WHAT AND WHY
Information needed to run recruitment.
Responsible party identity
Jobza is a trading name used by Ahmed Abdou, a South African sole proprietor. For purposes of POPIA, the responsible party is Ahmed Abdou trading as Jobza. Jobza is not currently a separate incorporated company. The service address is 1356 Giants Castle Avenue, Bergbron, Randburg, Gauteng, 1705, South Africa.
Information Officer status
Ahmed Abdou is the Information Officer by virtue of his position as the sole proprietor and head of this private body. His registration with the Information Regulator has not yet been completed, and he will take up the statutory Information Officer duties after registration is confirmed. Privacy enquiries and data-subject requests may be submitted through the protected form below or sent to customerservice@joinjobza.com.
Account and profile data
Jobza uses your verified email and account identifier, plus profile details you choose to add such as contact information, location, skills, experience, education, work preferences and availability. Jobza accounts are independent from ChatGPT and use verified email for access.
Account infrastructure and location
Account registration, verified email and session data are processed by Clerk on Jobza's behalf. Recruitment records are stored in PostgreSQL on Jobza's Hostinger runtime. Private CV payloads are protected with application-level authenticated encryption in Cloudflare R2, while PostgreSQL stores the account ownership and version metadata. Talent Pool discovery and administrative CV backup remain disabled on this Hostinger release. Provider locations and cross-border processing arrangements require final legal review before commercial launch.
Applications and hiring activity
Applications, consent records, profile snapshots, status changes and employer actions are used to provide the service, protect its integrity, answer disputes and improve operations.
Employer and organisation data
Organisation contact, registration, location, membership and verification information is used to review employers and control who may manage jobs and candidate applications.
Support and safety records
Support and personal-information requests are retained in PostgreSQL with application, employer-review and administrator audit records so Jobza can investigate concerns, explain decisions and prevent abuse. The separate signed-in job-report queue remains unavailable in this Hostinger release.
Local drafts and optional account CVs
The CV Builder and Interview Practice tool work inside your browser. Drafts stay in local browser storage by default and are not uploaded automatically. A signed-in candidate may separately choose Save private copy; only that explicit action sends an encrypted CV to private object storage. Jobza normally keeps the 10 newest restorable versions; an older version is retained temporarily only when it is the exact version the candidate approved for an unexpired employer contact request. Deleting a cloud CV permanently removes its stored versions; a separate local browser draft remains until you delete it from this browser. A private account CV is not automatically placed in the Talent Pool or shared with an employer.
Optional anonymous tool improvement counts
Career-tool measurement is off by default. If you choose to help, Jobza records only daily aggregate counts such as a tool start, generated result, export, helpful vote or broad error category. It does not send or store what you type, CV or vacancy text, interview answers, salary figures, contact details, account or session identifiers, IP addresses, referrers or full URLs. Your preference stays in this browser, Global Privacy Control and Do Not Track keep measurement off, cells with fewer than five events are hidden from the owner dashboard, and daily aggregates are deleted after 90 days. Synthetic performance tests are excluded and are never reported as people.
Optional AI career briefs
Where enabled, signing in and giving a separate sharing choice lets you send only the reviewed role, location, advert and evidence fields to OpenAI for a draft. Saved CVs and account profiles are not attached automatically. Do not include personal identifiers or confidential information. Processing may occur outside South Africa. Response storage is disabled, but OpenAI may retain abuse-monitoring records for up to 30 days; this is not zero retention. Jobza does not persist the brief or generated answer. A private usage ledger keeps pseudonymous account hashes, request hashes and timestamps for limits and duplicate prevention. On the first accepted request in a later UTC month, the previous month's entries are replaced by a monthly total; this cleanup is not a scheduled month-end deletion. Stopping a request cannot recall data already sent. Local tools remain available without AI; AI output needs human review and does not verify live jobs or make hiring decisions.
Optional Jobza Career Assistant
The free topic guide does not send its search text to an AI provider. Opening optional AI connects to Clerk to check and maintain your session. After you explicitly review and consent to each request, Jobza sends your question, any context you enter and its public guidance catalogue to OpenAI. Previous answers are not attached automatically; choosing to use one as context copies up to 4,000 characters into the visible context field for you to review. No saved CV, account profile or private dashboard information is attached. Remove names, contact details, identity numbers, passwords, verification codes and confidential information; automatic redaction is not provided. The provider processing and retention limitations described above also apply. Jobza does not persist question text or generated answers or store them in browser storage. Clearing this page cannot recall information already sent. The assistant shares the same usage ledger and allowance as the six tools. It does not browse live websites, send messages, submit job applications or make account changes. Curated navigation links are not citations verifying its generated advice.
Talent Pool is a separate choice
Joining the Talent Pool needs a separate, unticked consent. The searchable profile is pseudonymous—not fully anonymous—and is limited to fixed professional choices for work category, skill area, Gauteng location, experience, availability and work preference. It must be refreshed at least every 180 days to remain discoverable. Employers do not receive the candidate's name, contact details or full CV through search. A candidate must accept a specific introduction request before selected contact details from that exact saved CV version can be shared, and may pause, resume or withdraw.
No selling or automatic hiring decisions
Jobza does not sell candidate CVs. The Talent Pool is not designed to rank people, infer protected characteristics or make automatic hiring decisions. Employers remain responsible for fair, lawful and human-reviewed recruitment decisions.
Who receives information
Approved members of an organisation receive application information for genuine recruitment. Jobza administrators and infrastructure providers may process information only as needed to operate, secure and support the service.
Retention, deletion and security
Jobza aims to keep PostgreSQL recruitment, support and audit records only for active recruitment, safety and legal needs. Access is restricted by Clerk account, stable principal and role. CV Builder drafts stay on the device until the candidate clears them; an optional saved copy is encrypted before it is written to private object storage, with ownership and version metadata held separately in PostgreSQL. Jobza normally retains the 10 newest ready versions. Deletion first makes the account copy unavailable, then removes its encrypted objects and finalises the metadata so an interrupted request can safely resume. Talent Pool participation remains a separate consent-controlled choice. Signed-in candidates may submit access, correction, objection or deletion requests through the protected form below; additional identity verification may still be required before Jobza acts. Detailed retention periods, provider locations and incident contacts must be finalised before commercial launch.