Privacy Policy
Effective Date: March 1, 2026
Last Updated: March 1, 2026
1. Introduction
Welcome to SMARCH, operated by SMARCH Ideell Förening, registered in Stockholm, Sweden ("we," "us," "our"). We are committed to protecting your personal information and your right to privacy.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you:
- Visit our website at smarch.valleyberg.com
- Create an account on our platform
- Submit applications or surveys
- Use our team matching and collaboration services
- Interact with our optional hiring-partner visibility features
Key Points:
- Legal Basis: We process your personal data based on legitimate interest (operating a participant-centred team matching platform and related services) and, where applicable, your explicit consent.
- Geographic Scope: This Privacy Policy complies with the General Data Protection Regulation (GDPR) and primarily serves users in Sweden, Poland, and the broader EU/EEA region.
2. Information We Collect
2.1 Personal Identification Information
- Full name
- Email address
- Phone number (optional)
- Date of birth (minimum age: 18 years)
- Location/geographic information
2.2 Professional and Employment Information
- Resume/CV
- Cover letter
- Employment history
- Education history and qualifications
- Professional references
- Certifications and diplomas
- Skills and competencies
- Work preferences and availability
2.3 Survey and Matching Data
- Responses to skill-based surveys and questionnaires
- Work eligibility status (e.g., legal right to work in Sweden)
- Career goals and preferences
- Team-formation interests and commitments
2.4 Profile Information
- Profile images (stored on AWS S3 EU-North region)
- Account settings and preferences
- Opt-in/opt-out preferences for hiring-partner visibility
2.5 Technical Data
- IP address
- Browser type and version
- Operating system
- Referring URLs and access times
- Device information
- Usage data and analytics (collected through internal tools only)
2.6 Case Management Data
- Unique smarch case numbers assigned to your application
- Matching status and history
- Communication records related to your applications
3. How We Use Your Information
3.1 Core Platform Services
- Account Management: To create, maintain, and secure your user account
- Application Processing: To manage and process your applications, surveys, and participation records
- Skill-Based Matching: To match you with complementary collaborators and teams
- Hiring-Partner Visibility: To connect opt-in participants with hiring partners through our optional visibility features
3.2 Communication
- To communicate with you regarding applications, matches, and opportunities
- To send notifications about hiring-partner interest and meeting invitations
- To provide customer support and respond to your inquiries
- To send important updates about our services (non-marketing)
3.3 Quality and Improvement
- To assess skills, qualifications, and suitability for opportunities
- To improve our matching algorithms and related platform processes
- To enhance website functionality and user experience
- To analyze platform usage through internal analytics tools
3.4 Legal and Security
- To comply with legal obligations and regulatory requirements
- To protect our rights, privacy, safety, and property
- To enforce our Terms and Conditions
- To prevent fraud and maintain platform security
3.5 Artificial Intelligence Processing
We use AI services (OpenAI GPT and Anthropic Claude) to analyze survey responses and improve matching quality. Important:
- Only anonymized survey answers and case numbers are sent to AI providers
- No personally identifiable information (names, emails, phone numbers) is shared with AI services
- This processing involves data transfer to the United States
- You consent to this processing when submitting survey responses
4. How We Share Your Information
We implement a privacy-first approach and share your information only as described below:
4.1 Optional Hiring-Partner Visibility - Anonymized-First Approach
Initial Visibility (Anonymized):
- Hiring partners with active subscriptions can view anonymized opt-in participant profiles
- Anonymized profiles include: skills, experience, qualifications, work preferences
- Anonymized profiles exclude: name, gender, age, contact information, profile photo
Upon Hiring-Partner Interest:
- When a hiring partner expresses interest, you receive a meeting invitation
- You can accept or decline the invitation
- Upon acceptance, your full profile (including contact details) is revealed to that specific hiring partner
- Hiring partners can then schedule appointments using their preferred platforms
4.2 Team Matches and Collaboration
- When matched into a team, relevant profile information is shared to facilitate collaboration
- You control your visibility and can opt-out at any time
- Automatic Opt-Out: When you commit to active matched-team participation, you are automatically removed from hiring-partner visibility
4.3 Service Providers
We share your information with trusted third-party service providers who assist in operating our platform:
- Hosting Services: Heroku (application hosting), Heroku PostgreSQL (database)
- Storage Services: Amazon Web Services S3 (EU-North region) for profile images
- Email Services: DreamHost (current), with potential future migration to ConvertKit or similar
- AI Services: OpenAI and Anthropic (anonymized survey data only)
- Domain Services: Domain hosting and DNS providers
All service providers are contractually obligated to protect your data and use it only for specified purposes.
4.4 Legal Requirements
We may disclose your information when required to:
- Comply with applicable laws, regulations, or legal processes
- Respond to lawful requests from public authorities
- Enforce our Terms and Conditions
- Protect our rights, privacy, safety, or property
- Investigate potential violations or fraud
5. International Data Transfers
Your personal data may be transferred to and processed in countries outside the EU/EEA:
- United States: AI processing services (OpenAI, Anthropic) - anonymized data only
- Within EU: Primary data storage and processing occurs within EU/EEA (AWS EU-North, Heroku EU regions)
We ensure appropriate safeguards are in place for international transfers, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequate data protection measures by service providers
- Minimization of personal data in cross-border transfers
6. Data Retention
We retain your personal information only as long as necessary for the purposes outlined in this Privacy Policy:
6.1 Active Participants
- During Application Process: Until your case is resolved (matched, placed elsewhere, or closed)
- Team-Matching Participants: While you are actively engaged in team formation or collaboration through our platform
- Hiring-Partner Visibility: Until you opt-out, find employment, or notify us of placement
6.2 After Case Closure
When you find employment or are placed, we will either:
- Delete your personal data upon your request, or
- Mark your profile as "inactive - do not process" for record-keeping purposes
You may request complete deletion at any time (see Section 8)
6.3 Inactive Accounts
- Accounts inactive for 3 years will be flagged for review
- We will contact you before deletion
- You may reactivate or request immediate deletion
7. Data Security
We implement robust technical and organizational measures to protect your personal information:
7.1 Technical Measures
- Encryption of data in transit (SSL/TLS)
- Encryption of data at rest (database and file storage)
- Secure cloud infrastructure (AWS, Heroku)
- Regular security updates and patches
- Access controls and authentication mechanisms
- Secure API communications with third-party services
7.2 Organizational Measures
- Limited access to personal data (need-to-know basis)
- Employee confidentiality agreements
- Regular security training for staff
- Incident response procedures
- Regular security audits and assessments
Data Breach Notification: In the event of a data breach affecting your personal data, we will notify you and relevant supervisory authorities within 72 hours as required by GDPR.
8. Cookies and Tracking Technologies
We use a minimal set of cookies and similar technologies to operate and secure the platform, improve your experience, and remember your choices. We do not sell personal data.
8.1 What We Use
- Essential/session cookies — Required for login, CSRF protection, and core functionality.
- Preference storage — We store your cookie consent choice in
localStorage(keys:smarch_cookie_consent,smarch_cookie_consent_date). - Analytics — None by default in MVP. If enabled later, we will update this section and request consent.
8.2 Your Choices
- You can accept or decline non‑essential cookies. Essential cookies cannot be disabled because the platform would not function.
- You can withdraw or change your consent at any time using the button below.
- You can also control cookies through your browser settings.
9. Your Data Protection Rights (GDPR)
Under GDPR, you have the following rights:
- Right to Access: Request confirmation and copies of your personal data
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data
- Right to Restriction: Request limitation of processing in certain circumstances
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for any consent-based processing
- Right to Lodge a Complaint: File a complaint with your local data protection authority
Exercising Your Rights:
- Response Time: We will respond within 30 days
- How to Request: Please use our Contact form
- No Fee: Exercising your rights is free of charge
Supervisory Authorities:
- Sweden: Integritetsskyddsmyndigheten (IMY) - www.imy.se
- Poland: Urząd Ochrony Danych Osobowych (UODO) - www.uodo.gov.pl
Contact Us
If you have questions, concerns, or wish to exercise your data protection rights, please contact us:
SMARCH Ideell Förening
📬 Contact: Contact form
🌐 Website: smarch.valleyberg.com
💼 LinkedIn: Rafal Zygula
Data Protection Officer: For GDPR‑related inquiries, please use the Contact form and mention “Data Protection Inquiry”.
By using smarch, you acknowledge that you have read, understood, and agree to this Privacy Policy.
Last Updated: March 1, 2026
© 2026 SMARCH Ideell Förening. All rights reserved.