Privacy Policy
Last updated: March 2026
1. Who We Are (Data Controller)
IvyCV (ivycv.com) is operated as działalność nierejestrowana (unregistered activity) under Article 5 of the Polish Entrepreneurs' Law.
- Operator: Przemyslaw Konstanty
- Email: hello@ivycv.com
- Correspondence address: Romanowicza 1/118, 30-702 Kraków, Poland
We act as the data controller for all personal data processed through the Service. We do not have a Data Protection Officer (DPO) as we are not required to appoint one under GDPR Article 37. For privacy inquiries, contact us at the email above.
2. What Data We Collect
2.1 Data You Provide
- Account data: email address, hashed password (via Supabase Auth).
- CV data (Master Profile): name, contact information, work history, education, skills, certifications, languages, and any other career information you enter.
- Job listing text: job descriptions you paste for CV tailoring.
- Smart Interview answers: responses to pre-generation questions about your experience.
2.2 Data Collected Automatically
- Usage data: pages visited, generation counts, feature usage (no cross-site tracking).
- Session data: anonymous session tokens for rate limiting.
- Device data: browser type and version (for compatibility), screen resolution (for responsive layout).
2.3 Payment Data
Payment processing is handled entirely by Stripe. We never see, store, or process your card number, CVV, or full payment details. We receive only: transaction status, amount, currency, and Stripe customer/session identifiers.
3. Legal Basis for Processing (GDPR Article 6)
| Processing Activity | Legal Basis | GDPR Article |
|---|---|---|
| CV generation and Master Profile storage | Contract performance | Art. 6(1)(b) |
| Sending CV data to AI providers | Contract performance | Art. 6(1)(b) |
| Payment processing | Contract performance | Art. 6(1)(b) |
| Transactional emails (receipts, confirmations) | Contract performance | Art. 6(1)(b) |
| Rate limiting and abuse prevention | Legitimate interest | Art. 6(1)(f) |
| Marketing emails | Consent | Art. 6(1)(a) |
| Analytics (if enabled) | Consent | Art. 6(1)(a) |
| Tax record retention | Legal obligation | Art. 6(1)(c) |
Where we rely on legitimate interest (abuse prevention, security monitoring), our interest is protecting the Service and its users from fraud and abuse, which does not override your fundamental rights given the limited nature of the data involved (session tokens, request counts).
4. How We Use Your Data
- Generate tailored CVs based on your career information and job listings;
- Store your Master Profile for future CV generations;
- Process payments and manage download entitlements;
- Send transactional emails (purchase confirmations, download links);
- Enforce rate limits and prevent abuse;
- Improve the Service (aggregated, non-personal usage statistics only).
5. Use of Artificial Intelligence
- Your personal data (career information, job listings) is sent to third-party AI services to generate CV content. These services process your data solely for this purpose.
- AI providers used by IvyCV:
- Anthropic (Claude API) — CV generation, profile merge, document parsing. EU regional processing used where available. API data is NOT used for model training. Logs retained for 30 days maximum.
- Google Cloud (Gemini API, paid tier) — CV generation (alternative model). EU region (europe-west4, Belgium). Paid API tier: data NOT used for training.
- Both providers are bound by Data Processing Agreements (DPAs) that include EU Standard Contractual Clauses (SCCs) for international data transfers.
- No automated decisions with legal or similarly significant effects are made about you (GDPR Article 22). CV generation is content creation assistance — you have full control to review, edit, and decide whether to use the output. The Service does not make employment decisions, filter applications, or evaluate candidates.
6. Data Retention
| Data Type | Retention Period | Basis |
|---|---|---|
| Active user account and CV data | While account exists | Contract performance |
| Master Profile | While account exists | Contract performance |
| Payment records | 5 years from transaction | Polish tax law (Ordynacja podatkowa) |
| Anonymous session data | 30 days | Legitimate interest (rate limiting) |
| AI provider logs (Anthropic) | 30 days (automatic deletion) | Provider policy |
| Deleted account data | Immediate permanent deletion | GDPR compliance |
After account deletion, payment records are retained for 5 years as required by Polish tax law, but all personal identifiers are removed (anonymized).
7. Third Parties and Data Transfers
| Service | Purpose | Data Location | Transfer Safeguard |
|---|---|---|---|
| Anthropic (Claude API) | AI CV generation | US (EU regional processing available) | DPA with EU SCCs |
| Google Cloud (Gemini) | AI CV generation (alternative) | EU (europe-west4, Belgium) | DPA, EU-US Data Privacy Framework |
| Supabase | Database, authentication | EU | DPA |
| Stripe | Payment processing | US/EU | EU-US Data Privacy Framework, DPA |
| Vercel | Web hosting | Global CDN (EU edge) | DPA |
| Resend | Transactional email | US | DPA |
We do not sell your data to third parties. Data is shared only with the processors listed above, solely for the purposes described.
8. Your Rights (GDPR Articles 15-22)
You have the following rights regarding your personal data:
- Right of access (Art. 15) — request a copy of your personal data.
- Right to rectification (Art. 16) — correct inaccurate data via your Master Profile editor or by contacting us.
- Right to erasure (Art. 17) — delete your Account and all associated data via account settings (one-click deletion).
- Right to restriction of processing (Art. 18) — request that we limit processing of your data in certain circumstances.
- Right to data portability (Art. 20) — export your data in machine-readable JSON format via account settings.
- Right to object (Art. 21) — object to processing based on legitimate interest. Contact us to exercise this right.
- Right to withdraw consent (Art. 7(3)) — where processing is based on consent (marketing emails, analytics), you may withdraw at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, use the tools in your account settings or email hello@ivycv.com. We will respond within 30 days (GDPR Art. 12(3)).
9. Automated Decision-Making and Profiling
IvyCV does not make automated decisions that produce legal effects or similarly significant effects on you (GDPR Article 22). The AI generates CV content as a writing assistance tool. You retain full control: you review, edit, and decide whether to use any generated content. No employment decisions, candidate evaluations, or application filtering occurs within our Service.
10. Is Providing Data Mandatory?
Providing your personal data is not a statutory requirement but is necessary to use the Service:
- Email address — required for Account registration and transactional communications.
- CV data — required for CV generation (the core service). Without it, no CV can be generated.
- Payment data — required for purchases (processed by Stripe, not stored by IvyCV).
Refusing to provide this data means the corresponding Service features cannot be delivered.
11. Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with:
- UODO (Urząd Ochrony Danych Osobowych — Polish Data Protection Authority): uodo.gov.pl
- Or the supervisory authority in your EU member state of residence.
12. California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you additional rights:
- Right to know what personal data we collect and how it is used;
- Right to delete your personal data;
- Right to opt out of the sale or sharing of your personal data;
- Right to non-discrimination for exercising your privacy rights.
We do not sell or share your personal data as defined by the CCPA/CPRA. To exercise your rights, use the export or deletion tools in your account settings, or contact us at hello@ivycv.com.
13. Cookies
We use only strictly necessary cookies for authentication. No advertising, tracking, or analytics cookies are set. See our Cookie Policy for details.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to registered users via email. The "Last updated" date at the top indicates the most recent revision.
15. Contact
For privacy questions, data subject requests, or complaints:
- Email: hello@ivycv.com
- Correspondence address: Romanowicza 1/118, 30-702 Kraków, Poland
