devradar.hu · Legal documents
Privacy Policy
Effective from 10 July 2026 · Last updated: 19 August 2026 · Terms · Cookie Notice
1. Controller
- Digital Dynamics Kft. · 2724 Újlengyel, Nyári Pál utca 15., Hungary · Tax no.: 32509072-1-13
- Privacy contact: info@digitaldynamics.hu
Processing complies with the GDPR (EU 2016/679) and the Hungarian Privacy Act. Data is stored on the Provider's EU-based server.
2. Data, purposes, legal bases, retention
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
👤 Account data email, display name, password (hashed), Google/GitHub ID |
registration, sign-in | 6(1)(b) contract |
until account deletion |
🧑💻 Developer profile bio, skills, links, uploaded files (e.g. CV) — public only if you set it visible |
voluntary profile page | 6(1)(a) consent |
until deletion |
📨 Applications, messages application text, screening answers, conversations — visible to the advertiser. You can withdraw an application at any time in your account; your text is deleted immediately and the advertiser only sees that you stepped back. |
contacting the advertiser | 6(1)(b) contract |
90 days after withdrawal; 12 months once closed (rejected/hired); at most 24 months in any case — or until account deletion, whichever comes first |
💰 Salary submissions salary value detached from your identity; only the fact of submission is linked to the account |
anonymous salary statistics | 6(1)(b) contract |
statistics are anonymous; access is deleted with the account |
🔔 Job alerts email, search criteria |
sending alert emails | 6(1)(a) consent |
until unsubscribe |
🧾 Billing details name, address, tax number — when using paid services |
invoicing | 6(1)(c) legal obligation (Accounting Act) |
8 years |
📊 Visit & click measurement visited path or the fact of a click on a profile element (website, CV, GitHub…) + a random anonymous token and a salted, truncated fingerprint of the IP (the raw IP is not stored, no profiling), plus — if you arrived from another site — the DOMAIN of the referring page (without path or search term) — see section 7 |
improving the portal; aggregate profile statistics for developers | 6(1)(f) legitimate interest |
the token expires after 14 days; the log row is kept for at most 1 year, after which only aggregated reports remain |
🕒 Last activity a single timestamp: when you last used the service — overwritten. We do NOT store alongside it which pages you viewed, from which device or IP address; it is refreshed at most once per hour, so it cannot support minute-level movement tracking |
operating the service, managing inactive accounts | 6(1)(b) contract + legitimate interest |
90 days from the last activity, then deleted; immediately on account deletion |
🛡️ Security log IP address, event, path |
detecting and preventing abuse | 6(1)(f) legitimate interest |
90 days; abuse-related events up to 1 year |
✉️ Email log recipient, subject, status |
troubleshooting delivery | 6(1)(f) legitimate interest |
up to 90 days |
🔌 MCP & API log endpoint, tool and response code called, response time; for failed responses also a salted hash of the IP address (we do not store the raw IP). Contains no request or response content. |
measuring the machine interface, detecting errors and abuse | 6(1)(f) legitimate interest |
successful calls 365 days (contain no personal data); failed calls 60 days |
🤖 Crawler impersonation log the source IP address of the request, the name it claimed to be (e.g. “Googlebot”), the path group and a daily counter. A record is created ONLY when the request itself claims to be an automated search crawler AND the address is demonstrably absent from that provider’s officially published IP ranges. A human visitor’s IP address is NEVER stored here — visit measurement continues to store only a salted, truncated hash. We do not store the User-Agent, the full URL, cookies, headers or session identifiers. |
detecting and preventing unauthorised, deceptive use of the service; evidencing claims that protect our database | 6(1)(f) legitimate interest (GDPR Recital 49: network and information security; and sui generis database protection) |
90 days |
No automated decision-making or profiling takes place. Listing recommendations ("similar jobs") are based solely on the opened listing's attributes, not on you.
2/A. Data not obtained from you — job listings and company data
Most listings on this site do not come from us or directly from the advertiser, but from employers' own publicly available careers systems (ATS), and from job boards whose terms explicitly permit it. Article 14 GDPR requires us to inform you about this even if you never heard of us:
- What data: where the employer named a contact person in the listing text, that name and contact detail also appear in the text shown here. We do not extract or index it separately.
- Source: the source is shown on every listing, together with a link to the original posting.
- Why: legitimate interest (Art. 6(1)(f) GDPR) — so the jobseeker sees the complete listing and knows who to contact. We do not use it for marketing or outreach, and we do not pass it on.
- How long: until the listing expires. When it disappears from the source, it closes here too.
- What you can do: your rights under section 4 apply here as well, and you can request removal at any time via our takedown form — you do not have to establish an infringement to do so.
Company names, logos, trademarks. We display company names and logos solely for identification, so that jobseekers can see which employer is hiring. Trademarks and logos remain the property of their respective owners; their display does not imply any partnership, endorsement or other relationship between Dev Radar and the company. Removal requests can be filed here.
3. Recipients, processors
- netcup GmbH (Karlsruhe, Germany) — hosting provider (data-processing agreement in place).
- Google / GitHub — only if you sign in via OAuth.
- Stripe (card payments) and Billingo (e-invoicing) — when using paid services; card data is handled solely by Stripe.
- VIES (European Commission) — validating tax numbers entered on the billing form.
- Zippopotam.us — non-Hungarian postcode → town lookup (no personal data transferred).
- ipinfo.io — geolocating crawler (bot) IPs only; human visitors' IPs are never sent.
- Analyzza — cookie-less, anonymised web analytics (operated within the Provider's sphere).
- Google Cloud EMEA Limited (Vertex AI, EU region) — only when AI features are used (section 8); content is processed within the EU and may not be used for model training.
- Emails are sent by the Provider's own mail server; no third-party newsletter service.
4. Your rights
You may request access to, rectification or erasure of your data, restriction of processing, data portability, and you may object to processing based on legitimate interest. Consent can be withdrawn at any time. You can also delete your account and profile yourself in account settings.
Send requests to info@digitaldynamics.hu; we reply within 30 days.
5. Remedies
You may lodge a complaint with the Hungarian supervisory authority (NAIH, 1055 Budapest, Falk Miksa u. 9–11.; naih.hu) or bring the matter to court.
6. Cookies
The site uses only strictly necessary cookies and no third-party tracking — see the Cookie Notice.
7. First-party, anonymous visit & click measurement
The portal measures — on its own server, without any third party — how many people view individual pages (such as developer profiles) and how many click on profile elements (website link, CV, GitHub/LinkedIn profile, portfolio links, certificates). For this we store:
- a randomly generated anonymous identifier in the session cookie — it contains no personal data, does not track you across other websites, and expires after 14 days; its sole purpose is to distinguish "unique visitors" from total views;
- a salted, truncated fingerprint of the IP address (the raw IP is never stored and the fingerprint is not practically reversible) — used exclusively to filter out automated bot traffic.
- if you arrived from another website, that site's domain (e.g. "google.com") — the domain only: the path and any search term that the referrer may contain are never stored. This shows us which sites send us visitors; navigation between our own pages is not included.
There is no profiling, no cross-site tracking, no advertising use and no data sharing. Developers only see aggregate numbers about their own profile (e.g. "5 unique visitors clicked your website") — neither they nor we can identify who the visitor was. The legal basis is legitimate interest (Art. 6(1)(f) GDPR); given its nature it does not require consent, and you may object as described in section 4. The profile owner's own visits are not counted.
Apply click. When you click the “Apply” button on a job listing, we record the fact of the click — which listing someone set off from to apply. The button takes you straight to the employer's own site; we do not redirect through ourselves and have no access to the content of your application. For this we store a salted hash of your IP address whose salt changes every day, so the same visitor cannot be linked across two different days. The employer only ever sees an aggregate number; neither they nor we can identify you. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). The measurement stores nothing on and reads nothing from your device (it is neither a cookie nor a comparable technology), so it does not require consent; you may object as described in section 4.
Campaign tag. If you arrive by clicking one of our ads, the link carries our own, fixed-format tag (for example fb-devs1) that tells us which ad brought a visitor. We keep it for the duration of your session and, if you register, attach it to your account so we can see which campaign is worth running. The tag says nothing about you: it only identifies our own ad, its format is validated against a pattern, and anything that doesn't match is discarded. There is no Facebook, Google or other advertising pixel in our system, we pass no data to advertising platforms, and we do not track you across other websites. Legal basis: legitimate interest (Art. 6(1)(f) GDPR); you may object as described in section 4.
8. AI-powered features (Google Cloud Vertex AI, EU)
Some features of the portal use artificial intelligence. Each of them runs at the user's own initiative. The table below shows, feature by feature, what we pass to the model and what happens to the result — no feature sends more than this:
| Feature | What the model receives | What happens to the result |
|---|---|---|
AI job search (/ai-search) |
The text of your search query. Nothing else — no identifier, no profile, no history. Personal data (email address, phone number, tax number, bank account) is automatically stripped before sending, and we tell you on screen when this happens. | The model only writes search filters (e.g. “Python”, “Budapest”, “remote”). The actual search and the result cards come from our own database, not from the model. We do not store your query — neither in a database nor in a log. |
AI conversational search (/ai-chat) |
The same as above, plus the text of earlier turns of the conversation. The conversation lives in your browser and is sent back from there on each turn; closing the page ends it. Developer profile data never passes through the model — the server looks it up and renders it. | As above. No cookie, no database, no server-side log retains the conversation. |
| Profile fill from CV | The text of the CV (PDF) you upload, or the description you write about yourself. | A structured profile suggestion which you review and approve before saving. |
| Web CV generation | The profile data you provided. | A shareable CV page you can remove at any time with a single click. |
| Employer helpers | The listing data you entered (role, technologies, company). | Job-description drafts and screening-question suggestions that you edit and approve. |
| Pre-screening of submitted listings | The text of the submitted listing (not personal data). | A flag for the moderator. It never decides on its own and never rejects automatically — the final decision is always made by a human. |
Which AI we use, and where it runs. Processing is performed by Google Cloud Vertex AI using the Gemini 3.1 Flash Lite model, exclusively in a data centre located in the European Union (EU region). If we change the model or the provider, we will update this page accordingly.
Disclosure of machine interaction (Art. 50 EU AI Act). The AI search and the conversational interface are a machine system, not a human — we state this permanently in the interface and mark every machine reply separately. Machine replies can be wrong; the advertiser is responsible for the content of listings. The system does not evaluate or rank candidates, does not filter applications, and makes no decision about you — it only assembles search filters from what you write yourself. It therefore does not fall under the high-risk systems in Annex III point 4 (employment, recruitment) of the AI Act. We do not infer any characteristics about you and do not place you into any group.
Data processor. Google Cloud EMEA Limited acts as data processor under the Google Cloud Data Processing Addendum; submitted content is not used to train Google's models and is not retained persistently after processing. The Provider only passes the minimum content required for the given feature, and where we retain the result, it is stored on its own EU-based server.
Legal basis. Using the AI features is voluntary — the legal basis is performance of contract (Art. 6(1)(b) GDPR), and for processing an uploaded CV, your explicit request. For the AI search and the conversational interface we process no personal data: the query is not stored and is not linked to a person. No automated decision-making with legal effect takes place (Art. 22 GDPR).