CVLift

Privacy Policy

Last updated: 18 May 2026

1. Introduction and data controller

CVLift ("we", "us") is operated by Oxegena Sàrl, Switzerland. We are committed to protecting your personal data in accordance with the Swiss Federal Act on Data Protection (nDSG, in force since 1 September 2023) and, where applicable, the EU General Data Protection Regulation (GDPR).

For any data-related enquiries: [email protected]

2. Data we collect and why

DataPurposeLegal basis
Email addressAuthentication, CV ready notification, refund processingContract performance
Full nameCV document header personalisationContract performance
CV text contentAI optimisation pipelineContract performance
Profile photo (optional)Inserted into CV header if providedContract performance
Target role, industry, languagePipeline configurationContract performance
Job descriptionCV tailoring and ATS keyword matchingContract performance
Browser fingerprintFraud prevention — one free generation per userLegitimate interest
Payment dataProcessed exclusively by Stripe — we never store card dataContract performance
IP address and server logsSecurity and error monitoringLegitimate interest

3. How we process your CV data

Your CV text and job description are sent to our AI pipeline using the Anthropic Claude API and the Mistral AI API to rewrite and optimise your document. These providers process data on our behalf under data processing agreements. Your data is not used to train third-party AI models.

The optimised CV (DOCX) is stored temporarily in our database for download after payment. It is not shared with any party other than sub-processors listed in section 5.

4. How long we keep your data

DataRetention period
Email, name, CV text, photoUntil you delete your profile or request erasure
Generated CV documentsUp to 90 days after generation, unless you request deletion earlier
Credit purchase records10 years (Swiss CO Art. 958f)
Browser fingerprint12 months from last generation
Magic link tokens15 minutes (auto-deleted)
Refund records10 years (Swiss CO)
Server logs90 days rolling

5. Sub-processors and third parties

We share your data with the following sub-processors solely to deliver the service:

ProviderPurposeLocationApplicable lawTransfer safeguard
Scaleway SASDedicated server hostingFrance / EUGDPREU-internal — no transfer
Brevo SASTransactional email delivery (magic links, CV ready notifications)France / EUGDPREU-internal — no transfer
Cloudflare Inc.CDN, caching, DDoS protection — IP addresses and request metadata transit their networkUSA / EU edge nodesUS CLOUD ActSCCs + Data Privacy Framework
OpenRouter Inc.API routing layer to AI model providersUSAUS CLOUD ActSCCs
Anthropic PBCAI CV rewriting and optimisation (Claude API)USAUS CLOUD ActSCCs
Mistral AI SASAI CV processingFrance / EUGDPREU-internal — no transfer
Google Cloud Translation API (Google LLC)Translation of public customer reviews, including review text, city and countryUSA / global infrastructureUS CLOUD ActSCCs
Stripe Inc.Payment processingUSAUS CLOUD ActSCCs

We do not sell, rent, or trade your personal data for marketing purposes.

6. International data transfers and CLOUD Act disclosure

Our server infrastructure is located in France (EU) — operated by Scaleway SAS on a dedicated server owned by Oxegena Sàrl. Brevo SAS and Mistral AI SAS are also French companies with EU data storage. No international transfer occurs for data processed by these providers.

Data processed via US-based providers (Cloudflare, OpenRouter, Anthropic, Google Cloud Translation API, Stripe) is protected by Standard Contractual Clauses (SCCs) approved by the European Commission and recognised under Swiss nDSG. Cloudflare additionally participates in the EU-US Data Privacy Framework.

US CLOUD Act: The US Clarifying Lawful Overseas Use of Data Act (CLOUD Act, 2018) allows US authorities to compel US companies to produce data held anywhere in the world, including outside the US. This applies to Cloudflare, OpenRouter, Anthropic, Google LLC, and Stripe. We have no record of any such request being made in connection with CVLift. Any such request would be directed to the relevant provider, not to us. We would be notified to the extent permitted by law and would challenge any request we consider unlawful.

7. Your rights

Under Swiss nDSG and GDPR (where applicable), you have the right to access, correct, erase, and port your data, restrict processing, object to legitimate-interest processing, and lodge a complaint with the FDPIC.

To exercise these rights: [email protected]. You can also delete your profile directly from your profile page. We respond within 30 days.

8. Cookies

CVLift uses only functional cookies. No tracking or advertising cookies. See our Cookie Notice.

9. Security

We apply TLS encryption in transit, hashed authentication tokens, database access controls, and two-factor authentication for administrative access. Report security concerns to [email protected].

10. Children

CVLift is for users aged 18 and over. We do not knowingly collect data from minors.

11. Changes

Material changes will be communicated by email or prominent notice at least 14 days before taking effect.

12. Contact and complaints