and the daily translation limits; not tied to a person or to an IP address | 1 year |
| __cf_bm and similar by Cloudflare | detection of automated access, protection of the site | up to 30 minutes |
Because all of these cookies are strictly necessary within the meaning of section 25(2)(2) TDDDG, there is no consent banner here. You can delete cookies in your browser; you then have to log in again and the shortlist of this browser is empty.
Your browser also keeps small interface settings in its local storage. Those stay on your device and are not sent to me.
6. Features of the service
Search. Your search words, the place and the filters are part of the page address and are passed on to the sources that answer live: the Federal Employment Agency and Adzuna. My server makes that request, not your browser, so those sources never learn your IP address or your identifiers. Answers are cached for up to 30 minutes without any link to a person. Legal basis is Article 6(1)(b) GDPR, because this is exactly the service you asked for.
Translation. On request the service translates search words, titles and the text of an offer. A language model at Cloudflare (Workers AI) does that work. Only the text itself is sent, no identifier of yours. According to Cloudflare these inputs are not used to train its models. Finished translations are stored so that the same offer is not translated twice. Legal basis is Article 6(1)(b) GDPR.
Daily limits. So that one browser cannot use up the translation budget, the service counts per day how often the jh_device identifier asked for a translation. Only the date, the identifier and a number are stored. Legal basis is Article 6(1)(f) GDPR, the interest being a fair share of a limited resource.
Shortlist. When you save an offer, the jh_device identifier, the offer, the employer, the place and the time are stored. The list belongs to the browser, not to you as a person, and it stays until you remove the entry or delete the cookie. Legal basis is Article 6(1)(b) GDPR.
Marks of opened offers. So that the list shows what you have already looked at, the offer id and the time are stored, tied to your Telegram identifier or, without a Telegram login, to the jh_device browser identifier. These marks are deleted automatically after 90 days and immediately when access ends. Legal basis is Article 6(1)(f) GDPR, the interest being a readable result list.
Place suggestions. While you type in the place field, the page asks my own server for matching place names. Those requests are not stored and go to no third party.
7. Data inside the job offers
The collected offers are publicly published texts. They may contain personal data of third parties, for example the name, email address or telephone number of a contact person at the employer. The service shows them as the source published them, together with the link to the original.
Legal basis is Article 6(1)(f) GDPR. The legitimate interest is to show job seekers the way to apply; the employer pursues the same interest by publishing the offer. The data comes from the public sources listed in section 9. Informing every named person individually would take disproportionate effort under Article 14(5)(b) GDPR, which is why this policy provides the information here.
If you are named in an offer shown here and do not want to be, write to me on any channel from section 1. I remove the offer or the detail at once.
8. Who receives the data
Your data goes to nobody who is not named here. There is no sale and no disclosure for advertising.
| Recipient | For what | Role |
|---|---|---|
| Cloudflare | running the site, database, protection against attacks, translation through Workers AI | processor under Article 28 GDPR |
| Telegram | the voluntary login and the messages of the bot | independent provider |
Data goes to authorities only where the law obliges me to hand it over.
9. Where the offers come from
My server fetches the offers from public interfaces. Your browser never talks to those providers unless you click a link yourself.
- Federal Employment Agency (job search and statistics)
- service.bund.de
- Arbeitnow
- Jobicy
- Adzuna
- employer career pages on Personio, Greenhouse, Lever, Ashby, SmartRecruiters, Recruitee, Workable and Teamtailor
- Eurostat for the labour market figures
10. Transfers to third countries
Cloudflare runs a global network, so a request may be handled outside the European Union. The Standard Contractual Clauses of the European Commission are part of the data processing agreement with Cloudflare. Cloudflare, Inc. is also certified under the EU-US Data Privacy Framework.
If you use the Telegram login, the data named in section 4 is transferred to Telegram in the United Arab Emirates. There is no adequacy decision of the European Commission for that country and no Standard Contractual Clauses between Telegram and me. There is therefore a risk that authorities there access the data and that your rights are harder to enforce. You decide yourself whether to use this way; the transfer is based on your explicit consent under Article 49(1)(a) GDPR. Anyone who wants to avoid it uses the password.
11. Storage periods
| Data | Period |
|---|---|
| Connection data at Cloudflare | a few days, deleted by Cloudflare |
| Counters of failed login attempts | up to 24 hours after the block ends |
| Session with a password | 7 days |
| Session through Telegram | 90 days, earlier if access is lost |
| Telegram identifier, name, username, language | until consent is withdrawn or access ends for good |
| Shortlist | until you remove the entry or the cookie |
| Marks of opened offers | 90 days, immediately when access is lost |
| Daily translation counters | daily values, with no further link to a person |
| Job offers and their translations | while the offer is current, then removed from search |
12. Your rights
Towards me you have the following rights:
- access to the data stored about you (Article 15 GDPR),
- rectification of incorrect data (Article 16 GDPR),
- erasure (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- objection to processing based on legitimate interests (Article 21 GDPR),
- withdrawal of a given consent with effect for the future (Article 7(3) GDPR).
An informal message to the email address or the Telegram contact from section 1 is enough. I answer within one month. Since I hold nothing that identifies you apart from the Telegram identifier and random browser identifiers, I may need further details to match the data safely (Article 12(6) GDPR).
You may also lodge a complaint with a data protection supervisory authority (Article 77 GDPR), for example with Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, https://www.baden-wuerttemberg.datenschutz.de. The authority of your place of residence is competent as well.
13. Right to object
Where I process data on the basis of legitimate interests under Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. Here this concerns the protection against attacks, the marks of opened offers, the daily counters and the display of contact details inside job offers. After an objection I stop that processing unless I can show compelling legitimate grounds which override your interests.
14. Is providing data mandatory
You are not required by law or by contract to provide anything. Without the technically necessary data from sections 3 to 5 the service cannot work: without the session cookie the login is not kept, and without a login the service is closed.
15. No automated decision-making
There is no automated decision-making in individual cases and no profiling within the meaning of Article 22 GDPR. The order of the results and the machine classification of an occupation depend only on the content of the offer and on your query, not on any characteristic of you as a person.
16. Links to other sites
Offers and sources open on other websites. From the click onwards the privacy policy of that provider applies and it sees your IP address. So that as little as possible is revealed about you, this site sends no referrer ("no-referrer" policy).
17. Security
- Access runs over HTTPS only, enforced by HSTS.
- Session cookies are signed, httpOnly, secure and limited to this site (SameSite).
- Every changing request is checked for its origin, and the login form additionally by a one-time token and a growing block after failures.
- A strict Content Security Policy allows only the scripts of this site.
- The password and all keys are kept as secrets at the provider and are not in the source code.
18. Changes to this policy
When the service changes, this text changes with it. The version published here always applies; the date is at the end of the page.
Controller: Roman Zhuchenko, c/o Block Services, Stuttgarter Str. 106, 70736 Fellbach, Deutschland.
Updated: September 18, 2026Legal notice (Impressum)