Privacy notice
Career information deserves deliberate protection.
This notice covers the public DHAF website and protected client ERP. Effective 4 August 2026. Version 2026-08-04-dhaf-email-access-v4.
1. Controller and contact
Marwan Alkateb, operating the DHAF Career Intelligence concept in the Nijmegen region of the Netherlands, decides why and how client information is used and is the controller. Privacy questions and rights requests can be sent through /contact. Verified trade-registration, address, business email, tax and commercial details must be published before live paid services are activated.
2. Information DHAF processes
DHAF may process public enquiry details; verified email identity and secure-session records; onboarding and career preferences; verified career facts; matches, applications, tasks and messages; client-capacity and waitlist status; service orders and invoice metadata; private PDF or non-macro DOCX files; email-notification delivery records; and limited security and audit records.
Do not upload passports, BSN numbers, identity or residence documents, health or criminal data, political or religious views, bank credentials, payslips or confidential employer material. Remove unnecessary sensitive information from a CV before upload.
3. Purposes and legal bases
DHAF uses data for steps requested before a contract and contract performance, proportionate security and service-quality interests, legal invoice or compliance duties, and optional consent-based AI processing. Reading this notice is not blanket consent. DHAF needs an explicit client authorization before recording an application as submitted.
4. Providers and recipients
DHAF uses contracted cloud hosting, identity, transactional-email, file-scanning, payment and optional AI-processing providers to operate the service. When configured, Microsoft 365 sends generic portal notifications, an approved scanner checks files for malware, hosted checkout handles payment collection, and an AI API may assist with drafts using only approved facts after separate client consent. Notification emails do not include CV content or private career details. A person reviews all material. DHAF does not sell client data, publish private files or automatically send an application to an employer. The current provider register is available on request.
5. Locations and transfers
Provider infrastructure or support may involve processing outside the European Economic Area. Before production processing, DHAF must keep its processor and transfer register current and use an appropriate GDPR transfer mechanism where required.
6. Retention
Each client record has a retention-review date, not an automatic deletion promise. DHAF must operate documented periods for enquiries, client work, files, messages, audit records and backups. Legally required invoice records may be retained separately and do not justify keeping a CV for the same period.
7. Security and files
The ERP uses verified one-use email links, short-lived secure sessions, a private client access code for first access, administrator approval, server-side role and ownership checks, a private database and private object storage. PDF and DOCX files are limited, structurally checked and quarantined until an approved scanner reports them clean. Quarantined or rejected files cannot be downloaded. No system can guarantee absolute security.
8. Your rights
Subject to the GDPR conditions, a person may request access, correction, deletion, restriction, portability or object to processing through the portal or /contact. DHAF may ask proportionate verification questions and normally responds within one month. A complaint can also be made to the Dutch Data Protection Authority.
9. Matching, profiling and human review
Structured matching supports, but does not replace, human career judgment. DHAF does not make a solely automated hiring decision, reject a client automatically, or submit an application automatically. Clients can correct facts, question a recommendation and choose the next action.
10. Cookies, age, changes and incidents
Essential authentication and security technology may be used. This release does not intentionally use behavioural advertising. The service is for adults. Material notice changes receive a new version and require fresh acceptance when appropriate. DHAF records incidents and assesses regulatory and client notification duties without undue delay.
Help or a request: contact DHAF.