GDPR Compliance

Your data rights under the General Data Protection Regulation

Compliant

Your Rights Under GDPR

Right to Access

You can request a complete copy of all personal data we hold about you. Export your data anytime from Settings > Privacy > Export Data. We will respond to formal requests within 30 days.

Right to Rectification

You can update or correct your personal information at any time. Edit your profile in Settings or contact us to correct any inaccuracies in your data.

Right to Erasure

Also known as the "right to be forgotten." You can delete your account and all associated data from Settings. Data is permanently removed within 30 days of deletion request.

Right to Data Portability

You can download your data in standard, machine-readable formats (JSON, PDF). This includes your profile, assessments, career plans, resumes, and portfolio data.

Right to Object

You can opt out of AI processing of your data at any time from Settings. You can also object to marketing communications and analytics tracking.

Right to Restrict Processing

You can request that we limit how we process your data while a dispute is being resolved. During restriction, your data is stored but not actively processed.

Legal Basis for Processing

We process your data under the following lawful bases:

Consent

When you create an account and agree to our terms. You can withdraw consent at any time.

Contract

To provide the career development services you signed up for (assessments, career plans, job matching).

Legitimate Interest

To improve our platform, prevent fraud, and ensure security. We balance our interests against your privacy rights.

International Data Transfers

Your data may be processed in countries outside the European Economic Area (EEA)
We use Standard Contractual Clauses (SCCs) approved by the European Commission to safeguard transfers
All data transfers are encrypted using TLS 1.3 in transit and AES-256 at rest
Our cloud providers maintain EU-compliant data processing agreements

Data Protection Officer

Our Data Protection Officer oversees GDPR compliance
Contact: dpo@oforo.ai
Response time: Within 30 days for formal requests
You may also lodge a complaint with your local supervisory authority if you believe your rights have been violated

For more information, review our full policies: