Privacy Policy

Last updated: 05.05.2025

1. Introduction

Welcome to Connection Finder ("we", "us", "our"). This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our web application to upload LinkedIn connections and filter them for specific job opportunities.

2. Who is the controller?

MxSchons GmbH
Berliner Promenade 18
66111 Saarbrücken
Germany
acts as the data controller for all processing described in this notice. You can reach our Data Protection Officer (DPO) at max@peregrineproject.org.

3. What data we process & why

  • Connection URLs you upload (necessary to identify profiles you wish to evaluate).
  • Public LinkedIn profile fields (e.g. headline, work history, education, skills). We never circumvent technical measures or scrape hidden content.
  • Referral metadata (job ID, timestamp, your referral note, recruiter ID) when you choose to forward a candidate.

We process this data solely to assess each connection's suitability for the specific vacancy you selected and to let you decide whether to share the candidate's details with the recruiter.

4. Legal basis — legitimate interests (Art. 6 (1)(f) GDPR)

Our processing relies on our and the recruiter's legitimate interests in facilitating precise, candidate–friendly recruiting while respecting individuals' reasonable expectations to be approached for relevant roles. Our Legitimate Interests Assessment (LIA) concluded that these interests are not overridden by candidates' rights and freedoms. Key findings:

  • Purpose: Enable users to identify and refer the most relevant LinkedIn contacts for a defined job opening, thereby increasing the chances of mutually beneficial employment matches.
  • Necessity: Reviewing publicly available profile data is the least intrusive method to verify basic role fit before making contact. Alternative methods (mass email outreach, generic advertising) would create higher volumes of unsolicited communication.
  • Balancing & safeguards: We (i) limit collection to job–relevant fields, (ii) discard inferred or publicly available sensitive data (e.g. religion, sexual orientation, union membership), (iii) cache profile data for max 90 days, (iv) inform candidates at first outreach, and (v) honour Article 21 objections without delay.

You may object at any time to processing based on legitimate interests (see Section 8).

5. Sharing your data

We don't share candidate or profile information with the recruiter who created the referral link. You have to actively choose to forward a candidate. We do not sell or otherwise disclose data to third parties for independent purposes.

6. Retention

  • Cached candidate profile data: 90 days from initial retrieval.
  • Referral logs & audit data: 180 days after a referral is completed or withdrawn.
  • We immediately delete profile data if a candidate objects to processing.

7. Security measures

All systems are hosted on Fly.io's managed platform. We protect personal data with TLS 1.3 in transit, role–based access control, regular penetration tests, and least–privilege policies.

8. Your privacy rights

Under the GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and to receive a portable copy. To exercise any right, email us your LinkedIn profile URL at max@peregrineproject.org. You also have the right to lodge a complaint with your local supervisory authority.

9. International transfers

We store and process all application data on servers located in Fly.io's US data centres. Fly.io participates in the EU–US Data Privacy Framework and offers the Fly.io Privacy Policy. We have a Data Processing Agreement with them to provide an adequate safeguard for your personal data. Copies of the DPA are available on request.

10. Updates to this policy

We may update this notice from time to time. We will post the revised version here and, if the changes are significant, notify you by email or in–app alert. Please review this page periodically.