Who and what this covers
DCC provides the Deck platform. This policy covers davidcookscode.com and the Deck workspaces DCC provides to client businesses. A client business controls its own branded workspace and the records it enters there. The DCC apex site is a marketing and contact site; tenant operational data stays in tenant workspaces.
Information collected
The information depends on how you use the service:
- On davidcookscode.com, changing the language stores a language-preference cookie for one year. The apex site does not currently run analytics or advertising trackers. Choosing an email link opens your own email service; DCC receives what you choose to send.
- A job application records your name, email address, optional phone number and PDF résumé, the consent text and time, IP address, browser user-agent, verification state, application date, role applied for and recruitment stage.
- Client workspaces may contain operational records such as employee, document, guest and audit information entered by the client or its authorised users. The fields used depend on the Deck modules the client uses.
Why information is used
Information is used to operate and secure Deck, provide the features a client selected, support authorised users, keep audit records, and process and verify job applications. DCC does not use a careers applicant's information for an unrelated purpose through the current application flow.
Access and service providers
Tenant records are available to authorised users of that tenant and to authorised DCC administrators when support or platform administration requires it; administrator access is audited. Tenant data is not exposed to other tenants. When reCAPTCHA is configured on a public careers form, the form loads Google's reCAPTCHA service and sends the verification token and request IP address to Google for an abuse check.
Retention and redaction
The current careers process redacts an applicant's name, contact details, résumé, IP address, browser user-agent and pending verification details 180 days after the application. The row is not deleted: the tenant, role, application date, recruitment stage, and consent text and time remain for reporting and an audit trail. A person hired through Careers also has a separate employee record in the hiring business's workspace.
The 180-day period and its use for every recruitment outcome are current system behaviour, not a settled legal retention ruling. DCC is reviewing that period.
Tenant separation and security
Deck assigns tenant-owned records to a tenant and enforces database row-level access policies. Uploaded files are private and served through access-checked routes. Authorised cross-tenant administration is audited. These controls reduce risk but no online service can promise absolute security.
Your choices and requests
You can change the language cookie by choosing another language or remove it in your browser. For access, correction, deletion or another privacy request about a client workspace or job application, contact the client business first where practical and copy DCC support if platform help is needed. A request may require identity verification and may be limited where records must be kept for security, legal or audit reasons.
Contact
Privacy questions and platform-assisted requests can be sent to davidcookscode@gmail.com. Please identify the client workspace or job application concerned, but do not email passwords, verification codes or unnecessary identity documents.
