← Home

Privacy Policy

Last updated: April 2026

1. Who we are

This Service is operated by an individual controller ("we", "us") based in the EU. Contact: privacy@cvtally.com.

2. What data we process

Customer data: your email address (to send the results link).

Candidate data: the contents of the CVs you upload — which may include names, contact details, employment history, education, and any other information contained in the documents.

Payment data: handled entirely by Polar.sh; we do not receive or store payment card details.

3. How we use it

  • Process CVs through the AI pipeline to generate analysis and rankings
  • Send you the results link by email
  • Operate and improve the Service

We do not use candidate data for any purpose other than delivering your order.

4. Lawful basis

Processing your email: performance of the service contract. Processing candidate CVs: you (the customer/recruiter) are the data controller with legitimate interest or another basis under Art. 6 GDPR; we act as your data processor under the DPA.

5. Data retention

Original CVs are deleted within approximately 5 minutes of processing completion. Analysis results and unified PDFs are deleted 48 hours after processing. Your email is deleted at the same time. You can trigger immediate deletion using the "Delete now" button.

6. Data residency

All candidate data is stored in Cloudflare's EU jurisdiction (R2 with jurisdiction=eu). Email is sent via Resend's EU sending region. Anthropic (Claude API) processes data under their API terms; they do not train on customer API data.

7. Sub-processors

ProcessorPurposeLocation
CloudflareInfrastructure, storage, CDNEU (jurisdiction binding)
Polar.shPayment processing, MoRUSA
AnthropicAI analysis (Claude API)USA
ResendTransactional emailEU region

8. Your rights

Under GDPR you have the right to access, rectify, erase, restrict and port your personal data. Use the "Delete now" button for immediate erasure. For other requests: privacy@cvtally.com.

9. Cookies

We use Cloudflare Turnstile (bot protection) which sets a transient cookie. No marketing or tracking cookies. No analytics beyond Cloudflare's default network-level metrics (no individual user tracking).