LAST UPDATED: July 4, 2018
All capitalized terms that are not otherwise defined herein are defined in the "Terms".
What Information Do We Collect?
Our primary purpose in collecting personal information from you is to enable us to provide the Services that you have requested and registered for in a safe, smooth, efficient, and customized manner. This allows us to provide services and features that most likely meet your needs, and to customize our Service to match your needs. We only collect personal information about you that we consider necessary for achieving this limited purpose.
Personal and Identifying Information
In general, you can browse our Sites without telling us who you are or revealing any personal information about yourself. However, the various types of Users of our Services must provide various contact and identity information and other personal information that we refer to as Registration Data, as required for us to provide the Services. Once the Registration Data has been provided to use, you consent to our processing of the personal information contained in your Registration Data, and you are no longer anonymous to us. Where possible we endeavor to indicate which data fields are required and which fields are optional. In addition, as you use the Services, you can from time to time enter or send to us additional personal information
For all Users, we may collect and you consent to our use of your name, password, e-mail address, address, telephone number, education information, career and personal preferences, and any other personal information you choose to include in your profile or communicate to OptimalResume or other Users through your use of the Services. We do not collect and discourage you from including personal data revealing your racial or ethnic origin, political opinions, religious of philosophical beliefs, trade union membership, genetic data, biometric data, other health data, or data concerning your sex life or sexual orientation. Administrator and employer users may input additional information relating to their organization or employment opportunities. You expressly agree and represent that you have the right and authority, and have obtained all necessary consents, to provide any Registration Data or other information, including any personal information that is provided by you to OptimalResume.
You always have the option to not provide your personal information by choosing not to become a User or by not using the particular feature of the Services for which the information is being collected.
Some accounts on the Services, including, but not limited to employer accounts, are paid accounts. If you have signed up for a paid account, we may collect your credit card information and you consent to our processing of this information for billing or payment purposes.
Information Collected Automatically
Server Log Files
Our Internet pages collect a series of general data and information when a data subject or automated system calls up the website. This general data and information are stored in the server log files. Collected may be (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (so-called referrers), (4) the sub-websites, (5) the date and time (so-called timestamp) of access to the Internet site, (6) an Internet protocol address (IP address), (7) the internet service provider (ISP) of the accessing system, and (8) any other similar data and information that may be used in the event of attacks on our information technology systems.
When using this general data and information, we do not draw any conclusions about the data subject. Rather, this information is needed to (1) deliver the content of our website correctly, (2) optimize the content of our website as well as its advertisement, (3) ensure the long-term viability of our information technology systems and website technology, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in case of a cyber-attack. Therefore, we analyze pseudonymously collected data and information statistically, with the aim of increasing the data protection and data security of our enterprise, and to ensure an optimal level of protection for the personal information we process. The pseudonymous data of the server log files are stored separately from all personal information provided by a data subject.
How We Use Your Information
We comply with our obligations under GDPR by keeping personal information up to date where needed based on the purposes for which the personal information is being processed; by not collecting or retaining excessive amounts of data; and by ensuring that appropriate technical measures are in place to protect personal information from loss, alteration, misuse, unauthorized access and disclosure as it is transmitted, stored, or otherwise processed, and by using appropriate measures to securely destroy personal information when it is no longer needed by us.
Please see our "Terms" for information on what we do to account information when you terminate your User Account.
Our Disclosure of Your Information
Data Shared with Other Users through the Service. The data collected through the use of the Services, including personally identifiable information, may be shared with other Users upon your consent and in each instance in accordance with the permissions set to your User Account. End User Client Administrators (for example, career counselors or case managers) have visibility to End User’s profile information and files. Also, the Services may permit you to apply to jobs of interest to you. By applying for such a job posting, you will be sharing your personal information with the posting Employer.
Aggregated Data. You consent to our aggregation of your data, and you further consent to our use and disclosure of such information for a variety of purposes, including data analytics. However, in these situations, we do not disclose any information that could be used to identify you personally.
Public Areas of the Services. Users may be able to post Content that is viewable by others through the Services. For example, students can elect to share their resume with career counselors. All User Content posted by a User will be identifiable to that User’s username and you consent to such use.
Subsidiaries and Affiliates; Service Providers.. You consent to our use of affiliates, subsidiaries and unrelated service providers in the operation of the Services, and you consent to our disclosure of personal information to them in order to provide the services you have requested. For example, we may use the services of third-party hosting companies to host the operation of our Sites. This may involve the hosting of data, including personal information, on servers operated by those hosting companies. We may also use service providers to process payments of Users who wish to pay by credit card. We take care to use only service providers that we believe are reputable, who have agreed to comply with all applicable laws, and who are able to maintain the security of personal information and confidential information.
Storing or Processing Your Data Outside of the United States
Your personal information and other data is generally stored on servers in the United States. However, in some cases, personal information that we collect may be stored or processed outside of the United States. In such cases, we continue to protect the information with appropriate safeguards, but it may be subject to the legal jurisdiction of those countries and governmental authorities in those countries.
We will transfer personal information abroad only when there has been a documented adequacy determination, or where we have confirmed adequate privacy protections. If we transfer personal information abroad to a third party acting as our agent, we will also require the third party to have adequate privacy protections in place. We will transfer personal information to and on behalf of us and/or third party’s with whom we have an existing service agreement or as part of our legal obligations, each of which shall be subject to our policies, and only to the extent necessary for purposes of legitimate interests pursued by the data controller (or by a third party).
Sale of Business
You also consent to our disclosure of personal information to the acquirer or its agents in the course of the sale of our business. If we do this, the disclosure will be subject to confidentiality arrangements customary in such transactions.
Legal Basis For Processing Your Personal Information
For EU subjects, in respect of each of the purposes for which we use your personal information, the GDPR requires us to ensure that we have a legal basis for that use if you are within the EU. Art. 6(1) of the GDPR serves as the legal basis for processing operations for which we obtain the grounds to process personal information for a specific processing purpose. The legal bases depend on the services you use and how you use them. This means we collect and use your personal information only where:
We may also rely on your consent as a legal basis for using your personal information where we have expressly sought it for a specific purpose. If we do rely on your consent to a use of your personal information, you have the right to change your mind at any time (but this will not affect any processing that has already taken place).
Where we need to process your personal information either to comply with law, or to perform the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with the functionalities of the Services). In this case, we may have to stop you using our Services.
Duration of Storage of Your Personal Information
The criteria used to determine the period of storage of personal information is the underlying purpose for which the data was obtained and the related legal requirements. When the legal basis for retaining the information no longer exists, the corresponding data is routinely deleted, as long as it is no longer necessary for the fulfillment of the purpose for which our legal basis for processing was established.
More specifically, we retain your information for as long as your account is active or it is reasonably needed for the purposes set forth herein unless you request that we remove your personal information as described herein. We will only retain your personal information for so long as we reasonably need to use it for these purposes unless a longer retention period is required by law (for example for regulatory purposes). This may include keeping your personal information after you have deactivated your account for the period of time needed for us to pursue legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes and enforce our agreements.
Your rights and your personal information
If you are an EU resident, you have the right under this Privacy to:
How to exercise your rights.
If you are an EU resident and you want to exercise any of the rights described above, please contact us using the contact details below.
Typically, you will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, except in relation to Consent Withdrawal, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive, or, we may refuse to comply with your request in these circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal information (or to exercise any of your other rights). This is a security measure to ensure that personal information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Automated Decision Making
Your personal information will not be subject to automated decision making.
The data Controller for the purposes of the GDPR, other data protection laws applicable in Member states of the European Union and other provisions related to data protection this is:
PO Box 729
Pittsboro, NC 27312
Phone: +1 (877) 998-7654
We encourage interested EU subjects to raise any concerns about the collection, use, or processing of personal information using the contact information provided. In the event of a privacy related issue or complaint, we will investigate and attempt to promptly resolve any complaints and disputes regarding use and disclosure of personal information.
For complaints that cannot be resolved, we commit to cooperating with the panel established by the EU data protection authorities (DPAs) or the Swiss Federal Data Protection and Information Commissioner (FDPIC), as applicable, and to reasonably comply with the advice given by the panel or Commissioner about personal information transferred from the EU or Switzerland. In order to facilitate the handling of complaints, individuals in the EU can choose to contact their national DPA or use the form located at this link:
GDPR. On May 25, 2018, the General Data Protection Regulation (GDPR) takes effect in the European Union (EU). OptimalResume is committed to helping its partners and customers comply with GDPR.
Individuals in Switzerland can contact the Swiss Information Commissioner by visiting:
This independent dispute resolution process is provided at no cost to the individual.
Your OptimalResume User Account is protected by a password that you choose to protect your privacy and security. It is your sole responsibility to create, and periodically change, a strong password in order to prevent unauthorized access to your account, and to protect your password appropriately, and limit access to your computer or mobile device.
OptimalResume runs its computing services on Amazon Web Services (AWS) infrastructure. AWS has been architected to be one of the most flexible, reliable, scalable and secure cloud computing environments available today. We use industry security best practices, such as the use of SSL certificates to ensure a safe and secure environment. All data in transit is encrypted using industry-standard Secure Sockets Layer (SSL), a cryptographic protocol that is designed to protect against eavesdropping, tampering, and message forgery. All data is encrypted at rest using one of the strongest block ciphers available, Advanced Encryption Standard 256 (AES-256), a symmetric key encryption standard using 256-bit encryption keys.
While we strive to protect your information and data we cannot guarantee the security of your User Account information. Unauthorized entry or use, hardware or software failure and other factors, may compromise the security of user information at any time.
Other Information Collectors
It is our goal to make our privacy practices easy to understand. If you have questions, concerns or if you would like more detailed information, please email our privacy officer at email@example.com.