Nomado24 Logo

Privacy Policy

We take the protection of your personal data seriously. This privacy policy explains what data we process when you use nomado24.de, for which purposes, on which legal basis, how long we store it, and which rights you have.

1. Controller

Nomado24 UG (haftungsbeschränkt), Donnersbergweg 1, 67059 Ludwigshafen am Rhein, Germany. Email: anton.petuchow@nomado24.de, phone: +49 176 38445436.

No data protection officer has been appointed, as the legal requirements of Art. 37 GDPR do not apply to us.

2. Account and Registration

When you register, we process: name, email address, password (stored as a bcrypt hash, unreadable to us) and user role (job seeker or company). To confirm your email address we send a confirmation email (double opt-in).

Legal basis: Art. 6(1)(b) GDPR (provision of the user account).

Storage period: until you delete your account (see section 22).

Necessity: Without this information we cannot provide a user account. The public areas (job search, coworking overview) can be used without an account.

3. Profile and Onboarding

You can voluntarily add details to your profile, such as job title, professional experience, skills, languages, location, work-location preference, salary expectation, availability and a short bio. We use this information to suggest suitable jobs to you and to provide the features you request.

Legal basis: Art. 6(1)(b) GDPR. All profile details are voluntary; without them, only the profile-based features (e.g. job recommendations) are unavailable or limited.

Storage period: until you change them or delete your account.

4. Applications and Transfer to Companies

When you apply for a job via nomado24, we process your application documents (CV as PDF, cover letter, application date) and transmit them to the company you are applying to.

Important: From the moment of transmission, the respective company is an independent controller for the further processing of your application data. Its own privacy notices then apply in addition. For access or deletion requests concerning the company, please contact it directly; your rights towards us (section 21) remain unaffected.

Special categories of data: Please only upload information that is necessary for your application. If your CV or cover letter voluntarily contains special categories of personal data (e.g. health data, disability, religious beliefs, a photo), we process them exclusively to transmit your application, based on your explicit consent (Art. 9(2)(a) GDPR), which you give by submitting the application with this content and can withdraw at any time with effect for the future.

Legal basis: Art. 6(1)(b) GDPR (carrying out the application).

Storage period: We store your application data until you delete it or your account. Note: companies may retain transmitted applications to fulfil their own legal obligations (e.g. to preserve evidence under the German AGG, usually up to six months).

5. Messages between Applicants and Companies

We provide a messaging feature for communication around applications. We process the content and metadata (sender, recipient, time) of these messages in order to deliver them and display your inbox.

Legal basis: Art. 6(1)(b) GDPR.

Storage period: until the conversation or your account is deleted.

6. Job Recommendations and Semantic Search

To suggest suitable jobs, we convert selected profile details (job title, up to 12 skills, work-location preference and the first 400 characters of your bio) into mathematical representations (so-called embeddings). For this we use the Azure OpenAI service of Microsoft Ireland Operations Ltd. as a processor; processing takes place in an EU region. Your CV files are not used for this and are not transmitted to Azure OpenAI.

Legal basis: Art. 6(1)(b) GDPR (provision of the recommendation feature).

Storage period: The embeddings are updated when you change your profile and deleted with your account.

No automated decision-making: We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). In particular, we do not rank or score applicants for companies; the recommendation features merely suggest jobs to you, and you alone decide about your application.

7. AI Career Assistant (AI Advisor)

For the AI-powered career assistant we also use Azure OpenAI (Microsoft) as a processor, with processing in an EU region. When you use the AI Advisor, your chat messages and, if present in your profile, details such as job title, professional experience, skills, languages, location, work-location preference, salary expectation, availability, as well as the titles and companies of applications you submitted via nomado24, are transmitted to Azure OpenAI to answer your request.

Your inputs are not used by Microsoft to train AI models. For abuse monitoring, Microsoft may store inputs for up to 30 days (legal basis in this respect: Art. 6(1)(f) GDPR; legitimate interest in providing the service securely and free of abuse).

Please do not enter special categories of personal data (e.g. health data) in the chat if you do not want them to be processed.

Legal basis: Art. 6(1)(b) GDPR.

Storage period: We store your chat histories until you delete them. You can remove individual chats in your account at any time; when you delete your account, all chat histories are deleted.

8. Job Alerts and Newsletter (Double Opt-In)

You can subscribe to job alerts (email notifications about matching jobs) and our newsletter, also without a user account. For this we process your email address and your search criteria. The subscription only becomes active after confirmation via the link in our confirmation email (double opt-in). To prove your sign-up, we log the time of registration and confirmation.

Every email contains an unsubscribe link; you can also end your subscription at any time in the settings. Emails are sent via our processor Resend (see section 19).

Legal basis: Art. 6(1)(a) GDPR (consent); withdrawal takes effect for the future.

Storage period: until you unsubscribe; beyond that, we store the sign-up proof data for up to three years after unsubscribing in order to demonstrate the given consent (Art. 7(1) GDPR).

9. Coworking: Bookings and Reviews

When you book a coworking space via nomado24, we process your booking data (name, email, booked period, space) and transmit it to the operator of the space so that it can fulfil the booking. The operator is an independent controller for its further processing. Payment processing is described in section 11.

If you publish a review, it is displayed publicly on the space's page together with your username. You can delete your reviews at any time; they are also removed when you delete your account.

Legal basis: bookings Art. 6(1)(b) GDPR; publication of reviews Art. 6(1)(b) GDPR (a feature you requested).

Storage period: booking records are subject to statutory retention obligations (section 11); reviews until you delete them.

10. Community and Blog

In the community you can publish posts and comments. They are publicly visible together with your username. We reserve the right to moderate content that violates our guidelines.

Legal basis: Art. 6(1)(b) GDPR (provision of the feature); moderation based on Art. 6(1)(f) GDPR (legitimate interest in a safe, lawful platform).

Storage period: until deleted by you or together with your account.

11. Payments, Subscriptions and Billing Data

Paid services (Pro subscription, Founding Member, coworking bookings) are processed via our payment provider Stripe Payments Europe, Ltd. (Ireland). Your full payment and card data are processed exclusively by Stripe and are not stored by us. To fulfil its own legal obligations (e.g. anti-money-laundering and fraud prevention), Stripe may also act as an independent controller; see Stripe's privacy policy for details.

We ourselves store: subscription status, chosen plan or purchased service, billing period, Stripe customer and subscription identifiers, and the time the contract was concluded.

Legal basis: Art. 6(1)(b) GDPR; for the retention of billing data Art. 6(1)(c) GDPR.

Storage period: We retain billing and contract data to fulfil tax and commercial law obligations (Sec. 147 AO, Sec. 257 HGB; usually 6 to 10 years). This retention continues after account deletion; the data is separated from the account for this purpose.

12. Employer and Team Accounts

Companies can invite team members to their company account. If your company invites you, we receive your name and email address from the inviting person (data not collected from you, Art. 14 GDPR). We use this data exclusively to deliver the invitation and set up your account; you receive the information under this privacy policy at the latest with the invitation email. If you do not accept the invitation, we delete the data when the invitation expires.

Externally collected (aggregated) job ads may contain contact details of contact persons at the advertising companies. These originate from the public sources of the respective ad (Art. 14 GDPR); we process them exclusively to display the ad and remove them when it expires.

Legal basis: Art. 6(1)(b) GDPR (invitation/account), Art. 6(1)(f) GDPR (display of aggregated ads; legitimate interest in a comprehensive job offering).

13. Contact, Support and CRM (HubSpot)

When you contact us via the contact form or by email, we process your details to handle the request (Art. 6(1)(b) or (f) GDPR). We store requests until they have been fully handled, and beyond that only where legal obligations require it.

For customer communication and marketing we use HubSpot (HubSpot Ireland Ltd.; parent company HubSpot Inc., USA). HubSpot does not set cookies and does not track visitors on our website. We transmit personal data to HubSpot exclusively with your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future:

  • At registration and onboarding: Only if you have expressly agreed to marketing communication do we synchronise contact details and your onboarding information with HubSpot.
  • Contact form and newsletter: Transmission to HubSpot for handling or sending, based on your respective consent.

14. Web Analytics and Product Usage Analytics

We use three clearly separated methods:

a) Google Analytics 4 (only with consent)

With your consent via the cookie banner, we use Google Analytics by Google Ireland Ltd. for audience measurement. We have configured Google Consent Mode so that without consent no Google cookies are set and no identifiers are transmitted; IP anonymisation is enabled. Google also processes data in the USA (Google LLC).

Legal basis: Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) of the German TDDDG. Withdraw at any time via the cookie settings in the footer.

Storage period: Event data in Google Analytics is deleted after 14 months; for cookie lifetimes see the table in section 15.

b) Cookieless audience measurement (Umami, self-hosted)

For statistical audience measurement (page views, referrers, device type, country of origin, features used including search queries) we additionally use the self-hosted analytics software Umami. It runs entirely on our own infrastructure at Microsoft Azure in the EU; no data is transmitted to third parties. Umami sets no cookies and stores no information on your device; consent under Sec. 25 TDDDG is therefore not required. Your IP address is not stored permanently, but only processed briefly to derive the country of origin and a time-limited identifier that cannot be traced back to you.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in audience measurement and improving the service; measurement is purely statistical and involves no profiling of individuals). You can object to this processing at any time with effect for the future (Art. 21(1) GDPR), e.g. by email to the address above.

c) Product usage analytics in our own systems (first-party)

  • Account-related events: If you are logged in, we attribute certain events to your account (e.g. registration, login, application submission, bookings, CV uploads, use of the AI Advisor). Legal basis: Art. 6(1)(b) GDPR where the event is part of providing the requested feature, otherwise Art. 6(1)(f) GDPR (analysis and improvement of the service). These events are deliberately stored without IP address and without browser identifier.
  • Events with consent (analytics identifiers): Only with your cookie consent do we additionally store a random local identifier (n24_anon_id) and a session identifier (n24_session) to analyse usage behaviour across multiple page views. Legal basis: Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG. Upon withdrawal, the local identifiers are deleted and collection stops. If you consented before logging in, events collected this way may be attributed to your account upon a later login; the attribution happens via a separate event entry at the time of login.

Storage period and deletion (for c): We store usage events for 13 months; after that they are irreversibly anonymised (account, device and session identifiers as well as truncated search terms are removed). When you delete your account, attributed events are anonymised immediately. Your account-related usage events are part of the data export in your account settings.

Usage data is not transmitted to third parties for advertising purposes.

15. Cookies and Local Storage

We use technically necessary storage, as well as functional storage that solely saves your settings for features you use (e.g. appearance, remembered search filters), without consent (Sec. 25(2) no. 2 TDDDG). Analytics cookies and identifiers are only set with your consent via the cookie banner (Sec. 25(1) TDDDG, Art. 6(1)(a) GDPR). You can change or withdraw your choice at any time via "Cookie settings" in the footer.

NameTypeProviderPurposeLifetimeCategory
userToken, userAccessCookienomado24login sessionuntil logout or token expirynecessary
token, userLocal storagenomado24login sessionuntil logoutnecessary
cookieConsentLocal storagenomado24stores your cookie decision12 monthsnecessary
mapsConsentLocal storagenomado24stores your Google Maps consentuntil withdrawalnecessary
NEXT_LOCALECookienomado24language choiceuntil changednecessary
themeLocal storagenomado24appearance (light/dark)until changedfunctional
n24.jobs.nearCity, n24.jobs.radiusLocal storagenomado24remembered search filtersuntil deletedfunctional
n24_anon_idLocal storagenomado24pseudonymous analytics identifieruntil withdrawalanalytics (consent)
n24_sessionSession storagenomado24analytics session identifier30 minutesanalytics (consent)
_ga, _ga_*CookieGoogleaudience measurementup to 2 yearsanalytics (consent)

16. Maps and Geocoding

Google Maps (two-click solution): Maps on the coworking pages and the Google address search in forms only load after you have expressly agreed to loading Google Maps. Only with your click is a connection to Google established and your IP address transmitted to Google (Google Ireland Ltd.; processing also by Google LLC, USA). Google is independently responsible for this processing. We remember your consent locally (mapsConsent) and you can withdraw it at any time via the cookie settings. Legal basis: Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG.

Geocoding (Nominatim/OpenStreetMap): To convert addresses of coworking listings into map coordinates, we use the Nominatim service of the OpenStreetMap Foundation (United Kingdom; EU Commission adequacy decision) on the server side. Only the listing's address data is transmitted, no user identifiers. Legal basis: Art. 6(1)(b) GDPR (provision of the listing).

17. Hosting, Server Logs and Security

Our website and databases are operated at Microsoft Azure (Microsoft Ireland Operations Ltd.) in data centres within the EU; delivery happens via Azure Front Door (CDN) with an upstream web application firewall. When you visit the website, we automatically process IP address, browser type and version, operating system and time of access, insofar as this is necessary to deliver the page and ensure IT security (e.g. defence against attacks, rate limiting). Our application itself does not store IP addresses permanently; the infrastructure's access and firewall logs are automatically deleted after 30 days.

Security measures include TLS encryption, password hashing (bcrypt), access controls and regular security updates.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing the website securely and reliably).

18. Affiliate Links / Partner Links

Some job ads from external partners contain affiliate links: if you apply via such a link, nomado24 may receive a commission. There are no additional costs for you. For billing and reach measurement we count such clicks exclusively anonymously, without IP address and without personal data; the GDPR does not apply to this anonymous count data.

19. Recipients and Processors

We only share personal data as described in this policy: with companies when you apply (section 4), with space operators for bookings (section 9), with authorities where legally required (Art. 6(1)(c) GDPR), and with the following service providers, which (unless described otherwise) act for us as processors under Art. 28 GDPR:

ProviderPurposeRegistered office / processingThird-country transfer
Microsoft (Azure, Azure OpenAI)hosting, CDN/WAF, database, AI featuresIreland; processing in EU regionsMicrosoft Corp. (USA) is certified under the EU-US Data Privacy Framework
Stripe Payments Europe, Ltd.payment processingIrelandtransfers to Stripe Inc. (USA) based on EU standard contractual clauses or the DPF
Resend, Inc.sending transactional and notification emailsUSAEU standard contractual clauses (Art. 46(2)(c) GDPR)
Google Ireland Ltd.Google Analytics (only with consent), Google Maps (two-click)IrelandGoogle LLC (USA) is certified under the EU-US Data Privacy Framework
HubSpot Ireland Ltd.CRM and marketing communication (only with consent; no website tracking, no cookies)IrelandHubSpot Inc. (USA) is certified under the EU-US Data Privacy Framework
OpenStreetMap Foundation (Nominatim)geocoding of listing addressesUnited Kingdomadequacy decision (Art. 45 GDPR)

20. Transfers to Third Countries

Where data is transferred to the USA or other third countries, this happens on the basis of an EU Commission adequacy decision (Art. 45 GDPR, in particular the EU-US Data Privacy Framework for certified providers) or on the basis of EU standard contractual clauses (Art. 46(2)(c) GDPR), supplemented by technical and organisational safeguards. You can request a copy of the respective safeguards via the contact details above.

21. Your Rights

You have the following rights towards us regarding your personal data:

  • Access (Art. 15 GDPR): supplemented by the data export in your account settings
  • Rectification (Art. 16 GDPR): correction of inaccurate data
  • Erasure (Art. 17 GDPR): "right to be forgotten"
  • Restriction of processing (Art. 18 GDPR): temporary blocking instead of deletion
  • Data portability (Art. 20 GDPR): receiving your data in a structured, machine-readable format
  • Withdrawal of given consent (Art. 7(3) GDPR): at any time with effect for the future; the lawfulness of processing carried out before withdrawal remains unaffected

Right to object (Art. 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Art. 6(1)(f) GDPR. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. Where your data is processed for direct marketing, you have the right to object to this processing at any time and without giving reasons; after the objection, your data will no longer be used for direct marketing purposes.

To exercise your rights, an informal message to anton.petuchow@nomado24.de is sufficient.

Right to lodge a complaint (Art. 77 GDPR): You can complain to a data protection supervisory authority, in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz, Germany, www.datenschutz.rlp.de.

22. Account Deletion, Storage Periods at a Glance

You can delete your account at any time in the settings. Deletion is carried out immediately: account, profile, application and message data as well as uploaded files (CVs, cover letters) are deleted, AI Advisor chats removed, usage events anonymised, and any HubSpot contact as well as newsletter and alert subscriptions deleted or ended.

Exceptions to immediate deletion:

DataPeriodReason
Billing and contract data6 to 10 yearsSec. 147 AO, Sec. 257 HGB
Applications already transmitted to companiesper the company's privacy noticesindependent controllership of the company
Proof of given consent (e.g. double opt-in)up to 3 years after unsubscribingduty of proof, Art. 7(1) GDPR
Anonymised usage statisticsunlimitedno personal reference

23. Minimum Age

Our service is directed at persons aged 16 or older.

24. Changes to this Privacy Policy

We adapt this privacy policy when our services or the legal requirements change. The current version can always be found on this page. In the case of material changes affecting processing based on consent, we will ask for your consent again.

Last updated: July 2026 (Version 2.0)