Skip to main content
COLLABme

Privacy policy

Last updated: 28 August 2026

What data we collect, why, how long we keep it, and how to exercise your rights.

In brief

COLLABme connects project owners, companies, educational institutions and talents. To do this, we process personal data: the information you provide (profile, applications, messages), data generated by your use of the platform — site, web applications and mobile app included — (interactions, navigation events) and data from services you choose to connect (Google, LinkedIn, your calendar).

Three principles guide this policy: we only collect what serves the service, we never sell your data, and you stay in control — visibility of your profile, consent for audience measurement, optional connections, and account deletion at any time via your settings. One exception, which we prefer to state outright rather than leave you to discover it: our mobile app measures its own startup times and counts launches without asking for permission. These measurements do not identify you and do not track what you do; the section ‘Why we use your data’ explains the legal basis.

Who is responsible for processing?

The publisher of COLLABme, identified in the legal notices, is responsible for processing the data described in this policy. For any questions, email us at info@collabme.be.

Special case: within an organisation’s workspace (member management, leave, attendance, internal documents), the organisation decides the purposes — it acts as the data controller and COLLABme as the data processor, hosting and securing the data on its behalf. To exercise your rights over this data, contact your organisation first; we assist them in responding.

The data we collect

Depending on the features you use, we process the following categories of data:

  • Account and login — email address, first name and last name, avatar, preferred language. Login is passwordless via a link sent by email or through Google or LinkedIn (we then receive your identifier, name, email and profile picture from these services).
  • Profile and facets — displayed name, public handle (@handle), profile and cover photos, title, bio, skills, experiences, education, sector, date of birth, phone number, contact email, address and location you declare, daily rate, availability, as well as information specific to each facet (student, freelancer, teacher, employee, investor, project owner). We never collect your device’s location: the location is the one you enter yourself.
  • Content and interactions — posts, comments, reactions, polls and votes, reviews, skill recommendations, connections and subscriptions, favourites, event participation.
  • Applications — your cover letter, the facet you apply with, and the compatibility score calculated (see the section on AI).
  • Messaging — the content of your messages and their attachments, your reactions, your online presence status, and the original language of messages (for translation when reading).
  • Organisation workspace — your role and position, department and reporting line, daily presence (office, remote work, absence, travel), remote work agreements, leave requests (type, dates, reason) and supporting documents, internal documents and approvals, interviews and onboarding paths. A sick leave certificate may constitute health data: see "Who sees what" and "Security".
  • Financial data — the private activity log of your freelance facet (clients, amounts, invoice and payment status), the declarative log of your investments, your displayed rates. If you subscribe to a paid plan, payment is handled by our provider Stripe: we never store your card number, only a customer reference and subscription events.
  • External calendar (optional) — if you connect Google Calendar or Microsoft Outlook, we store encrypted access tokens, your availability (free/busy slots) and, for your personal use only, your calendar events.
  • Verifications — school email address (the verification code is stored in hashed form), certificates and diplomas issued by institutions or companies, and, for minors, the name and email of the legal guardian who gave consent.
  • Technical and usage data — product events collected first-party across the whole platform, mobile app included (screens and pages viewed, actions taken such as applying, publishing, searching, sharing or switching facet), with no IP address kept, no search text, no message content and no full page address — the identifiers it contains are replaced before sending —, linked to an anonymous identifier created only after your consent; if you consent to audience measurement, anonymised journey recordings and heatmaps (clicks and scrolling on web, gestures and screens displayed on mobile), with input fields and conversations masked before recording; push notification subscriptions (technical address of the browser or device and user-agent); and an IP address processed ephemerally, in memory, solely to protect against abuse — it is never stored in the database.
  • Mobile app technical measurements — app startup and screen display durations, number of launches, app version, device type and OS version, as well as the domain name of the slowest network service at startup. These measurements contain neither your identity nor the content of your screens, nor what you type, nor the full addresses of pages visited — single-use codes received via link (invitation, email address confirmation, parental consent) are removed before any transmission. They are linked to a technical installation ID, unique to the app and separate from your account, which remains as long as the app is installed. Unlike audience measurement, these do not depend on your consent: see the next section.

Why we use your data

Each processing activity is based on a lawful basis under the GDPR:

  • Providing the service (contract performance) — creating and managing your account, displaying your profile, publishing your content, sending your applications, routing your messages, operating organisation spaces, processing subscription payments.
  • Connecting users (contract performance) — calculating suggestions and compatibility scores between profiles and opportunities, based on your profile content and listings.
  • Securing the platform (legitimate interest) — preventing abuse and fraud, rate limiting, handling reports, moderating flagged content.
  • Communicating with you (contract performance) — login emails, activity-related notifications, responses to your requests.
  • Measuring and improving (consent) — audience statistics and usage analysis, only if you accept them via the consent banner.
  • Connecting third-party services (consent) — external calendar, CollabCoach assistant: each connection is optional and revocable.
  • Measuring the performance of our mobile app (legitimate interest) — knowing how long the app takes to start and display a screen, how often it is launched and on which versions, so we can fix slowness and errors. These measurements are not used for advertising or profiling, nor are they linked to your profile. You can object by writing to us (see ‘Your rights’); on your device, the only way to stop them is to uninstall the app.
  • Complying with legal obligations — retaining payment records for accounting and tax purposes, responding to legally valid requests from authorities.

Matching, AI and automated decisions

The core of COLLABme is a matching engine: your profile and opportunity content is transformed into numerical representations (embeddings), then a language model evaluates compatibility between a profile and an opportunity. This processing is carried out by our provider Mistral AI, hosted within the European Union. The resulting score is indicative: it helps sort and suggest, but it does not make any decisions.

When an interview is being prepared, the platform can generate separate preparation guides for the recruiter and the candidate, based on the profile and the listing. Messages in the chat can be translated when read into your language; the message text is then sent to the AI provider solely for this translation. The CollabCoach assistant only acts when you enable it, and each of its actions is logged in a reversible and auditable journal.

No decision producing legal effects on you or significantly affecting you is made entirely automatically under Article 22 of the GDPR: accepting or rejecting an application always remains a human decision made by the recruiter. If you believe a score or suggestion is unfair, contact us: a human will review your case.

Who sees what

  • Your public profile (displayed name, photo, title, skills, public content) is visible to other users. Published freelance showcases are also visible to non-logged-in visitors and may be indexed by search engines — you choose whether to publish your showcase or not.
  • Your applications are only visible to the recipient organisation. The interview guide generated for the recruiter is not shown to you, and vice versa.
  • Your messages are only visible to participants in the conversation. Our teams do not access them unless a participant reports a message: the moderation team then only sees a limited window around the reported message, reconstructed from the reporter’s perspective.
  • In an organisation space, your HR data (position, presence, leave) is only visible to authorised personnel within the organisation. A colleague’s type of leave is treated as confidential information: a member without management rights sees that someone is absent, but not why.
  • Your private logs (freelance activity, investments) are never visible to other users.
  • Ghost mode removes the notification sent when viewing a profile; the view is still recorded technically, and reciprocity applies.

Who we share your data with

We do not sell your data. We only share it with service providers who help us operate the service, each limited to their specific purpose:

  • Mistral AI (European Union) — matching calculation, interview guide generation, message translation upon reading, CollabCoach assistant.
  • Brevo (European Union) — sending login emails and transactional emails.
  • Stripe — payment and subscription processing, VAT calculation, invoices, and client portal.
  • Google — login to your account (if you choose to) and Google Calendar (if you connect it).
  • Microsoft — Outlook Calendar (if you connect it) and, with your consent for audience measurement, Microsoft Clarity: heatmaps and anonymised journey recordings on the site, the web applications and the mobile app. This tool is never enabled for an account identified as belonging to a minor.
  • LinkedIn — login to your account (if you choose to); additionally, an opportunity may be published on the COLLABme LinkedIn page after human validation, never your profile.
  • PostHog (hosted in the European Union) — product usage statistics, only after your consent.
  • Our hosting provider (European Union) — server hosting, database, file storage, and backups.
  • Expo (United States) — technical measurement of our mobile app: startup and navigation durations, number of launches, app and OS versions. No content, messages, or account identifiers are transmitted.
  • Your browser’s notification services (Google, Mozilla, Apple) — delivery of push notifications you have enabled.
  • Public authorities — only on legally valid requests.

Transfers outside the European Union

Our servers and database are hosted in the European Union, and our main AI and email providers are European. Some providers (Stripe, Google, Microsoft, LinkedIn) may process data in the United States: these transfers are governed by the EU–US Data Privacy Framework or by the European Commission’s standard contractual clauses. Microsoft Clarity, with your consent, processes session recordings outside the European Union under the same framework. The technical measurements of our mobile app are processed by Expo in the United States.

How long we retain your data

  • Your account and its content — as long as the account exists. Account deletion, available in your settings, permanently removes your profile and its contents.
  • Usage event data (first-party analytics) — 13 months, automatically purged daily.
  • Journey recordings and heatmaps (Microsoft Clarity) — kept by Microsoft under its own retention policy, then deleted. We keep no copy of them on our servers.
  • Mobile app technical measurements (Expo) — retained by Expo according to its own retention policy. We do not keep any copies on our servers.
  • Login sessions — approximately 30 rolling days; temporary tokens (magic link, email change, OAuth) expire between 15 and 60 minutes.
  • Notifications — deleted 24 hours after being read.
  • Messaging — for the duration of the conversation; a conversation’s encryption key may be destroyed, making its content permanently unreadable.
  • Payment traces — retained after account deletion, for the duration of our accounting and tax obligations.
  • Reports and moderation logs — for as long as necessary to process and evidence our due diligence.

How we protect your data

All communications are encrypted in transit (TLS). Messaging content and attachments are encrypted at rest, with a unique key per conversation — the platform holds these keys to enable service features (translation, search, reporting): this is not end-to-end encryption, and we are transparent about it. Access tokens for your calendar are encrypted. Leave certificates are stored in a private space, accessible only to authorized managers in your organization, and never cached.

Our team’s access to data is strictly limited to what is necessary: since August 2026, messaging is no longer viewable from our back office — only a message reported by a participant can be reviewed, within a limited window. The database is subject to automated encrypted backups within the European Union.

In the event of a data breach likely to pose a risk to your rights, we will notify the supervisory authority within 72 hours and inform you directly if the risk is high, in accordance with Articles 33 and 34 of the GDPR.

Your rights

You have the rights provided by the GDPR: access, rectification, erasure, restriction of processing, objection, portability, withdrawal of consent at any time, and the right to set directives for the handling of your data after your death.

Most can be exercised directly in the platform: your profile is updated in your settings, account deletion is available and takes effect immediately, and consent for audience measurement can be withdrawn from the Cookie Policy page, from the web applications' settings (« Privacy » section) and from the Settings → Privacy screen of the mobile app. For the rest, email us at info@collabme.be — we respond within one month.

If you believe your rights are not being respected, you can file a complaint with the Data Protection Authority (APD), rue de la Presse 35, 1000 Brussels, www.autoriteprotectiondonnees.be — or with the supervisory authority in your country of residence.

Minors

COLLABme welcomes students, some of whom are minors. Registering a minor requires the consent of their legal guardian: we collect their name and email address for this purpose, and certain actions — such as applying for an opportunity — remain blocked until this consent is confirmed. The legal guardian can withdraw their consent at any time by writing to us.

Journey recording and heatmap tools are never enabled for an account identified as belonging to a minor, including in the mobile app, and whatever choice is made in the consent banner. This exclusion relies on the date of birth declared in the profile: until it is filled in, we cannot know that an account belongs to a minor.

Changes to this policy

We may update this policy to reflect changes in our service or regulations. The last update date is shown at the top of the page. In the event of a significant change — new purpose, new recipient, new data category — we will notify you via the platform or by email before it takes effect.

Contact us

For any questions about your personal data or to exercise your rights: info@collabme.be. The full contact details of the publisher are available in the legal notices.