Privacy Policy
for the use of the NomadWorks online platform
Last updated: 28 June 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR; Datenschutz-Grundverordnung, DSGVO) and the Austrian Data Protection Act (Datenschutzgesetz, DSG) is:
NomadWorks GmbH DC Tower Donau-City-Straße 7/30 1220 Vienna Austria
Email: [email protected]
2. General
The protection of your personal data is of particular importance to us. We process your personal data exclusively in accordance with the applicable statutory provisions, in particular the GDPR, the Austrian Data Protection Act (DSG), and other applicable data protection provisions.
This Privacy Policy informs you about:
- which personal data we collect,
- for which purposes we use this data,
- on which legal basis the processing takes place,
- to which recipients data may be transferred,
- how long data is stored, and
- which rights you are entitled to as a data subject.
The Privacy Policy applies to all services and functions of the NomadWorks platform, including the website, the user account, job postings, applications, messaging functions, and all other services offered.
3. Definitions
This Privacy Policy uses the definitions of the GDPR.
Personal data (personenbezogene Daten) Personal data is any information relating to an identified or identifiable natural person. This includes, for example, name, address, telephone number, email address, IP address, or location data.
Processing (Verarbeitung) Processing refers to any operation involving personal data, such as collecting, storing, organizing, transferring, modifying, erasing, or archiving.
Data subject (betroffene Person) A data subject is any natural person whose personal data is processed.
Controller (Verantwortlicher) The controller is NomadWorks GmbH, which decides on the purposes and means of processing personal data.
Processor (Auftragsverarbeiter) Processors are companies that process personal data exclusively on behalf of NomadWorks GmbH, for example hosting, payment, or software service providers.
4. Scope
This Privacy Policy applies to:
- visitors to the website,
- registered tradespeople,
- private clients,
- commercial clients,
- applicants,
- interested parties,
- users of the contact form, and
- all persons who use the services of NomadWorks.
It applies regardless of whether use takes place within Austria or from another Member State of the European Union.
5. Legal Bases for Processing
The processing of personal data takes place exclusively on the basis of the statutory provisions.
Depending on the processing operation, we base the processing in particular on the following legal bases:
Art. 6(1)(a) GDPR Consent of the data subject (e.g., for optional cookies or certain data processing operations).
Art. 6(1)(b) GDPR Performance of a contract or implementation of pre-contractual measures, for example when registering a user account, creating job postings, or processing applications.
Art. 6(1)(c) GDPR Compliance with statutory obligations, in particular tax-law and company-law retention obligations.
Art. 6(1)(f) GDPR Safeguarding the legitimate interests of NomadWorks GmbH, for example to ensure IT security, to prevent misuse, to improve our services, and to assert or defend legal claims.
6. Categories of Personal Data
Depending on your use of our platform, the following categories of personal data in particular may be processed:
Master data
- First and last name
- Company name
- Contact person
- Address
- Country
- Telephone number
- Email address
Account data
- Username
- Encrypted password
- Registration date
- Email verification
- Language settings
Profile data
- Profile photo
- Description
- Occupation
- Qualifications
- Professional experience
- Skills
- Willingness to travel
- Preferred countries of assignment
Application data
- Applications
- Messages
- Uploaded documents
- CV
- Certificates
- Trade licenses (Gewerbeberechtigungen)
- References
Company data
- Company logo
- VAT ID (UID-Nummer)
- Billing address
- Contact person
Payment data
- Invoice information
- Payment status
- Payment amount
- Invoice number
- Payment method
Payment card data is processed exclusively by our payment service provider and is not stored by NomadWorks.
Usage data
- IP address
- Browser type
- Operating system
- Device type
- Language
- Date and time of access
- Log files
- Cookies
- Session information
7. Minors
Use of the platform is permitted exclusively to persons of legal age.
Registrations by persons under 18 years of age are not permitted. Should we become aware that personal data of minors has been processed, it will be erased without undue delay, unless there is a statutory obligation to continue storing it.
8. Registration and User Account
To use the functions of NomadWorks, the creation of a personal user account is required.
Registration is possible exclusively via a valid email address. After completing registration, the user receives an email with a confirmation link. The user account is activated only after the email address has been successfully confirmed.
As part of registration, the following personal data in particular may be processed:
- First and last name
- Email address
- Encrypted password
- Place of residence and country
- Telephone number (optional)
- Language settings
- Time of registration
- IP address
- Information on email verification
The processing takes place for the setup and administration of the user account and for the secure authentication of users.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract)
9. User Profiles
NomadWorks is aimed at both tradespeople and private and commercial clients. Users may voluntarily provide further information in their profile.
This includes, for example:
- Profile photo
- Job title
- Description
- Qualifications
- Professional experience
- Skills
- Language skills
- Preferred countries of assignment
- Willingness to travel
- Company logo
- Company information
Insofar as this information is publicly visible, the respective user decides on its content.
Publication takes place exclusively for the placement of suitable employment and contract relationships.
Legal basis: Art. 6(1)(b) GDPR
10. Job Postings
Clients can publish job postings via NomadWorks.
Among others, the following data may be processed:
- Company name
- Contact person
- Place of work
- Job title
- Description of the activity
- Start of work
- Salary
- Accommodation
- Meals
- Type of contract
- Images
- Other voluntary information
The published job postings may be published on the platform and — where provided for — via the official social media channels of NomadWorks.
Legal basis: Art. 6(1)(b) GDPR
11. Applications
Tradespeople can apply to published job postings via the platform.
As part of an application, the following data in particular may be processed:
- Name
- Contact data
- Profile information
- Application message
- Uploaded documents
- CV
- Certificates
- Proof of trade license (Gewerbenachweise)
- References
This data is made available exclusively to the respective clients, insofar as this is necessary for carrying out the application procedure. NomadWorks does not use this data for its own advertising purposes.
Legal basis: Art. 6(1)(b) GDPR
12. Document Upload
Users may voluntarily upload documents to the platform.
This includes, for example:
- CVs
- Proof of qualifications
- Certificates
- Trade licenses
- References
- Other application documents
These documents are stored exclusively to provide applications and profile information. The user decides which documents to upload. The documents are made accessible only to authorized persons.
Legal basis: Art. 6(1)(b) GDPR
13. Messaging Function
NomadWorks provides an internal messaging function. Registered users can communicate with one another via this function.
The following in particular are processed:
- Message content
- Date and time
- Sender
- Recipient
- File attachments
The storage takes place to provide the communication function and to ensure traceability in support or misuse cases. Automated analysis of message content does not take place.
Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (legitimate interest in secure platform operation)
14. Rating System
After the successful completion of an employment or placement relationship, tradespeople and clients can rate one another.
The following may be processed:
- Star rating
- Rating text
- Date of the rating
- Link to the respective collaboration
The ratings serve transparency, quality assurance, and the protection of users against abusive conduct. NomadWorks reserves the right to review ratings and to remove them in the event of violations of statutory provisions or the terms of use.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in quality assurance and trust building)
15. Contact Form
Visitors can contact NomadWorks via the contact form.
The following data in particular may be processed:
- Name
- Email address
- Subject
- Message
- Date and time of the request
- IP address
The data is used exclusively to process the respective request.
Legal basis: Art. 6(1)(b) GDPR (contractual or pre-contractual requests); Art. 6(1)(f) GDPR (general requests)
16. Invoices and Payment Processing
For chargeable services, NomadWorks automatically generates invoices.
The following may be processed:
- Name
- Company name
- Billing address
- VAT ID
- Payment amount
- Tax information
- Invoice number
- Payment status
- Time of payment
Invoices are stored in accordance with the statutory retention obligations. Payment processing takes place exclusively via our external payment service provider Stripe. NomadWorks does not store complete credit card or bank account data.
Legal basis: Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR (statutory retention obligations)
17. Service Providers Used and Recipients of Personal Data
To provide and operate the NomadWorks platform, we use selected external service providers. They support us with the technical provision of the platform, payment processing, web analytics, map display, the automation of processes, and the publication of job postings on social networks.
Insofar as these service providers process personal data on our behalf, this takes place on the basis of a data processing agreement (Auftragsverarbeitungsvertrag) pursuant to Art. 28 GDPR or another basis permissible under data protection law.
17.1 Sharetribe
For the technical operation of the platform, we use the Sharetribe software.
The following data in particular is processed via Sharetribe:
- User accounts
- Registration data
- Email address
- Profile data
- Job postings
- Applications
- Messages
- Ratings
- Uploaded documents
- Images
- Login information
- IP address
- Browser and device information
- Technical log data
The processing takes place exclusively to provide and securely operate the platform.
Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
17.2 Stripe
For payment processing, we use the payment service provider Stripe.
Stripe processes in particular:
- Name
- Company name
- Billing address
- VAT ID
- Email address
- Payment amount
- Invoice data
- Payment status
- Payment method
- IP address
- Device information
- Information on fraud prevention
Payment card information is processed exclusively by Stripe. NomadWorks does not store complete credit card or bank data.
The processing takes place exclusively to carry out payment transactions and to comply with statutory obligations.
Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR.
17.3 Zapier
To automate internal business processes, we use Zapier.
Depending on the respective automation process, the following data in particular may be processed:
- Name
- Email address
- Job postings
- Job title
- Invoice information
- Payment status
- Technical identification data
Zapier processes exclusively the data that is required for the respective automation.
Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
17.4 Buffer
To schedule and publish job postings on our official social media channels, we use Buffer.
The following may be processed:
- Job title
- Description
- Images
- Links to the job posting
- Time of publication
Buffer does not receive any payment data or confidential application documents.
Legal basis: Art. 6(1)(f) GDPR.
17.5 Plausible Analytics
For the statistical analysis of the use of our website, we use Plausible Analytics.
The following information in particular may be processed:
- Pages visited
- Referrer
- Browser type
- Operating system
- Device category
- Language settings
- Screen resolution
- Country
- Date and time of the visit
Plausible Analytics is configured in a privacy-friendly manner. The sole aim is the creation of aggregated visitor statistics to improve our offering.
Legal basis: Art. 6(1)(f) GDPR.
17.6 Mapbox
For the display of interactive maps, we use Mapbox.
The following in particular may be processed:
- IP address
- Browser information
- Device information
- Map requests
- Zoom levels
- Interactions with maps
- Location data (only if the user enables this)
The processing takes place exclusively to provide the map functions.
Legal basis: Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.
17.7 Facebook and Instagram
To publish job postings and company information, we use our official pages on Facebook and Instagram.
The following in particular may be processed:
- Published content
- Images
- Comments
- Likes
- Reactions
- Click data
- Publicly visible profile information
Insofar as users interact directly with our social media pages, the processing is additionally carried out by the respective platform operator.
Further information can be found in the respective provider's data protection provisions.
Legal basis: Art. 6(1)(f) GDPR.
17.8 LinkedIn
To publish job postings and company information, we use LinkedIn.
The following in particular may be processed:
- Published content
- Images
- Comments
- Reactions
- Click data
- Publicly visible profile data
Insofar as users interact directly with our LinkedIn company page, the data processing is additionally carried out by LinkedIn.
Legal basis: Art. 6(1)(f) GDPR.
17.9 Google Search Console
For the technical search engine optimization of our website, we use Google Search Console.
The following in particular are processed:
- Search queries
- Impressions
- Clicks
- Positions in the search results
- Technical information about indexed pages
- URL data
Google Search Console serves exclusively the analysis and improvement of the findability of our website in search engines.
No direct creation of personal user profiles by NomadWorks takes place via this service.
Legal basis: Art. 6(1)(f) GDPR.
17.10 IONOS
Our internet domain is managed via IONOS.
As part of domain management, technical data may be processed insofar as this is necessary for the operation of the domain and the DNS infrastructure.
The actual platform is technically operated via Sharetribe.
Legal basis: Art. 6(1)(f) GDPR.
17.11 MongoDB
For the storage and management of certain platform-related data, we use MongoDB, a database service provided by MongoDB, Inc.
Depending on the use of the platform, MongoDB may process or store data such as: user and account-related data; platform and application data; technical information; log and system data; and other data generated in connection with the use and operation of the platform.
MongoDB is primarily used as a technical backend database and does not normally place cookies on users' devices through our website.
The processing is carried out for the purpose of providing, maintaining, securing, and technically operating the platform.
Where MongoDB processes personal data on our behalf, the processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.
Further information on data processing by MongoDB can be found in MongoDB's privacy documentation.
17.12 Resend
For the sending and technical delivery of transactional and platform-related emails, we use Resend.
Resend may process data such as: email address; sender and recipient information; email content; delivery and transmission information; technical and log data; and information concerning the delivery status of emails.
We use Resend in particular to send emails required for the operation of the platform, such as registration-related messages, account notifications, application-related communications, and other service or administrative emails.
The processing is carried out for the purpose of providing reliable email communication in connection with the use and operation of the platform.
Where Resend processes personal data on our behalf, the processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR. If email tracking technologies, such as open or link tracking, are activated, additional information concerning the interaction with an email may be processed. Where required by applicable law, such technologies will only be used on an appropriate legal basis.
Further information on data processing by Resend can be found in Resend's privacy documentation.
17.13 Cloudinary
For the storage, optimization, processing, and delivery of images and other media content on our platform, we use Cloudinary.
Cloudinary may process data such as: images and other media files uploaded to the platform; technical information relating to the delivery of media content; IP address; device and browser information; request and log data; and metadata associated with uploaded media files, where applicable.
Cloudinary enables us to efficiently store, optimize, and deliver images and other media content used on the platform. When media content is delivered through Cloudinary, a connection may be established between the user's device and Cloudinary's infrastructure. In this context, technical information, including the user's IP address, may be transmitted to Cloudinary.
The processing is carried out for the purpose of providing, optimizing, securing, and technically operating the media functions of the platform.
Where Cloudinary processes personal data on our behalf, the processing is carried out on the basis of a data processing agreement pursuant to Art. 28 GDPR.
Further information on data processing by Cloudinary can be found in Cloudinary's privacy documentation.
18. Cookies and Consent Management
Our website uses cookies and comparable technologies to ensure the technical operation of the platform, to improve user-friendliness, and to provide certain functions.
Cookies are small text files that are stored on the user's device.
We distinguish between:
- technically necessary cookies,
- functional cookies,
- analysis cookies (insofar as used),
- optional cookies.
Cookies that are not technically necessary are generally set only after the corresponding consent of the user.
The management of cookie settings takes place via the cookie consent management deployed on our website. The user can change or withdraw their consent at any time with effect for the future.
19. Server Log Files
When our website is accessed, technical information is automatically processed by the hosting provider.
This includes in particular:
- IP address
- Date and time of access
- Browser type
- Operating system
- Referrer URL
- Pages accessed
- HTTP status codes
- Amount of data transferred
This data serves exclusively to ensure secure and stable operation of the platform as well as error analysis and misuse detection. This data is generally not combined with other personal data.
Legal basis: Art. 6(1)(f) GDPR.
20. Storage Period
We store personal data only for as long as this is necessary for the respective processing purposes or as long as statutory retention obligations exist.
The storage period is based in particular on:
- statutory retention periods,
- tax-law provisions,
- company-law provisions,
- legitimate interests,
- existing contractual relationships.
Once the respective processing purpose no longer applies, personal data is erased or anonymized, unless statutory obligations preclude erasure. Invoice and accounting records are stored in accordance with the statutory retention obligations.
21. Data Transfer to Third Countries
Some of the service providers we use — in particular Stripe, Google, Meta (Facebook/Instagram), LinkedIn, Zapier, Buffer, and Mapbox — may process personal data outside the European Economic Area (EEA; Europäischer Wirtschaftsraum, EWR), in particular in the USA, or draw on companies within international group structures.
Insofar as data is thereby transferred to a third country, we base this exclusively on one of the bases provided for in Chapter V of the GDPR (Art. 44 et seq.):
- adequacy decision (Angemessenheitsbeschluss) of the European Commission — for transfers to the USA, in particular the EU-U.S. Data Privacy Framework (DPF), insofar as the respective recipient is certified under it;
- standard contractual clauses (Standardvertragsklauseln) pursuant to Art. 46(2)(c) GDPR — insofar as no adequacy decision applies, in particular for recipients not certified under the DPF;
- further safeguards or derogations permissible pursuant to Art. 46 or Art. 49 GDPR.
Where we base a transfer on standard contractual clauses, we additionally assess on a case-by-case basis whether an essentially equivalent level of protection exists in the third country concerned (transfer impact assessment; Transfer-Folgenabschätzung). Where necessary, we take supplementary measures — such as encryption, pseudonymization, or supplementary contractual assurances — in order to ensure an adequate level of protection in accordance with the case law of the European Court of Justice (Europäischer Gerichtshof; "Schrems II").
A copy of the respective safeguards — in particular the standard contractual clauses — can be requested via the contact details listed in the "Controller" section.
22. Recipients of Personal Data
Personal data is disclosed to third parties only insofar as this is necessary to fulfill our contractual or statutory obligations.
Recipients may in particular be:
- Sharetribe
- Stripe
- Zapier
- Buffer
- Plausible Analytics
- Mapbox
- Google (Google Search Console)
- IONOS
- Tax advisors
- Authorities
- Courts
- Payment service providers
- IT service providers
Disclosure for advertising purposes does not take place.
23. Data Security
NomadWorks uses appropriate technical and organizational measures (technische und organisatorische Maßnahmen) to protect personal data against loss, manipulation, unauthorized access, disclosure, or other impermissible processing.
These include in particular:
- encrypted data transmission (TLS/SSL),
- access restrictions,
- role-based authorization concepts,
- password protection,
- regular security updates,
- data backups,
- logging of security-relevant operations.
Despite all the security measures deployed, complete protection cannot be guaranteed for data transmissions over the internet.
24. Rights of Data Subjects
Data subjects have, in accordance with the GDPR, in particular the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent given, with effect for the future
To exercise these rights, data subjects can contact us at any time using the contact details listed in the "Controller" section.
25. Right to Lodge a Complaint
Data subjects have the right to lodge a complaint with a data protection supervisory authority regarding the processing of their personal data.
Data subjects may contact the supervisory authority of their habitual residence, their place of work, or the place of the alleged infringement.
For NomadWorks, the competent Austrian Data Protection Authority (Österreichische Datenschutzbehörde) is in particular the point of contact:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde) Barichgasse 40–42 1030 Vienna Austria Website: https://www.dsb.gv.at
The use of other administrative or judicial remedies remains unaffected.
26. Changes to This Privacy Policy
We reserve the right to adapt this Privacy Policy if this becomes necessary due to technical developments, new statutory requirements, or changes to our services.
The version published on our website at the time of the visit applies in each case. In the event of material changes, registered users will be informed in a suitable manner, insofar as this is required by statute.
27. Data Protection Contact
If you have questions about the processing of personal data or about exercising your data protection rights, you can contact us at any time:
NomadWorks GmbH
DC Tower
Donau-City-Straße 7/30
1220 Vienna
Austria
Email: [email protected]
Appendix – Overview of Service Providers Used and Data Processed
The following overview summarizes the service providers used, the personal data processed in each case, and the purpose of processing.