Legal
Privacy Policy
Status: Version 2.0, in force from 1 September 2026
Internities GmbH — website internities.com, platform app.internities.com and administration interface admin.internities.com
This version continues the version published on 5 July 2026 (version 1.1). It reflects the scope of services and of processing that takes effect when the student area is switched on on 1 September 2026. The text contains no reservations, placeholders or editorial notes.
This privacy policy informs you, pursuant to Art. 13 and Art. 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), which personal data we process, for what purposes and on what legal basis this takes place, to whom we pass data on, how long we store it and what rights you have.
Internities is a two-sided internship placement platform. Students create a profile, upload documents and apply for internship and working-student positions. Companies advertise positions, review applications and decide on invitation and rejection. In addition, we display job advertisements which we take from publicly accessible career pages, and we operate an Ambassador Program with student referrers. Where necessary for understanding, we distinguish expressly between these groups of users below.
We have structured this policy so that for every individual processing operation you can find the purpose, the legal basis, the recipients and the storage period. Sections 5 to 19 follow the process you go through with us. Sections 20 to 26 summarise the cross-cutting information: automated decisions, data obtained from other sources, information you are required to provide, recipients, third-country transfers, storage period and security. Sections 27 to 29 concern your rights.
This policy exists in a German and an English language version. Both bear the same date, are published at the same time and reflect the same scope of processing; they are amended only together. The German version is authoritative. The English version serves comprehension; where it diverges in substance, the German text applies. The earlier English version 1.1 no longer reflects the scope of processing described here and is not delivered alongside this version.
A note on the citations. German statutory provisions are cited in German and untranslated (§ 25 TDDDG, § 38 Abs. 1 BDSG), because a translated name does not identify the provision. § denotes the section, Abs. the sub-section, S. the sentence, Nr. the number, lit. the letter and UAbs. the sub-paragraph. TDDDG is the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (the German Telecommunications Digital Services Data Protection Act), BDSG the Bundesdatenschutzgesetz (the German Federal Data Protection Act), UWG the Gesetz gegen den unlauteren Wettbewerb (the German Act against Unfair Competition), AO the Abgabenordnung (the German Fiscal Code), HGB the Handelsgesetzbuch (the German Commercial Code), EStG the Einkommensteuergesetz (the German Income Tax Act), AGG the Allgemeines Gleichbehandlungsgesetz (the German General Equal Treatment Act) and ArbGG the Arbeitsgerichtsgesetz (the German Labour Courts Act). References of the form "section 12.9" without a statute name are references to a section of this privacy policy.
1. Controller, contact and scope
1.1 Controller
The controller within the meaning of Art. 4 Nr. 7 GDPR is:
Internities GmbH, Hansastraße 42, 20144 Hamburg, Germany. Registered with the commercial register of the Local Court (Amtsgericht) of Hamburg under HRB 197434. VAT identification number DE460791180. Represented by the management: Gwendolin Lüders, Alexander Krink, Boris Albert. Email: hello@internities.de
Below we refer to ourselves as "Internities", "we" or "us".
1.2 Contact on data protection matters
For all data protection concerns — information, rectification, erasure, restriction, portability, objection, withdrawal of a consent, requesting a copy of the safeguards for third-country transfers under section 24, or requesting a review of an automated decision by a person — you can reach us at:
- Email: hello@internities.de
- Postal address: Internities GmbH, Hansastraße 42, 20144 Hamburg
Our email address ends in .de even though our website is reachable at internities.com. That is not an error; both addresses belong to us.
Enquiries to hello@internities.de arrive in a mailbox hosted by Microsoft. Microsoft is our processor in this respect (section 23); the information in section 24 applies to the third-country aspect.
We are established in the Union; a representative under Art. 27 GDPR therefore does not need to be designated.
1.3 Scope
This policy applies to our website internities.com, to the platform app.internities.com, to our internal administration interface admin.internities.com and to the emails we send you in that connection. It applies to
- students and prospective students who use our platform or apply to use it,
- persons acting for a company that holds or creates a company account with us,
- participants in our Ambassador Program and persons applying for it,
- visitors to our websites, and
- persons whose data we did not collect from them directly; section 21 additionally applies to that group.
For Internities' employees, this policy applies only in so far as they use the platform themselves as users. We inform them separately about the processing of their data in the employment relationship — including the logs described in sections 18.2 to 18.4.
For third-party websites to which we link — in particular the career pages of the companies on which you apply in the case of external job advertisements (section 13) — the privacy notices of the respective providers apply.
1.4 Minimum age
Our platform is addressed exclusively to persons who have reached the age of 18; it is not offered to minors. By registering and using it you warrant that you are of full age. Since our offering is addressed exclusively to persons of full age, we do not knowingly process personal data of minors; the special consent threshold for children under Art. 8 Abs. 1 GDPR is therefore not relevant. We do not check age separately and do not collect a date of birth. If we become aware that a minor holds an account or has transmitted data to us, we delete the account and the associated data without undue delay and treat any consent given up to that point as ineffective.
1.5 What we do not do
So that you can place the following sections in context, four clarifications at the outset:
- We do not sell personal data and do not pass it on for third-party advertising purposes.
- We do not make your content available to the artificial intelligence providers we use for the training or fine-tuning of models; that is excluded by contract (section 10.4).
- We embed no advertising networks and no social media plug-ins on our pages. We use no tracking pixels in our emails; we do not evaluate opens and clicks (section 17.3).
- There is no candidate database searchable by companies. A company sees nothing of you until you have applied to it (section 12.2).
2. Terms that occur frequently in this text
- Role means an internship or working-student position presented on the platform.
- Partner companies are companies with their own account with us, which create their roles themselves and receive applications through the platform.
- External job advertisements are roles which we take from publicly accessible career pages. The companies concerned are not our customers and receive no applications through us (section 13).
- ESCO is the European classification of skills, competences and occupations published by the European Commission. We use it as a common vocabulary for the comparison between profiles and roles and refer to it below as the "European skills catalogue".
- Match value is the calculated metric expressing how well your profile fits the requirements of a role (section 11).
- Processors are service providers who process personal data exclusively on our instructions and on the basis of a contract under Art. 28 Abs. 3 GDPR.
3. Which categories of personal data we process
3.1 All user groups
- Account data: name, email address, password hash or passwordless sign-in, role (student, company, ambassador), language choice.
- Usage and log data: IP address, timestamps, device and browser information, application events such as sign-ins, page views and applications.
- Communication data: support enquiries and messages, in-platform messages, notifications, email correspondence with our team.
- Records of contract and consent acceptances: time, version of the text accepted, source of the declaration, IP address and browser identifier.
3.2 Students
- Profile data: higher education institution, field of study and study fields, stage of study, intended and highest degree obtained, expected date of graduation, overall grade, skills, fields of interest, preferences as to working environment, language skills, links to third-party profiles (such as LinkedIn or GitHub), information on work authorisation, current place of residence and willingness to relocate, availability period and desired duration, and a freely worded short text about you.
- Information on previous activities: name of the previous employer as free text, and industry and duration from predefined lists.
- Information on honours and extracurricular engagement.
- Uploaded documents: CV, transcripts of records, certificates of achievement, certificates, letters of recommendation, cover letters and certificates of enrolment, in each case including the text recognised from them and the structured information derived from them.
- The result of the enrolment check and the evidence submitted for it.
- Answers to the questionnaires on interests and on the preferred working environment.
- Matching data: skills mapped to the European skills catalogue, match values, suitability bands, match word and checklist for external job advertisements (section 13.2), academic metric, grounds for exclusion under mandatory requirements, and the associated calculation traces.
- Application data: application status, times, rejection decisions and rejection records.
- Connection and communication data: contact requests and their status, the email address released after acceptance, chat messages and attachments, interview appointments and calendar files.
- Clicks on external job advertisements (section 13.3).
- Exclusively in the context of a handover after a confirmed hiring (section 12.7): telephone number and postal address.
We do not collect a date of birth as a profile field. Where a document you upload contains a date of birth, section 9 applies.
3.3 Companies and their staff
- Company data: company name, industry, website, location, logo and header image.
- Contact persons and team members: names, email addresses, roles and authorisations; for invited persons not yet registered, the email address used for the invitation.
- Job advertisements, answers to the role questionnaire, requirement profiles, editing sessions, published versions, and the description and summary texts generated from them.
- Billing data: subscription and plan status, customer identifier and subscription identifier of the payment service provider, billing email address, extent of the role quotas activated, period of any trial phase, and process logs of the billing operations including the references returned by Stripe to the respective payment or management page. The actual payment and invoicing data is processed exclusively at the payment service provider (section 15).
3.4 Ambassadors
- Application data: name, email address, telephone number, higher education institution, degree programme, semester, information on student groups and reach, free text on motivation, available weekly hours, languages, optional identifiers on professional and social networks, and a free text field for referrals.
- Records of participation: version and time of acceptance of the programme terms, a checksum over the text accepted, IP address, browser identifier and a snapshot of the identity information at the time of acceptance.
- Attribution data on companies referred (section 16.3).
- Reward and payout data: identifier of the payout account and release status. You enter identity, tax and bank data exclusively with our payment service provider (section 16.5).
- Private notes in the Ambassador dashboard, which are visible only to you.
3.5 Persons whose data we did not collect from them directly
These include contact persons named in job advertisements we have taken over, third parties named in free text by other users — such as referees in letters of recommendation and CVs —, persons named in the referral field of an ambassador application, and invited team members of companies. Section 21 applies to these persons.
4. Purposes and legal bases at a glance
We state the legal basis for each processing operation individually in the relevant section. This section summarises them ordered by legal basis, so that you can in particular identify against which processing operations you have the right to object under Art. 21 Abs. 1 GDPR.
4.1 Processing for the performance of the use contract — Art. 6 Abs. 1 UAbs. 1 lit. b GDPR
- Registration, access request, sign-in and session management (section 6).
- Checking of enrolment status as a condition of the conclusion of the contract (section 7).
- Creation and maintenance of the student profile, the interests, the preferences as to working environment, the information on previous activities, honours and engagement, and the shortlists (section 8).
- Storage and provision of uploaded documents, their text recognition and structural evaluation (section 9).
- Mapping of skills and requirements to the European skills catalogue and calculation of the match values (section 11).
- Application, application management, status tracking and the communication that follows from it (section 12).
- Creation of company accounts, member administration, creation of positions and the associated AI functions (sections 10.3 and 14).
- Handling of subscriptions and paid access (section 15).
- Application to and operation of the Ambassador Program, and appointment bookings (section 16).
- Sending of system and status messages that serve the contract (section 17.1).
- Handling of users' support enquiries (section 18.1).
4.2 Processing on the basis of your consent — Art. 6 Abs. 1 UAbs. 1 lit. a GDPR
- Transmission of the text obtained from your documents to the model that maps your skills to the European skills catalogue (sections 9.5 and 11.1).
- Release of your contact email address to a company after acceptance of a contact request (section 12.5).
- Handover of your master data and of the documents you have selected to the hiring company after a confirmed hiring (section 12.7); in so far as the documents released contain data under Art. 9 Abs. 1 GDPR, additionally Art. 9 Abs. 2 lit. a GDPR.
- Automated checking of your certificate of enrolment, in so far as it contains data under Art. 9 Abs. 1 GDPR (section 7.3); additionally Art. 9 Abs. 2 lit. a and Art. 22 Abs. 4 GDPR.
- Advertising emails (section 17.4), additionally based on § 7 Abs. 2 Nr. 2 UWG.
- Setting and reading the referral cookie (section 5.3), additionally based on § 25 Abs. 1 TDDDG.
- Reach measurement with Vercel Web Analytics (section 5.5), additionally based on § 25 Abs. 1 TDDDG.
Every consent is voluntary and can be withdrawn at any time with effect for the future; the details are in section 27.7.
4.3 Processing to safeguard legitimate interests — Art. 6 Abs. 1 UAbs. 1 lit. f GDPR
For each of these processing operations we name the specific interest we pursue:
- Delivery of the websites and the technical connection logs arising at the hosting provider in that process. Interest: technically fault-free operation protected against abuse (section 5.1).
- Security of the platform, prevention of abuse and fraud, malware scanning of uploaded files, rate limiting and bot defence. Interest: protection of accounts, of uploaded documents and of the availability of the service against attacks, mass account creation and malware (sections 5.6, 9.2, 19.3).
- Operations, error diagnosis and stability, including error capture in the browser, internal error logging and technical usage telemetry of our AI functions. Interest: detection and remedying of disruptions and control of the cost and load of the models used (sections 5.7, 19.1, 19.2).
- Records of consents given and administration of connections. Interest: fulfilment of our accountability obligation under Art. 5 Abs. 2 and Art. 7 Abs. 1 GDPR (sections 6.4, 12.5).
- Documentation of rejection decisions and proof of delivery of the rejection email. Interest: preservation of evidence for the defence against claims under the German General Equal Treatment Act within the periods laid down in § 15 Abs. 4 AGG and § 61b Abs. 1 ArbGG (section 12.3).
- Continuation of a minimal record after the deletion of a rejected application. Interest: avoidance of an inadvertent repeat application for the same published version of the same role (section 12.8).
- Taking over, evaluating and displaying publicly accessible job advertisements. Interest: building an offering of positions that is useful to students even where there is not yet a contractual relationship with the advertising company (section 13.1).
- Logging of a click on an external job advertisement. Interest: traceability of your own application history and measurement of which advertisement sources are actually useful to students (section 13.3).
- Ordering of the list of external job advertisements by proximity to your fields of interest, your industry preference, your prior experience and your field of study. Interest: showing you first, out of a large stock of externally sourced advertisements, the ones that are substantively closest (section 13.2).
- Logging of the catalogue search and of the operational signals of the matching. Interest: quality, accuracy and traceability of the mapping (sections 11.6, 19.4).
- Attribution of referrals to ambassadors without a cookie, via the account metadata, and the display of the first name and the initial of the last name when a referral code is entered. Interest: correct and manipulation-resistant attribution of commission-relevant referrals (section 16.3).
- Delivery log of our emails. Interest: reliable delivery, detection of undeliverable addresses and error diagnosis (section 17.3).
- Observance of objections and undeliverable addresses by way of a suppression list, in so far as the entry does not already rest on a withdrawal or objection. Interest: permanent avoidance of undeliverable sendings (section 17.6).
- Internal notifications to our team. Interest: orderly internal operations and timely response to disruptions (section 17.7).
- Retention of a notice of illegal content and of the decision taken on it beyond the processing of the notice. Interest: proof of proper and non-arbitrary handling as against the supervisory authority and in the event of a dispute, and detection of abusive repeat notices (section 18.5).
- Internal administration views, logged disclosure of personal data to our staff, and the read-only view from the user's perspective. Interest: operations, support and clarification of abuse, with traceable control of staff access at the same time (sections 18.2 to 18.4).
- Communication with contact persons of companies in the context of the business relationship, and their assignment to processing operations (sections 14.1, 14.4).
- Disclosure to authorities and courts, in so far as it is necessary to assert, exercise or defend legal claims. Interest: legal defence (section 23.4).
You may object to each of these processing operations under Art. 21 Abs. 1 GDPR; for direct marketing the separate notice in section 28 applies.
4.4 Processing for the fulfilment of legal obligations — Art. 6 Abs. 1 UAbs. 1 lit. c GDPR
- Records of consents given and of contract versions accepted, Art. 7 Abs. 1 GDPR (section 6.4).
- Implementation and documentation of withdrawal and objection, Art. 7 Abs. 3 and Art. 21 Abs. 3 GDPR (sections 17.6 and 17.7).
- Handling and documentation of data subject requests, Art. 12 to Art. 22 GDPR (section 27).
- Deletion and anonymisation of data that has fallen due, Art. 5 Abs. 1 lit. e and Art. 17 Abs. 1 lit. a GDPR (section 19.5).
- Ensuring the factual accuracy of grades read out, Art. 5 Abs. 1 lit. d and Art. 16 GDPR (section 8.3).
- Invoicing, accounting and retention under § 14 UStG, § 14b UStG, § 147 AO and § 257 HGB (section 15.5).
- Documentation of the withdrawal instruction and of any declaration on the early commencement of the service under §§ 312f, 355 ff. BGB (section 15.4).
- Operation of the notice-and-action procedure for illegal content, confirmation of receipt and notification of the decision under Art. 16 of Regulation (EU) 2022/2065 (section 18.5).
5. Accessing our websites, cookies and access to your terminal equipment (§ 25 TDDDG)
5.1 Delivery of the pages and the hosting provider's logs
Our three interfaces are operated by Vercel Inc.; delivery and the execution of the server code take place in a data centre in Frankfurt am Main. When each page is accessed, our hosting provider processes technical connection data: the IP address of your device, the path requested, the request method, timestamps, and information about the browser and operating system. We keep no log of our own about this; the data arises at our hosting provider, which acts as our processor in this respect. We do not take those logs into our own systems; they arise and remain exclusively with our hosting provider and are deleted there in accordance with the retention rule applicable to the plan we have booked. The decisive criterion for the duration is the necessity for the delivery of the pages, for troubleshooting and for the defence against attacks (Art. 13 Abs. 2 lit. a Alt. 2 GDPR); they are not kept beyond that. We will tell you, on request to hello@internities.de, the period applicable at the time of your enquiry and where it is stated in our hosting provider's documentation. For storage periods generally see section 25.
The purpose is the delivery of the website, the stability of operations, and the detection and prevention of attacks and overload. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in technically fault-free operation protected against abuse.
5.2 Strictly necessary storage on your terminal equipment
We store information on your terminal equipment and access it in so far as this is strictly necessary in order to provide the service you have expressly requested. Access is permissible without consent in that respect under § 25 Abs. 2 Nr. 2 TDDDG; the subsequent processing we base on Art. 6 Abs. 1 UAbs. 1 lit. b GDPR for the sign-in session and otherwise on Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in a functional, usable and secure provision. The entries are the following:
- sb-…-auth-token (cookie) — your sign-in session. Lifetime: according to the session and renewal cycle of the sign-in.
- NEXT_LOCALE (cookie) — the language you have chosen. Lifetime: 1 year where a language is expressly chosen, otherwise until the end of the session.
- internities_consent_v1 (local storage) — your decision in the consent banner. Lifetime: until you clear your browser's storage or we change the version of the banner.
- internities_launch_preview (cookie, only after entry of a key, signed and not readable by scripts) — internal preview gate for staged activations. Lifetime: 30 days.
- announcement-dismissed:… and system-status-dismissed:… (session storage) — notice bars you have dismissed. Lifetime: until the end of the session.
- internities.locale.synced (session storage) — technical protection against a duplicate language synchronisation. Lifetime: until the end of the session.
- companyWalkthroughDismissed:… and companyWalkthroughSeenSteps:… (local storage) — progress of the introductory walkthrough on the company side; the authoritative storage takes place server-side in your profile. Lifetime: until you clear your browser's storage.
- student-roles-density (local storage) — the display density of the position list you have chosen. Lifetime: until you clear your browser's storage.
- internities.viewAs (local storage) and admin:saved-views:… (local storage) — only in our internal administration interface and only for our staff: metadata of the view from the user's perspective under section 18.3, and saved filter views. Lifetime: until sign-out from the administration interface.
5.3 Technologies requiring consent
Without your consent we set no further cookies and store no further information on your terminal equipment. Two categories require consent:
- Referral attribution — the cookie internities_ref containing an ambassador's referral code, lifetime 45 days. It is set exclusively on app.internities.com and exclusively where you have consented for that category. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG. Details in section 16.3.
- Reach measurement — Vercel Web Analytics, see section 5.5.
5.4 Consent banner, withdrawal and binding to the respective address
On your first visit we show a banner in which you can permit or refuse the optional categories individually. On the first level, "Necessary only" stands on an equal footing with "Accept all"; nothing is pre-selected. Strictly necessary technologies under section 5.2 remain active in every case.
You can change your decision at any time — through the "Cookie settings" link in the page footer or, if you cannot find the link, by an informal message to hello@internities.de. Withdrawal is as easy as giving consent (Art. 7 Abs. 3 S. 4 GDPR) and takes effect immediately.
Your decision is stored exclusively locally in your browser; we make no copy of it on our servers. Because browsers keep local storage separately per address, your decision applies only to the address on which you made it: internities.com and app.internities.com keep separate decisions, and you are asked once on each. If you clear the local storage or use another device, we ask again.
5.5 Reach measurement
We use Vercel Web Analytics for reach and usage measurement. Page views, the referring page, the country, the browser type and the device type are recorded. According to the provider's method, no cookies are set and no cross-device identifiers are formed in the process. Because technical characteristics of your browser are nevertheless read out, we obtain your consent under § 25 Abs. 1 TDDDG as a precaution. The administration interface admin.internities.com is not measured.
Measurement starts only after you have consented in the banner for the "Analytics" category; before that, no corresponding script is loaded. If you withdraw your consent, transmission ends immediately. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. a GDPR. The recipient is Vercel Inc.; for the third-country aspect see section 24.
5.6 Bot defence
On publicly accessible form routes — sign-in, access request, enrolment check, company registration, ambassador application and redemption of access codes — we use Cloudflare Turnstile in order to fend off automated mass requests. The verification module required for this is loaded from challenges.cloudflare.com when the respective page is opened. In doing so, Turnstile may access information on your terminal equipment and evaluates technical characteristics of your browser; for the verification we transmit a single-use token and your IP address to Cloudflare. Turnstile serves exclusively to prevent abuse and not to measure reach. We do not store the verification signals.
We base the access to your terminal equipment on § 25 Abs. 2 Nr. 2 TDDDG and the subsequent processing on Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in protecting publicly accessible forms against automated abuse.
5.7 Error diagnosis in the browser
We use Sentry to detect technical errors. Only error events are recorded, not normal page navigation: the error message, the technical call path, the address and request method concerned, and information on browser, time zone and language setting. Your user identifier is not transmitted in clear text but as a hash value, which is a pseudonymisation and not an anonymisation (section 19.1). Before dispatch, a filter removes identifiable email addresses, access tokens and identifiers from the report. The data is processed in Sentry's European data region.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in fault-free and secure operation. For the storage period see section 25.
5.8 Fonts
We use our own fonts delivered with our application (currently Poppins, JetBrains Mono and Satoshi). They are bundled at build time and delivered from our own infrastructure; no requests are sent to third-party servers for them when you visit our website.
6. Access to the student platform, account and records
6.1 Access request and waiting list
Access to the student platform begins with an access request. In it you give your email address and declare whether you accept our General Terms and Conditions and this privacy policy; optionally you may consent to receiving advertising emails.
We store your email address in the form entered and in a normalised form, the university domain derived from it, the processing status of your request, the source of the admission, your language choice and, for evidentiary purposes, your IP address and your browser identifier.
If your email address comes from a higher education institution known to us, you receive an access link or are placed on the waiting list.
If it does not come from a higher education institution known to us, two things happen. First, we automatically record your request as an expression of interest for your institution so that we can decide whether to add it. That is not a route you choose but a direct consequence of your request; it occurs irrespective of what you decide afterwards. What is stored is your email address in the form entered and in normalised form, the university domain derived from it, your IP address, your browser identifier and the number of your attempts. The purpose is to open up further higher education institutions for our offering; the legal basis for this is Art. 6 Abs. 1 UAbs. 1 lit. f GDPR. You may object to this processing under Art. 21 Abs. 1 GDPR (section 27.6); we will then delete the entry. Second, following the request we offer you the option of proving your student status by means of a document (section 7). If you do not want an automated check, the route via an examination by a person described in section 7.3 is also open to you.
Our list of admitted university domains itself contains no personal data.
The legal basis is Art. 6 Abs. 1 UAbs. 1 lit. b GDPR for the pre-contractual handling of your request, Art. 6 Abs. 1 UAbs. 1 lit. c GDPR in conjunction with Art. 7 Abs. 1 GDPR for the record data, Art. 6 Abs. 1 UAbs. 1 lit. a GDPR in conjunction with § 7 Abs. 2 Nr. 2 UWG for any advertising consent given, and Art. 6 Abs. 1 UAbs. 1 lit. f GDPR for the bot protection, the rate limiting and the expression of interest described above. For the storage period see section 25.
6.2 Creation, activation and sign-in
After admission you receive a personalised activation link. When redeeming it you set a password and accept our General Terms and Conditions and this privacy policy. We store your account with the email address and the password hash, and the record under section 6.4.
At each sign-in we check your credentials and establish a session; your role assignment is taken from your profile into the session information so that the application knows which areas you may see. The session is maintained by a cookie (section 5.2). You can change your password yourself and reset it using the "Forgot password" function; for this we send a single-use link and store the token only as a hash value, not in clear text. You can likewise change your sign-in email address; confirmation takes place by way of a link to the new address.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR; for the security mechanisms additionally Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in protecting accounts against unauthorised access.
6.3 Shortlists
You can save roles, file them in folders you name yourself, and follow companies. This information is visible only to you; companies do not learn that you have saved a role or are following them. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR.
6.4 Records of contract and consent acceptances
We keep a register in which we document which version of our terms and of this policy you accepted and when, and which consents you have given or withdrawn. What is stored is the assignment to your account or — before the account is created — to your email address, the type of declaration, the version identifiers accepted, the source of the declaration, the time, and your IP address and browser identifier. We need this information in order to be able to demonstrate, under Art. 5 Abs. 2 and Art. 7 Abs. 1 GDPR, who agreed to which text and when.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. c GDPR in conjunction with Art. 7 Abs. 1 and Art. 5 Abs. 2 GDPR; for the technical characteristics additionally recorded, Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in an evidentially reliable attribution of the declaration.
7. Enrolment check — a solely automated decision in the individual case
If your email address does not come from a higher education institution known to us, you can prove your student status by means of a certificate of enrolment. This section describes a solely automated decision within the meaning of Art. 22 Abs. 1 GDPR. Please read it carefully.
7.1 What happens
You upload a document. It is placed in a separate storage area that is not publicly accessible. Three steps then run:
- Text recognition. The document is transmitted to Google Document AI and converted into text there. Processing takes place in an EU region. We store the recognised text in full.
- Examination by a language model. An extract of the recognised text — the first 12,000 characters — is transmitted to a language model of Anthropic PBC in the United States. The model assesses whether the text evidences a valid, current enrolment and returns a score between 0 and 100, a result, the fields it has read out and a short statement of reasons.
- Decision. If the score reaches the threshold value we have laid down, your access is activated automatically. If it does not, your request is refused automatically. No human being is involved in this process. Only where a technical error occurs is the matter routed for manual handling; it is then precisely not refused automatically.
For this we store: your email address, file name, file type and file size, the storage location, the complete recognised text, a measure of the reliability of the text recognition, the score, the result, the fields read out and the statement of reasons of the examination, the designation of the model used, and the time and version of your declaration regarding the automated examination.
7.2 The logic involved, the significance and the envisaged consequences (Art. 13 Abs. 2 lit. f GDPR)
The model assesses five points: whether the document is legible and complete in substance; whether it is recognisably from a higher education institution and the issuing body is identifiable; whether it is in your name and is not merely a blank form; whether it shows a stage of study or an academic year that is current at the time of the examination and bears a plausible date of issue; and whether the information is internally consistent and does not point to a different or imitated document. A score on a scale from 0 to 100 arises from that assessment.
If the score reaches the threshold value we have laid down, this leads to activation, otherwise to refusal. We do not state the threshold value here, because publishing it would facilitate the targeted circumvention of the check and thereby impair the security of the platform (Art. 32 Abs. 1 GDPR); for the same reason we do not reproduce the individual features by which the model determines the five points above. We will tell you on request the score of your own examination, the model's statement of reasons and the threshold value applicable at the time of your examination (Art. 15 Abs. 1 lit. h GDPR); contact us at hello@internities.de for this.
What is not assessed. Your grades, your origin, your nationality and your age are not assessment criteria. Whether your document names a degree programme or a faculty does affect the assessment, because that is a feature of genuine certificates of enrolment — which degree programme you are taking does not. Where your document contains information not required for the proof, it is transmitted along with the rest (section 7.1) but is not assessed.
The significance of the decision lies in whether you can use the student platform. The decision has no wider effect: your information is not passed on to third parties on the basis of this decision and is not evaluated for other purposes. The envisaged consequence is that only persons who are actually enrolled obtain access to the student area.
7.3 Legal basis and permissibility
The legal basis for the processing is Art. 6 Abs. 1 UAbs. 1 lit. b GDPR; the examination is a pre-contractual measure at your request.
Access to the platform does not depend on this examination. There are three ways of proving student status:
- via the email address of a higher education institution which we have added to our list of recognised university domains. On this route neither a document check nor an examination by an AI system takes place; no document is even requested. In practice this is the normal case — by far the greater part of the access grants made so far came about in this way.
- via uploading a certificate of enrolment, where your email address does not come from a recognised university domain. This section 7 applies only to that route.
- via an examination by a person. If you do not want an automated examination, write to us before uploading at hello@internities.de with the keyword "Immatrikulationsprüfung, manuell"; we will then check the evidence by hand, without any disadvantage to you.
Where the proof is furnished by way of a document, its automated evaluation is indispensable for that route. We base the solely automated decision on Art. 22 Abs. 2 lit. c GDPR: before the examination begins you expressly consent to the automated examination of your document. That consent is freely given because access to the platform does not depend on it; the other two routes are open to you independently of it and are named in the submission process itself.
Special categories of personal data in your certificate. A certificate of enrolment may contain data under Art. 9 Abs. 1 GDPR that we do not need. Because we do not automatically remove such data before transmission to the service providers named in section 7.1 (section 7.5), we obtain your express consent under Art. 9 Abs. 2 lit. a GDPR before the examination starts. It is at the same time the basis under Art. 22 Abs. 4 GDPR for a solely automated decision to be permitted to rest on a text that may contain such data. As suitable measures to safeguard your rights and freedoms we have provided for: the express notice in section 7.5 of this policy to redact, before uploading, everything not required for proving enrolment; the limitation of the transmission to the language model to an extract of 12,000 characters; the limitation of the result to the pure question of access without any further use (section 7.2); the deletion of the certificate and of the recognised text under section 25; and the route to a review by a person under section 7.4. You may withdraw the consent at any time with effect for the future (section 27.7); we will then delete the certificate without undue delay. Without that consent we cannot examine the evidence by way of the document route; the other two routes remain open to you unchanged.
7.4 Your rights and the concrete route to them (Art. 22 Abs. 3 GDPR)
You have the right to obtain the intervention of a natural person on our side, to express your own point of view and to contest the decision. In concrete terms, proceed as follows:
- Write an email to hello@internities.de with the keyword "Immatrikulationsprüfung" and the email address with which you submitted the evidence.
- In that email you can express your point of view and attach further or different evidence. A fresh submission through the form is not possible after a refusal; please therefore use this route if you wish to submit a new or more legible document.
- A member of our team examines the matter manually, looks at the document submitted and the model's statement of reasons, and replies to you without undue delay, as a rule within five working days and in any event within the period laid down in Art. 12 Abs. 3 GDPR.
- If the manual examination is in your favour, we activate your access.
We inform you of the outcome of the automated examination in every case by email to the address you provided — including where the examination went against you. The notification points out that the examination took place without the involvement of a human being and names the point of contact for review by a person described above, including the email address and the keyword. You therefore do not have to look for this route in this policy; it is stated in the notification itself.
7.5 Note on sensitive information
In practice, certificates of enrolment regularly contain a date of birth and occasionally a nationality; they may in addition contain information you do not have to provide for this purpose. Please redact or remove, before uploading, everything not required for proving enrolment. This applies in particular to information from which health data, religious or philosophical beliefs, ethnic origin, political opinions, trade union membership or data concerning sex life may be derived.
On this route we use no technical procedure that automatically removes such information before transmission to the service providers named (section 9.7).
8. Your student profile
8.1 Master data, preferences and free text
You create and maintain your profile yourself. For this we process the profile information listed in section 3.2. Information originating from an uploaded document becomes part of your profile only when you confirm it (section 9.4).
For previous activities, industry and duration must be selected from predefined lists; only the name of the previous employer is free text. That name does not enter the match value (section 11.3) but is displayed to a company after you apply (section 12.2).
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR. Storage period: for the duration of your account.
8.2 Interests and information on the working environment
You can state fields of interest and preferences as to your desired working environment. The answers consist of predefined categories and scales; in addition you can describe what interests you in a free text field. That free text is stored exclusively for you; it is transmitted neither to companies nor to a provider of artificial intelligence and does not enter suggestions that others see. The suggestions we make to you on that basis are calculated according to fixed rules; no AI model is involved in them.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR.
8.3 Transcript of records, overall grade and academic metric
From a transcript of records you upload, we derive an overall grade and an academic metric. The calculation follows a fixed, versioned rule and takes place without the involvement of an AI model: the grades, weighted by credit points, are converted into a value between 0 and 100; to this is added a supplement, limited in amount to a maximum of 15 points, for recorded honours, extracurricular engagement and the volume of credit points taken. Without a documented grade no supplement is awarded, and without a grade no metric arises at all.
You can additionally record honours and engagement yourself and confirm, correct or discard entries we have read out. Your correction is decisive for the result.
If you consider the overall grade we have read out to be incorrect, you can dispute it. For this we store the value you dispute, the time and your reasons. Such a dispute is examined by a person. The grade itself is never overwritten by hand but corrected exclusively by a fresh evaluation of the document.
The academic metric itself is not displayed to companies; the overall grade is displayed (section 12.2).
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR; for the handling of disputes additionally Art. 6 Abs. 1 UAbs. 1 lit. c GDPR in conjunction with Art. 5 Abs. 1 lit. d and Art. 16 GDPR.
8.4 AI-supported mapping of your field of study
If you enter your field of study or your study fields in a free text field, a language model of Mistral AI SAS (France) maps your entry to an official catalogue entry and suggests the result to you. Only the designations you have entered are transmitted — at most five per operation — not your name and not your identifier. Only what you confirm yourself is adopted.
Your fields of interest are not affected by this. You select them from a fixed list; no AI model is involved and nothing is transmitted to a provider of artificial intelligence (section 8.2). A language model suggests fields of interest only on the company side, and there for the role advertised, not for you (section 10.3).
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR. The confirmed mapping becomes part of your profile; we delete the technical usage data of the model call after 90 days (section 19.2).
9. Uploaded documents
9.1 Which documents, where they are stored, who can see them
You can upload CVs, transcripts of records, certificates of achievement, certificates, letters of recommendation and cover letters (PDF, JPEG or PNG, up to 10 MB). The files are stored in a private storage area which no one can access without a valid, tightly time-limited retrieval link. On upload we remove embedded additional information from the file and check whether the file type actually corresponds to the one stated.
Companies do not receive your documents. In the application process they see only which types of documents you have stored — not the files themselves. An exception applies only after a confirmed hiring and only for the documents you release individually for that purpose (section 12.7).
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR.
9.2 Malware scanning
Every uploaded file is scanned for malware before any further use. For this we transmit the file in full, together with the file name and file type, to Ionx Solutions LLP (United Kingdom, product name "Verisys"); only the European endpoint of the service is addressed. We receive back the scan result and a checksum which we bind to the file. As long as no positive scan result is available, the file remains blocked. Attachments in the in-platform chat are scanned in the same way (section 12.6).
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR in conjunction with Art. 32 Abs. 1 GDPR, with the interest in protecting our systems and all users against malware.
9.3 Text recognition
After the malware scan, every uploaded document is automatically converted into text. For this we transmit the raw data of the file to Google Document AI; processing takes place in an EU region. We store the recognised text in full because all further evaluation steps build on it.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR.
9.4 Evaluation and pre-filling of your profile
From the recognised text we obtain structured information. For this we transmit the text — up to 30,000 characters — to language models: the determination of the document type takes place via Mistral AI SAS (France), and the structured evaluation and any necessary correction of the result format via Anthropic PBC (United States). What is transmitted is the text read out and the structured information derived from it, not the raw file.
Depending on the document, the following are read out: contact details, education and career stages, courses taken and grades, skills, projects, language skills, honours, certificates and referees named in letters of recommendation. From the results we create suggestions for your profile and a short summary.
Suggestions are suggestions. No value read out becomes a binding part of your profile without your confirmation. You can change or discard every suggestion.
Note regarding third parties. Where your document contains information about other persons — for example the name and contact details of a referee — that information is transmitted along with the rest and stored. Please upload only documents you are permitted to upload, and redact third parties' contact details where they are not necessary for your application. Section 21 applies to the third parties concerned.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR.
9.5 Your separate consent for the skills comparison, and its withdrawal
When you upload, we ask you separately whether the text of that document may be used for the mapping to entries of the European skills catalogue (section 11.1). That consent is document-specific: it applies only to the document in question and is stored together with the document in a single operation. Without that consent we do not use the document for that purpose. For this we store the time of your consent, the version of the consent text and the place where you gave it.
A decision once taken cannot be changed afterwards for a document already uploaded. You can withdraw the consent at any time with effect for the future by deleting the document concerned — deletion also cancels all mappings derived from it. If you wish to declare the withdrawal without deleting the document, please write to us at hello@internities.de; we will then implement the withdrawal by hand. The lawfulness of processing carried out up to the withdrawal remains unaffected (Art. 7 Abs. 3 S. 1 GDPR).
The legal basis of the transmission is your consent under Art. 6 Abs. 1 UAbs. 1 lit. a GDPR; for the documentation of the consent, Art. 6 Abs. 1 UAbs. 1 lit. c GDPR in conjunction with Art. 7 Abs. 1 GDPR.
9.6 Where an evaluation run has to be repeated
Where the evaluation of a document fails technically, a person from our team can trigger it again. In doing so, the document is transmitted again to the service providers named in sections 9.3 and 9.4. The operation is logged. Error messages we store about it may contain extracts of the document content.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR; for the logging additionally Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in traceable and controllable operations.
9.7 Special categories of personal data (Art. 9 GDPR)
We do not request special categories of personal data within the meaning of Art. 9 Abs. 1 GDPR from you — such as health data, information on religious or philosophical beliefs, ethnic origin, political opinions, trade union membership or sex life — and do not process them in a targeted manner.
Such information may, however, be unintentionally contained in documents you upload and in free text fields, for example a note of severe disability in a transcript or affiliation to a denominational employer in a CV. We therefore ask you to redact, before uploading, all information not required for the respective purpose, and not to enter sensitive information in free text fields. At the places in the logged-in area where you upload documents, we point this out to you expressly; for the submission of the certificate of enrolment, the notice in section 7.5 applies.
There is no automatic technical detection and suppression of special categories before transmission to our processors. The only automatic replacement that takes place concerns contact details and identifiers before the mapping to the skills catalogue (section 11.1); it does not capture substantively sensitive information.
How matters stand with the legal basis — stated openly. When a document is uploaded we ask for one consent. It concerns exclusively the use of the document text for the mapping to entries of the European skills catalogue (section 9.5), is voluntary and has no effect on the other processing steps: the malware scan (section 9.2), the text recognition (section 9.3) and the evaluation to pre-fill your profile (section 9.4) run even if you do not give that consent. We do not currently obtain a separate, express consent to the processing of special categories under Art. 9 Abs. 2 lit. a GDPR for the document route — and we do not assert one here either.
For this case we rely on the following: we do not request such information, do not direct the processing at it, do not evaluate it in a targeted manner and derive no assessment from it; we expressly ask you to redact it before uploading; and we delete a document without undue delay if you tell us that it contains such information — write to us at hello@internities.de for that purpose.
Whether that suffices in law is not conclusively settled, and we would rather tell you than conceal it. Art. 9 Abs. 1 GDPR is a prohibition of processing in principle. Whether a processing operation which is not directed at such information but unavoidably captures it in a document or free text requires one of the exceptions in Art. 9 Abs. 2 GDPR is assessed differently by different authorities and commentators. We are having this question examined by lawyers and will supplement this policy as soon as the result is available; if it emerges that an express consent is necessary, we will obtain it and state it here.
What that means for you. Please do not upload a document whose sensitive information you cannot or do not wish to redact. For the application function we need at least a CV and a transcript of records (section 22); neither has to contain data under Art. 9 Abs. 1 GDPR. A different situation applies to the certificate of enrolment: there we obtain a separate consent before the examination starts, without which the examination does not take place (section 7.3).
10. Use of artificial intelligence: overview, providers and no training
10.1 Overview of the systems and providers used
We use AI systems at several points of the platform. Language models of Anthropic PBC (United States), language models of Mistral AI SAS (France) and Google Document AI for text recognition (processing in an EU region) are used. The following processing operations take place in production; they are not planned or future functions.
The allocation of the individual functions to the providers is as follows:
- Google Document AI handles the text recognition from uploaded documents.
- Mistral AI SAS handles the determination of the document type, the mapping of study fields, the suggestion of fields of interest for an advertised role (company side, section 10.3) and the shortening of job descriptions.
- Anthropic PBC handles all other model calls: the extraction of structured information from documents, the examination of the certificate of enrolment, the mapping of skills to the European skills catalogue, the generation and summarising of job descriptions, and the evaluation of external job advertisements taken over. With Anthropic there are two technically separate processing routes: the model call from within our application, and the model call from the service that maps skills to the skills catalogue.
Marking of AI-generated texts — position today. On the company side, texts pre-filled and generated by an AI system are expressly marked as such (section 10.3). The same applies on the student side: the machine-generated description text of a role is expressly marked as AI-generated text and carries the notice that a language model created it from the details of the position. External job advertisements carry the notice that we found the position on the company's public career page and that the key details and the description text shown there were generated by a language model from the original advertisement; the associated external company profile carries the notice that it was created automatically from public sources and that the profile text shown there was machine-generated by a language model. As a deployer we are not under a legal obligation to mark them under Art. 50 of Regulation (EU) 2024/1689 in the cases described here; the marking is voluntary. We do not currently apply any additional machine-readable marking to such texts.
10.2 Where artificial intelligence merely supports — and where it does not
In the following functions, the artificial intelligence produces exclusively suggestions which take effect only upon confirmation by a human being: the mapping of fields of study (section 8.4), the evaluation of your documents (section 9.4), the mapping to the skills catalogue (section 11.1) and the company-side functions (section 10.3), each of which is released by a person of the company.
Two functions are excepted from this:
- The enrolment check under section 7 takes a solely automated decision; no human being is involved in the regular course.
- For the external job advertisements under section 13.1, we publish the machine-generated description text ourselves. A person from our team checks only whether the mandatory particulars are complete, not whether each individual particular is substantively correct. The original advertisement on the company's career page is therefore always authoritative.
10.3 AI functions on the company side
When a company creates a position, we use AI models for the following steps: reading an inserted job description into structured information, suggesting official catalogue entries for the skills required, suggesting fields of interest for the role, generating the student-visible job description in German and English, shortening that description, and generating summaries per questionnaire section for the internal company view.
These functions process the company's inputs and the master data of the position. They do not assess students and process no student data. The input field for the advertisement text to be inserted expressly points out that no applicant data should be inserted. Every description generated is released by a person of the company before publication. None of these outputs enters the match value as a figure.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR; in so far as personal data of the company's staff is processed in the course of this, additionally Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in conducting the business relationship.
10.4 No training with your data
We use the AI models named exclusively for processing in ongoing operations. Under the data processing agreements concluded with the providers, your personal data is not used for the training or fine-tuning of the models.
11. Skills comparison, match value and suitability ranking
11.1 Mapping of your skills to the European skills catalogue
From the information you have confirmed and — only where you have consented under section 9.5 — from the texts of your documents, we derive a skills profile expressed in the entries of the European skills catalogue.
The process: we break the text down into individual statements. Before a statement leaves our database, we automatically replace email addresses, telephone numbers, web addresses, account numbers and similar identifiers with placeholders. Names and substantively sensitive information are not replaced by that procedure. The statement thus processed, together with at most one sentence of context, is transmitted to Anthropic PBC (United States); the model suggests matching catalogue entries for it.
The model only suggests. It assigns neither a figure, nor a level, nor a confidence value. A suggestion takes effect only when you confirm it. Without your consent on upload, a document is not used for this purpose.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. a GDPR for the transmission of document texts to the service provider named; otherwise Art. 6 Abs. 1 UAbs. 1 lit. b GDPR for the creation of the skills profile.
11.2 Requirement profile of the roles
On the other side, we derive from the information a company provides about its role a requirement profile in the same catalogue language. Here too a language model suggests; a person of the company confirms the selection. No personal data of students enters this step.
11.3 How the match value is calculated — the logic involved
The match value is determined purely by calculation. No figure generated by an AI model, no level assigned by a model and no confidence value enters it. AI support exists before that — in reading out your documents, in suggesting skills and in mapping study fields and fields of interest; each of those suggestions takes effect only when you confirm it.
Exactly four areas enter the calculation:
- Your confirmed catalogue skills and the levels confirmed for them, compared against the confirmed requirement profile of the role.
- Your fields of interest.
- Your information on the desired working environment.
- Your academic metric under section 8.3, compared with the academic level set by the company.
A fixed value table applies to the comparison of a skill with a requirement: an identically worded catalogue entry counts in full, a closely related entry counts proportionately less, more distant entries do not count. The company can weight the four areas differently; the skills area cannot be set to zero and cannot be excluded from the calculation. Areas for which no information is available drop out of the calculation instead of being rated as zero. In addition, the value can increase by at most 15 percentage points where you meet characteristics of a position expressly marked as preferred.
The rule is versioned and frozen for the respective publication of the position. The result is additionally classified into three suitability bands. Before you apply for a role, we record the authoritative state: your skills profile, the published version of the role and the version of the calculation rule. That makes it traceable on what basis the value came about.
Your information on previous activities and the name of a previous employer do not enter the match value.
This processing constitutes profiling within the meaning of Art. 4 Nr. 4 GDPR. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR. Without this processing a comparison is not possible.
11.4 Mandatory requirements and automatic exclusion
Companies can mark individual requirements as mandatory — for example a particular work authorisation, a period of availability, a minimum duration, a location or a maximum grade. Where your information does not meet such a mandatory requirement, your application is automatically assigned to the group of applications not eligible for consideration and appears to the company in a separate section of the list, together with the respective ground of exclusion. Your match value is not altered in the process but merely sorted differently.
In that case too, only a person of the company decides on invitation, offer or rejection. You may at any time request that a person at Internities review the automatic classification; contact us at hello@internities.de for that purpose. We reply without undue delay, as a rule within five working days.
11.5 Suitability ranking towards companies — significance and envisaged consequences (Art. 13 Abs. 2 lit. f GDPR)
Companies see the applications for a position in four separate sections: the applications eligible for consideration, those excluded because of a mandatory requirement, those not yet calculated, and those for which the calculation has technically failed. Applications in the last two groups carry no value; no substitute value is formed for them. The list of applications eligible for consideration is by default sorted in descending order by the numerical value.
Significance and envisaged consequences. The ranking determines the order in which a company reviews applications. The envisaged consequence is that companies see first the applications which best fit the requirements. A lower rank position may result in your application being reviewed later, less attentively or — where there is a large number of applications — not at all. The same applies where the calculation for your application is not available.
The decision on invitation, offer or rejection is always taken by a person on the company's side; the platform itself makes no status change in the application procedure and rejects no application automatically. In law the calculation is therefore profiling under Art. 4 Nr. 4 GDPR and not a solely automated decision under Art. 22 Abs. 1 GDPR.
Classification under the AI Act. A system that assesses and orders applications in the context of access to employment is a high-risk AI system under Annex III No. 4(a) of Regulation (EU) 2024/1689. We treat the suitability ranking described here as such a system and are its provider in that respect; the advertising company is the deployer. We have bound the companies by contract to use the assessment solely as an aid, to appraise every application independently and not to reject any application solely because of the numerical value, the band, the rank position or the assignment to a separate section. If you would like an explanation of the role the system played in a decision concerning you, contact the company or contact us at hello@internities.de; we provide the information necessary for that purpose.
As a student you see only your suitability band for a position, not the numerical value. If you would like to know which values and which version of the rules underlay a particular assessment, we will tell you on request.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR as against both contracting sides.
11.6 Catalogue search, notifications and operational signals
When you or a company search the catalogue for skills, we log the search session, the search text in a cleaned form, the hits and the entries actually selected. Before storage, the search text is cleaned of identifiable contact details. From the search data we additionally form daily aggregates without any personal reference, in order to identify which competences are in demand.
We inform you about completed mapping runs in the application and — where you have permitted emails — by email. Those messages contain only counts, never the content of a statement from your documents.
Legal basis: for the search itself Art. 6 Abs. 1 UAbs. 1 lit. b GDPR; for the logging Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in the quality, accuracy and traceability of the mapping. For the storage period see section 25.
12. Applications, disclosure to companies, rejections and communication
12.1 Application and application management
You can apply for a position as soon as five areas of your profile are complete: the profile information, a CV, a transcript of records, your interests and your information on the working environment. A higher education or a school transcript suffices as a transcript of records; where no higher education transcript is available, the application is marked accordingly for the company.
With the application we store the status of the application, the time of submission, your statement on work authorisation, your current place and country, your willingness to relocate and your willingness to work remotely, your available period and the desired duration, and the links to the recorded state of skills and requirements. You can withdraw an application at any time.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR.
12.2 What a company sees, and when
This is the point at which data leaves our sphere of responsibility. Hence the detail:
Before you apply, a company sees nothing of you. There is no candidate database searchable by companies. If a company opens a profile for which no application exists for one of its roles, it receives the same response as for a page that does not exist.
After you apply and before a contact release, the authorised members of the advertising company see:
- your display name, first name and last name;
- your education details: higher education institution, field of study and study fields, stage of study, intended and highest degree obtained, expected date of graduation, and your overall grade, your credit points, a classification of your course load into bands and the number of your honours;
- the area names of your extracurricular engagement from a predefined short list, not its designation verbatim;
- whether you already have relevant experience, for each activity recorded its industry from a predefined list, the duration in bands (up to three months, three to six months, more than six months) and, where you have recorded it, the name of the previous employer;
- from your application: the statement on work authorisation, your current place of residence and country, your willingness to relocate, your willingness to work remotely, your availability period and the desired duration;
- which types of documents you have stored;
- from the matching: the match value, the suitability band, the breakdown across the four areas, the list of requirements compared and any grounds of exclusion under section 11.4. For each requirement compared, the statement from your documents on which the mapping rests is also displayed, in each case in the wording in which you provided it, with contact details and identifiers replaced by placeholders under section 11.1, and expressly marked as self-declared and unverified.
Not visible at this stage: your email address, your telephone number, your documents themselves, your freely worded short text, your academic metric and your shortlists.
After you accept a contact request, your email address additionally becomes visible and the message channel is opened (section 12.5).
After a hiring confirmed by both sides, and only upon your separate, document-specific release, the company receives a handover package (section 12.7).
Note on sensitive information in displayed statements. The statement displayed for a requirement comes from your documents. Where it contains data under Art. 9 Abs. 1 GDPR — for example a reference to a severe disability, to trade union membership or to religious affiliation — it is displayed to the company with that content. Before display we remove only contact details and identifiers, not substantively sensitive information. We do not currently obtain a separate consent to the disclosure of such information to the company: the consent under section 9.5 concerns only the evaluation of the document by us and does not cover a disclosure to a separate controller. The same applies here as in section 9.7, to which we expressly refer. You can remove any statement originating from a document from your skills profile at any time; the display to companies then ceases for future calculations.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR. On the company's controllership from the point at which it takes note of the data, see section 12.9.
12.3 Rejection decision, evidentiary documentation and dispatch
The company maintains the status of your application. We store the status, the time and the person acting, and notify you of changes. Where a company decides against you, the following happens:
- The rejection is triggered by a person of the company, individually or for a selection of several applications. No automatic rejection takes place.
- We record the decision in a tamper-evident evidentiary log. That log contains exclusively technical identifiers, timestamps and a reason code from a closed list; it contains no names and no free text. The reason code does not leave our database and is not communicated to you.
- Before dispatch there is a window of 15 minutes in which the company can reverse the decision.
- After that window has expired we send the rejection in the name of the company by email. The email contains your first name, the title of the position, the name of the company and a note that it is sent on behalf of that company. It contains neither a ground of rejection nor a match value.
- We log the delivery of the rejection email per recipient, because statutory time limits attach to receipt.
The purpose of the evidentiary log and of the proof of delivery is the preservation of evidence for the defence against claims, in particular under the German General Equal Treatment Act. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR; our interest, and that of the company, is the defence against such claims within the periods laid down in § 15 Abs. 4 AGG and § 61b Abs. 1 ArbGG. Art. 6 Abs. 1 UAbs. 1 lit. b GDPR applies to the dispatch in the name of the company, in relation to you and to the company.
12.4 Contact request
Before contact details are disclosed, we manage a connection request with the states "requested", "accepted", "declined" and "withdrawn". We store the identifiers involved, the status and the times; there is no free text field in this process. We also store these states in order to be able to demonstrate your consent to the later contact release.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR in conjunction with Art. 5 Abs. 2 and Art. 7 Abs. 1 GDPR; our interest is accountability for the consent given.
12.5 Contact release and its withdrawal
If, as a student, you accept a connection request, we release your account email address to the authorised members of the requesting company. That disclosure rests on your consent under Art. 6 Abs. 1 UAbs. 1 lit. a GDPR, which you give by accepting. We do not pass on telephone numbers at this step.
You can withdraw that consent at any time with effect for the future; the lawfulness of processing carried out up to the withdrawal remains unaffected (Art. 7 Abs. 3 S. 1 GDPR). You can declare the withdrawal as easily as you gave the consent (Art. 7 Abs. 3 S. 4 GDPR) — through the settings in your account or by email to hello@internities.de. Withdrawal ends any further contact release. Please note: the withdrawal takes final effect for the operation in question; a fresh request regarding the same operation is not possible afterwards.
12.6 Messages, attachments and scheduling
After a connection has been accepted, students and companies can exchange messages, attach files and propose and confirm interview appointments through an in-platform channel; for confirmed appointments we send a calendar file in which your email address is listed as a participant. Attachments are scanned for malware as described in section 9.2 and released only afterwards; they are reachable exclusively through tightly time-limited retrieval links. Conversations can be reported in order to combat abuse; we store such reports for review purposes.
Please note: what you write in messages and attachments is up to you. It may contain information about third parties; section 21 applies to them.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR for both contracting sides; for the reports and the malware scan, Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in a communication channel free of abuse. If you withdraw your consent under section 12.5, any further contact release ends; communication already exchanged remains unaffected by this, in so far as its further processing is necessary for the performance of the contract or for the examination of abuse.
12.7 Handover package after a confirmed hiring
Where you and a company confirm a hiring, you can release a handover package. In doing so you decide per data group what is handed over. Selectable are: contact details, address, education details, language skills, information on previous activities and your documents. You select your documents individually. Two groups cannot be deselected, without which a handover package would make no sense: your name details — first name, last name, display name and any date of birth stored — and the details of the position placed. The release dialogue accordingly designates the first group as "name and date of birth". If you do not wish to hand over even these, decline the request in its entirety — that is possible at any time and has no effect on the hiring itself. For this purpose we additionally collect your telephone number and your postal address; these two fields are collected exclusively in this dialogue and are required nowhere else, and we store them only if you actually release the associated group.
The release is a consent. Once given, it can no longer be changed for the individual operation, but it can be withdrawn at any time with effect for the future. The withdrawal immediately blocks the company's retrieval route. Data the company has already retrieved before the withdrawal is in its own systems; we have no access to it. We have therefore bound the company by contract to delete the data handed over within 14 days after your withdrawal, unless a statutory retention obligation prevents this. You can assert your rights against the company under Art. 15 to Art. 21 GDPR directly there; we support you in doing so (section 12.9). The company's retrieval access lapses automatically after 30 days in any event. From the handover onwards, the company is independently responsible for the further processing.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. a GDPR; in so far as the documents released contain data under Art. 9 Abs. 1 GDPR, additionally your express consent under Art. 9 Abs. 2 lit. a GDPR. The release dialogue points this out to you separately and requires your express agreement for that data too.
12.8 How long application data remains
- Rejected applications: six months after receipt of the rejection we delete the substantive application data. What remains is a minimal record which serves exclusively to prevent you from inadvertently applying again for the same published version of the same role; the legal basis for that record is Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in avoiding duplicate applications. The period reflects the periods laid down in § 15 Abs. 4 AGG and § 61b Abs. 1 ArbGG with a safety margin.
- Withdrawn applications: deletion six months after the withdrawal.
- Pending applications: until the procedure is concluded, otherwise until your account is deleted.
12.9 The role of Internities and of the companies
Internities is the controller within the meaning of Art. 4 Nr. 7 GDPR for the provision of the platform, the matching and the communication channels.
As soon as a company takes note of applicant data and uses it for its own selection decision, it is independently responsible for that processing; that applies in particular to the review of the application, the selection decision and any use outside the platform. In that respect the information obligations and your rights are directed against the company. We bind the companies by contract to use the data exclusively for the respective selection procedure. In particular, they are expressly prohibited from using it for advertising, from including it in a company-internal applicant pool beyond the current procedure, and from any disclosure to third parties unless you have separately consented.
For two processing operations, Internities and the respective company jointly determine the purposes and means within the meaning of Art. 26 Abs. 1 GDPR: the compilation and ranking of the applicant cohort according to the requirements, mandatory criteria and weightings set by the company (section 11), and the sending of the rejection in the name of the company (section 12.3).
The essence of the arrangement (Art. 26 Abs. 2 S. 2 GDPR). For these two processing operations, the following allocation of obligations applies between Internities and the respective partner company:
- Internities is your point of contact (Art. 26 Abs. 1 S. 3 GDPR). You can address any concern regarding these two processing operations to hello@internities.de. You may nevertheless also assert your rights under Art. 26 Abs. 3 GDPR directly against the company.
- The information obligations under Art. 13 and Art. 14 GDPR for these two processing operations are fulfilled by Internities — by way of this policy.
- Requests for information, rectification, erasure, restriction, data portability and objection are received by Internities, answered by it for its own sphere and forwarded by it without undue delay to the company in so far as they concern the company's sphere; we tell you to whom we have forwarded them. The company is obliged towards us to cooperate within ten working days — only in that way can we meet the period under Art. 12 Abs. 3 GDPR towards you.
- The technical execution of the cohort formation and of the sending of rejections lies with Internities; the substantive specifications — requirements, mandatory criteria, weightings — and the selection decision lie with the company.
- The security of processing under Art. 32 GDPR on the platform is Internities' responsibility; the company is responsible for it in its own systems.
- A personal data breach in these processing operations is notified by Internities under Art. 33 GDPR, and Internities communicates it to you where necessary under Art. 34 GDPR; the company informs us without undue delay of every breach that comes to its knowledge.
We will make the full wording of this arrangement available to you on request at hello@internities.de, in so far as no trade secrets stand in the way.
For all other processing operations, the separate controllership described above applies.
13. External job advertisements
13.1 Where these advertisements come from and what we do with them
Alongside the roles of our partner companies, we display positions which we take from publicly accessible career pages. That happens in two ways: by manual transfer by a person from our team, and by automatic retrieval of the official job feeds of the applicant tracking systems used by the companies. We store the advertisement text taken over verbatim.
From that text we have a language model of Anthropic PBC (United States) read out the key details and generate a uniformly structured description text. The advertisement is marked as external and carries the notice that we found the position on the company's public career page and that the key details and the description text displayed were generated by a language model from the original advertisement; an external company profile additionally carries the notice that it was created automatically from public sources and that the profile text displayed there was machine-generated by a language model (section 10.1). The original text is not displayed to students. A person from our team checks before publication whether the mandatory particulars are complete; we do not check whether each individual particular is substantively correct. The companies concerned are not partners of ours, do not maintain these entries and have not confirmed them. The original advertisement on the company's career page is the only authoritative source.
External advertisements do not go through the skills comparison under section 11: for them there is no match value from the European skills catalogue and no suitability ranking towards a company. We do, however, order the list of external advertisements according to your profile; how that happens is described in section 13.2.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, in so far as the texts taken over contain personal data. Our interest is to show students a usable and current offering of positions even where there is not yet a contractual relationship with the advertising company. In so far as an advertisement text contains information about a contact person, section 21 applies.
The raw text taken over is deleted as soon as the associated entry is removed from the catalogue, and at the latest 30 days thereafter. Advertisements that can no longer be found on the company's career page are archived automatically and are no longer displayed to students; the same period applies to the raw text taken over for an archived entry.
13.2 How we order external advertisements for you
So that the advertisements closest to you appear at the top, we compare every external advertisement with your profile and order the list by the result of that comparison. This takes place on our servers before the list is delivered to you.
What enters the order. Four items of your information are compared with weightings: your fields of interest (greatest weight), the industry of the advertising company, your prior experience — what is compared here is the substantive proximity of the industries, not a text — and your field of study. A calculated value arises from that comparison.
What is additionally displayed but not weighted. Nine further items — place of work, work authorisation, availability, type of position, stage of study, enrolment status, languages, type of internship and a grade requirement — appear to you as a checklist with the states "met", "not met" or "no information". They do not enter the calculated value. Where a requirement expressly set by the advertisement is not met in respect of place of work, work authorisation or availability, the advertisement is ranked below substantively comparable advertisements; substantively better-fitting advertisements are unaffected by this.
A missing entry does not harm you. A criterion for which we have no information enters neither the numerator nor the denominator of the calculation.
What you see. You are shown a match word and the checklist referred to. We show you a match word only where three conditions are met at the same time: a minimum number of criteria must have been assessable at all; we must have been able to carry out a comparison for at least half of the weighted criteria that an advertisement states; and you must have stored fields of interest. Where one of those conditions is absent — in particular for as long as you have not stated any fields of interest — we show you no match word but the note that we cannot yet say anything about it.
What we do not release. The calculated value itself is not displayed to you, does not leave our systems and is in particular not transmitted to the advertising company. The companies concerned are not our customers; they learn from us neither that you have seen one of their advertisements nor any of your information (section 13.1).
This processing is profiling within the meaning of Art. 4 Nr. 4 GDPR. It is not an automated decision within the meaning of Art. 22 Abs. 1 GDPR: it determines only the order of a list which you can freely search, filter and switch yourself to "newest" or "nearest". The calculation is performed afresh each time the list is opened; no stored stock of match values arises in the process.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR. Our interest is to show you first, out of a large stock of externally sourced advertisements, the ones that are substantively closest. You may object to this processing under Art. 21 Abs. 1 GDPR (section 27.6); we will then switch your list permanently to the order of publication.
13.3 When you click on an external advertisement
An application for an external advertisement does not run through us but through the company's career page. When you activate the button that forwards you there, we store the identifier of the role, your user identifier and the time. We do not transmit that event to the company concerned or to third parties.
The purpose is, on the one hand, to be able to attribute your own application history to you and, on the other, to evaluate which advertisement sources are actually useful to students. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interests named. You may object to this processing under Art. 21 Abs. 1 GDPR (section 27.6).
13.4 If you are named in such an advertisement
If you are named by name or with contact details as a contact person in an advertisement we have taken over, we process data which we did not collect from you directly. What applies in that case is set out in section 21.
14. Company accounts, positions and referral attribution
14.1 Registration, company data and members
On registration we collect the data of the person acting (name, business email address, password) and the data of the company (company name, industry, website, location, billing email address). We log the acceptance of our terms and of this policy in accordance with section 6.4.
You can invite further persons into your company account. For this we store the invited person's email address, the role intended for them, the time of the invitation and an expiry date of seven days; we store the invitation token only as a hash value. In that case the email address comes from the inviting company and not from the invited person themselves (section 21).
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR as against sole traders and as against the company; as against employees of legal persons and until an invitation is accepted, Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in conducting the business relationship and in setting up the team access requested by the company; for the record of the declarations, Art. 6 Abs. 1 UAbs. 1 lit. c GDPR in conjunction with Art. 7 Abs. 1 GDPR.
14.2 Company profile, logo and header image
You can upload a logo and a header image. These files are stored in a private storage area and are displayed to students by way of time-limited retrieval links. Please upload only images to which you hold the necessary rights; where persons are identifiable in an image, the company is responsible for ensuring that their consent has been obtained.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR.
14.3 Creating and publishing positions
When creating a role you go through a structured questionnaire. We store your answers, the assignment to the person editing, the editing sessions and the published versions. The AI functions used in the process are described in section 10.3.
You can duplicate a role. The questionnaire answers are copied along with it; information about persons contained in free text is thereby reproduced.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR; for the assignment of the editing sessions to the person acting, additionally Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in the traceability of changes.
14.4 Referral attribution
Where a company comes to us via an ambassador's referral code, we record that attribution: the code used, the time and the person attributed. The basis is either the identifier carried without a cookie in the metadata of the registration account, or the cookie described in section 5.3. The attribution takes place once, when the account is created. Details are set out in section 16.3.
14.5 Deletion of the company account
If the sole administering person deletes the company account, the company, the associated member accounts and the stored files are deleted; beforehand, the mappings in the skills comparison are cancelled and any current subscription with the payment service provider is terminated. We send a confirmation when this is complete. Excluded from deletion is data which we are required by law to continue to retain, in particular invoicing data.
Where the contract ends without the account being deleted — for example because a subscription expires — the company account remains in place; we make the data of the company account available to the company in text form on request to hello@internities.de. In that case the account is deleted only once the administering person deletes it under the first paragraph; the statutory retention obligations remain unaffected. For personal data of applicants, the periods in section 12.8 apply.
14.6 Appointments with our team
You can book an introductory or advisory appointment with our team through our website. For this we process the type of conversation, your name, your email address, a context text you word freely, the period you prefer and your time zone. To hold the appointment we create a calendar entry with an online meeting at Microsoft; in doing so, your name, your email address, the subject and the text you entered are transmitted to Microsoft. Please do not enter information about third parties or sensitive information in the free text field.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR as against sole traders and as against the company; as against employees of legal persons, Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in initiating and conducting the business relationship. Storage period: section 25.
15. Payments, subscriptions and withdrawal
15.1 Subscriptions on the company side
Companies conclude paid subscriptions. For each company account we maintain the contract and plan status, the extent of the role quotas activated (called "slots" in our General Terms and Conditions), the period of any trial phase (called "entry phase free of charge" there) and the billing email address.
Payment processing takes place through Stripe. When setting up and operating a subscription, we transmit to Stripe in particular the email address of the person acting used for billing, the company name and an internal identifier of the company account; we receive back information on the subscription and the invoice. You enter the billing address, any VAT identification number and the means of payment directly on the payment page operated by Stripe. Payment data such as card numbers does not reach our systems. We mirror paid invoices as a copy into your invoice overview.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR; for retention under tax and commercial law, Art. 6 Abs. 1 UAbs. 1 lit. c GDPR.
15.2 Change of subscription, termination and process logs
Companies can switch their subscription to a higher or lower plan, terminate it and revoke the termination. For this we store the previous and the new plan, the time of the switch, the time at which it takes effect and the status of a change scheduled for the end of the period.
In addition we keep a process log of the billing operations and store acknowledgements of the event notifications sent to us by Stripe. Both serve to detect simultaneous or repeated operations, to avoid duplicate executions and payment errors, and to make aborted operations traceable. The process log also contains the references returned by Stripe to the respective payment or management page.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR; for the process and acknowledgement logs, Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in consistent and traceable billing.
15.3 Paid access for students
For paid access for students, the same applies to purchase, renewal and termination as on the company side: payment processing takes place through Stripe, you enter the payment data directly with Stripe, and we store in our application the customer identifier, the subscription identifier, the status and the term. Before paid access expires, we remind you by email 14 days and 3 days in advance. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR.
15.4 Withdrawal instruction and documentation of the withdrawal
Consumers have a statutory right of withdrawal in respect of the distance contracts concluded through our platform — including where no consideration is payable but personal data is provided (§ 312 Abs. 1a S. 1 BGB); the details and the model withdrawal form are set out in the withdrawal instruction, which forms part of our General Terms and Conditions. For evidentiary purposes we store which version of the withdrawal instruction was transmitted to you on conclusion of the contract, whether and when you made a declaration on the early commencement of the service, and whether and when you declared the withdrawal.
That storage is required by law; legal basis: Art. 6 Abs. 1 UAbs. 1 lit. c GDPR in conjunction with §§ 312f, 355 ff. BGB.
15.5 Invoices and statutory retention
We keep an invoice register with the invoice numbers, amounts, times and payment status. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. c GDPR in conjunction with § 14 UStG, § 14b UStG, § 147 AO and § 257 HGB. For as long as a statutory retention obligation exists, we block the data concerned for all other purposes instead of deleting it.
15.6 The role of Stripe and the third-country aspect
Stripe acts as our processor for payment processing. For the fulfilment of its own statutory obligations to establish identity and to prevent money laundering, Stripe is at the same time an independent controller within the meaning of Art. 4 Nr. 7 GDPR; as a payment institution, Stripe is itself an obliged entity under § 2 Abs. 1 Nr. 3 GwG (the German Money Laundering Act). Stripe's privacy notices apply in that respect. Our contracting party is Stripe Payments Europe, Limited, established in Ireland; within the Stripe group a transfer to the United States may occur. The safeguards applicable to that are set out in section 24.
16. Ambassador Program
16.1 Application to participate
You can apply for the programme through a public form. We process the application data named in section 3.4 for selection and for the operation of the programme. Your application additionally reaches our internal team mailbox as a full-text copy (section 17.7).
Please note: if you name other persons in the referral field by name or with contact details, we process their data too. Please name only persons who agree to this. Section 21 applies to those persons.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR as a pre-contractual measure at your request and for the performance of the programme contract; for the processing of third parties named by you, Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in checking the plausibility of your statements.
16.2 Interviews, access code and programme terms
For introductory and selection interviews you book an appointment through our website. For this we process the type of conversation, your name, your email address, a context text you word freely, the period you prefer and your time zone. To hold the appointment we create a calendar entry with an online meeting at Microsoft; in doing so, your name, your email address, the subject and the text you entered are transmitted to Microsoft.
After an acceptance you receive a personal access code. You redeem it on internities.com — in the process your IP address and browser identifier are transmitted to our bot protection to prevent abuse (section 5.6) — and are then taken to the account creation. We document the acceptance of the programme terms in an evidentially reliable manner with the version identifier, the time, a checksum over the text accepted, your IP address, your browser identifier and a snapshot of your name and email details at the time of acceptance.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR; for the record of acceptance, Art. 6 Abs. 1 UAbs. 1 lit. c GDPR in conjunction with Art. 7 Abs. 1 GDPR and additionally Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in being able to prove the conclusion of the contract.
16.3 Referral attribution and display of the name
Where a company reaches our registration through your referral link or enters your referral code, we attribute the new company account to you once, when the account is created. The referral code is carried primarily in the metadata of the registration account; no cookie is required for that. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in a correct attribution of commission-relevant referrals; in relation to the referring person at the same time Art. 6 Abs. 1 UAbs. 1 lit. b GDPR.
In addition — and only where consent has been given for the "referral attribution" category — we store the cookie internities_ref containing the referral code for 45 days, so that the attribution is retained if the registration is completed later. Without that consent no such cookie is set; the attribution then continues to work through the account metadata. Legal basis for the cookie: Art. 6 Abs. 1 UAbs. 1 lit. a GDPR in conjunction with § 25 Abs. 1 TDDDG.
While a complete referral code is being entered, we display through a rate-limited query the first name and the initial of the last name of the referring person, so that the attribution can be checked. We do not disclose the full last name or the email address. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in the verifiability of the attribution.
16.4 Your dashboard
In your dashboard you see the companies attributed to you. Only the company name and the status are displayed; contact details of the companies and individual amounts are not displayed. You receive no personal data of students. You can create private notes; these are visible only to you.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR; for the status display of the company referred, additionally Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in traceable settlement.
16.5 Rewards and payout
Ambassadors receive rewards for companies successfully referred that go on to pay. For settlement and for evidentiary purposes we store persistent identifiers of the parties involved, the commission rate, the base amount, the identifiers of the invoice and of the payout, and information on any chargeback within the first 60 days.
For the payout we use Stripe's onboarding. You enter your identity, tax and bank data exclusively with Stripe; it does not reach our systems. In our application we store only the identifier of the payout account and the release status. For the identity and money-laundering checks, Stripe is an independent controller.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR; for the retention, Art. 6 Abs. 1 UAbs. 1 lit. c GDPR in conjunction with § 147 AO and § 257 HGB.
17. Email dispatch, notifications and advertising
17.1 System and status messages
We send you system and status messages that serve the contract, within the application and by email, for example to confirm registration, for access and recovery links, on application status, connections, messages, interview appointments, rejections in the name of the company, billing, expiry of paid access and support. In doing so we process your email address, your form of address, your language choice and the information required for the operation in question.
You can unsubscribe from individual categories of email notification; certain notices within the application remain in place for systemic reasons. These messages are not advertising within the meaning of § 7 UWG.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR as against contracting parties; as against employees of company customers, Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in performing the contract with the company.
17.2 Who sends the emails
The dispatch of our platform-triggered emails is handled by Plus Five Five, Inc. (product name "Resend"); addresses and content are transmitted. The emails for sign-in, for confirming the email address and for password recovery are sent through the authentication layer of our database service provider Supabase, Inc. To be distinguished from this is the mailbox hello@internities.de operated by Microsoft for personal communication, support and the handling of data subject requests; it does not serve automated dispatch.
17.3 Delivery log
For every email we send, we log the delivery history: an irreversible hash value of the recipient address — not the address itself —, the type of message, the delivery event, an identifier of the dispatch and technical metadata without any personal reference. Delivery, delay, rejection and complaint are recorded in particular. We do not evaluate opens and clicks; we discard the corresponding notifications from our dispatch service provider. We do not store the subject and content of the messages in this log.
The purpose is proof of delivery, detection of undeliverable addresses and troubleshooting. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in reliable and demonstrable delivery, with pseudonymised storage and a short period; for rejection emails additionally with the interest in proof of receipt. For the storage period see section 25.
17.4 Advertising emails
You receive advertising emails about our offering only where you have expressly consented. The consent takes effect in a two-step procedure: you declare it on registration, and it becomes active only upon your confirmation through a confirmation link. Until then we send no advertising. We store the status of your consent and a record line with the time, the version identifier of the consent text, the IP address and the browser identifier.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. a GDPR in conjunction with § 7 Abs. 2 Nr. 2 UWG for the dispatch; Art. 6 Abs. 1 UAbs. 1 lit. c GDPR in conjunction with Art. 7 Abs. 1 GDPR for the record.
17.5 One-off information about the availability of the offering
To persons who have registered for access to the platform, and to participants in the Ambassador Program, we communicate once that the offering is available and how they can use it. That message fulfils the request with which you registered with us; it advertises no further product.
How that message is delivered. It is delivered to all recipients in the groups named; the suppression list under section 17.6 is not checked before it. That applies even where your address is listed there as permanently undeliverable. The message nevertheless carries an unsubscribe link and the technical headers for one-click unsubscription; if you activate it, we enter your address in the suppression list and you will receive no further advertising approach from us. Where you have objected to advertising approaches or withdrawn a consent, that does not prevent the dispatch of this one message; in that case we send it only in so far as it is based on Art. 6 Abs. 1 UAbs. 1 lit. b GDPR, and we observe your objection for every further approach.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR. Where the registration does not rest on a use relationship, we base the message on Art. 6 Abs. 1 UAbs. 1 lit. a GDPR in conjunction with § 7 Abs. 2 Nr. 2 UWG and send it only to persons who have consented. You receive advertising beyond that exclusively under section 17.4.
17.6 Suppression list
We maintain a suppression list of email addresses to which no advertising and no bulk message may be sent. It contains addresses whose holders have objected to advertising approaches or withdrawn a consent, and addresses that are permanently undeliverable. What is stored is the address in clear text — the suppression works only that way —, the scope of the suppression, the reason and the time.
This list is checked before every advertising dispatch. Where the check cannot be carried out, the dispatch does not take place. Excepted from that check is the one-off information about the availability of the offering under section 17.5; it is delivered without the list being queried beforehand. We do not send any other bulk messages.
The suppression list continues to exist even after your account has been deleted, because only then does it serve its purpose: without the entry we could not observe your objection permanently. Entries are removed only where you yourself expressly consent again.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. c GDPR in conjunction with Art. 7 Abs. 3 and Art. 21 Abs. 3 GDPR for entries based on a withdrawal or objection; otherwise Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in not writing again to undeliverable addresses. We base the continuation after a deletion on Art. 17 Abs. 3 lit. b GDPR.
17.7 Unsubscribing, withdrawal and internal notifications
Every advertising email contains an unsubscribe link by which you can unsubscribe with one click; in addition, our advertising emails contain the technical headers by which your email program can offer one-click unsubscription. You can also withdraw your consent at any time in the notification settings of your account or by email to hello@internities.de. Withdrawal is as easy as giving consent (Art. 7 Abs. 3 S. 4 GDPR). To evidence the exercise of the right, we store the time, the IP address and the browser identifier.
Certain events trigger a message to our internal team mailbox: incoming ambassador applications as a full-text copy, support and appointment notifications, and technical alerts and a daily error summary in pseudonymised form. The mailbox is hosted at Microsoft Ireland Operations Limited. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in orderly internal operations and a timely response to disruptions.
18. Support, administration and internal controls
18.1 Support enquiries
You can open a support ticket through the application. In doing so we process the metadata of the matter and your messages verbatim. Please tell us only the information necessary to resolve your concern, and in particular refrain from special categories of personal data under Art. 9 Abs. 1 GDPR and from information about third parties. If you nevertheless transmit such information of your own accord, we process it exclusively to handle your concern on the basis of the express consent you thereby give (Art. 9 Abs. 2 lit. a GDPR); you can withdraw that consent at any time by asking us at hello@internities.de to delete the message concerned. The identity of the person from our team handling the matter is not displayed to you.
A matter with no further response is closed automatically after seven days.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. b GDPR as against users; as against employees of company customers, Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in providing support for the contracting party.
18.2 Administration views, masking and inspection of clear data
Our administration interface displays personal data masked by default. In order to view clear data — such as a complete email address — an authorised person from our team must state a reason; only then is the data displayed. Every such inspection is logged, and logged before the data becomes visible. Extracts can be exported as a file for work lists; that too is logged.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in orderly operations, the handling of support and abuse cases, and the control of access to clear data.
18.3 View from the user's perspective
For error diagnosis, authorised persons from our team can take a strictly read-only view from the perspective of a user account. In that view nothing can be changed, sent or deleted; every attempt to make a change is blocked. Access is limited to two minutes, requires a statement of reasons and is logged twice. Accounts of our own team cannot be viewed in this way.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in remedying errors which cannot otherwise be reproduced. We consider this measure proportionate because it is strictly read-only, tightly time-limited, subject to a duty to state reasons and fully logged; those limitations are the safeguards that carry the balancing.
18.4 Log of administrative interventions
We log all interventions by our team in the administration interface in a tamper-evident manner: the person acting and the person concerned, the type of action, the record concerned, the reason stated, the time, the IP address and the browser identifier.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR in conjunction with Art. 5 Abs. 2 GDPR, with the interest in the traceability and abuse control of administrative access. Where your account has been deleted in the meantime, the log may still contain a copy of your email address until its period expires; the basis for that is Art. 17 Abs. 3 lit. e GDPR.
18.5 Notification of illegal content (Art. 16 DSA)
At internities.com/report-illegal-content we provide a form through which any individual or entity — including without a user account and without logging in — can notify us of content they consider to be illegal. The form is reachable through the footer of our website, through the footer of the application and through the legal notice (Impressum).
What we process in this connection. The explanation of why the content is considered illegal, the indication of the storage location of the content notified, the type of item notified, and the name and email address of the individual or entity submitting the notice. The name and email address are dispensed with for notices concerning content that involves an offence under Articles 3 to 7 of Directive 2011/93/EU (Art. 16 Abs. 2 lit. c DSA). Added to this are the time of receipt and technical metadata of the transmission. Where your explanation contains information about further persons, section 21 applies to them.
What we do with it. We confirm receipt, examine the notice, decide on it and notify you of the decision together with the possibilities for redress. The confirmation and the notification go exclusively to the email address stated in the notice.
🔴 We do not verify that address. Anyone who completes the form does not have to log in and does not prove their identity. We therefore send the confirmation of receipt and the notification of the decision to the address stated, without being able to establish whether it belongs to the person submitting the notice. Please therefore do not state an address that does not belong to you, and note that the notification reproduces the matter notified.
Legal bases. For the operation of the procedure, the confirmation of receipt and the notification of the decision: Art. 6 Abs. 1 UAbs. 1 lit. c GDPR in conjunction with Art. 16 Abs. 1, Abs. 4 and Abs. 5 of Regulation (EU) 2022/2065; the Regulation is directly applicable Union law within the meaning of Art. 6 Abs. 3 UAbs. 1 lit. a GDPR and lays down the obligation with sufficient precision. For the retention beyond the handling of the notice: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in being able to demonstrate the proper and non-arbitrary handling and to detect abusive repeat notices. An objection under Art. 21 Abs. 1 GDPR is possible against the retention; we can accede to it only in so far as our evidentiary obligations under the Regulation named do not stand in the way.
Recipients. Our email service provider for sending the confirmation and the notification (section 23) and, where the notice gives cause for it, the competent authorities (Art. 18 DSA). The person submitting the notice is not disclosed to the person affected by the notice unless that is indispensable for handling it or legally required.
Storage period. 24 months from the decision on the notice (section 25).
19. Processing that runs in the background
19.1 Internal error logging
In addition to the error diagnosis in the browser (section 5.7), we maintain an internal error log in our own database. It contains the cleaned error message and its context, an identifier for grouping errors of the same kind and — where the error can be attributed to an account — an irreversible hash value of your user identifier. That hash value is a pseudonymisation, not an anonymisation: it allows us to check whether a particular account was affected.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in the detection and remedying of disruptions.
19.2 Usage data of the AI functions
For every call to a language model we log the function, the provider, the model designation, the number of text units processed, the reason for termination, the duration, the outcome and — only in the document route — an irreversible hash value of your user identifier. The content of the requests and of the responses is not stored in the process. No provider receives this usage data back from us.
The purpose is cost and volume control, and the detection of abuse and malfunction. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in economic and technical control over the use of chargeable external services.
19.3 Rate limiting
To protect against overload and automated attacks, we limit the number of requests per unit of time. Depending on the endpoint, your IP address or your user identifier serves as the key. The counters are kept at Upstash, Inc. in a data centre in Frankfurt am Main; no content data is processed in the process.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in the availability of the service and the prevention of abusive use.
19.4 Operational monitoring of the matching
We record technical operational signals of the matching procedure — run states, processing reservations and failures — and notify our team in the event of disruptions.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR in conjunction with Art. 32 Abs. 1 GDPR, with the interest in operational and data security.
19.5 Automatic deletion and anonymisation runs
Part of the periods named in section 25 is enforced by scheduled procedures which delete or anonymise data that has fallen due and keep a log about this without any personal reference. Those procedures are themselves a processing operation.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. c GDPR in conjunction with Art. 5 Abs. 1 lit. e and Art. 17 Abs. 1 lit. a GDPR.
19.6 Technical response buffer
Where our database calls its own endpoints, the response is buffered briefly. The buffer may contain extracts of the respective response and thus, in an individual case, personal data; it is emptied automatically after approximately six hours.
Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in the technical traceability of internal processes.
20. Automated decisions and profiling at a glance
This section summarises what is described in detail in sections 7 and 11 and in that respect fulfils the information requirements of Art. 13 Abs. 2 lit. f GDPR.
20.1 The one solely automated decision
There is exactly one processing operation in which a decision with effect concerning you is taken solely by automated means: the examination of the certificate of enrolment (section 7). The logic, significance, envisaged consequences, legal basis, the basis under Art. 22 Abs. 4 GDPR for special categories and the route to a review by a person are set out there.
20.2 Profiling without an automated decision
The calculation of the match value, the classification into suitability bands, the checking of mandatory requirements and the ranking of the applicant list that follows from it (section 11) constitute profiling within the meaning of Art. 4 Nr. 4 GDPR. They are not a solely automated decision: a person of the company decides on your application in every case; the procedure makes no status change itself and rejects no application.
A second, separate instance of profiling is the ordering of the list of external job advertisements under section 13.2. That too is not an automated decision; it determines only the order of a list and is not made accessible to any company.
We do, however, openly point out two things: the applicant list is by default sorted in descending order by the calculated value, and the order may influence which applications are read first and more attentively. Where an application does not meet a mandatory criterion set by the company, it is kept in a separate section of the list and displayed there with the ground of exclusion. In that case too, the decision on the status of the application remains with a person of the company; independently of that, you can request under section 11.4 that a person at Internities review the automatic classification.
20.3 Where artificial intelligence merely supports
All other AI-supported functions produce suggestions which take effect only upon confirmation by a human being; the two exceptions are set out in section 10.2.
21. Data we did not collect from you directly (Art. 14 GDPR)
This section is addressed to persons whose data we have obtained from other sources.
21.1 What data is involved and where it comes from
- Contact persons in external job advertisements. We take advertisement texts from publicly accessible career pages of the companies and from their official job feeds. Those texts may contain names, business email addresses, business telephone numbers and forms of address of contact persons. The text is stored verbatim and transmitted to a language model for evaluation (section 13.1).
- Third parties named by users. Third parties may be named in free text and documents of our users: referees in letters of recommendation and CVs (section 9.4), persons in the referral field of an ambassador application (section 16.1), persons in support messages (section 18.1) and persons in messages between users (section 12.6). In those cases the source is the respective user.
- Invited team members of companies. Until an invitation is accepted, the email address comes from the inviting person of the company (section 14.1).
- Data from payment processing. From Stripe we receive information on subscriptions, invoices and payouts (sections 15 and 16.5).
21.2 Purposes and legal bases
- Contact persons in external advertisements. We store the advertisement text in its original form in order to be able to reproduce the advertisement correctly in substance and to trace changes to the original advertisement, and we evaluate it by machine in order to generate key details and a structured description text from it. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR. Our interest lies in the completeness and currency of our catalogue of positions.
Our balancing, stated openly: we do not need the information about contact persons for our purpose, do not evaluate it separately and do not approach the persons named on that basis. Weighing against you is that we store the text verbatim and transmit it for evaluation to a processor in the United States (sections 21.3 and 24.2), and that an address named in the text may contain your name. Weighing in your favour are the purpose limitation to the pure display of the advertisement, the short storage period of the raw text (section 25), the exclusion of any approach, and your right to object under Art. 21 Abs. 1 GDPR (section 21.4), exercisable at any time, with which we comply without further examination. Weighing in your favour further is that the information was made publicly accessible by the advertising company itself — we do not, however, treat that circumstance as decisive in itself.
If you are named in such a text and do not want that to be the case, a message to hello@internities.de suffices; we will remove the information without undue delay (section 21.4).
- Third parties named by users. We process this information exclusively in order to render the respective service to the person naming them, and in the case of an ambassador application in order to check plausibility. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR. Our interest: we cannot check the content of texts posted by users in advance without making the service unusable. We do not approach the persons named on the basis of that information.
- Invited team members. We use the address exclusively to deliver the invitation and to create the account. Legal basis: Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the inviting company's interest in setting up team access; from acceptance onwards, Art. 6 Abs. 1 UAbs. 1 lit. b GDPR. The invitation email contains the reference to this privacy policy and thereby also fulfils the information requirement under Art. 14 Abs. 3 lit. a GDPR.
- Data from payment processing. Art. 6 Abs. 1 UAbs. 1 lit. b und lit. c GDPR.
21.3 Recipients, third-country aspect and storage period
The advertisement text in its original form is transmitted to Anthropic PBC (United States) for machine evaluation; otherwise the recipients follow from section 23 and the third-country transfers from section 24. The storage period follows from the section referred to in each case and from section 25; information about third parties in free text shares the fate of the operation in which it appears.
21.4 Your rights
You have the same rights as all other data subjects (sections 27 to 29), in particular the right to erasure and the right to object under Art. 21 Abs. 1 GDPR. If you are named in a text stored with us and do not wish us to continue processing that information, write to us at hello@internities.de. We will examine the case and remove the information without undue delay, unless a statutory retention obligation stands in the way.
21.5 When and how we provide information
We inform data subjects within one month of obtaining the data, at the latest at the time of the first communication where we communicate with them, and at the latest at the time of disclosure where the data is disclosed to third parties (Art. 14 Abs. 3 GDPR).
Where individual information is impossible for us or would involve a disproportionate effort, we make it publicly available here (Art. 14 Abs. 5 lit. b GDPR). That concerns in particular contact persons in advertisements taken over, in so far as we hold no contact details beyond the advertisement text and the attribution of a passage to a particular person is not possible beyond doubt, and third parties named in free text where we cannot reliably infer from the information whether and how the person can be reached, and where making contact solely for the purpose of notification would itself be an additional processing operation.
22. Whether provision is required (Art. 13 Abs. 2 lit. e GDPR)
You are not legally obliged to provide us with personal data. Part of the information is, however, necessary for the conclusion or performance of the use contract. We therefore state for each item what the consequence of not providing it is:
- Email address, name and password. Necessary for the conclusion of the contract. Without them we cannot create an account.
- Access to the student platform. Either an email address of a university domain known to us or a certificate of enrolment is necessary (section 7). Without one of the two we cannot activate access.
- Profile information, CV, transcript of records — called "Notenblatt" in the application and "Zeugnis" in our General Terms and Conditions —, interests and information on the working environment. Necessary in order to use the application function. Without them you can view the offering of positions but cannot apply.
- Information on work authorisation, availability, place of residence and desired duration. Necessary for the application. Without them we cannot check the mandatory requirements of a position; the application cannot be submitted. Where your information does not meet a mandatory criterion, you cannot successfully apply for the role in question.
- Telephone number and postal address. Necessary only for the handover after a confirmed hiring (section 12.7). Without them the handover package cannot be provided; the hiring itself does not depend on them.
- Consent to the use of the model when uploading a document (section 9.5). Voluntary. Without it, the document concerned is not evaluated for the mapping to the European skills catalogue; all other functions remain open to you.
- Acceptance of a contact request and release of your email address (section 12.5). Voluntary. Without it, no direct contact and no message channel with the company concerned comes about.
- Consent to advertising emails (section 17.4). Voluntary. Not giving it or withdrawing it has no effect whatsoever on the use of the platform.
- Consent to optional cookies (section 5.3). Voluntary. Without it the platform functions in full; only the attribution of a referral may be lost in individual cases.
- Payment data (section 15). Necessary for contracts for consideration. Without it no contract for consideration comes about.
In addition, the following in particular are voluntary: your freely worded short text, the statement of previous activities, the statement of honours and engagement, and the uploading of documents beyond the transcript of records. If you do not provide this information, no disadvantage arises for you; individual functions are then unavailable or available only to a limited extent, and your match value may be lower because fewer confirmed items of information are available.
The same applies correspondingly to companies: the company name, the contact details of the person acting and the information in the role questionnaire are necessary in order to create a company account and to publish a position; for paid plans, the billing data is necessary in addition.
23. Recipients and processors
23.1 Principle
Within our company, only those persons receive access who need it for their task; access to clear data additionally requires a statement of reasons and is logged (section 18.2). Externally, we pass on data only in so far as this is described in this policy, you have consented, or we are legally obliged to do so. We do not sell personal data and do not pass it on to third parties for advertising purposes.
23.2 Service providers acting for us
The following service providers process personal data on our behalf on the basis of a contract under Art. 28 Abs. 3 GDPR. For transfers to third countries, the safeguards under section 24 apply in addition.
- Supabase, Inc. — database, authentication including the dispatch of the sign-in, confirmation and recovery emails, file storage, real-time connections and background functions. All the stores named in this policy are held here unless expressly stated otherwise. The project is operated in the Ireland region. Company seat: United States.
- Vercel Inc. — hosting and execution of our applications and the operational logs arising in the process; execution is fixed to the Frankfurt am Main region. All requests run through this infrastructure. Vercel also provides the reach measurement under section 5.5. Seat: United States.
- Plus Five Five, Inc. ("Resend") — dispatch of our platform-triggered emails including addresses and content, and feedback on delivery status. Seat: United States.
- Anthropic PBC — language models. There are two technically separate processing routes: the model call from within our application (examination of the certificate of enrolment, extraction of structured information from documents, generation of job descriptions and summaries, evaluation of external job advertisements) and the model call from the service that maps skills to the European skills catalogue. What is transmitted is the text obtained from documents, or individual statements formed from it, and the texts entered by companies; raw files are not transmitted. Seat: United States.
- Mistral AI SAS — language models for the determination of the document type, the mapping of study fields, the suggestion of fields of interest for advertised roles and the shortening of job descriptions. What is transmitted is the respective input text and the text obtained from documents. Seat: France.
- Google Cloud EMEA Limited (Google Document AI) — text recognition; the raw data of the uploaded document is transmitted for this. Processing is configured to an EU region; the contracting party is established in Ireland, and group access by Google LLC (United States) is not excluded.
- Ionx Solutions LLP ("Verisys") — scanning of uploaded files and chat attachments for malware; the complete file contents are transmitted. Seat: United Kingdom; the European endpoint of the service is addressed.
- Stripe Payments Europe, Limited (Ireland) and Stripe, Inc. (United States) — payment processing, subscription management and payout onboarding. Processor for the billing, and at the same time independent controller for its own obligations relating to identity verification and the prevention of money laundering.
- Cloudflare, Inc. — protection of publicly accessible forms against automated access; your IP address, browser signals and a verification token are processed. Seat: United States.
- Upstash, Inc. — store for rate limiting; user identifiers or IP addresses with request counters are processed temporarily, no content data. Frankfurt am Main region; seat: United States.
- Functional Software, Inc. ("Sentry") — capture of application errors; cleaned event data and an irreversible hash value of the user identifier are transmitted. European data region Frankfurt; seat: United States.
- Microsoft Ireland Operations Limited — two separate services: first, the hosting of the central mailbox hello@internities.de for general communication, support, internal notifications and the handling of data subject rights, in the course of which all incoming and outgoing correspondence including sender and recipient details, subject, message text and attachments is processed; second, the calendar and online meeting function for appointment bookings under sections 14.6 and 16.2. Depending on the concern, special categories under Art. 9 GDPR cannot be ruled out in a message addressed to us; the legal basis in that respect is your express consent given by sending it, under Art. 9 Abs. 2 lit. a GDPR, and otherwise section 18.1. Seat: Ireland; group connection: United States.
These service providers in turn use sub-processors — for example Amazon Web Services for the database operation, Twilio in the chain of the malware scan and OpenAI in the chain of the database platform. We will make a complete and current list available to you on request at hello@internities.de.
23.3 Other users and companies
- Companies advertising positions on our platform receive applicant data in accordance with section 12.2, the contact email address released under section 12.5 and the documents handed over under section 12.7. On the allocation of roles, see section 12.9.
- Students see the roles and company profiles published by companies.
- Ambassadors see exclusively the company names attributed to them and their status (section 16.4); they receive no personal data of students.
23.4 Authorities and legal proceedings
We pass data on to authorities and courts in so far as we are legally obliged to do so or in so far as this is necessary to assert, exercise or defend legal claims. The legal basis is Art. 6 Abs. 1 UAbs. 1 lit. c GDPR or Art. 6 Abs. 1 UAbs. 1 lit. f GDPR, with the interest in defending against claims.
23.5 Data sources that are not recipients
From the operators of the applicant tracking systems whose public feeds we use to retrieve job advertisements (section 13.1), we receive data; we transmit none to them. We hold the European skills catalogue locally; no connection to the European Commission arises during the matching.
24. Transfers to third countries (Art. 44 ff. GDPR)
24.1 Principle
Some of the recipients named in section 23.2 have their seat or their group connection outside the European Union. In those cases a transfer of personal data to a third country may take place, or access from a third country cannot be excluded. For each of those cases we have agreed appropriate safeguards. You can obtain a copy of the respective safeguards on request at hello@internities.de.
In so far as processing takes place exclusively in the European Union or the European Economic Area, no third-country transfer occurs in that respect; any support or remote access from a third country is nevertheless covered per provider by the safeguards set out below.
24.2 Recipients in the United States
- Supabase, Inc. Processing takes place in an EU project in Ireland. A third-country connection arises through possible support and remote access from the United States. Basis: EU standard contractual clauses (module 2, controller to processor) under Implementing Decision (EU) 2021/914 in conjunction with Art. 46 Abs. 2 lit. c GDPR.
- Vercel Inc. Execution is fixed to Frankfurt am Main; build, log and administration data may reach the United States. Basis: EU standard contractual clauses (module 2) under Implementing Decision (EU) 2021/914 in conjunction with Art. 46 Abs. 2 lit. c GDPR, supplemented by the addendum for transfers to the United Kingdom.
- Plus Five Five, Inc. ("Resend"). Basis: EU standard contractual clauses (module 2) under Implementing Decision (EU) 2021/914 in conjunction with Art. 46 Abs. 2 lit. c GDPR. The provider additionally relies on a certification under the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795).
- Anthropic PBC. Basis: EU standard contractual clauses (module 2) under Implementing Decision (EU) 2021/914 in conjunction with Art. 46 Abs. 2 lit. c GDPR, supplemented by the addenda for the United Kingdom and Switzerland. As supplementary measures, the limitation of storage to the duration of the processing and the exclusion of use for training purposes have been agreed.
- Google LLC (group access to the text recognition operated in the Union). Processing and storage take place in the EU region; the contracting party is Google Cloud EMEA Limited in Ireland. For any remaining group or support access, the EU standard contractual clauses under Implementing Decision (EU) 2021/914 in conjunction with Art. 46 Abs. 2 lit. c GDPR apply; in addition, Google LLC relies on a certification under the EU-US Data Privacy Framework.
- Stripe. The contracting party is Stripe Payments Europe, Limited, established in Ireland; the third-country connection arises through intra-group onward transfer to the United States. Basis: EU standard contractual clauses (modules 1 and 2) under Implementing Decision (EU) 2021/914 in conjunction with Art. 46 Abs. 2 lit. c GDPR; in addition, the US entity relies on a certification under the EU-US Data Privacy Framework.
- Cloudflare, Inc. Basis: EU standard contractual clauses under Implementing Decision (EU) 2021/914 in conjunction with Art. 46 Abs. 2 lit. c GDPR; in addition, Cloudflare relies on a certification under the EU-US Data Privacy Framework.
- Upstash, Inc. Processing and storage take place in Frankfurt am Main. For the remaining access by the US entity, the EU standard contractual clauses (module 2) under Implementing Decision (EU) 2021/914 in conjunction with Art. 46 Abs. 2 lit. c GDPR apply.
- Functional Software, Inc. ("Sentry"). Processing in the European data region Frankfurt. For the remaining access by the US entity, the EU standard contractual clauses (module 2) under Implementing Decision (EU) 2021/914 in conjunction with Art. 46 Abs. 2 lit. c GDPR apply; in addition, the provider relies on a certification under the EU-US Data Privacy Framework.
- Microsoft Corporation (group connection of Microsoft Ireland Operations Limited). The contracting party is an EU entity; within the EU Data Boundary, personal data is stored and processed in the European Union. For any remaining transfers to Microsoft Corporation, the EU standard contractual clauses under Implementing Decision (EU) 2021/914 in conjunction with Art. 46 Abs. 2 lit. c GDPR and the addendum for the United Kingdom apply; in addition, Microsoft relies on a certification under the EU-US Data Privacy Framework. A residual risk exists in the case of support or remote access from the United States.
What you should know about this: In the United States, authorities may access data under certain conditions, and the legal remedies available to data subjects there do not correspond to those within the European Union. The standard contractual clauses above and the supplementary measures agreed are intended to limit that risk; they cannot exclude it.
For the recipients that additionally rely on a certification under the EU-US Data Privacy Framework, we base the transfer on the standard contractual clauses named above irrespective of that certification. On our arrangement, the certification is not decisive for the permissibility of the transfer.
24.3 Recipients in the United Kingdom
This concerns Ionx Solutions LLP. For the United Kingdom, the European Commission adopted an adequacy decision under Art. 45 Abs. 3 GDPR by Implementing Decision (EU) 2021/1772 of 28 June 2021; that decision was time-limited from the outset. For as long as an adequacy decision of the European Commission applies to the United Kingdom, the transfer is based on Art. 45 Abs. 1 GDPR; a separate safeguard under Art. 46 GDPR is then not required. If no such decision applies any longer, we base the transfer on the EU standard contractual clauses under Implementing Decision (EU) 2021/914 (module 2) in conjunction with Art. 46 Abs. 2 lit. c GDPR, and state that at this point. We will tell you at hello@internities.de which legal act applies at the time of your enquiry; the overview of adequacy decisions maintained and published by the European Commission is authoritative. You can obtain a copy of the safeguards under section 24.5.
24.4 Mistral AI SAS
Mistral AI SAS has its seat in France and is therefore established in the European Union. We have concluded a contract with it under Art. 28 Abs. 3 GDPR. We are currently clarifying with the provider in which region the processing technically takes place and which sub-processors are used in the process. Should it emerge that data is processed outside the European Economic Area, we will state that here together with the safeguard then applicable. You can obtain a copy of the contractual bases on request at hello@internities.de.
24.5 How to obtain a copy of the safeguards
We will make a copy of the standard contractual clauses and of the supplementary agreements available to you on request. Please contact hello@internities.de or our postal address for that purpose.
25. Storage period and deletion
We store personal data only for as long as is necessary for the respective purpose or as statutory retention obligations require. The information below states the maximum duration we have laid down; where the purpose ceases earlier, we delete earlier. The applicable period is also stated with each individual processing operation.
Bound to the account — deletion or anonymisation with the account: profile data, preferences, interests, information on the working environment, information on previous activities, honours and engagement, shortlists, the confirmed skills profile, the academic metric and overall grade, pending applications, and company and ambassador master data.
Access and account
- Access requests from students: anonymisation 90 days after the account is activated; requests that do not lead to an activation at the latest 12 months after the date of the request.
- Unconfirmed entries of the former interest list: 7 days. A few records from January and February 2026 remain from that function, which has since been discontinued; they will be anonymised with the next scheduled clean-up.
- Records of contract and consent acceptances: for the duration of the account for accountability purposes; thereafter the record line remains in anonymised form.
- Access codes of the Ambassador Program that were never redeemed: 30 days after expiry.
Documents and their evaluation
- Certificates of enrolment: deletion of the file, of the text recognised from it and of the extracted fields 30 days after the final decision. The score, the outcome, the reasoning, the threshold applied and the designation of the model used are retained for a further 60 days for the human review under section 7.4; the record is deleted 90 days after the final decision.
- Uploaded documents and the data obtained from them, including the recognised text and the structured evaluation results: at most 24 months from the upload; earlier if you delete the document or your account. Confirmed profile information you have adopted from a document remains in existence as profile data.
- Intermediate data of the mapping to the European skills catalogue — run logs, individual statements, suggestions and metadata of the model calls: 90 days. Excepted are statements and selection operations underlying an entry you have confirmed; they are retained as evidence of provenance for as long as the entry exists.
Matching
- Calculations arising when browsing the offering of positions: 90 days.
- Calculations belonging to an application: for the duration of the application in accordance with the application periods; otherwise deletion with the account.
- Logs of the catalogue search, operational signals of the matching and notifications from the matching: 90 days.
Applications and communication
- Rejected applications: deletion of the substantive information 6 months after delivery of the rejection; the minimal record under section 12.8 remains.
- Withdrawn applications: 6 months.
- Evidentiary log of rejection decisions under section 12.3: 4 years from the decision.
- Proof of delivery for rejection emails: 24 months; all other delivery logs 90 days.
- Contact requests, messages, attachments, interview appointments and appointment proposals: 180 days after the connection ends; for existing connections, for their duration. Reports concerning conversations, and notices of illegal content under section 18.5 including the information about the person submitting the notice: 24 months from the decision on the notice.
- The hiring company's retrieval access to documents handed over under section 12.7: 30 days; the release decision and its log 4 years from the release.
- Notifications within the application: 12 months.
Company side and external advertisements
- Company account and member accounts after the end of the contract: no automatic deletion; deleted once the administering person deletes the account, otherwise in accordance with the statutory retention obligations.
- Invitations to team members: 90 days from creation, provided the invitation is no longer open.
- Deleted positions including the associated requirement profiles, questionnaire answers and description texts: final deletion 30 days after deletion by the company.
- Raw texts of external job advertisements taken over: deletion when the associated advertisement is removed, at the latest 30 days thereafter.
- Click log for external job advertisements: 12 months from the click; earlier if you delete your account or the advertisement is removed.
Billing and Ambassador Program
- Invoices and accounting records: for the duration of the retention periods under commercial and tax law pursuant to § 147 AO, § 257 HGB and § 14b UStG, calculated from the end of the calendar year in which the record arose.
- Process and acknowledgement logs of the billing: 12 months.
- Reward and payout records of the Ambassador Program: 10 years from the end of the year in which the claim arose. If you delete your account, those records remain in anonymised form.
- Rejected ambassador applications: anonymisation 6 months after the decision. Applications not decided: 12 months. Applications of ambassadors accepted: for the duration of participation in the programme.
- Acceptances of the programme terms by persons who have left the programme: 10 years from the acceptance.
- Appointment bookings (appointments with our team under section 14.6 and introductory and selection interviews of the Ambassador Program): 12 months after the appointment.
Support, administration and technology
- Support matters and the associated messages: 24 months after the matter is closed.
- Log of administrative interventions and log of the view from the user's perspective: 12 months.
- Connection logs at our hosting provider: according to its plan-dependent retention rule; the decisive criterion is the necessity for delivery, troubleshooting and the defence against attacks, and we will state the exact period on request (section 5.1). Internal error log: 90 days. Error data captured at Sentry: according to the retention rule there, at most 90 days.
- Usage data of the AI functions: 90 days.
- Rate-limiting counters: at most around 48 hours, as a rule a few minutes.
- Technical response buffer: around 6 hours.
Email advertising
- Suppression list under section 17.6: indefinitely, for as long as the objection or the undeliverability persists. The entry is deleted where you expressly consent to advertising approaches again.
Statutory retention obligations take precedence over deletion. For as long as such an obligation exists, we block the data for all other purposes instead of deleting it.
After an account is deleted, your personal data is deleted or anonymised unless statutory retention obligations stand in the way. Individual record lines may continue to exist in anonymised form or in a form limited to the retention purpose; that applies in particular to the records under section 6.4, to the log under section 18.4 and to the suppression list under section 17.6.
26. Security of processing
We take appropriate technical and organisational measures to protect your data against unauthorised access, loss or alteration (Art. 32 GDPR). These include in particular:
- encrypted transmission of all connections to our services;
- database-side access rules which determine, for each table, who may read and write which row, and which take effect independently of the application code;
- access controls and role-based authorisations;
- private file stores without public addresses; access exclusively through tightly time-limited, individually generated retrieval links;
- scanning of every uploaded file for malware, release only after a positive result and no release in the event of an error;
- masking of personal data by default in our administration interface, inspection of clear data only with a statement of reasons and with prior logging;
- tamper-evident logging of administrative interventions;
- rate limiting and protection of publicly accessible forms against automated access;
- single-use, time-limited tokens for sign-in, recovery and invitations; passwords are stored exclusively as a hash value;
- removal of identifiable personal data from error messages before they are stored and transmitted.
27. Your rights
Under the General Data Protection Regulation you have the following rights. You can exercise them at any time by contacting us at hello@internities.de or by post at the address named in section 1.1.
27.1 Access (Art. 15 GDPR)
You will receive information as to whether and which personal data we process about you, for what purposes, from which categories, to which recipients, for what duration and from what source, and a copy of that data. For the automated decision under section 7 you additionally receive meaningful information about the logic involved and about the significance and the envisaged consequences (Art. 15 Abs. 1 lit. h GDPR); this includes the score determined for your evidence, the model's statement of reasons and the threshold value applicable at the time of your examination. The rights and freedoms of other persons are safeguarded in the process (Art. 15 Abs. 4 GDPR); we release information about third parties contained in free text only in so far as their rights are not thereby infringed.
27.2 Rectification (Art. 16 GDPR)
We rectify inaccurate data; we complete incomplete data. You can change many items directly in your account; that applies also to the information obtained from your documents and confirmed by you. For the overall grade we have read out from documents, the dispute procedure under section 8.3 is additionally open to you, and for entries read out concerning honours and engagement, the confirm-and-discard function. If you cannot change an item yourself, write to us.
27.3 Erasure (Art. 17 GDPR)
You can request the erasure of your data. You can also delete your account yourself in the account settings; the deletion then also covers your files and the evaluations attached to them, and it is irreversible.
If you would like access under section 27.1 beforehand, please make that request before the deletion — once it has been carried out we can no longer serve it.
Excluded from erasure is data which we are legally obliged to retain or which we need in order to assert, exercise or defend legal claims; we block that data for further use instead. Also excluded are the record and suppression data expressly named in this policy.
27.4 Restriction of processing (Art. 18 GDPR)
Under the conditions of Art. 18 Abs. 1 GDPR, you can request that we only store your data and no longer use it — for example while an objection is being examined or for as long as you need the data for legal proceedings. Please address such a request to hello@internities.de; we implement it organisationally.
27.5 Data portability (Art. 20 GDPR)
In so far as we process your data by automated means on the basis of a consent or for the performance of a contract, you will receive the data you have provided to us in a structured, commonly used and machine-readable format, or you can request its transmission to another controller in so far as this is technically feasible.
27.6 Objection (Art. 21 Abs. 1 GDPR)
You may object at any time, on grounds relating to your particular situation, to processing operations which we base on Art. 6 Abs. 1 UAbs. 1 lit. f GDPR; that includes profiling based on that provision. The processing operations based on that legal basis are listed individually in section 4.3. If you object, we will no longer process the data concerned, unless we can demonstrate compelling legitimate grounds which override your interests, or the processing serves to assert, exercise or defend legal claims. For direct marketing, the separate notice in section 28 applies.
27.7 Withdrawal of consents (Art. 7 Abs. 3 GDPR)
You can withdraw consents given at any time with effect for the future, without affecting the lawfulness of the processing carried out up to that point. Withdrawal is as easy as giving consent. In concrete terms:
- Advertising: through the notification settings of your account or the unsubscribe link in every advertising email (section 17.7).
- Reach measurement and referral attribution: through "Cookie settings" in the page footer or informally to hello@internities.de (section 5.4).
- Use of a document text for the skills comparison: by deleting the document or by notifying us (section 9.5).
- Release of your email address to a company: by revoking the agreement in the respective operation or through the settings of your account (section 12.5).
- Release of a handover package: by notifying us (section 12.7).
27.8 Intervention of a person in automated decisions (Art. 22 Abs. 3 GDPR)
For the enrolment check under section 7 you have the right to obtain the intervention of a natural person on our side, to express your own point of view and to contest the decision. Section 7.4 describes the concrete route to that. You can request a review of the automatic classification against mandatory requirements under section 11.4.
27.9 Notification to recipients (Art. 19 GDPR)
Where we rectify, erase or restrict data, we communicate this to all recipients to whom we have disclosed the data, unless this proves impossible or involves disproportionate effort. On request we will inform you of those recipients.
27.10 How to exercise your rights
Address your concern informally to hello@internities.de or to our postal address. Exercising your rights is free of charge for you. We reply without undue delay, and in any event within one month of receipt. Where your concern is complex or several concerns are made, we may extend that period by up to two further months; we will inform you of an extension and of its reasons within the first month (Art. 12 Abs. 3 GDPR).
Where there are reasonable doubts as to your identity, we may request additional information to identify you (Art. 12 Abs. 6 GDPR). We do this in order to protect your data against unauthorised disclosure.
Enquiries to hello@internities.de arrive in a mailbox hosted at Microsoft; Microsoft is our processor in that respect (section 23.2), and any transfer to a third country is governed by the safeguards in section 24.
28. Your right to object to direct marketing
You have the right to object at any time to the processing of your personal data for the purposes of direct marketing. This also applies to profiling to the extent that it is related to such direct marketing. If you object, we will no longer process your data for those purposes — without exception, without any duty on your part to give reasons, and without any disadvantage arising for you in your use of the platform (Art. 21 Abs. 2 und Abs. 3 GDPR).
The objection is free of charge and requires no particular form. You can declare it in particular
- through the unsubscribe link in every advertising email,
- through the notification settings in your account, or
- by an informal message to hello@internities.de.
We will then enter your email address permanently in the suppression list under section 17.6, so that you receive no advertising from us in future either.
This notice is presented separately from the other information deliberately (Art. 21 Abs. 4 GDPR).
29. Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement (Art. 77 Abs. 1 GDPR).
The supervisory authority competent for us is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany, telephone +49 40 428 54 4040, email mailbox@datenschutz.hamburg.de, web https://datenschutz-hamburg.de
30. Changes to this privacy policy and processing for another purpose
30.1 Continued development
We update this privacy policy where the platform, our data processing or the legal requirements change. The current version is always available on our website; you can identify the status from the version and date stated at the beginning. We will inform you of material changes in an appropriate manner and, where necessary, obtain your renewed agreement. We will make earlier versions available to you on request.
30.2 Processing for another purpose
Where we intend to process your data for a purpose other than the one originally stated, we will inform you in advance of that other purpose and of all further relevant information (Art. 13 Abs. 3 and Art. 14 Abs. 4 GDPR). Where the new processing must rest on a consent, we obtain that consent beforehand.
30.3 Version status
This version bears the version number 2.0 and the date 31 August 2026. It enters into force with the activation of the student area on 1 September 2026 and applies from that time to all users, including to accounts created before that time; until then the version published on 5 July 2026 (version 1.1) applies. Which version of this policy you accepted and when is documented in the register of records under section 6.4. That applies irrespective of which version of our General Terms and Conditions is authoritative for your contract: for data protection information, the current version of this policy always applies.