Privacy Policy
Last Updated: March 21, 2025
Table of Contents
- 1. Introduction
- 2. Information We Collect
- 3. How We Use Your Information
- 4. Legal Basis for Processing
- 5. AI Processing and Data Usage
- 6. How We Share Your Information
- 7. Third-Party Service Providers
- 8. Data Security
- 9. Data Retention
- 10. Your Rights and Choices
- 11. International Data Transfers
- 12. Children's Privacy
- 13. Regulatory Compliance
- 14. Changes to This Privacy Policy
- 15. Contact Information
Key Privacy Points
• We collect personal information to provide our resume template services and AI assistant features
• Your resume data is yours - we do not sell it to third parties
• Our AI assistant processes your resume data to provide personalized suggestions
• We implement robust security measures to protect your personal information
• You have control over your data with options to access, edit, or delete it
• We comply with various data protection regulations including GDPR, CCPA, and others
• For users in the European Economic Area, we provide additional information on data protection
1. Introduction
At CVNio Inc. ("CVNio," "we," "us," or "our"), we respect your privacy and are committed to protecting your personal information. This Privacy Policy describes how we collect, use, and share information about you when you use our website, resume template services, and AI assistant features (collectively, the "Services").
Please read this Privacy Policy carefully to understand our practices regarding your personal information. By using our Services, you acknowledge that you have read and understood this Privacy Policy.
Note for European Economic Area Users
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we provide additional information about how we process your personal data in accordance with the General Data Protection Regulation (GDPR).
1.1 Scope of This Privacy Policy
This Privacy Policy applies to information we collect when you use our Services, including when you create an account, subscribe to our services, create and edit resumes, use our AI assistant, or otherwise interact with CVNio.
1.2 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the updated Privacy Policy on our website and updating the "Last Updated" date at the top of this policy. We encourage you to review this Privacy Policy periodically to stay informed about our data practices.
1.3 Your Consent
By using our Services, you consent to the collection, use, and sharing of your personal information as described in this Privacy Policy. If you do not agree with our policies and practices, you should not use our Services.
2. Information We Collect
We collect several types of information from and about users of our Services, including:
2.1 Information You Provide to Us
We collect information you provide directly to us, including:
- Account Information: When you create an account, we collect your name, email address, password, and other registration information.
- Payment Information: If you subscribe to our paid services, we collect payment details, billing address, and other information necessary to process your payment.
- Resume Content: We collect the information you input into your resume, which may include your education history, work experience, skills, certifications, contact information, career objectives, and other personal and professional details.
- Communications: We collect information you provide when you contact us, respond to surveys, or communicate with our customer support.
- AI Assistant Interactions: We collect your queries and interactions with our AI assistant to provide and improve our services.
2.2 Information We Collect Automatically
When you use our Services, we automatically collect certain information, including:
- Usage Information: We collect information about your interactions with our Services, such as the features you use, the templates you view or download, and your interactions with our AI assistant.
- Device Information: We collect information about the device you use to access our Services, including the hardware model, operating system and version, unique device identifiers, and mobile network information.
- Location Information: We may collect information about your approximate location as determined by your IP address.
- Log Information: We collect log information when you use our Services, including access times, pages viewed, and your IP address.
- Cookies and Similar Technologies: We use cookies and similar technologies to collect information about your browsing activities and to recognize you across different Services and devices. For more information about our use of cookies, please see our Cookie Policy.
2.3 Information from Third Parties
We may receive information about you from third parties, including:
- Social Media Platforms: If you choose to link your social media account to our Services, we may receive information from the social media platform, such as your profile information.
- Business Partners: We may receive information about you from our business partners, such as when you access our Services through a co-branded or partner website.
- Service Providers: We may receive information from service providers that help us operate our Services, including payment processors and customer service providers.
3. How We Use Your Information
We use the information we collect for various purposes, including:
Purpose | Information Used |
---|---|
Providing and Improving Our Services | Account information, resume content, usage information, device information |
Personalizing Your Experience | Usage information, resume content, AI interactions |
Processing Payments | Payment information, account information |
Communicating With You | Account information, communications |
Providing AI Assistant Features | Resume content, AI interactions, usage information |
Analyzing and Improving Our Services | Usage information, device information, log information |
Protecting Our Services | Account information, usage information, device information, log information |
Marketing and Advertising | Account information, usage information |
3.1 Providing and Improving Our Services
We use your information to provide, maintain, and improve our Services, including to process transactions, manage your account, and provide customer support. This includes using your resume content to enable you to create, edit, and download resumes using our templates.
3.2 Personalizing Your Experience
We use your information to personalize your experience with our Services, such as recommending templates that may be relevant to your industry or career level, and providing tailored content and recommendations.
3.3 Processing Payments
We use your payment information to process subscription payments and send you receipts and invoices. We work with third-party payment processors who handle your payment information in accordance with industry standards.
3.4 Communicating With You
We use your information to communicate with you about our Services, respond to your inquiries, and send you updates, security alerts, and support messages. We may also send you marketing communications, subject to your communication preferences.
3.5 Providing AI Assistant Features
We use your resume content and interactions with our AI assistant to provide personalized suggestions for improving your resume, optimizing your content for Applicant Tracking Systems (ATS), and other AI-powered features.
3.6 Analyzing and Improving Our Services
We use information about how you use our Services to analyze trends, track user engagement, and gather demographic information about our user base. This helps us improve our Services and develop new features.
3.7 Protecting Our Services
We use information to verify accounts, prevent fraud, monitor suspicious or illegal activities, and enforce our Terms of Service.
3.8 Marketing and Advertising
With your consent, we may use your information to send you promotional materials about our Services and other products or services that may be of interest to you. You can opt out of receiving marketing communications at any time.
4. Legal Basis for Processing
For users in the European Economic Area (EEA), United Kingdom, and other jurisdictions where applicable, we rely on the following legal bases to process your personal information:
4.1 Contractual Necessity
We process your personal information as necessary to fulfill our contractual obligations to you, including providing our Services as described in our Terms of Service. This includes:
- Processing your account information to create and maintain your account
- Processing your resume content to provide resume creation and editing services
- Processing payment information to handle subscriptions
4.2 Legitimate Interests
We process your personal information when it is in our legitimate interests to do so, balanced against your rights and interests. Our legitimate interests include:
- Improving and personalizing our Services
- Ensuring the security of our Services
- Analyzing how users interact with our Services to enhance user experience
- Promoting our Services through direct marketing (subject to your marketing preferences)
4.3 Consent
We process certain personal information based on your explicit consent, including:
- Using your data for AI processing and training (with opt-out options)
- Sending marketing communications (where required by law)
- Using cookies and similar technologies (except strictly necessary cookies)
You can withdraw your consent at any time through your account settings or by contacting us.
4.4 Legal Obligation
We may process your personal information to comply with legal obligations, such as:
- Responding to legal requests from authorities
- Complying with tax and accounting requirements
- Meeting data protection obligations
5. AI Processing and Data Usage
5.1 How Our AI Uses Your Data
Our AI assistant processes your resume content and interactions to provide personalized suggestions and improvements. This processing involves analyzing your resume structure, content, and format to identify areas for improvement and provide recommendations based on best practices in resume writing.
5.2 AI Training and Anonymization Process
To improve our AI assistant, we may use aggregated and anonymized data derived from user interactions. Our anonymization process includes:
- Removing all personally identifiable information including names, contact details, and specific employer names
- Converting specific dates to general time periods
- Generalizing unique job titles and responsibilities to industry-standard terminology
- Removing specific location data beyond general region/country
- Aggregating data across many users to eliminate individual patterns
- Implementing technical safeguards including differential privacy techniques
We do not use individual user data to train our AI models in a way that could identify you or reveal your specific resume content to others.
5.3 Opting Out of AI Features and Training
You can control how our AI assistant uses your data through your account settings. Specifically, you can:
- Disable specific AI features (such as content suggestions or ATS optimization)
- Opt out of AI-powered suggestions entirely while still using template features
- Opt out of having your anonymized data used for AI model training (this will not affect your ability to use the AI features)
To adjust these settings, go to Account Settings > Privacy > AI Features and Training. If you opt out of AI processing entirely, your resume data will not be processed by our AI systems, though you may lose access to certain features that rely on AI processing.
5.4 AI Decision-Making
Our AI assistant makes suggestions and recommendations, but it does not make automated decisions that would have legal or similarly significant effects on you. All AI suggestions are provided for your consideration, and you retain full control over whether to accept or reject them.
5.5 Third-Party AI Technologies
Our AI features may incorporate third-party AI technologies. When we use such technologies, we ensure that these third parties adhere to our data protection standards and do not retain your personal data beyond what is necessary to provide the service.
6. How We Share Your Information
We may share your information in the following circumstances:
6.1 With Your Consent
We may share your information when you direct us to do so, such as when you choose to share your resume with potential employers through our platform or when you authorize us to connect with third-party services.
6.2 With Service Providers
We may share your information with third-party service providers who perform services on our behalf, such as payment processing, data analysis, email delivery, hosting, customer service, and marketing assistance. These service providers are contractually obligated to use your information only as necessary to provide services to us and are subject to confidentiality obligations.
6.3 For Legal Reasons
We may share your information if we believe it is necessary to:
- Comply with applicable laws, regulations, legal processes, or governmental requests
- Enforce our Terms of Service and other agreements
- Detect, investigate, and prevent fraud, security breaches, or technical issues
- Protect the rights, property, or safety of CVNio, our users, or others
6.4 In Connection with Business Transfers
If CVNio is involved in a merger, acquisition, sale of assets, bankruptcy, or other corporate change, we may transfer your information as part of that transaction. We will notify you if your information becomes subject to a different privacy policy as a result of such a transfer.
6.5 Aggregated or De-identified Information
We may share aggregated or de-identified information that cannot reasonably be used to identify you. For example, we may share anonymous, aggregated statistics about how users interact with our Services to improve our offerings.
Important Note About Your Resume Data
We understand that your resume contains sensitive personal and professional information. We do not sell your resume data to third parties for marketing purposes. Your resume data is only shared with third parties as described in this Privacy Policy and with your explicit consent (such as when you choose to apply for a job through our platform).
7. Third-Party Service Providers
We work with various third-party service providers to operate our Services. These providers may have access to your personal information only to perform tasks on our behalf and are obligated not to disclose or use it for any other purpose.
7.1 Categories of Service Providers
We engage the following categories of service providers:
- Cloud Infrastructure Providers: For hosting our application and data storage (e.g., AWS, Google Cloud)
- Payment Processors: To handle subscription payments and billing (e.g., Stripe, PayPal)
- Analytics Providers: To help us understand how users interact with our Services (e.g., Google Analytics)
- Customer Support Platforms: To help us communicate with users and provide support
- Email Service Providers: To send notifications, marketing emails, and newsletters
- AI and Machine Learning Services: To power our AI assistant features
- Security Service Providers: To protect our Services against fraud and security threats
7.2 Data Processing Agreements
We enter into Data Processing Agreements (DPAs) with our service providers that process personal data on our behalf. These agreements require our service providers to:
- Process personal data only according to our documented instructions
- Implement appropriate technical and organizational security measures
- Ensure confidentiality of the data
- Assist us in responding to data subject requests
- Delete or return all personal data after the end of the service
- Submit to audits and inspections to verify compliance
7.3 Third-Party Links and Services
Our Services may contain links to third-party websites, products, or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party websites you visit.
8. Data Security
We take the security of your personal information seriously and implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction.
8.1 Security Measures
Our security measures include:
- Encryption of sensitive data in transit (using TLS) and at rest (using AES-256)
- Secure user authentication procedures including multi-factor authentication options
- Regular security assessments and penetration testing
- Access controls and authorization procedures
- Monitoring for suspicious activities
- Employee training on data security practices
- Security incident response procedures
8.2 Data Breach Procedures
In the event of a data breach that affects your personal information, we will notify you in accordance with applicable laws and regulations. We have implemented procedures to address potential data breaches, including:
- Identifying and assessing the nature and scope of the breach
- Containing and mitigating the breach
- Notifying affected individuals, regulators, and other required parties within required timeframes (72 hours for GDPR compliance where applicable)
- Investigating the cause of the breach and implementing measures to prevent future breaches
8.3 Your Role in Security
While we implement security measures to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We encourage you to take steps to protect your account, such as:
- Using a strong, unique password for your CVNio account
- Not sharing your account credentials with others
- Logging out of your account after using shared computers
- Keeping your devices and browsers updated
- Being cautious of phishing attempts or suspicious communications
9. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
9.1 Active Accounts
For active accounts, we retain your account information, resume content, and other data for as long as your account is active. This allows you to access and update your resumes, use our Services, and receive support.
9.2 Deleted Accounts
If you delete your account, we will delete or anonymize your personal information within 30 days, except for information that we are required to retain for legal purposes or legitimate business interests. For example, we may retain information to:
- Comply with legal obligations
- Resolve disputes
- Enforce our agreements
- Protect against fraudulent or illegal activity
9.3 Specific Retention Periods
We apply the following specific retention periods to different types of data:
- Account Information: Retained for the duration of your account plus 30 days after deletion
- Resume Content: Retained for the duration of your account plus 30 days after deletion
- Payment Information: Retained for 7 years as required by tax and accounting regulations
- Usage Logs: Retained for 90 days for security and performance analysis
- Communication Records: Retained for 2 years for customer service purposes
- Marketing Preferences: Retained until you opt out or close your account
9.4 Backup Data
To ensure data integrity and business continuity, we maintain backup copies of our databases. Your information may remain in these backup systems for up to 90 days after deletion from our active systems.
9.5 Anonymized Data
We may retain anonymized, aggregated data derived from user information indefinitely for analytical purposes and service improvement.
10. Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information. These may include:
10.1 Access and Portability
You have the right to access the personal information we hold about you. You can view most of this information by logging into your account. You may also request a copy of your personal information in a structured, commonly used, and machine-readable format.
10.2 Correction
You have the right to correct inaccurate or incomplete personal information. You can update most of your information directly through your account settings.
10.3 Deletion
You have the right to request the deletion of your personal information. You can delete your account through your account settings or by contacting us. Note that we may retain certain information as required by law or for legitimate business purposes, as described in the Data Retention section.
10.4 Restriction and Objection
You have the right to restrict or object to the processing of your personal information in certain circumstances. For example, you may object to the processing of your personal information for direct marketing purposes.
10.5 Consent Withdrawal
If we process your personal information based on your consent, you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing based on your consent before its withdrawal.
10.6 Communication Preferences
You can manage your communication preferences by:
- Updating your preferences in your account settings
- Clicking the "unsubscribe" link in our marketing emails
- Contacting us directly
10.7 How to Exercise Your Rights
To exercise your rights, you can:
- Use the relevant features in your account settings
- Contact us at privacy@cvnio.com
- Submit a request through our support form
We will respond to your request within the timeframe required by applicable law (typically within 30 days). We may need to verify your identity before processing your request.
10.8 Region-Specific Rights
For California Residents: Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), you have additional rights, including the right to know what personal information we collect, the right to delete your personal information, the right to opt-out of the sale or sharing of your personal information, and the right to non-discrimination for exercising your rights.
For European Economic Area, United Kingdom, and Swiss Residents: You have additional rights under the GDPR, including the right to lodge a complaint with a supervisory authority.
11. International Data Transfers
CVNio is based in the United States, and we process and store information on servers located in the United States and other countries. As a result, we may transfer your personal information to countries outside of your country of residence, which may have data protection laws that are different from those in your country.
11.1 Data Transfer Mechanisms
When we transfer personal information from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we use appropriate safeguards, such as:
- Standard Contractual Clauses approved by the European Commission
- Data protection agreements with our service providers and partners
- Binding Corporate Rules where applicable
- Adequacy decisions where available
- Other lawful data transfer mechanisms
11.2 Your Rights Regarding International Transfers
If you are located in the EEA, United Kingdom, or Switzerland, you have the right to obtain information about the safeguards we use for transferring your personal information. You can contact us for more information about these safeguards.
11.3 Data Localization Options
For users in certain regions, we may offer data localization options to keep your data stored in specific geographic regions. You can check availability and enable these options in your account settings under Privacy > Data Storage.
12. Children's Privacy
Our Services are not directed to children under the age of 18, and we do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take steps to delete that information as quickly as possible.
If you believe that we may have collected personal information from a child under 18, please contact us immediately at privacy@cvnio.com.
13. Regulatory Compliance
13.1 GDPR Compliance
For users in the European Economic Area (EEA) and the United Kingdom, we comply with the General Data Protection Regulation (GDPR) and the UK GDPR.
13.2 CCPA/CPRA Compliance
For California residents, we comply with the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), providing:
- The right to know what personal information we collect and how we use it
- The right to delete personal information
- The right to opt-out of the sale or sharing of personal information
- The right to non-discrimination for exercising privacy rights
We do not sell personal information as defined by the CCPA/CPRA. For more information about your California privacy rights, visit our California Privacy Notice.
13.3 Other Regional Compliance
We also comply with other regional data protection laws, including:
- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)
- Brazil's General Data Protection Law (LGPD)
- Australia's Privacy Act
- Other applicable data protection laws
13.4 Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our privacy practices and ensuring compliance with data protection laws. You can contact our DPO at dpo@cvnio.com if you have questions or concerns about our privacy practices.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by:
- Posting the updated Privacy Policy on our website
- Updating the "Last Updated" date at the top of this Privacy Policy
- Sending an email to users who have provided us with their email address
- Providing in-app notifications about significant changes
We encourage you to review this Privacy Policy periodically to stay informed about our data practices.
For material changes that significantly affect your rights or how we use your personal information, we will provide at least 30 days' notice before the changes take effect, unless the changes are required by law or address newly discovered security vulnerabilities.
15. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
CVNio Inc.
Attn: Privacy Officer
Email: privacy@cvnio.com
Address: 30 N Gould St, Sheridan, WY 82801, USA
Phone: +1 (307) 555-0123
For users in the European Union and other regions outside the United States, you may still contact us using the information above for any privacy-related inquiries. We will handle all international requests in accordance with applicable data protection laws.
For European Economic Area residents, you may also have the right to lodge a complaint with your local data protection authority if you believe that our processing of your personal information does not comply with applicable data protection laws.
When contacting us regarding a privacy-related matter, please include "Privacy Request" in the subject line to help us route your inquiry appropriately and respond promptly.