Privacy Policy
What personal data we handle, why we handle it, who receives it and how you stay in control of it.
Last updated:
1. Who is responsible for your data
The controller of the personal data collected through this website is Doomity LLC, a limited liability company incorporated in the State of New Mexico, United States of America, with its registered address at 412 W 7th Street, Clovis, NM 88101, United States, operating the website https://doomity.com.
For any matter related to this policy or to your personal data, you can write to us at llc@doomity.com. That is the single address we use for privacy matters, and a real person reads it.
Doomity LLC has no establishment in the European Union. Even so, the General Data Protection Regulation (Regulation (EU) 2016/679, the GDPR) applies to us under its Article 3(2)(a), because we offer our services to people located in the European Union and this website is directed at them, including in Spanish and in Portuguese. We therefore apply the GDPR to the processing described here.
2. What data we process
We only process the data you send us through our forms, plus a small amount of technical data that is unavoidable when a website is served over the internet. We do not buy data, we do not enrich it with external sources and we do not build profiles.
3.1. Contact form
| Field | Required or optional | What it is for |
|---|---|---|
| Name (2 to 100 characters) | Required | To address you properly |
| Email address | Required | To reply to you |
| Phone number, with international prefix | Required | Alternative channel to reach you |
| Company (2 to 100 characters) | Required | To understand the context of the request |
| Subject (5 to 200 characters) | Required | To route the request internally |
| Project needs (20 to 2,000 characters) | Required | The content of your enquiry |
| Voice recording (max. 6 MB: mp3, wav, m4a, ogg, webm, weba) | Optional | To explain the request by voice if you prefer |
| Attached file (max. 6 MB: pdf, doc, docx, txt, png, jpg, jpeg, webp) | Optional | Supporting material you choose to send |
| locale (added automatically) | Automatic | Language of the page, so we reply in the same language |
| page_url (added automatically) | Automatic | Full URL of the page you wrote from, including its query string, so we know the context |
3.2. Job application form
| Field | Required or optional | What it is for |
|---|---|---|
| Name | Required | To identify your application |
| Email address | Required | To reply to you |
| LinkedIn profile URL | Required | To review your professional background |
| Role you apply for | Required | To assess the right fit |
| Years of experience (range) | Required | To assess the right fit |
| Eligibility to work (free text) | Required | To check the practical viability of hiring |
| CV in PDF format, max. 5 MB | Required | To assess your application |
| Message | Optional | Anything else you wish to tell us |
| locale (added automatically) | Automatic | Language of the page |
| page_url (added automatically) | Automatic | Full URL of the page the application was sent from |
3.3. Technical data
| Data | How we obtain it | What it is for |
|---|---|---|
| IP address | From the connection itself | Abuse limiting only: we allow a maximum of 12 submissions per hour per IP address and per form. It is held in the volatile memory of the server that handles the form, it is not sent by email and it is not stored anywhere else. |
| Country | Deduced from the cf-ipcountry header provided by Cloudflare | To serve the site in a suitable language. Only the country is derived; the IP address behind it is not stored. |
| Language cookie doomity_locale | Set in your browser when you choose a language | To remember the language you chose (en, es or pt) for 12 months. It is a technical cookie: it is not a unique identifier and it does not allow tracking. |
Providing the fields marked as required is a contractual requirement in the sense of Article 13(2)(e) of the GDPR: without them we simply cannot answer your enquiry or assess your application. The optional fields are entirely up to you, and leaving them empty has no negative consequence.
We do not ask you for special categories of data (health, beliefs, trade union membership and similar), and we ask you not to include them in free-text fields, in attachments or in your CV.
3. Why we process it and on what legal basis
| Purpose | Legal basis | Retention |
|---|---|---|
| Answering the enquiries you send through the contact form and preparing a possible working relationship | Article 6(1)(b) of the GDPR: steps taken at your request prior to entering into a contract. Secondarily, Article 6(1)(f): our legitimate interest, which is specifically our interest in reading and answering a message that you yourself decided to send us. | 24 months from the last contact |
| Assessing your application for a role at Doomity | Article 6(1)(b) of the GDPR: steps taken at your request prior to entering into a contract. We do not ask for your consent to take part in a selection process, because consent is not the right basis for it. | 12 months from receipt |
| Keeping your CV for future openings once the process is over | Article 6(1)(a) of the GDPR: your express consent, which we ask for separately and which you can withdraw at any time. | Only for as long as your consent stands |
| Remembering the language you chose and keeping the site secure | Article 6(1)(f) of the GDPR: our legitimate interest, which is specifically showing you the site in the language you asked for and keeping it available and free of attacks. These cookies are also covered by the exemption in Article 5(3) of Directive 2002/58/EC, because they are strictly necessary for a service you expressly requested. | Language cookie: 12 months |
| Limiting abusive or automated use of the forms | Article 6(1)(f) of the GDPR: our legitimate interest, which is specifically preventing our forms from being used for spam or for attacks that would degrade the service for everyone else. | Maximum of 1 hour, the length of the limiting window itself |
| Loading the Koalendar meeting scheduling widget | Article 6(1)(a) of the GDPR: your consent. The widget does not load until you accept it in the cookie banner, and Article 22(2) of Spanish Law 34/2002 and Article 5 of Portuguese Law 41/2004 also require that consent. | See the terms of Koalendar for the data it collects once loaded |
Where we rely on legitimate interest, we have weighed our interest against your rights and freedoms and concluded that the processing is limited, expected by you and not intrusive. You can object to it at any time, as explained in section 8.
4. Who receives your data
Your data is received internally only by the people at Doomity who need it to answer you or to assess your application. Beyond that, we rely on these providers, which act as processors on our instructions and under a data processing agreement:
| Provider | What it does |
|---|---|
| Cloudflare, Inc. (United States) | Hosting, content delivery network, security and anti-abuse protection for the website and for the code that processes the forms. |
| Resend, operated by Plus Five Five, Inc. (United States) | Delivery of the transactional email that carries your form submission, including any attachment or CV, to our mailbox. |
| Koalendar | Meeting scheduling widget. It only comes into play if you accept cookies and actually use the widget to book a meeting. |
Form submissions are handled by code running at Cloudflare and are then sent to a single Doomity mailbox by email through Resend, with your own email address set as the reply-to address. We do not store form submissions in any database of our own: there is no database behind our forms.
We do not sell your personal data. We do not share it with third parties for advertising purposes. We do not use it to train artificial intelligence models, ours or anyone else. We will only disclose data to a public authority where a valid legal obligation requires it.
5. International transfers
Doomity LLC is established in the United States, so the data you send us is processed there.
When you are in the European Union and you fill in one of our forms, that data reaches us directly. Following the Guidelines 05/2021 of the European Data Protection Board, direct collection by a controller established in a third country is not a transfer within the meaning of Chapter V of the GDPR, because there is no exporter separate from the importer. What does apply is the GDPR itself, which binds us through its Article 3(2)(a).
There are transfers to our providers in the United States, Cloudflare and Resend. Those transfers are covered by the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, which are included in the data processing agreements we have signed with them, together with the technical and organisational measures those agreements require.
Doomity LLC is not certified under the EU-US Data Privacy Framework. We mention the framework only to be clear that we do not rely on it.
You can ask us for a copy of these safeguards by writing to llc@doomity.com, and we will provide it.
6. How long we keep it
| Data | Retention period |
|---|---|
| Commercial enquiries sent through the contact form | 24 months from the last contact with you |
| Applications and CVs | 12 months from receipt; longer only with your express consent |
| Abuse limiting data (IP address) | A maximum of 1 hour, the length of the limiting window |
| Language cookie doomity_locale | 12 months |
These periods are a commitment on our part: once they expire, we delete the data or we anonymise it irreversibly, unless we have to keep it to deal with a legal claim.
We want to be honest about one limitation. Because form submissions reach us as email messages, how long they physically survive also depends on our mailbox and on our email provider, including their backups. We apply our retention periods within that mailbox, but the deletion of a message is not always instantaneous across every copy of it.
7. Your rights
The GDPR gives you the following rights over your personal data:
- Access: to know whether we are processing your data and to obtain a copy of it.
- Rectification: to have inaccurate or incomplete data corrected.
- Erasure: to have your data deleted when it is no longer necessary for the purpose it was collected for.
- Restriction: to have us keep your data but stop using it, for example while a dispute about its accuracy is resolved.
- Objection: to object at any time to processing based on our legitimate interest, in which case we stop unless we can show compelling legitimate grounds that override your interests.
- Portability: to receive the data you gave us in a structured, commonly used and machine-readable format, and to have it sent to another controller where technically feasible.
- Withdrawal of consent: where processing is based on your consent, to withdraw it at any time. Withdrawal is not retroactive: it does not affect the lawfulness of what we did before you withdrew it.
To exercise any of them, write to llc@doomity.com stating which right you wish to exercise. So that we do not hand your data to somebody else, we may ask you for reasonable evidence of your identity, normally by asking you to write from the same email address you used with us.
We will answer within one month of receiving your request. If the request is particularly complex or if we receive several from you, we may extend that period by two further months, and we will tell you within the first month if that happens. Exercising these rights is free of charge.
8. Complaints to a supervisory authority
If you believe we have not handled your data or your request properly, we would rather you told us first at llc@doomity.com, because most issues can be solved quickly. In any case, you always have the right to lodge a complaint with a data protection supervisory authority.
- Spain: Agencia Española de Protección de Datos (AEPD), https://www.aepd.es
- Portugal: Comissão Nacional de Proteção de Dados (CNPD), https://www.cnpd.pt
You may also complain to the supervisory authority of the European Union country where you habitually reside or work, or where the alleged infringement took place. You do not need our permission or our involvement to do so.
9. Automated decisions and profiling
We do not make decisions about you based solely on automated processing, and we do not carry out profiling of any kind. There is no algorithm scoring you, ranking you or filtering you out.
In particular, every job application is read and assessed by a person at Doomity. No candidate is discarded automatically.
10. Security measures
We would rather describe what we actually do than promise labels we do not hold. These are the measures in place:
- All traffic between your browser and our site travels encrypted with TLS (HTTPS), and so does the sending of your form submission to our mailbox.
- Data minimisation: we ask only for what we need for each purpose, and the technical data we handle is reduced to the minimum, with no analytics of any kind.
- No database of our own for form submissions: what we do not store cannot be leaked from our side.
- Access control: only the people at Doomity who need the data in order to answer you or assess your application can reach the mailbox that receives it.
- Rate limiting per IP address, at a maximum of 12 submissions per hour and per form, together with the anti-bot protection provided by our infrastructure provider, in order to stop abuse and automated attacks.
- Limits on the size and on the accepted formats of uploaded files, which reduces the attack surface of the forms.
- Agreements with our providers that oblige them to apply technical and organisational security measures and to act only on our instructions.
No measure makes a system completely immune. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the competent supervisory authority as required by Articles 33 and 34 of the GDPR.
11. Children
This website is aimed at professionals, companies and people looking for professional opportunities. It is not directed at children, and it is not intended for people under 16 years of age.
We do not knowingly collect data from people under 16. If you believe that a child has sent us personal data, please write to llc@doomity.com and we will delete it without delay.
12. Changes to this policy
We may update this policy when our services change, when we change providers or when the applicable rules change. The version published on this page is always the one in force, and the date at the top tells you when it was last updated.
If a change materially affects how we use your data, for example a new purpose or a new category of recipient, we will highlight it visibly on the site and, where the law requires it, we will ask for your consent again before applying it.
13. Contact
For any question about this policy, about how we handle your data or about the exercise of your rights, write to llc@doomity.com.
Postal address: Doomity LLC, 412 W 7th Street, Clovis, NM 88101, United States.