Privacy Policy
Last updated: 2026-09-06
1. Introduction
CV Score is a service of The CodeCave GmbH ("we", "us", "our"). This Privacy Policy explains how we process personal data when you visit our website at cvscore.net, use the web application at app.cvscore.net, or have your CV evaluated through it (together, "the Service").
Because we are established in Germany, the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) apply to all of our processing, regardless of where you live. Depending on your location, you may hold additional rights under local law — for example under the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, Singapore's PDPA or South Africa's POPIA. Those are addressed in dedicated sections below.
This policy is effective as of the date shown above and describes the Service as it works today. Our company details are also published in our Imprint.
2. Controller
The controller for the processing described here, within the meaning of Article 4(7) GDPR, is:
The CodeCave GmbH
Alfred-Nobel-Straße 29
50226 Frechen, North Rhine-Westphalia
Germany
- Represented by:
- Aleksandar Vuk Jovanovic, Tilman Kieselbach
- Commercial register:
- HRB 44492, Amtsgericht Bielefeld
- VAT identification number:
- DE 346809827
- General contact:
- info@thecodecave.de
Because the controller is established within the European Union, no representative under Article 27 GDPR is required or appointed. For privacy matters, please write to privacy@cvscore.net.
3. Data We Process
Which data we process depends on how you use the Service:
Account Data
An account is required to run an evaluation. We process:
- Your email address
- Your password — stored only as a cryptographic hash by our authentication provider, never in plain text
- Alternatively, if you sign in with Google: the email address and basic profile information Google transmits to us
- An internal user identifier (UUID) and the timestamps of account creation and sign-in
- Whether your email address has been confirmed
- Your marketing consent status and, where applicable, the time and channel of a later opt-out
CV Files
When you upload a CV for evaluation, we process:
- The uploaded PDF file (maximum 5 MB and 3 pages)
- The file name, file size and page count
- A SHA-256 checksum of the file, used to recognise a re-upload of the same document and avoid charging you twice
- The report language you selected and the upload timestamp
What happens to the file: your PDF is stored in a private storage area assigned to your account and stays there until you delete the evaluation or your account. It is not deleted automatically after processing. The text extracted from the PDF is held in memory only for the duration of the analysis and is not stored as a separate document. The findings in your report are written by the model itself, so they can refer to the content of your CV and reproduce individual formulations from it.
Evaluation Results
For each evaluation we store:
- The overall score and the scores of the 8 categories and their subcategories
- The positive and negative findings for each subcategory, up to three top strengths and up to seven key improvements, each rated as high or medium impact
- These texts are written by the model itself; they can refer to the content of your CV and reproduce individual formulations from it
- The model identifier, prompt version and schema version used, so a result stays reproducible
- Processing status, any error message, and whether and when the full report was unlocked
Payment Data
Payments are processed by our payment provider Polar. On our side we store only:
- The email address used for the purchase
- Amount, currency, status, the transaction reference of the provider and the purchased product
- Your credit balance and a log of every credit movement — credited on purchase, spent when a report is unlocked
- For accounts with a legacy subscription: its plan, status and current period
- Whether a one-off, time-limited offer was shown to you and whether you redeemed it
- A record that a checkout was started (checkout identifier, email address, product), which we use to detect abandoned purchases
When you start a purchase, we transmit your email address and your internal account identifier to Polar so that the payment can be assigned to your account. We never receive or store your card number, card verification value or other payment credentials. Those, together with the billing details required to determine the correct tax rate, are processed by Polar under its own responsibility. For invoices and for managing a subscription we forward you to Polar's customer portal.
Optional Questionnaire
After an analysis we may ask a few voluntary questions in order to put your result into context. Answers are stored as ranges only, never as exact figures:
- Number of applications sent and interviews obtained, as a range
- Salary expectation as a band, including the option not to disclose it
- Whether you are currently between roles or employed and looking to change
- Whether you want to change jobs and whether you would like to be contacted for feedback
Feedback and Support
If you send us feedback or a support request from within the application, we store:
- Your message and whether you flagged it as feedback or as a support request
- The email address of your account and the time of submission
Technical and Usage Data
When you use the website or the application, the following is processed automatically:
- Server log data from our hosting providers, including IP address, date and time, the resource requested, HTTP status and referring page
- Browser and device information transmitted by your browser
- Application error logs, which record technical error messages rather than CV content
- Your IP address for rate limiting and abuse prevention
- Your sign-in token, stored in your browser (see section 16)
- Aggregated reach measurement data (see section 16)
4. How We Obtain This Data
Directly from you: When you create an account, upload a CV, answer the optional questionnaire, buy a report or contact us.
Automatically: Through server logs, the technically necessary sign-in token and our own reach measurement when you use the Service.
From Google: If you choose to sign in with Google, we receive your email address and basic profile information from Google.
From our payment provider: Polar notifies us when a checkout is started, a payment succeeds, is refunded or is disputed, and transmits the email address, amount and transaction reference to us.
5. Purposes and Legal Bases
We process personal data only where a legal basis under Article 6(1) GDPR applies:
| Purpose | What happens | Legal basis |
|---|---|---|
| Providing the evaluation | Accepting the upload, extracting the text, the AI analysis, storing and displaying your report | Performance of a contract, Art. 6(1)(b) GDPR |
| Account and authentication | Creating your account, signing you in, keeping the session secure | Performance of a contract, Art. 6(1)(b) GDPR |
| Credits and unlocking reports | Recognising duplicate uploads by checksum, accounting for credits, unlocking a full report | Performance of a contract, Art. 6(1)(b) GDPR |
| Payments and invoicing | Processing purchases, handling refunds and chargebacks, keeping accounting records | Performance of a contract, Art. 6(1)(b); legal obligation for retention, Art. 6(1)(c) GDPR |
| Transactional email | Notifying you once your report is ready, at the address of your account | Performance of a contract, Art. 6(1)(b) GDPR |
| Reminder about an unfinished purchase | A single reminder if you started a checkout and did not complete it, at most once per week | Legitimate interest in completing a purchase you started, Art. 6(1)(f) GDPR |
| Marketing email | Reminder about a report you have not unlocked, prompt to re-check your CV after 14 days without activity, one-off request for a review | Consent, Art. 6(1)(a) GDPR — withdrawable at any time |
| Optional questionnaire | Putting your result into context and personalising the report | Consent, Art. 6(1)(a) GDPR — answering is voluntary |
| Feedback and support | Answering your enquiries and fixing the problems you report | Performance of a contract, Art. 6(1)(b); legitimate interest in customer communication, Art. 6(1)(f) GDPR |
| Reach measurement | Aggregated statistics about how our pages are used, on our own infrastructure | Legitimate interest in privacy-preserving statistics, Art. 6(1)(f) GDPR |
| Security and stability | Server logs, rate limiting, defending against abuse and automated attacks | Legitimate interest in a secure service, Art. 6(1)(f) GDPR |
| Aggregate statistics | Counting completed evaluations for a figure shown on our pages — a pure total, with no reference to individuals | Legitimate interest in transparent figures, Art. 6(1)(f) GDPR |
| Legal compliance | Complying with statutory obligations and responding to lawful requests | Legal obligation, Art. 6(1)(c) GDPR |
We do NOT use your CV for advertising, for profiling, or to train AI models, and we do not sell personal data.
6. AI Processing and Automated Decisions
Your CV is evaluated fully automatically. This section explains exactly what happens, what leaves our systems, and how we assess this under Article 22 GDPR.
How the Evaluation Works
When you submit a CV:
- We check the file (PDF, at most 5 MB and 3 pages) and, using a checksum, whether you have already had exactly this document evaluated in the same language.
- The text is extracted on our own server. If the PDF contains no machine-readable text, text recognition (OCR) runs on the same server. No third party is involved in either step. The PDF itself is stored in the private storage area of your account.
- The extracted CV text is sent to the API of OpenAI, together with our evaluation instruction. The model used is gpt-4o-mini, at temperature 0 and with a fixed seed, so the same text produces a largely identical result.
- The result is stored with your account and displayed to you. The full report is shown once it has been unlocked.
What is transmitted to OpenAI: the complete extracted text of your CV. If your CV contains your name, address, telephone number, email address, date of birth, employers or similar details, they are part of that text — we do not remove or pseudonymise them beforehand. We do not transmit your account identifier, your login email address or any payment data.
What Is Assessed
The model rates the document across eight categories:
- Contact Information & Header
- Professional Summary
- Work Experience
- Education & Qualifications
- Skills & Competencies
- Layout & Visual Design
- Language & Communication
- Strategic Positioning & ATS Readiness
Important Limitations
- Not a recruiting tool: CV Score is built for your own self-assessment. It is not designed for employer screening, applicant selection or HR processes.
- No guarantees: a high score does not guarantee interviews or offers, and a low score does not mean you are unqualified.
- Document quality only: the evaluation assesses the presentation of the document, not your qualifications, your experience or your suitability for a role.
- No legal or career advice: the result is informational and does not constitute professional advice.
Is This an Automated Decision Under Article 22 GDPR?
The evaluation is produced without human involvement. In our assessment it is nevertheless not a decision that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22(1) GDPR: you request the analysis yourself, the result is advisory, it is shown only to you, and no third party — in particular no employer and no recruiter — receives it or decides anything on its basis. We do not pass results on to employers, recruiters or job platforms. This assessment is ours; if you see it differently, you are welcome to contest it using the routes below.
Human Review
Independently of the assessment above, we grant you the safeguards of Article 22(3) GDPR voluntarily:
- You can request a human review of any evaluation by writing to support@cvscore.net
- You can state your own point of view and contest the result
- We respond to such requests within one month
AI Model Training
We use OpenAI through its business API. Under OpenAI's API terms, content submitted via the API is not used to train OpenAI's models by default. We ourselves do not use your CV, your results or your feedback to train models of our own.
7. Recipients of Your Data
We pass data on only in the following cases:
Processors: Service providers who process data strictly on our instructions and are bound by a data processing agreement under Article 28 GDPR. They are listed in section 8.
Payment provider: Polar processes the payment itself under its own responsibility and only reports the outcome back to us.
Legal obligations: We disclose data where we are legally required to do so, for example to courts or public authorities acting within their powers.
Business transfers: If our business or parts of it are transferred, data may pass to the acquirer. We would inform you of such a change in advance.
We do not sell your personal data. We do not rent it out, trade it, and do not make it available to third parties for their own advertising purposes.
8. Processors
We use the following service providers to operate CV Score:
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| OpenAI | AI evaluation of the CV text | The extracted text of your CV, including any personal data it contains | USA |
| Supabase | Authentication, database, file storage | Account data, CV files, evaluation results, payment records, questionnaire answers, feedback | USA |
| Google Cloud | Hosting of our API backend and the scheduled jobs behind our emails | All data processed by the backend while in transit, plus server logs | Servers in Frankfurt, Germany (europe-west3); provider group based in the USA |
| Netlify | Delivery of the web application at app.cvscore.net | IP address and request data in server logs | USA |
| Railway | Delivery of the website at cvscore.net | IP address and request data in server logs | USA |
| Polar | Payment processing and invoicing | Email address, payment and billing data, transaction data | USA |
| Resend | Sending our transactional and marketing emails | Email address and the content of the email sent | USA |
Details on each provider, on the flow of your data and on the safeguards we rely on are set out in our Processor List.
If we add or replace a processor, we update this policy and the processor list. Our reach measurement runs on our own infrastructure and is therefore not listed here — see section 16.
9. Transfers to Third Countries
Some of our processors are established in the United States or belong to a US-based group. Where that is the case, personal data is transferred to a country outside the European Economic Area that has not been recognised by the European Commission as offering an equivalent level of protection.
Safeguards
We rely on the following safeguards for these transfers:
- Standard contractual clauses: the clauses adopted by the European Commission under Article 46(2)(c) GDPR, agreed with our providers as part of the data processing agreements.
- EU-US Data Privacy Framework: where a provider is certified under the framework, Article 45 GDPR applies in addition, based on the European Commission's adequacy decision of 10 July 2023.
- Supplementary measures: encrypted transmission, access limited to what is necessary, and data minimisation — in particular we do not transmit account identifiers or payment data to our AI provider.
Which Data Goes Where
The text of your CV is transmitted to OpenAI in the USA. Account data, CV files and results are stored with Supabase, a US company. Payments run through Polar, emails through Resend, both US companies. Our API backend runs on Google Cloud servers in Frankfurt, Germany, but Google is a US-based group. In addition, the application at app.cvscore.net loads its typeface from Google Fonts; your browser contacts servers of Google LLC directly in the process and transmits your IP address to them. The pages at cvscore.net use fonts we host ourselves. Despite the safeguards above, a residual risk remains that authorities in a third country may seek access to data under local law; we cannot rule this out.
10. Retention
We keep data for as long as it is needed for the purpose it was collected for, or for as long as we are legally required to keep it. There is no automatic deletion after a fixed period — you decide when your evaluations go:
| Data | Retention | Notes |
|---|---|---|
| Account data | Until you delete your account | You can delete your account yourself in the application at any time |
| CV files | Until you delete the evaluation or your account | Not deleted automatically after processing |
| Evaluation results | Until you delete the evaluation or your account | Kept so you can revisit earlier reports |
| Questionnaire answers and feedback | Until you delete your account | Deleted together with the account |
| Email log | Until you delete your account | Records which lifecycle emails were sent, so we do not write to you twice |
| Payment records | For the statutory commercial and tax retention periods | In Germany usually 6 or 10 years (§ 257 HGB, § 147 AO). The link to your account is removed when the account is deleted; the transaction data itself has to remain |
| Server and error logs | For as long as needed for operation and security | Deleted according to the retention rules of our hosting providers |
You can delete each individual evaluation and your entire account yourself in the application at any time. Deleting an evaluation removes its record from the database and requests the deletion of the associated PDF file from storage. Deleting your account removes your account at our authentication provider together with the records tied to it — evaluations, results, questionnaire answers, feedback, credit balance and credit movements, subscription data, checkout records, the email log and your consent status. Payment records are kept, without the link to your account, for as long as the retention periods above require. Copies may remain in backups for a short time until those backups are rotated in the ordinary course. If you would like a deletion confirmed, write to privacy@cvscore.net.
11. Your Rights
You have the following rights in relation to the personal data we process about you:
- Access (Art. 15 GDPR): Obtain confirmation as to whether we process data about you, and a copy of that data
- Rectification (Art. 16 GDPR): Have inaccurate data corrected and incomplete data completed
- Erasure (Art. 17 GDPR): Have your data deleted where one of the grounds in the GDPR applies
- Restriction (Art. 18 GDPR): Require us to restrict processing instead of deleting the data
- Data portability (Art. 20 GDPR): Receive the data you provided in a structured, commonly used, machine-readable format
- Objection (Art. 21 GDPR): Object at any time to processing based on our legitimate interests, on grounds relating to your particular situation
- Withdrawal of consent (Art. 7(3) GDPR): Withdraw consent you have given at any time, with effect for the future — including your consent to marketing emails, using the unsubscribe link in every such email or your account settings
You can delete evaluations and your entire account yourself in the application at any time. For everything else, write to privacy@cvscore.net. We respond within one month; where a request is complex, that period may be extended by up to two further months, and we will tell you if that happens.
12. Complaints and Supervisory Authority
If you believe that we process your data unlawfully, you can lodge a complaint with a supervisory authority — without prejudice to any other remedy.
- Competent authority for us: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
- Your local authority: You may also complain to the supervisory authority of your habitual residence or place of work
- Right to an explanation: You can ask us to explain the logic behind the automated evaluation (see section 6)
- Judicial remedy: You retain the right to an effective judicial remedy under Art. 79 GDPR
The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, because our registered office is in Frechen, North Rhine-Westphalia.
We answer requests under the GDPR within one month. Where necessary, that period may be extended by two further months, taking into account the complexity and number of requests; we will inform you of any extension.
13. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
Categories of Personal Information
In the past 12 months we have collected the following categories:
- Identifiers: email address, IP address, account identifier
- Professional information: the content of your CV
- Commercial information: purchases and payment records
- Internet activity: aggregated usage of our pages and of the application
Your California Rights
- Right to Know: Request disclosure of the categories and the specific pieces of personal information we have collected
- Right to Delete: Request deletion of your personal information, subject to statutory exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt out of the sale or sharing of personal information — we neither sell nor share it
- Right to Limit Use of Sensitive PI: Limit the use of sensitive personal information — we use it only to provide the Service
- Right to Non-Discrimination: Not be treated differently for exercising your privacy rights
Automated Decision-Making Technology (ADMT)
Our evaluation is produced by automated processing. Accordingly:
- You have the right to information about how the evaluation works (see section 6)
- You can request a human review of any evaluation
- You can avoid automated processing entirely by not submitting a CV
To protect your data, we may need to verify your identity before answering a request. We use the email address associated with your account for that.
To exercise your California rights, write to privacy@cvscore.net with "CCPA Request" in the subject line. We respond within 45 days.
You may appoint an authorised agent to make a request on your behalf. We may ask for proof of that authorisation.
14. UK Privacy Rights (UK GDPR)
If you are located in the United Kingdom, you have rights under the UK General Data Protection Regulation and the Data Protection Act 2018:
Your rights largely mirror those under the EU GDPR set out in sections 11 and 12: access, rectification, erasure, restriction, portability, objection and the safeguards around automated decisions.
You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. Please note that we are established in Germany, so the supervisory authority responsible for us is the one named in section 12.
Note: the UK Data (Use and Access) Act 2025 has amended parts of UK data protection law. We will update this policy as implementing guidance is published.
15. Other Jurisdictions
Brazil (LGPD)
Residents of Brazil have rights under the Lei Geral de Proteção de Dados, including access, correction, anonymisation, portability and deletion. Complaints can be filed with the ANPD, the national data protection authority.
Canada (PIPEDA)
Residents of Canada have rights under the Personal Information Protection and Electronic Documents Act to access and correct their personal information. Complaints can be filed with the Office of the Privacy Commissioner of Canada.
Australia (Privacy Act)
Residents of Australia have rights under the Privacy Act 1988 to access and correct their personal information. Complaints can be filed with the Office of the Australian Information Commissioner.
Singapore (PDPA)
Residents of Singapore have rights under the Personal Data Protection Act to access and correct their personal data. Complaints can be filed with the Personal Data Protection Commission.
South Africa (POPIA)
Residents of South Africa have rights under the Protection of Personal Information Act to access, correct and delete their personal information. Complaints can be filed with the Information Regulator.
For requests under one of these laws, write to privacy@cvscore.net and tell us where you are located.
16. Cookies, Local Storage and Reach Measurement
We keep what is stored on your device to the minimum the Service needs to work:
Technically Necessary Storage
- Sign-in token (sb-…-auth-token): once you have signed in, your session token is stored in your browser's local storage so you stay signed in between page loads. Without it the application cannot be used. Legal basis: § 25(2) TDDDG, because this storage is strictly necessary to provide the service you requested.
Reach Measurement with Rybbit
To get a rough picture of how our pages and the application are used, we use Rybbit. The software runs on a server we operate ourselves; no data is passed to third parties, and it is not an advertising network. Rybbit sets no cookies, but it does store one randomly generated identifier in your browser's local storage, which lets us tell a returning visit from a new one within the same browser. It records the pages opened, the referring page, the approximate region, the device and browser type and individual interactions — inside the application also events such as a completed upload or an unlocked report, in some cases together with technical values such as the identifier of an evaluation or a score. Your name and your email address are never transmitted to it. You can delete or block the identifier at any time; our Cookie Policy explains how. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in data-minimising statistics.
What We Do Not Use
- No advertising cookies, no retargeting, no advertising networks
- No third-party analytics services such as Google Analytics
- No social media plug-ins or tracking pixels
- No session recording or mouse tracking
- No cross-site tracking of your behaviour
Third-Party Storage
If you sign in with Google, Google may store data on its own domains. If you make a purchase, Polar may do the same on its checkout pages; for invoices and for managing a subscription we likewise forward you to Polar. The application at app.cvscore.net also loads its typeface from Google Fonts; your browser contacts servers of Google LLC in the process and transmits your IP address to them. The pages at cvscore.net use fonts we host ourselves. If you use the share button, the link generated contains nothing but your numerical score, and the platform you publish it on applies its own rules. All of these processes are governed by the privacy policies of the providers concerned, not by ours.
You can delete data stored locally at any time through your browser settings. If you delete the sign-in token, you will be signed out and will have to sign in again.
Further details are in our Cookie Policy.
17. Security
We take appropriate technical and organisational measures to protect your data:
- All traffic between your browser, our website, the application and our API is encrypted in transit (HTTPS/TLS)
- Uploaded CV files are held in a private storage area, separated per user; they are not publicly accessible
- Evaluations and results can only be retrieved through our authenticated API; direct database access is restricted by row-level security
- Every endpoint that handles personal data requires a valid sign-in token; requests without one are rejected
- Passwords are only ever stored as cryptographic hashes; sign-in with Google is available as an alternative
- Rate limits on uploads, on account deletion and on other sensitive endpoints, to make automated abuse expensive
- The API may only be called from our own domains (CORS allow list)
- Uploads are restricted by file type, size and page count before they are processed
- Notifications from our payment provider are only accepted with a valid cryptographic signature
- Unsubscribe links in our emails are cryptographically signed, so nobody can unsubscribe someone else's address
- Access credentials are supplied to the runtime environment as environment variables and are not part of our source code
No transmission over the internet and no form of storage is completely secure. We cannot therefore guarantee absolute security.
If you find a security vulnerability, please report it to us at security@cvscore.net before disclosing it publicly.
18. Minors
The Service is not intended for people under the age of 16. We do not knowingly collect data from children under 16.
If we become aware that we have received data from a child under 16, we delete it without undue delay. If you believe this has happened, please contact privacy@cvscore.net.
19. Data Breaches
In the event of a personal data breach:
- We notify the competent supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms (Art. 33 GDPR)
- We notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR)
- We document every breach, its effects and the measures taken
- We maintain procedures to detect, investigate and remedy incidents
If you believe your data may have been compromised, contact us immediately at security@cvscore.net.
20. Changes to This Policy
We update this policy when our processing changes. We inform you of material changes by:
- Publishing the updated version on this page with a new date
- Emailing registered users where the change is significant
- Displaying a notice within the Service
We recommend reviewing this page from time to time. The version published here is always the one that applies.
Where a change materially affects your rights or the way we use your data, we announce it at least 30 days before it takes effect.
21. Contact
For questions, requests or complaints about data protection, please contact us:
Privacy enquiries
Data subject requests
privacy@cvscore.net(Please write "Data subject request" in the subject line)
Security issues
General support
Postal address
The CodeCave GmbH, Alfred-Nobel-Straße 29, 50226 Frechen, Germany
We aim to reply to general enquiries within five business days and to complete requests under the GDPR within one month.
Privacy Questions
The questions we are asked most often about data handling.
Who is responsible for my data?
The CodeCave GmbH, Alfred-Nobel-Straße 29, 50226 Frechen, Germany, registered at Amtsgericht Bielefeld under HRB 44492. Because we are established in the EU, no representative under Article 27 GDPR is required. You can reach us at privacy@cvscore.net.
Is my CV stored after the evaluation?
Yes. Your PDF stays in the private storage area of your account until you delete the evaluation or the whole account. It is not deleted automatically after processing, so that you can revisit earlier reports. Deletion is available in the application at any time.
What exactly is sent to OpenAI?
The complete text extracted from your CV, together with our evaluation instruction, is sent to OpenAI's API and processed by the gpt-4o-mini model. If your CV contains your name, address or contact details, they are part of that text — we do not remove them. We do not transmit your account identifier, your login email address or any payment data. Under OpenAI's API terms, this content is not used to train its models by default.
Where is my CV converted into text?
On our own server. Text extraction and, for scanned PDFs, the text recognition step both run in our backend, which is hosted on Google Cloud servers in Frankfurt, Germany. No external service is involved in this step.
Is this an automated decision under Article 22 GDPR?
In our assessment it is not, because you request the analysis yourself, the result is purely advisory, it is shown only to you, and no third party decides anything on its basis. We nevertheless grant the safeguards of Article 22(3) voluntarily: you can request a human review at support@cvscore.net, state your point of view and contest the result.
How long do you keep my data?
There is no automatic deletion period. Account data, CV files and results are kept until you delete the evaluation or your account. Payment records have to be retained for the statutory commercial and tax retention periods, in Germany usually 6 or 10 years, even after an account is deleted.
Which emails will I receive, and how do I stop them?
Transactional messages — the notice that your report is ready — are part of the service you asked for. A reminder about an unfinished purchase may be sent at most once a week. All other emails, such as the prompt to re-check your CV or the request for a review, are sent only with your consent, which you can withdraw at any time using the unsubscribe link in every such email.
Where can I complain?
You can always write to us at privacy@cvscore.net first. You also have the right to lodge a complaint with a supervisory authority — for us that is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia in Düsseldorf, or alternatively the authority where you live or work.