JobsToDo
← All policies

Privacy Policy and GDPR Notice

Policy version: 1.1Effective from: 04 August 2026

How J2D collects, uses, shares, secures and retains personal data under GDPR and Cyprus law.

Platform operator: JobsToDo (also referred to as “J2D”) is a registered trading name of One Terrene International Group, a company limited by guarantee registered in Cyprus under number HE435117. JobsToDo trading-name registration: EE56780A. VAT number: CY10435117H.

Registered address: Vasileias 10B, Latsia, 2232, Cyprus. Office: 107 Giannou Kranidioti, Office 311, 2231 Latsia, Cyprus. Legal contact: legal@jobstodo.eu.

1. Controller and scope

One Terrene International Group is the controller for personal data processed in operating J2D, except where another party is independently responsible for its own processing. This notice applies to visitors, account holders, buyers, sellers, company representatives, applicants, legacy-account users and persons whose information is submitted for verification, safety, support or transactions.

2. Data we collect

  • Account and contact data, including name, email, telephone number, country, language and login/security records.
  • Profile, professional, qualification, skills, portfolio and company information.
  • Identity, address, face-photo, KYC/KYB and evidence-review information where required.
  • Marketplace requests, services, offers, invitations, orders, milestones, files, messages, deliveries, reviews and dispute records.
  • Payment, payout, invoice, VAT, tax-residency and DAC7 information, including information received from payment providers.
  • Device, browser, IP address, security-event, cookie, push-subscription and PWA information.
  • For local tasks, the agreed destination and limited event-based location evidence where enabled; J2D does not provide either party with the other party’s movement history.
  • Support requests, complaints, moderation decisions, legal correspondence and policy-acceptance records.

3. Purposes and legal bases

J2D processes data to create and secure accounts, provide marketplace and transaction functions, verify identity and claims, prevent fraud and abuse, process payments, meet tax and regulatory duties, provide support, resolve disputes, operate push alerts, improve services and establish or defend legal claims. Depending on the activity, the legal basis is performance of a contract, steps requested before a contract, compliance with legal obligations, legitimate interests, consent, or protection of vital interests in exceptional safety situations. Where consent is relied upon, it may be withdrawn without affecting earlier lawful processing.

4. Sharing and recipients

Data may be shared with payment processors, hosting and storage providers, email and notification providers, security and fraud-prevention providers, professional advisers, auditors, verification providers, public authorities and other service providers acting under appropriate terms. Transaction parties receive only the information reasonably needed for the transaction. For approved local-task hires, limited contact and approved face-photo information may be disclosed to the verified parties; exact home addresses are not made public. J2D does not sell personal data to advertisers.

5. International transfers

Where a provider processes data outside the European Economic Area, J2D will use an available lawful transfer mechanism, such as an adequacy decision, standard contractual clauses or another permitted safeguard, and will assess supplementary protections where required.

6. Retention

J2D retains data according to purpose, necessity, legal obligation and risk. Ordinary account and operational data are retained while needed to provide the service and are periodically reviewed. Following account closure or a valid deletion request, data that is no longer required will be deleted or anonymised through the operational deletion process. Limited safety, dispute, fraud-prevention and legal-claims records may normally be retained for up to 24 months after closure or resolution, and longer where an active matter or law requires it. Accounting books, invoices, contracts, payment and supporting records are retained for at least six years after the end of the calendar year to which they relate. Tax, VAT, DAC7, KYC/KYB and regulatory records are retained for the applicable statutory period. Policy acceptances and compliance records may be retained as evidence of legal compliance.

7. Your rights

Subject to GDPR conditions and exceptions, you may request access, correction, erasure, restriction, portability or objection, and may withdraw consent. You may also complain to the Office of the Commissioner for Personal Data Protection in Cyprus. Requests should be sent to legal@jobstodo.eu. J2D may need to verify identity before acting and may retain information that law requires or that is necessary for legal claims, fraud prevention or transaction integrity.

8. Automated tools and ranking

J2D may use automated tools to detect spam, malware, fraud, prohibited contact details, suspicious activity and policy risk, and to assist matching, recommendations, trust or ranking. These tools support platform decisions but do not remove J2D’s responsibility to review significant contested decisions where required. Public ranking information should be read together with the Marketplace Rules and any ranking explanation presented in the interface.

9. Security

J2D uses role-based access, authentication controls, logging, encryption in transit, restricted storage, backups, monitoring and other proportionate measures. No online system is risk-free. Users must protect their credentials and avoid sending unnecessary sensitive information through marketplace messages.

10. Children and changes

J2D is not intended for children who cannot lawfully enter into the relevant agreements. This notice may be updated where services, providers or legal requirements change. Material changes will be issued as a new policy version and acceptance may be required.