Huunt
Legal
Terms of Service Privacy Policy Suppl. Privacy Notice Annex A Annex B Annex C Imprint
Support
legal@huunt.ai
Huunt
Legal
Terms of Service Privacy Policy Suppl. Privacy Notice Annex A Annex B Annex C Imprint
Support
legal@huunt.ai

Suppl. Privacy Notice

1. What this document is about 2. Relationship to the general Privacy Policy 3. Two separate processing levels 4. What your institution sees by default 5. What your institution does NOT see by default 6. Active release by you ("User-Controlled Sharing") 7. OCEAN / Big Five personality data 8. Pseudonymisation and clear names in reports and records 9. Disclosure to third parties by your institution 10. Legal bases at a glance 11. Storage in the institutional context 12. Your rights and your points of contact 13. End of institutional use 14. Changes to this notice

Supplementary Privacy Notice for Use via Institutional Customers

Last updated: 26 July 2026 · Version 1.0

Please note: This English version is provided for information only. The legally binding version is the German original („Ergänzende Datenschutzinformation für die Nutzung über institutionelle Kunden"). In the event of any discrepancy, the German version prevails.


1. What this document is about

This notice is addressed to users who do not use Huunt as private, self-paying end customers, but through an institution that provides and pays for your access to Huunt.

Such institutions include in particular:

  • education and training providers (e.g. AZAV-accredited providers),
  • transfer and outplacement companies,
  • employers in the context of workforce measures,
  • universities and career services.

Below we refer to this institution as "your institution". In the underlying framework agreement between Huunt GmbH and your institution, it is referred to as the "Customer" and you are referred to as the "End User".

This notice explains which additional data flows arise because you use Huunt within such an institutional contract — and which of your data your institution can and cannot see.


2. Relationship to the general Privacy Policy

This document supplements our general Privacy Policy and does not replace it.

  • For your actual use of Huunt (job search, CV, cover letters, applications, the AI agent "Ethain"), the provisions of the general Privacy Policy continue to apply without change.
  • This document governs only the specific aspects that arise because your institution finances your access and administers it via a management dashboard.

In the event of conflict, this document applies to the administrative and data-sharing matters governed here; otherwise the general Privacy Policy applies.


3. Two separate processing levels

Your data is processed on two clearly separated levels. This separation is the core of our data protection model.

3.1 Core product — Huunt is the independent controller

For your actual application and job-search content, Huunt GmbH alone is the controller (Art. 4(7) GDPR). This concerns in particular:

  • your CV and profile,
  • the AI-assisted creation and optimisation of application documents,
  • job matching and the application copilot,
  • the sending and management of your applications.

This processing takes place within your own user relationship with Huunt and not on behalf of your institution. Your institution does not issue instructions in this respect and has no influence over the AI processing of your content.

3.2 Management level — Huunt acts on behalf of your institution

So that your institution can manage the access it finances, Huunt operates a management dashboard. For the administrative data processed there, Huunt acts as a processor for your institution (Art. 28 GDPR). The controller for this level is your institution.


4. What your institution sees by default

In the management dashboard, only administrative and status information is visible to your institution by default:

  • Master data: name and email address (usually provided by your institution itself or entered by you at registration), where applicable an avatar, group assignment;
  • License and status data: activation/license status, last login, remaining term;
  • aggregated usage metrics: summarised information on activity (e.g. whether you are active or inactive, aggregated application and feature activity).

At this level, your institution sees summarised factors, not content. For example, it can see that and to what extent you have been active — but not to which employers you have applied or what your applications contain.

Legal basis. Huunt provides this administrative and aggregated usage data to your institution on the basis of legitimate interests (Art. 6(1)(f) GDPR) — namely the interest of your institution and of Huunt in the proper administration, documentation and billing of the institutionally provided access. Your institution then processes this data on its own legal basis (e.g. its measure, programme or employment contract with you) and is independently responsible to you for this.


5. What your institution does NOT see by default

Your sensitive content remains hidden by default. Without your active release, your institution in particular does not see:

  • your CV with your experience and skills profile,
  • your detailed application history (date, specific employers, position, status),
  • your detailed job matches with match scores and AI evaluations.

In the delivery state of your account, visibility of this content towards your institution is disabled. If a section has not been released to your institution, it is shown to them in a neutral form (e.g. "not released") — without revealing any content.


6. Active release by you ("User-Controlled Sharing")

You may voluntarily release the sensitive content from Section 5 to your institution — for example, so that a coach can optimise your CV together with you. This release is:

  • granular — you release individual categories (e.g. CV only) or withhold them;
  • active — the release is made through your unambiguous action (opt-in), never through mere use;
  • revocable at any time — you can withdraw it individually or entirely, with effect for the future;
  • verifiable — grant and withdrawal are logged with a timestamp (Art. 7(1) GDPR).

Legal basis: your consent (Art. 6(1)(a) GDPR). A release is not a precondition for using Huunt. If you refuse or withdraw a release, you can continue to use Huunt in full. A coach may ask you for a release; there is no obligation to grant one.


7. OCEAN / Big Five personality data

If you use the optional OCEAN/Big Five feature, this personality data is never included in institutional reports, evaluations or calculation records and is not part of your institution's management dashboard. This exclusion is a firm boundary of our data model and applies regardless of any release or report settings of your institution.


8. Pseudonymisation and clear names in reports and records

For billing and for evidence purposes, Huunt generates reports and calculation records on behalf of your institution.

8.1 Default: pseudonymised

By default, you are shown pseudonymised in these reports and records — that is, with a unique ID instead of your clear name.

8.2 Exception: clear names only upon your institution's assurance

Your institution can enable the "Clear names in reports and records" option in its settings — for example, because it must provide evidence with clear names to the Federal Employment Agency (Bundesagentur für Arbeit), an accredited body (Fachkundige Stelle) or other funding or contracting authorities.

This option only takes effect if your institution expressly assures Huunt that it:

  • has an independent, GDPR-compliant legal basis to process personal data — including your clear name — in the course of programme delivery and to disclose it in reports/records to third parties (e.g. the Federal Employment Agency, accredited bodies, funding or contracting authorities), and
  • has informed you in accordance with Art. 13/14 GDPR about this processing and disclosure.

Responsibility for the existence of this legal basis and for informing you lies with your institution, not with Huunt. Huunt displays clear names solely on the documented instruction and assurance of your institution. Records already created remain unchanged; a change to the setting only affects documents generated in the future.

If you wish to know whether the clear-name option is enabled for your access, please contact your institution; upon request, we can also inform you of the current status.


9. Disclosure to third parties by your institution

If your institution forwards reports or records to third parties (e.g. the Federal Employment Agency, an accredited body, funding or contracting authorities), this disclosure takes place under your institution's own responsibility and on its legal basis. For questions about the purpose, scope and recipients of this disclosure, your institution is your correct point of contact.


10. Legal bases at a glance

Processing Controller Legal basis
Core product (job search, applications, AI) Huunt GmbH Art. 6(1)(b) / (a) / (f) GDPR (see general Privacy Policy)
Master data, license/status data, aggregated usage data in the dashboard Your institution (Huunt as processor) Art. 6(1)(f) GDPR for provision by Huunt; your institution's own legal basis for further processing
Release of sensitive content to your institution Huunt / your institution Art. 6(1)(a) GDPR (your consent)
Clear names in reports/records Your institution Your institution's own legal basis; documented instruction and assurance towards Huunt
Retention of records and invoices Your institution / Huunt Art. 6(1)(c) GDPR in conjunction with statutory or funding-law retention obligations

11. Storage in the institutional context

In addition to the retention periods in the general Privacy Policy, the following applies to the administrative and reporting area:

  • Live administrative data and released content: When your institution's contract with Huunt ends, your institution has a 30-day export window; after that, this administrative data is deleted unless a statutory retention obligation prevents this.
  • Pseudonymised reports and calculation records: where statutory or funding-law obligations require this, they remain retrievable for your institution for at least 5 years after the end of the contract.
  • Invoices: 10 years (§ 147 AO, § 257 HGB — German tax and commercial law).
  • Your Huunt account and the core content processed within it remain with you — regardless of the end of the contract between your institution and Huunt (see Section 13).

12. Your rights and your points of contact

You have the data subject rights set out in the general Privacy Policy (access, rectification, erasure, restriction, data portability, objection, withdrawal of consent, complaint to a supervisory authority).

Because of the shared controllership, please direct your requests as follows:

  • Your core content and your account (CV, applications, AI features, releases): Huunt GmbH, legal@huunt.ai.
  • Administrative data in the dashboard, reports/records, use of clear names and their disclosure to third parties: your institution as the responsible controller. Huunt supports your institution in this to the extent required by law.

If you are unsure whom to contact, a message to legal@huunt.ai is sufficient — we will direct you to the right place.


13. End of institutional use

When your participation in the measure ends, or your institution's contract with Huunt ends, you remain the owner of your Huunt account. The access converts into a regular user account; the management level and visibility towards your former institution cease to apply. From then on, only the general Privacy Policy and the general Terms of Use apply to your continued use.


14. Changes to this notice

We may adapt this notice if our services, the technologies used or the legal situation change. The current version is available on our website at all times.


Huunt GmbH · Knesebeckstraße 76 · 10623 Berlin · legal@huunt.ai