Legal
Privacy Policy
This policy explains what Duskline collects, why we collect it, who can see it, and what you can ask us to do with it. It applies to every worker, company and visitor on the platform.
Last updated 1 August 2026
1. Who we are
Duskline operates a verified-company messaging network for hiring. For the purposes of data protection law, Duskline is the data controller for account data, verification records and platform metadata. Where a verified company processes a worker's profile to assess them for a role, that company is an independent controller for its own hiring records.
2. Data we collect
Account data. Your name, email address, role (worker or company), a hashed password held by our authentication provider, and the verification status of your email address.
Worker profile data. Profile photo, full legal name, date of birth, gender (optional), country, state or province, city, phone number, biography, highest education level, profession, and any resume, certificates or portfolio links you choose to upload.
Company dossier data. Company name and email, logo, description, website and social links, headquarters location, workforce size, years in operation, industry, workplace media, and the names, photographs and descriptions of your leadership bodies.
Content data. Job links you create, the messages, images and files exchanged in conversations, and the notifications generated for your account.
Usage data. Link click counts, message counts, timestamps, and technical logs needed to keep the service secure and available.
3. How we use your data
- To create and operate your account, including one-time-code email verification.
- To review company dossiers and decide whether to grant, withhold or revoke verification.
- To deliver messages, attachments and notifications between the two parties.
- To present a worker's profile to a company they have started a conversation with, and to present a company's verified profile to workers who open its links.
- To send transactional email — welcome messages, verification codes and account notices — through our email service provider.
- To detect fraud, abuse and misrepresentation, and to enforce our Terms.
4. Legal bases
We process data to perform our contract with you (operating your account and delivering messages), on the basis of legitimate interests (fraud prevention, verification, service security), with your consent where you supply optional information such as gender, gender identity, portfolio links or workplace media, and to comply with legal obligations where they apply.
5. Who can see what
A worker's profile becomes visible to a company only once a conversation exists between them, or once the worker opens that company's job link and bids for the role. A verified company's profile is visible to any worker who opens one of its active links.
Message content is visible only to the two participants of that conversation and to Duskline staff acting on a specific abuse, safety or legal report.
We do not sell personal data, and we do not run third-party advertising.
6. Processors we use
Duskline relies on Google Firebase for authentication, database storage and file storage, and on a dedicated transactional email service for one-time codes and account email. These providers process data on our instructions under contractual data-protection terms.
7. International transfers
Duskline is used in every region we support, so your data may be processed outside your home country. Where data leaves a jurisdiction with data-transfer restrictions, we rely on standard contractual clauses or an equivalent approved transfer mechanism.
8. Retention
Account, profile and conversation data is retained while your account is active. When you delete your account, profile data and file uploads are removed and your authentication record is destroyed. A conversation may remain visible to the other participant in anonymised form where deleting it would destroy their own hiring record. Verification decisions and abuse reports are retained for up to twenty-four months for safety purposes.
9. Security
Data is encrypted in transit. Access to production data is restricted to staff who need it, all database reads are constrained by per-user access rules, and file uploads are scoped to the uploading account. No system is perfect; if a breach affects you we will notify you and the relevant supervisory authority as required.
10. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, export it, restrict or object to processing, and withdraw consent for optional fields. Account deletion is available in Settings and takes effect immediately. For any other request, contact us at privacy@duskline.com; we respond within thirty days.
11. Children
Duskline is not available to anyone under the age of 16, or under the minimum working age in their jurisdiction if that age is higher. We delete accounts we discover to be under age.
12. Changes to this policy
We will post any material change on this page and, where the change affects how we use your data, notify you in-app before it takes effect.
13. Contact
Privacy enquiries: privacy@duskline.com. Trust and verification enquiries: trust@duskline.com.