TailorForCV LogoTailorForCV
BETA

Privacy Policy

Last updated: December 17, 2024

Effective date: December 17, 2024

1. Data Controller

The Controller of your personal data is:

Operational Excellence With Dmytro Krasnoshlyk

Wichrowa 4C/6, 53-027 Wrocław, Poland

NIP: 8943206937

Email: [email protected]

We operate under Polish law as a sole proprietorship (jednoosobowa działalność gospodarcza). This Privacy Policy applies to both tailorforcv.com and tailor4cv.com domains.

2. Information We Collect

We collect and process the following categories of personal data:

2.1 Account Information

  • Full name
  • Email address
  • Authentication credentials (managed by Clerk)
  • Account creation and last login dates

2.2 User Content

  • CV/Resume documents (text content extracted from uploads)
  • Job descriptions submitted for analysis
  • Profile information (skills, experience, education, projects, contact details)
  • Notes and preferences related to job applications
  • Tailored CV versions generated by our AI

2.3 Payment Information

  • Stripe customer ID
  • Transaction history (amount, date, description)
  • Credit balance and expiration dates
  • Payment information is processed and stored by Stripe (we do not store credit card details)

2.4 Usage Data

  • IP address (anonymized)
  • Browser type and version
  • Pages visited and features used
  • Date and time of access
  • Referring website addresses
  • Device information (operating system, screen resolution)

2.5 Cookies and Tracking Technologies

We use cookies and similar technologies to improve your experience. For detailed information, please see our Cookie Policy.

3. Legal Basis for Processing

Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:

  • Contract Performance (Art. 6(1)(b) GDPR): Processing necessary to provide our CV analysis and tailoring services
  • Consent (Art. 6(1)(a) GDPR): For analytics cookies and marketing communications (where applicable)
  • Legal Obligation (Art. 6(1)(c) GDPR): Retention of financial records as required by Polish tax law
  • Legitimate Interests (Art. 6(1)(f) GDPR): Fraud prevention, system security, and service improvement

4. How We Use Your Information

We use your personal data for the following purposes:

  • Service Delivery: To analyze your CV against job descriptions using AI technology and provide match scores, gap analysis, and tailored CV versions
  • Account Management: To create and manage your user account, authenticate your identity, and maintain your profile
  • Payment Processing: To process credit purchases, manage your credit balance, and maintain transaction records
  • Communication: To send you service-related notifications, technical notices, updates, and support messages
  • Service Improvement: To analyze usage patterns, improve our AI models, and enhance user experience
  • Security: To detect and prevent fraud, abuse, and security incidents
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes

5. AI Processing and Third-Party Services

5.1 AI Service Providers

Your CV and job description data is processed by artificial intelligence services to generate analysis and tailored content. We use multiple AI providers with fallback mechanisms to ensure service reliability:

  • Google Gemini (Google LLC, USA) - Primary AI analysis
  • OpenAI (OpenAI, L.L.C., USA) - AI processing and content generation
  • Anthropic Claude (Anthropic PBC, USA) - AI analysis and validation

Important: Your data is not used to train public AI models. We use these services solely for processing your requests. Data processing agreements (DPAs) are in place with all AI providers, and international data transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission.

5.2 Other Third-Party Service Providers

We share your data with the following service providers who process data on our behalf:

Clerk (Clerk Inc., USA)

Purpose: Authentication and user management
Data processed: Name, email, authentication tokens
Location: United States
Safeguards: Standard Contractual Clauses (SCCs), DPA in place
Privacy Policy: https://clerk.com/legal/privacy

Stripe (Stripe, Inc., USA)

Purpose: Payment processing and subscription management
Data processed: Payment information, transaction records, customer ID
Location: United States (with EU data residency options)
Safeguards: PCI-DSS Level 1 certified, Standard Contractual Clauses (SCCs)
Privacy Policy: https://stripe.com/privacy

Railway (Railway Corp)

Purpose: Application hosting and database services
Data processed: All user data and application data
Location: Amsterdam, Netherlands (EU)
Safeguards: EU-based infrastructure, GDPR compliant

Google Analytics (Google LLC, USA)

Purpose: Website analytics and usage statistics
Data processed: Anonymized IP addresses, browsing behavior, device information
Location: United States
Safeguards: IP anonymization enabled, Google Analytics 4 (GA4) with enhanced privacy controls
Privacy Policy: https://policies.google.com/privacy
Opt-out: Google Analytics Opt-out Browser Add-on

Cloudflare (Cloudflare, Inc., USA)

Purpose: Content delivery network (CDN), DDoS protection, and web analytics
Data processed: IP addresses, request logs, performance metrics
Location: Global network with EU data centers
Safeguards: EU-U.S. Data Privacy Framework certified
Privacy Policy: https://www.cloudflare.com/privacypolicy/

Sentry (Functional Software, Inc., USA)

Purpose: Error tracking and performance monitoring
Data processed: Error logs, stack traces, browser version, page URLs, anonymized user identifiers
Location: United States
Safeguards: Standard Contractual Clauses (SCCs), data minimization practices
Privacy Policy: https://sentry.io/privacy/

5.3 International Data Transfers

Some of our service providers are located outside the European Economic Area (EEA), primarily in the United States. We ensure adequate protection of your personal data through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs) with all processors
  • EU-U.S. Data Privacy Framework participation (where applicable)
  • Technical and organizational security measures

6. Data Retention

We retain your personal data for different periods depending on the type of data and legal requirements:

Active Account Data:

Your profile, CVs, job analyses, and related data are retained as long as your account is active. You can delete individual items at any time through your dashboard.

Inactive Accounts:

Accounts with expired credits and no activity for 3 months after credit expiration may be flagged for deletion. We will send you an email notification 30 days before deletion, giving you the opportunity to reactivate your account.

Account Deletion:

When you delete your account, your personal data is marked for deletion and removed from active systems within 30 days. Data may remain in encrypted backups for an additional 60 days (90 days total) before permanent deletion.

Financial Records:

Transaction records and invoices are retained for 5 years as required by Polish tax and accounting regulations (Ustawa o rachunkowości). This data is stored separately in Stripe and is not deleted when you close your account.

Analytics Data:

Anonymized analytics data is retained for 26 months in Google Analytics (GA4 default setting).

Legal Hold:

If required by law, court order, or to resolve disputes, we may retain certain data beyond the periods stated above.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption: Data in transit is encrypted using TLS/SSL; data at rest is encrypted in our databases
  • Access Controls: Strict access controls and authentication mechanisms limit data access to authorized personnel only
  • Security Monitoring: Continuous monitoring for security threats, vulnerabilities, and unauthorized access attempts
  • DDoS Protection: Cloudflare protection against distributed denial-of-service attacks
  • Regular Backups: Encrypted backups stored securely in EU data centers
  • Jailbreak Protection: AI input sanitization to prevent prompt injection and data extraction attacks
  • Secure Development: Regular security audits and code reviews

Despite our efforts, no method of transmission over the Internet or electronic storage is 100% secure. If you suspect any unauthorized access to your account, please contact us immediately at [email protected].

8. Your Rights Under GDPR

As a data subject in the European Union, you have the following rights regarding your personal data:

Right to Access (Art. 15 GDPR)

You can request a copy of all personal data we hold about you. You can view and export your data from your dashboard, or contact us at [email protected].

Right to Rectification (Art. 16 GDPR)

You can update and correct your personal information directly in your account settings at any time.

Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR)

You can request deletion of your personal data by deleting your account or contacting us. Note: We may need to retain certain data to comply with legal obligations (e.g., financial records for tax purposes).

Right to Restriction of Processing (Art. 18 GDPR)

You can request that we limit the processing of your data in certain circumstances (e.g., while we verify data accuracy).

Right to Data Portability (Art. 20 GDPR)

You can export your data in a structured, commonly used, machine-readable format (JSON) from your dashboard.

Right to Object (Art. 21 GDPR)

You can object to processing based on legitimate interests. You can also opt-out of analytics cookies at any time.

Right to Withdraw Consent (Art. 7(3) GDPR)

Where processing is based on consent (e.g., cookies), you can withdraw consent at any time through cookie settings.

Right to Lodge a Complaint (Art. 77 GDPR)

You have the right to lodge a complaint with the supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych (PUODO)

ul. Stawki 2, 00-193 Warszawa, Poland

Phone: +48 22 531 03 00

Website: https://uodo.gov.pl

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days as required by GDPR.

9. Cookies and Tracking

We use cookies and similar tracking technologies to provide and improve our Service. For comprehensive information about the cookies we use, their purposes, and how to manage them, please refer to our Cookie Policy.

You can control cookie preferences through the banner displayed on your first visit or by adjusting your browser settings. Note that disabling certain cookies may affect the functionality of our Service.

10. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay via email at the address associated with your account.

We will also notify the Polish supervisory authority (PUODO) within 72 hours of becoming aware of the breach, as required by Article 33 of GDPR.

If you suspect any unauthorized access to your data, please immediately contact us at [email protected].

11. Children's Privacy

Our Service is intended for individuals who are at least 18 years old. We do not knowingly collect personal data from children under 18 years of age.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected], and we will delete such information from our systems.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify you via email at least 30 days before the changes take effect
  • Display a prominent notice on our website or dashboard

Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy. If you do not agree with the changes, you may close your account.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Controller:

Operational Excellence With Dmytro Krasnoshlyk

Wichrowa 4C/6, 53-027 Wrocław, Poland

NIP: 8943206937

Email: [email protected]

General Support: [email protected]

We will respond to your inquiry within 30 days in accordance with GDPR requirements.

This Privacy Policy is governed by the General Data Protection Regulation (GDPR) (EU) 2016/679 and Polish data protection laws. It applies to tailorforcv.com and tailor4cv.com.