Your Data, Your Rights

Privacy Policy

We are committed to protecting your personal data and being fully transparent about how we use it.

Effective date: 1 April 2025  ·  Last updated: 1 April 2025

1. Introduction

Trainee.in is a career development platform operated by Tagsom AB ("we," "us," "our"). We help students, graduates, and early-career professionals find internships and junior employment opportunities through AI-assisted tools, job listings, and career resources.

This Privacy Policy explains what personal data we collect about you, why we collect it, how we use and protect it, and what rights you have under applicable law — including the EU General Data Protection Regulation (GDPR) (Regulation 2016/679) and the Swedish Data Protection Act (Dataskyddslagen).

By using Trainee.in, you acknowledge that you have read and understood this Privacy Policy. This Policy should be read alongside our Terms of Service.

2. Data Controller

The entity responsible for the processing of your personal data under this Policy is:

Tagsom AB

Organisation number: 5568961071

Registered address: Virkesvägen 13, 120 78 Stockholm, Sweden

Data protection enquiries: support@trainee.in

General enquiries: info@tagsom.com

3. Personal Data We Collect

We collect only the data necessary to provide and improve the Service. The categories of data we collect are as follows:

A. Data you provide directly

  • Account information: Your email address, name, and password (stored in hashed form) when you register.
  • Profile and career data: Information you voluntarily enter into your trainee profile, including your CV content, educational background, work experience, skills, and career interests.
  • Questionnaire responses: Answers you provide through our onboarding or career preference questionnaires, used to personalise the Service.
  • Support communications: The content of messages and queries you send to support@trainee.in.

B. Data collected automatically

The following data is collected automatically when you visit or interact with Trainee.in:

  • Technical data: IP address, browser type and version, operating system, device type, and screen resolution.
  • Usage data: Pages visited, time spent, click paths, referral source (UTM parameters), and feature interactions.
  • Cookies and similar technologies: See Section 9 for full details.

4. How We Use Your Data & Legal Basis

Under GDPR, we are required to have a valid legal basis for every processing activity. The table below sets out our purposes and the corresponding legal basis.

Purpose of ProcessingData UsedLegal Basis (GDPR Art. 6)
Providing the Service: account creation, login, saving your profile and CV data.Account data, profile dataArt. 6(1)(b) — Performance of contract
AI-assisted CV and cover letter generation using the profile data you enter.Profile data, questionnaire responsesArt. 6(1)(b) — Performance of contract
Job matching: identifying and presenting internship and job listings relevant to your profile.Profile data, career preferencesArt. 6(1)(b) — Performance of contract
Transactional communications: account verification, password resets, and service updates.Email addressArt. 6(1)(b) — Performance of contract
Platform security: fraud prevention, abuse detection, and error monitoring.Technical data, IP addressArt. 6(1)(f) — Legitimate interest
Analytics and product improvement: understanding how users interact with the platform.Usage data (anonymised)Art. 6(1)(a) — Consent (via cookie banner)
Anonymised research and market reports: generating aggregated, non-identifiable labour market insights.Aggregated, anonymised profile and usage dataArt. 6(1)(f) — Legitimate interest (data is fully anonymised before use)
Legal compliance: responding to lawful requests from authorities or enforcing our Terms of Service.As requiredArt. 6(1)(c) — Legal obligation

5. Automated Processing & AI Tools

Trainee.in uses artificial intelligence and automated processing as core parts of the Service, including to generate CV drafts, cover letters, and job-match recommendations based on your profile data. We want to be transparent about this.

  • AI-generated content: When you use our AI tools, your profile information (e.g., skills, experience, career goals) is processed to generate personalised output. The results are suggestions only — you review and control what is ultimately used or submitted.
  • Job matching: Our platform may use automated logic to rank and surface job listings relevant to your profile. This is not a fully automated decision with legal or similarly significant effects; you retain full control over which opportunities to pursue.
  • Your rights regarding automated processing: Under GDPR Article 22, you have the right not to be subject to decisions based solely on automated processing that significantly affect you. If you have concerns about how automated tools are influencing outcomes for you, contact us at support@trainee.in to request human review.

6. Third-Party Service Providers (Sub-processors)

We do not sell your personal data. We share data only with trusted third-party providers who act as data processors on our behalf, under contractual obligations consistent with GDPR. The following sub-processors are currently engaged:

  • Supabase (Database & Authentication): Stores user accounts, profile data, and platform data. Servers are located in the EU.
    Privacy Policy
  • Vercel (Hosting & Infrastructure): Hosts the Trainee.in web application and processes server access logs and IP addresses to deliver the Service.
    Privacy Policy
  • Google Analytics (Web Analytics): Used to measure website traffic and user behaviour in aggregate. Data is pseudonymised and only activated with your cookie consent.
    Privacy Policy
  • Google Search Console (Search Performance): Used to monitor technical SEO performance. Does not process individual user data.
  • Common Ninja (Cookie Consent Management): Manages your cookie preferences and ensures analytics cookies are only activated with your explicit consent.
    Privacy Policy

7. International Data Transfers

Tagsom AB is headquartered in Stockholm, Sweden (EU/EEA). Some of our sub-processors, including Google, may process data in the United States or other countries outside the EU/EEA.

When personal data is transferred outside the EU/EEA, we ensure an adequate level of protection through one or more of the following mechanisms:

  • EU–US Data Privacy Framework (DPF): Where providers are certified under the DPF, this provides an adequacy decision basis for transfers to the US.
  • Standard Contractual Clauses (SCCs): EC-approved contractual terms that impose GDPR-equivalent obligations on the recipient.
  • Adequacy decisions: For transfers to countries the European Commission has determined provide an adequate level of data protection.

You may request further details about the specific transfer mechanisms in place by contacting us at support@trainee.in.

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, or as required by applicable law. Our specific retention periods are as follows:

  • Active account data: Retained for as long as your account remains active. You may request deletion at any time via Settings or by emailing support@trainee.in.
  • After account deletion: Your personal data will be permanently deleted within 30 days of account closure, except where we are required to retain certain records by law (e.g., for accounting or fraud prevention purposes). Any such retained data will be kept for no longer than 7 years as required under Swedish accounting law.
  • Inactive accounts: Accounts inactive for more than 12 consecutive months may be deleted following advance email notice (see our Terms of Service for full details). We will notify you before any deletion occurs.
  • Analytics data: Retained for up to 14 months in Google Analytics before automatic deletion.
  • Support correspondence: Retained for up to 2 years to maintain a record of resolved enquiries and support quality.
  • Anonymised research data: Aggregated, anonymised data used for market research reports is not subject to deletion timelines as it cannot be used to identify you.

9. Cookies & Tracking Technologies

We use cookies and similar technologies on Trainee.in. You are presented with a cookie consent banner on your first visit, through which you can accept or decline non-essential cookies. The categories of cookies we use are:

  • Strictly necessary cookies: These are essential for the website to function. They include authentication session cookies (managed by Supabase) that keep you logged in. These cookies cannot be disabled as the Service cannot function without them. No consent is required for these under ePrivacy rules.
  • Analytics cookies (Google Analytics): These cookies collect anonymised data about how visitors use the site — such as which pages are most visited and where users drop off. They are only placed on your device if you click "Accept" in the cookie consent banner. You can withdraw your consent and disable these cookies at any time by clicking the cookie preferences link in the footer.

To change your cookie preferences at any time, use the cookie settings option in the website footer, or clear your browser cookies and revisit the site.

10. Your GDPR Rights

As a data subject under the GDPR, you have the following rights. To exercise any of them, contact us at support@trainee.in. We will respond within 30 days.

  • Right of access (Art. 15): Request a copy of the personal data we hold about you, along with information on how it is processed.
  • Right to rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
  • Right to erasure — "right to be forgotten" (Art. 17): Request deletion of your personal data where it is no longer necessary, you withdraw consent, or processing is unlawful.
  • Right to restriction of processing (Art. 18): Request that we limit how we process your data in specific circumstances.
  • Right to data portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format (e.g., JSON or CSV) so you can transfer it to another service.
  • Right to object (Art. 21): Object to processing based on legitimate interests — including profiling for job matching purposes. We will cease processing unless we can demonstrate compelling legitimate grounds.
  • Right to withdraw consent (Art. 7(3)): Where we process your data on the basis of consent (e.g., analytics cookies), you may withdraw that consent at any time without affecting the lawfulness of prior processing.
  • Rights regarding automated decisions (Art. 22): You have the right not to be subject to solely automated decisions that produce significant legal effects. See Section 5 for more detail.

Right to lodge a complaint

If you believe we have processed your personal data in violation of applicable law, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY):

Website: www.imy.se ·  Email: imy@imy.se

11. Data Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, accidental loss, alteration, or disclosure. Our measures include:

  • SSL/TLS encryption for all data in transit between your browser and our servers
  • Encryption of data at rest within our database infrastructure (Supabase)
  • Bcrypt hashing of passwords — we never store passwords in plain text
  • Access controls limiting internal access to personal data to authorised personnel only
  • Regular security reviews of our platform and third-party sub-processors

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (IMY) within 72 hours, and will inform affected users without undue delay where required by law.

Despite our efforts, no system is completely secure. If you suspect any unauthorised access to your account, please contact us immediately at support@trainee.in.

12. Minors

Trainee.in is accessible to users aged 16 and above. We do not knowingly collect personal data from children under the age of 16. If you believe a child under 16 has provided us with personal data without appropriate parental consent, please contact us at support@trainee.in and we will promptly delete that data.

Users aged 16–17 should review this Policy with their parent or guardian and confirm they have the necessary consent to use the platform as required under the laws of their country of residence.

13. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes to our data practices, service features, or applicable law. The "Last updated" date at the top of this page will be revised accordingly.

For material changes — such as a new category of data being collected, a new purpose for processing, or a new sub-processor being added — we will notify registered users by email at least 14 days before the change takes effect. Continued use of the Service after a change is effective constitutes acceptance of the updated Policy.

We encourage you to review this page periodically to stay informed about how we protect your data.

14. Contact Us

For any questions, requests, or concerns about this Privacy Policy or our data practices, please get in touch:

User Support & Data Requests

Email: support@trainee.in

Response within 30 days for GDPR requests

Legal & Corporate

Tagsom AB

Email: info@tagsom.com

Virkesvägen 13, 120 78 Stockholm, Sweden