Privacy Policy
GDPR-native by design
ApplicantGrid is built in Munich and fully governed by the EU General Data Protection Regulation (GDPR). We do not sell your data. We do not share it with advertisers. You have full rights to access, correct, and delete everything we hold about you.
1 Who we are
ApplicantGrid is operated as a sole proprietorship (Einzelunternehmen) registered in Munich, Germany under the name M2Talents. For the purposes of GDPR, we are the data controller for personal data collected through applicantgrid.com.
Registered address: Munich, Bavaria, Germany
Contact: [email protected]
2 Data we collect and why
We are a pre-launch product. Currently, the only personal data we collect is email addresses submitted through the waitlist form. When the product launches, the scope of data collected will be updated here before processing begins.
| Data | Why we collect it | How long |
|---|---|---|
| Email address (waitlist) | To notify you when ApplicantGrid launches and provide early access | Until launch + 12 months, or until you unsubscribe |
| Analytics data (if consented) | To understand how visitors find and use the site so we can improve it. Collected via Google Analytics 4 with IP anonymisation enabled. | 14 months (GA4 default), then automatically deleted |
| Technical logs | Standard server logs (IP address, browser, request path) for security and uptime monitoring. Not linked to individuals. | 30 days, then automatically deleted |
We do not collect names, phone numbers, CVs, or payment details at this stage.
3 Legal basis for processing
Under GDPR Article 6, we process personal data only where we have a lawful basis:
- Consent (Art. 6(1)(a)) — Analytics cookies and tracking. You can withdraw consent at any time using the cookie banner or by emailing us.
- Legitimate interests (Art. 6(1)(f)) — Security logging, fraud prevention, and product improvement using anonymised data.
- Contract performance (Art. 6(1)(b)) — When you sign up for the product, we process your data to deliver the service you requested.
We do not rely on "legitimate interests" for marketing. Waitlist emails are sent based solely on your explicit sign-up action.
4 Cookies and analytics
We use Google Analytics 4 (GA4) with Consent Mode v2. This means:
- No analytics cookies are set until you explicitly accept via the banner.
- If you decline, only cookieless, aggregated modelling data is used — no identifiers are stored.
- IP addresses are anonymised before any data reaches Google's servers.
- We do not use advertising, remarketing, or cross-site tracking cookies.
- We do not use Facebook Pixel, TikTok Pixel, or any other ad-platform trackers.
You can change your analytics preference at any time by clicking .
5 How long we keep your data
We keep personal data only as long as necessary for the purpose it was collected, or as required by law. Specific retention periods are shown in the table in Section 2.
When you request deletion of your data (see Section 7), we will erase it within 30 days unless we are legally required to retain it (e.g. tax records under German commercial law, which must be kept for 10 years).
6 Who we share data with
We do not sell your data. We do not share it with advertisers. We use a small number of trusted processors to operate the service:
| Processor | Purpose | Location |
|---|---|---|
| Cloudflare | Website hosting, CDN, DDoS protection | EU (data centre selection) |
| Cloudflare D1 | Waitlist database | EU |
| Google Analytics 4 | Site analytics — only if you consent | EU (data processing amendment in place) |
All processors are bound by GDPR-compliant Data Processing Agreements (DPAs). Google Analytics operates under the EU–US Data Privacy Framework.
7 Your rights under GDPR
As a data subject under GDPR, you have the following rights. To exercise any of them, email [email protected]. We will respond within 30 days.
Right of access
Request a copy of all personal data we hold about you.
Right to rectification
Ask us to correct inaccurate or incomplete data.
Right to erasure
Request deletion of your data ("right to be forgotten").
Right to restrict processing
Ask us to pause processing while a dispute is resolved.
Right to data portability
Receive your data in a structured, machine-readable format.
Right to object
Object to processing based on legitimate interests.
Withdraw consent
Withdraw analytics consent at any time — no consequences.
Right to complain
Lodge a complaint with the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).
8 Data security
We take reasonable technical and organisational measures to protect your data, including:
- HTTPS encryption for all data in transit (TLS 1.2+)
- Access controls limiting who can query the waitlist database
- Regular security reviews of our infrastructure
- No passwords stored — waitlist is email-only
In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Article 33–34.
9 Children
ApplicantGrid is a professional job search tool intended for adults. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child under 16 has submitted data to us, please contact [email protected] and we will delete it promptly.
10 Changes to this policy
We may update this Privacy Policy as the product evolves. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify waitlist subscribers by email.
We will never reduce your rights under this policy without your explicit consent.
11 Contact and complaints
For any privacy-related question, request, or complaint:
Data Controller
ApplicantGrid / M2Talents
Munich, Bavaria, Germany
Email: [email protected]
If you are not satisfied with our response, you have the right to lodge a complaint with the German supervisory authority:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de