Privacy Policy

LAST UPDATED: July 4, 2018

OptimalResume.com, Inc. ("OptimalResume", "ThinkOptimal", "we", "us", "our" and terms of similar meaning) understands that your privacy rights are important to you. Therefore, we provide this Privacy Policy in order to describe our privacy practices, including how we collect, use, process, store, and disclose your information and data in the course of providing our Services (as that term is defined in our Terms of Use also referred to as the "Terms").

We encourage you to read and understand our "Terms" and this Privacy Policy before using our Services. By accepting the "Terms" and Privacy Policy in registration for the Services, you will be required to expressly agree and consent to our collection, use and disclosure of your personal information in accordance with this Privacy Policy. This Privacy Policy is incorporated into and subject to our "Terms".

Our processing of personal information, such as names, addresses, e-mail addresses, and/or telephone numbers, shall, when required by applicable law, be undertaken consistent with the requirements of the General Data Protection Regulation ("GDPR"). For purposes of GDPR, OptimalResume may, depending on the circumstances, be a data controller or a data processor, as defined by GDPR (contact details below). When OptimalResume is the data controller, this means we decide how your personal information is processed and for what purposes, although our ability to process your personal information may be subject to your rights under the GDPR, which we have described below. Whether as the data controller or data processor, we have implemented numerous technical and organizational measures to protect the processing of personal information processed through this website. However, Internet-based data transmissions may in principle have security gaps, so absolute protection may not be guaranteed. We have put in place procedures to deal with any actual or suspected personal information breach. In the event that personal information is compromised as a result of such a breach of security, we will notify those persons whose personal information has been compromised, in accordance with the notification procedures set forth in this Privacy Policy and as required by law.

All capitalized terms that are not otherwise defined herein are defined in the "Terms".

What Information Do We Collect?

Our primary purpose in collecting personal information from you is to enable us to provide the Services that you have requested and registered for in a safe, smooth, efficient, and customized manner. This allows us to provide services and features that most likely meet your needs, and to customize our Service to match your needs. We only collect personal information about you that we consider necessary for achieving this limited purpose.

Personal and Identifying Information

In general, you can browse our Sites without telling us who you are or revealing any personal information about yourself. However, the various types of Users of our Services must provide various contact and identity information and other personal information that we refer to as Registration Data, as required for us to provide the Services. Once the Registration Data has been provided to use, you consent to our processing of the personal information contained in your Registration Data, and you are no longer anonymous to us. Where possible we endeavor to indicate which data fields are required and which fields are optional. In addition, as you use the Services, you can from time to time enter or send to us additional personal information

For all Users, we may collect and you consent to our use of your name, password, e-mail address, address, telephone number, education information, career and personal preferences, and any other personal information you choose to include in your profile or communicate to OptimalResume or other Users through your use of the Services. We do not collect and discourage you from including personal data revealing your racial or ethnic origin, political opinions, religious of philosophical beliefs, trade union membership, genetic data, biometric data, other health data, or data concerning your sex life or sexual orientation. Administrator and employer users may input additional information relating to their organization or employment opportunities. You expressly agree and represent that you have the right and authority, and have obtained all necessary consents, to provide any Registration Data or other information, including any personal information that is provided by you to OptimalResume.

You always have the option to not provide your personal information by choosing not to become a User or by not using the particular feature of the Services for which the information is being collected.

Payment Information

Some accounts on the Services, including, but not limited to employer accounts, are paid accounts. If you have signed up for a paid account, we may collect your credit card information and you consent to our processing of this information for billing or payment purposes.

Information Collected Automatically

In order for you to use the Services, we automatically collect some information about you. Unless otherwise stated in this Privacy Policy, OptimalResume aggregates this type of information from all of its Users and only uses such information in aggregate form and not to identify any individual User.

Cookies

Our Internet pages utilize cookies. Cookies are text files that are stored in a computer system via an Internet browser. We only use cookies that are essential for the Services to work properly. We do not use tracking cookies or cookies for analytics, advertising, or other functional services like survey and chat tools. When you use the Services, you consent to our use of these essential cookies. We use essential cookies for:

  • Sign-in and Authentication. We use cookies to authenticate you. When you sign in, we store a unique ID number and the time you signed in, in an encrypted cookie on your device. This cookie allows you to move from page to page within the site without having to sign in again on each page.
  • Security. We use cookies to process information that helps us secure our products, as well as detect fraud and abuse.
  • Performance: We use cookies to make sure that our websites remain up and running by redirecting traffic to a load balancer.
The data subject may, at any time, prevent the setting of cookies through our website by means of a corresponding setting of the Internet browser used, and may, as a result, deny the future setting of cookies. Furthermore, already set cookies may be deleted at any time via an Internet browser or other software programs. This is possible in all popular Internet browsers. If the data subject deactivates the setting of cookies in the Internet browser used, not all functions of our website may be entirely usable.

Server Log Files

Our Internet pages collect a series of general data and information when a data subject or automated system calls up the website. This general data and information are stored in the server log files. Collected may be (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (so-called referrers), (4) the sub-websites, (5) the date and time (so-called timestamp) of access to the Internet site, (6) an Internet protocol address (IP address), (7) the internet service provider (ISP) of the accessing system, and (8) any other similar data and information that may be used in the event of attacks on our information technology systems.

When using this general data and information, we do not draw any conclusions about the data subject. Rather, this information is needed to (1) deliver the content of our website correctly, (2) optimize the content of our website as well as its advertisement, (3) ensure the long-term viability of our information technology systems and website technology, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in case of a cyber-attack. Therefore, we analyze pseudonymously collected data and information statistically, with the aim of increasing the data protection and data security of our enterprise, and to ensure an optimal level of protection for the personal information we process. The pseudonymous data of the server log files are stored separately from all personal information provided by a data subject.

How We Use Your Information

We comply with our obligations under GDPR by keeping personal information up to date where needed based on the purposes for which the personal information is being processed; by not collecting or retaining excessive amounts of data; and by ensuring that appropriate technical measures are in place to protect personal information from loss, alteration, misuse, unauthorized access and disclosure as it is transmitted, stored, or otherwise processed, and by using appropriate measures to securely destroy personal information when it is no longer needed by us.

You consent to our access and use of your Registration Data and other information we obtain from you, and other information we obtain from your current and past activities on the Services, to (1) provide the Services to you; (2) resolve service disputes; (3) troubleshoot problems; (4) measure consumer interest in our products and services, inform you about job opportunities, services, events and updates; (5) customize your experience; (6) detect and protect us against error, fraud and other criminal activity; (7) enforce our "Terms"; (8) provide you with system or administrative messages; (9) and as otherwise agreed to by you and described to you at the time of collection or in an updated version of this Privacy Policy.

Please see our "Terms" for information on what we do to account information when you terminate your User Account.

Our Disclosure of Your Information

We will not share your personal information with third parties except as described in this Privacy Policy and in accordance with your User Account settings and permissions. We will not sell or rent your personally identifiable information to third parties without your explicit consent. The following describes some of the ways that your information may be disclosed in the normal provision of the Services to you:

Data Shared with Other Users through the Service. The data collected through the use of the Services, including personally identifiable information, may be shared with other Users upon your consent and in each instance in accordance with the permissions set to your User Account. End User Client Administrators (for example, career counselors or case managers) have visibility to End User’s profile information and files. Also, the Services may permit you to apply to jobs of interest to you. By applying for such a job posting, you will be sharing your personal information with the posting Employer.

Aggregated Data. You consent to our aggregation of your data, and you further consent to our use and disclosure of such information for a variety of purposes, including data analytics. However, in these situations, we do not disclose any information that could be used to identify you personally.

Public Areas of the Services. Users may be able to post Content that is viewable by others through the Services. For example, students can elect to share their resume with career counselors. All User Content posted by a User will be identifiable to that User’s username and you consent to such use.

Subsidiaries and Affiliates; Service Providers.. You consent to our use of affiliates, subsidiaries and unrelated service providers in the operation of the Services, and you consent to our disclosure of personal information to them in order to provide the services you have requested. For example, we may use the services of third-party hosting companies to host the operation of our Sites. This may involve the hosting of data, including personal information, on servers operated by those hosting companies. We may also use service providers to process payments of Users who wish to pay by credit card. We take care to use only service providers that we believe are reputable, who have agreed to comply with all applicable laws, and who are able to maintain the security of personal information and confidential information.

Law and Harm; Jurisdictions. Notwithstanding anything to the contrary in this Privacy Policy, we may preserve or disclose your information if we believe that it is reasonably necessary to comply with a law, regulation or legal request; to protect the safety of any person; to address fraud, security or technical issues; or to protect our or any other person’s rights or property. However, nothing in this Privacy Policy is intended to limit any legal defenses or objections that you may have to a third party’s request, including requests made by government or regulatory authorities, to disclose your information.

Storing or Processing Your Data Outside of the United States

Your personal information and other data is generally stored on servers in the United States. However, in some cases, personal information that we collect may be stored or processed outside of the United States. In such cases, we continue to protect the information with appropriate safeguards, but it may be subject to the legal jurisdiction of those countries and governmental authorities in those countries.

We will transfer personal information abroad only when there has been a documented adequacy determination, or where we have confirmed adequate privacy protections. If we transfer personal information abroad to a third party acting as our agent, we will also require the third party to have adequate privacy protections in place. We will transfer personal information to and on behalf of us and/or third party’s with whom we have an existing service agreement or as part of our legal obligations, each of which shall be subject to our policies, and only to the extent necessary for purposes of legitimate interests pursued by the data controller (or by a third party).

Sale of Business

You also consent to our disclosure of personal information to the acquirer or its agents in the course of the sale of our business. If we do this, the disclosure will be subject to confidentiality arrangements customary in such transactions.

Legal Basis For Processing Your Personal Information

For EU subjects, in respect of each of the purposes for which we use your personal information, the GDPR requires us to ensure that we have a legal basis for that use if you are within the EU. Art. 6(1) of the GDPR serves as the legal basis for processing operations for which we obtain the grounds to process personal information for a specific processing purpose. The legal bases depend on the services you use and how you use them. This means we collect and use your personal information only where:

  • You provide consent for our collection and use;
  • We need it to provide you the services, including to operate the services, to improve the services, to communicate with you about the services, to send you promotional communications that may be of specific interest to you, to provide customer support and personalized features and to protect the safety and security of the Services;
  • It satisfies a legitimate interest (which is not overridden by your data protection interests), such as for research and development, to market and promote the Services and to protect our legal rights and interests; or
  • We need to process your data to comply with a legal or regulatory obligation.

We may also rely on your consent as a legal basis for using your personal information where we have expressly sought it for a specific purpose. If we do rely on your consent to a use of your personal information, you have the right to change your mind at any time (but this will not affect any processing that has already taken place).

Where we need to process your personal information either to comply with law, or to perform the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with the functionalities of the Services). In this case, we may have to stop you using our Services.

Duration of Storage of Your Personal Information

The criteria used to determine the period of storage of personal information is the underlying purpose for which the data was obtained and the related legal requirements. When the legal basis for retaining the information no longer exists, the corresponding data is routinely deleted, as long as it is no longer necessary for the fulfillment of the purpose for which our legal basis for processing was established.

More specifically, we retain your information for as long as your account is active or it is reasonably needed for the purposes set forth herein unless you request that we remove your personal information as described herein. We will only retain your personal information for so long as we reasonably need to use it for these purposes unless a longer retention period is required by law (for example for regulatory purposes). This may include keeping your personal information after you have deactivated your account for the period of time needed for us to pursue legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes and enforce our agreements.

Your rights and your personal information

If you are an EU resident, you have the right under this Privacy to:

  • Request access to your personal information. If you are within the EU, this enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
  • Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
  • Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right if you are within the EU to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
  • Object to processing of your personal information. This right exists where we are relying on a legitimate interest as the legal basis for our processing and there is something about your particular situation, which makes you want to object to processing of your personal information on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
  • Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
  • Request the transfer of your personal information. If you are within the EU, we will provide to you, or a third party you have chosen, your personal information in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
  • Withdraw consent. This right only exists where we are relying on consent to process your personal information ("Consent Withdrawal"). If you withdraw your consent, we may not be able to provide you with access to the certain specific functionalities of our web site. We will advise you if this is the case at the time you withdraw your consent.

How to exercise your rights.

If you are an EU resident and you want to exercise any of the rights described above, please contact us using the contact details below.

Typically, you will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, except in relation to Consent Withdrawal, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive, or, we may refuse to comply with your request in these circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal information (or to exercise any of your other rights). This is a security measure to ensure that personal information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

Automated Decision Making

Your personal information will not be subject to automated decision making.

Further processing

If we wish to use your personal information for a new purpose, not covered by this Privacy Policy, or by existing consent or contractual obligations, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent to the new processing.

Contact Details

The data Controller for the purposes of the GDPR, other data protection laws applicable in Member states of the European Union and other provisions related to data protection this is:

GDPR contact:

OptimalResume.com, Inc.

PO Box 729

Pittsboro, NC 27312

Phone: +1 (877) 998-7654

Email: privacyinfo@optimalresume.com

We encourage interested EU subjects to raise any concerns about the collection, use, or processing of personal information using the contact information provided. In the event of a privacy related issue or complaint, we will investigate and attempt to promptly resolve any complaints and disputes regarding use and disclosure of personal information.

For complaints that cannot be resolved, we commit to cooperating with the panel established by the EU data protection authorities (DPAs) or the Swiss Federal Data Protection and Information Commissioner (FDPIC), as applicable, and to reasonably comply with the advice given by the panel or Commissioner about personal information transferred from the EU or Switzerland. In order to facilitate the handling of complaints, individuals in the EU can choose to contact their national DPA or use the form located at this link:

GDPR. On May 25, 2018, the General Data Protection Regulation (GDPR) takes effect in the European Union (EU). OptimalResume is committed to helping its partners and customers comply with GDPR.

http://ec.europa.eu/newsroom/document.cfm?doc_id=42962.

Individuals in Switzerland can contact the Swiss Information Commissioner by visiting:

https://www.edoeb.admin.ch/edoeb/de/home.html

This independent dispute resolution process is provided at no cost to the individual.

Children’s Privacy

The Services are not intended for children under the age of sixteen (16). If you are under the age of eighteen (18), we encourage you to review our Terms and this Privacy Policy with an adult to understand what type of information we collect, how it is used and how it may be disclosed.

Security

Your OptimalResume User Account is protected by a password that you choose to protect your privacy and security. It is your sole responsibility to create, and periodically change, a strong password in order to prevent unauthorized access to your account, and to protect your password appropriately, and limit access to your computer or mobile device.

OptimalResume runs its computing services on Amazon Web Services (AWS) infrastructure. AWS has been architected to be one of the most flexible, reliable, scalable and secure cloud computing environments available today. We use industry security best practices, such as the use of SSL certificates to ensure a safe and secure environment. All data in transit is encrypted using industry-standard Secure Sockets Layer (SSL), a cryptographic protocol that is designed to protect against eavesdropping, tampering, and message forgery. All data is encrypted at rest using one of the strongest block ciphers available, Advanced Encryption Standard 256 (AES-256), a symmetric key encryption standard using 256-bit encryption keys.

While we strive to protect your information and data we cannot guarantee the security of your User Account information. Unauthorized entry or use, hardware or software failure and other factors, may compromise the security of user information at any time.

Other Information Collectors

Except as otherwise expressly included in this Privacy Policy, this document only addresses the use and disclosure of information we collect from you. To the extent that you disclose your information to other parties through the Services, different rules may apply to their use, collection and disclosure of the personal information you disclose to them. Since we do not control the information use, collection or disclosure policies of third parties, you are also subject to the privacy policies of such other parties. We encourage you to ask questions before you disclose your personal information to others, including to employers that you are introduced to through the Services.

Users Outside of the United States. If you are a non-U.S. user of the Services, by using our Services, you acknowledge and agree that your personal information may be processed for the purposes identified in this Privacy Policy. In addition, your personal information may be processed in the country in which it was collected and in other countries, including the United States, where laws regarding processing of personal information may be less stringent than the laws in your country. By providing your data, you consent to such transfer.

Changes to This Privacy Policy

OptimalResume may amend this Privacy Policy from time to time. The use of information we collect is subject to the Privacy Policy in effect at the time the information is used; therefore it is important for you to review this Privacy Policy each time it is updated. If we make any material changes, we will change the Last Updated date above and post the new Privacy Policy here: https://optimalresume.com/privacy. We'll also notify you by posting an announcement on the Site(s). You should consult this Privacy Policy regularly for any changes.

Questions?

It is our goal to make our privacy practices easy to understand. If you have questions, concerns or if you would like more detailed information, please email our privacy officer at privacyinfo@optimalresume.com.