Privacy notice
Last updated 21 August 2026. This notice covers the cvgraph website (cvgraph.ai), the waitlist, and the cvgraph application (app.cvgraph.ai). It is written to meet Articles 12–14 of the GDPR: plain language, everything in one place.
1. Who we are
cvgraph is operated by Peritus slf., a company registered in Reykjavík, Iceland ("we") — the data controller for the personal data described here. We have not appointed a Data Protection Officer; our privacy lead is reachable at privacy@cvgraph.ai.
2. What data we collect, and how
Account data — email address and authentication details, collected when you sign up.
Career data — the skills, roles, occupations, courses, and related information you enter to build your graph. You control what goes in. If you use the AI-assisted import, your CV document itself is never uploaded to us: your own AI assistant produces a structured file, and only the entries you confirm are stored.
Waitlist data — the email address you confirmed via double opt-in, with the time of consent.
Billing data — held by Paddle, our merchant of record (see section 4); we receive subscription status only, never full payment details.
Technical data — short-lived IP-based rate-limiting keys, server logs, and error reports that are scrubbed of personal data before storage.
All of this comes directly from you or from your use of the service — we do not buy data about you or collect it from third parties.
3. Why we process it (purposes and legal bases)
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing your account and graph | Account data, career data | Contract (Art. 6(1)(b)) |
| AI features: exposure, JD-fit, Ask | Career data you submit to the feature | Contract (Art. 6(1)(b)) |
| Sharing graphs you choose to share | The graph edition you share | Contract (Art. 6(1)(b)) |
| Waitlist and early-access emails | Email address, consent record | Consent (Art. 6(1)(a)) |
| Billing and subscription status | Subscription state (payments handled by Paddle) | Contract (Art. 6(1)(b)); legal obligation for tax records |
| Security, abuse prevention, rate limiting | IP address (short-lived), request metadata | Legitimate interest (Art. 6(1)(f)): keeping the service safe |
| Error monitoring | Scrubbed technical error reports | Legitimate interest (Art. 6(1)(f)): service reliability |
| Aggregate analytics | Page views without identifiers | Legitimate interest (Art. 6(1)(f)): understanding usage |
We do not sell personal data, we do not use your career data to train AI models, and we do not build advertising profiles.
4. Who receives your data
Subprocessors — service providers processing data on our instructions:
| Provider | Role | Location | Transfer safeguard |
|---|---|---|---|
| Vercel Inc. | Hosting, CDN, aggregate analytics | USA / EU edge | EU-U.S. Data Privacy Framework + SCCs |
| Supabase | Application database (accounts, career graphs) | EU region | SCCs with US parent where applicable |
| Resend | Transactional and waitlist email | EU region (US company) | SCCs |
| Upstash | Rate-limiting store (short-lived IP/email keys) | EU/US | SCCs / DPF |
| Functional Software, Inc. (Sentry) | Error monitoring — reports scrubbed of personal data before storage | EU/US | DPF + SCCs |
| Anthropic, PBC | AI model provider for Ask, JD-fit, and exposure features | USA | SCCs; API data not used for model training |
| OpenAI, LLC | Text-embedding API used by JD-fit to match job-description requirements against skills | USA | SCCs / DPF; API data not used for model training |
| Cloudflare, Inc. | DNS and inbound email routing for cvgraph.ai addresses | USA / global | DPF + SCCs |
Independent controllers — Paddle.com Market Limited processes your payment and billing data as merchant of record under its own privacy policy. People you share a graph link with receive the content of that shared edition. Beyond these, we disclose personal data only where the law requires.
We update this list when subprocessors change; the date at the top of this notice reflects the current version.
5. International transfers
We prefer EU regions where our providers offer them. Where a provider processes data outside the EEA (see the table above), the transfer relies on an adequacy decision, the EU-U.S. Data Privacy Framework, or Standard Contractual Clauses.
6. How long we keep it
Account and career data: while your account exists, deleted within 30 days of account deletion. Waitlist emails: until you unsubscribe or ask us to delete them. Rate-limiting keys: hours to days by design. Scrubbed error reports: 90 days. Billing records: retained by Paddle for as long as tax law requires.
7. Your rights
Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to processing based on legitimate interests, receive a portable copy, and — where processing rests on consent — withdraw that consent at any time without affecting earlier processing. Write to privacy@cvgraph.ai and we will respond within one month. You also have the right to complain to a supervisory authority: Persónuvernd, the Icelandic Data Protection Authority (personuvernd.is), or the authority of your own country.
8. Automated processing and profiling
AI-exposure scores, JD-fit scores, and Ask answers are produced by automated systems from the data you provide. They are informational outputs shown to you — we make no decisions about you with legal or similarly significant effect based on them, and no automated decision-making within the meaning of Article 22 GDPR takes place.
9. What you must provide
An email address is required to create an account (we cannot provide the service without it). Everything else — every skill, role, and document-derived entry — is voluntary; the only consequence of leaving something out is a less complete graph.
10. Cookies and analytics
This site sets no tracking cookies, which is why there is no cookie banner. We use two strictly functional preferences: your theme choice (stored in your browser’s local storage) and, if you switch it, your display currency (a single functional cookie). Neither identifies you or follows you anywhere.
Page views and anonymous interaction events (for example, which call-to-action button was clicked) are counted in aggregate with Vercel Analytics, which sets no cookies and stores no identifiers on your device. If you arrive via a campaign link, its UTM tags are kept for the duration of the tab (sessionStorage) and attached to those aggregate events so we know which campaign brought visitors — they identify the campaign, not you.
If you sign up after arriving via a campaign link, we record that campaign source (the UTM tags of the link you arrived from) on your account as first-party attribution — our own record of which marketing source brought you, used only to measure our campaigns. No third-party marketing pixel or tracker is involved.
11. Children
The service is not directed at children and requires users to be at least 16. We do not knowingly process children’s data; if you believe a child has created an account, contact us and we will delete it.
12. Security
Data is encrypted in transit, access is restricted and role-based, payment data never touches our systems, and error reports are scrubbed before storage. No system is perfectly secure; if a breach affects your rights we will notify you and the supervisory authority as the GDPR requires.
13. Changes and contact
We will update this notice as the service evolves and change the date above; for material changes affecting your rights we will tell you by email or in the product. Questions: privacy@cvgraph.ai.