Privacy Policy
Last updated: 18 May 2026
1. Introduction and data controller
CVLift ("we", "us") is operated by Oxegena Sàrl, Switzerland. We are committed to protecting your personal data in accordance with the Swiss Federal Act on Data Protection (nDSG, in force since 1 September 2023) and, where applicable, the EU General Data Protection Regulation (GDPR).
For any data-related enquiries: [email protected]
2. Data we collect and why
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Authentication, CV ready notification, refund processing | Contract performance |
| Full name | CV document header personalisation | Contract performance |
| CV text content | AI optimisation pipeline | Contract performance |
| Profile photo (optional) | Inserted into CV header if provided | Contract performance |
| Target role, industry, language | Pipeline configuration | Contract performance |
| Job description | CV tailoring and ATS keyword matching | Contract performance |
| Browser fingerprint | Fraud prevention — one free generation per user | Legitimate interest |
| Payment data | Processed exclusively by Stripe — we never store card data | Contract performance |
| IP address and server logs | Security and error monitoring | Legitimate interest |
3. How we process your CV data
Your CV text and job description are sent to our AI pipeline using the Anthropic Claude API and the Mistral AI API to rewrite and optimise your document. These providers process data on our behalf under data processing agreements. Your data is not used to train third-party AI models.
The optimised CV (DOCX) is stored temporarily in our database for download after payment. It is not shared with any party other than sub-processors listed in section 5.
4. How long we keep your data
| Data | Retention period |
|---|---|
| Email, name, CV text, photo | Until you delete your profile or request erasure |
| Generated CV documents | Up to 90 days after generation, unless you request deletion earlier |
| Credit purchase records | 10 years (Swiss CO Art. 958f) |
| Browser fingerprint | 12 months from last generation |
| Magic link tokens | 15 minutes (auto-deleted) |
| Refund records | 10 years (Swiss CO) |
| Server logs | 90 days rolling |
5. Sub-processors and third parties
We share your data with the following sub-processors solely to deliver the service:
| Provider | Purpose | Location | Applicable law | Transfer safeguard |
|---|---|---|---|---|
| Scaleway SAS | Dedicated server hosting | France / EU | GDPR | EU-internal — no transfer |
| Brevo SAS | Transactional email delivery (magic links, CV ready notifications) | France / EU | GDPR | EU-internal — no transfer |
| Cloudflare Inc. | CDN, caching, DDoS protection — IP addresses and request metadata transit their network | USA / EU edge nodes | US CLOUD Act | SCCs + Data Privacy Framework |
| OpenRouter Inc. | API routing layer to AI model providers | USA | US CLOUD Act | SCCs |
| Anthropic PBC | AI CV rewriting and optimisation (Claude API) | USA | US CLOUD Act | SCCs |
| Mistral AI SAS | AI CV processing | France / EU | GDPR | EU-internal — no transfer |
| Google Cloud Translation API (Google LLC) | Translation of public customer reviews, including review text, city and country | USA / global infrastructure | US CLOUD Act | SCCs |
| Stripe Inc. | Payment processing | USA | US CLOUD Act | SCCs |
We do not sell, rent, or trade your personal data for marketing purposes.
6. International data transfers and CLOUD Act disclosure
Our server infrastructure is located in France (EU) — operated by Scaleway SAS on a dedicated server owned by Oxegena Sàrl. Brevo SAS and Mistral AI SAS are also French companies with EU data storage. No international transfer occurs for data processed by these providers.
Data processed via US-based providers (Cloudflare, OpenRouter, Anthropic, Google Cloud Translation API, Stripe) is protected by Standard Contractual Clauses (SCCs) approved by the European Commission and recognised under Swiss nDSG. Cloudflare additionally participates in the EU-US Data Privacy Framework.
US CLOUD Act: The US Clarifying Lawful Overseas Use of Data Act (CLOUD Act, 2018) allows US authorities to compel US companies to produce data held anywhere in the world, including outside the US. This applies to Cloudflare, OpenRouter, Anthropic, Google LLC, and Stripe. We have no record of any such request being made in connection with CVLift. Any such request would be directed to the relevant provider, not to us. We would be notified to the extent permitted by law and would challenge any request we consider unlawful.
7. Your rights
Under Swiss nDSG and GDPR (where applicable), you have the right to access, correct, erase, and port your data, restrict processing, object to legitimate-interest processing, and lodge a complaint with the FDPIC.
To exercise these rights: [email protected]. You can also delete your profile directly from your profile page. We respond within 30 days.
8. Cookies
CVLift uses only functional cookies. No tracking or advertising cookies. See our Cookie Notice.
9. Security
We apply TLS encryption in transit, hashed authentication tokens, database access controls, and two-factor authentication for administrative access. Report security concerns to [email protected].
10. Children
CVLift is for users aged 18 and over. We do not knowingly collect data from minors.
11. Changes
Material changes will be communicated by email or prominent notice at least 14 days before taking effect.
12. Contact and complaints
Questions: [email protected]
Complaints: Swiss FDPIC — www.edoeb.admin.ch