eveilo Privacy Policy  ·  Wersja polska
Legal document

Privacy Policy of eveilo.com

Effective from: 24 August 2026
Version 1.0
Compliant with Regulation (EU) 2016/679 (GDPR)
Language note. This English version is provided for convenience. In the event of any discrepancy, the Polish version prevails. The Polish version is available at https://eveilo.com/polityka-prywatnosci.
Personal Data Controller
ULTIMO SOLUTIO Katarzyna Bilińska
ul. Myszyniec 25, 05-255 Arciechów
NIP: 775 236 91 48  ·  REGON: 366801676
E-mail for data protection matters: hello@eveilo.com

This Privacy Policy describes the rules for processing personal data on eveilo.com, an online CV and cover letter builder with artificial intelligence features (CV import from files, AI document review, document translations, AI-assisted cover letters). This document has been drawn up on the basis of Regulation (EU) 2016/679 (GDPR), the Polish Act of 18 July 2002 on Providing Services by Electronic Means, the Polish Act of 30 May 2014 on Consumer Rights and the Polish Civil Code.

1Data Controller

The controller of personal data processed in connection with the use of eveilo.com is ULTIMO SOLUTIO Katarzyna Bilińska, ul. Myszyniec 25, 05-255 Arciechów, NIP: 775 236 91 48, REGON: 366801676 (hereinafter: the Controller).

In all matters concerning the protection of personal data, you can contact us at the e-mail address: hello@eveilo.com.

The Controller has not appointed a Data Protection Officer (DPO), as it is not obliged to do so under Article 37 of the GDPR.

2Scope of data processed

Account data

  • first name and surname or a name provided by the User
  • e-mail address (used for logging in and communication)
  • password (stored exclusively as a cryptographic hash, bcrypt algorithm)
  • country
  • Google account identifier (only when signing in with Google)

Sign-in with Google (optional)

The Service allows optional sign-in via a Google account (provider: Google Ireland Limited). In that case the following data are obtained from Google: e-mail address, first name and surname, and the Google account identifier. Relevant information is displayed below the sign-in button.

Document content entered by the User

The content of the created documents (CVs and cover letters) is entered by the User personally. It may include, in particular: professional experience, education, skills, contact details placed in the document and any other information the User decides to include. The scope of these data depends solely on the User's decision.

Photo (image), optional

The User may voluntarily add a photo to a document. The image is processed solely for the purpose of placing it in the created document and solely on the User's initiative. The photo can be removed in the editor at any time.

Payment data (no card numbers)

In connection with a one-time purchase of Full Access, the following are processed: payment amount and date, declared country, IP address and the country of the payment card. Payment card numbers are not processed or stored by the Controller: card data are handled exclusively by the payment operator (Mollie B.V.).

One-time payment, no subscription. Full Access (PLN 39 gross for 30 days) is paid for once, with no automatic renewal. Card data are not saved, so no recurring charges are possible. After 30 days the access expires automatically, and the User's account and documents remain preserved.

Technical data and logs

  • IP address (also used to determine, on a one-off basis, the default billing country using a local DB-IP geolocation database; the IP address is not transferred to third parties for this purpose, and the user can change the country at checkout)
  • browser information (technical server logs)

Newsletter (optional)

  • e-mail address and the date of consent to receive the newsletter (voluntary checkbox during registration or in account settings)

3Purposes and legal bases of processing

Purpose of processing Legal basis Scope of data
Provision of the service: registration and maintenance of the account, document editor, PDF export Article 6(1)(b) GDPR (performance of a contract) Account data, document content, photo (if added)
Sending the newsletter: information about new features and tips on application documents Article 6(1)(a) GDPR (consent); consent can be withdrawn at any time in the account settings, without affecting the lawfulness of processing carried out before the withdrawal E-mail address, date of consent; data processed until the consent is withdrawn
Performance of AI features (CV import from files, document review, translations, AI-assisted cover letters) Article 6(1)(b) GDPR (performance of a contract) Document content transmitted to the feature at the User's request
Handling payments and keeping accounting records Article 6(1)(c) GDPR (legal obligation, tax and accounting regulations) Payment data (amount, date, declared country, IP address, card country)
Ensuring the security of the Service and keeping technical logs Article 6(1)(f) GDPR (legitimate interest) IP address, browser information
Handling requests and correspondence (including complaints) Article 6(1)(f) GDPR (legitimate interest) E-mail address, content of the request
Establishing, pursuing or defending legal claims Article 6(1)(f) GDPR (legitimate interest) Account data, payment data, correspondence

4Data retention periods

Data category Retention period
Account data and document content (including the photo) Until the account is deleted by the User (on their own, in the account settings, at any time). Expiry of Full Access does not result in deletion of the account or the documents.
Accounting data (payment records) 5 years, in accordance with tax and accounting regulations
Technical logs Up to 12 months
Backups Up to 30 days (backups made daily, overwritten on a rotating basis)

After the account is deleted, the User's data are permanently erased, with the exception of accounting data (5 years) and technical logs (up to 12 months). Data may remain in backups for up to 30 days after deletion, after which they are overwritten.

5Data recipients

Personal data may be transferred to the following categories of data recipients:

Entity Role Country
Hetzner Online GmbH
Industriestr. 25, 91710 Gunzenhausen, Germany
Application hosting and data storage (server in a data centre in Helsinki) Germany, server: Finland (EU)
Mollie B.V.
Keizersgracht 313, 1016 EE Amsterdam, Netherlands
Payment operator (BLIK, Przelewy24, payment card); card data held exclusively by the operator Netherlands (EU)
Anthropic PBC Performance of AI features (generation, translation, document review) via API USA (details in sections 6 and 7)
Google Ireland Limited Optional sign-in via a Google account Ireland (EU)
E-mail provider
Polish e-mail hosting provider
Handling the domain's e-mail (servers in Poland) Poland (EU)
Accounting office Accounting services for sales records Poland (EU)
Authorised public authorities Disclosure of data solely on the basis of and within the limits of the law Poland (EU)

Personal data are not sold or shared with third parties for marketing purposes.

6Transfers of data outside the EEA

As a rule, personal data are processed within the European Union (the application servers are located in Finland, e-mail in Poland, payments in the Netherlands).

The only transfer of data outside the European Economic Area concerns the performance of AI features: document content is sent to the Anthropic API (Anthropic PBC, USA) solely for the purpose of performing the function requested by the User (generation, translation, document review).

The transfer is based on: the European Commission's decision on the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses (SCC). Under the commercial terms of the Anthropic API, the transmitted data are not used to train models.

7AI features and data

The Service offers features supported by artificial intelligence: CV import from files, AI document review, document translations into 5 languages (Polish, English, German, French, Spanish) and AI-assisted creation of cover letters.

Document content is sent to the Anthropic API only at the moment the User uses a given feature and only to the extent necessary for its performance (data minimisation principle). Merely storing and editing documents in the Service does not involve transmitting their content to the API.

Data are not used to train models. Under the commercial terms of the Anthropic API, content transmitted as part of the AI features is not used to train artificial intelligence models.

8User rights

Under the GDPR, the User has the following rights with respect to their personal data:

  • Right of access (Article 15 GDPR): obtaining information about the data being processed and a copy of them.
  • Right to rectification (Article 16 GDPR): requesting the correction of inaccurate data or the completion of incomplete data.
  • Right to erasure (Article 17 GDPR): requesting the erasure of data when they are no longer necessary for the purposes for which they were collected.
  • Right to restriction of processing (Article 18 GDPR): requesting the restriction of processing in the cases specified by law.
  • Right to data portability (Article 20 GDPR): receiving the data in a structured, commonly used format.
  • Right to object (Article 21 GDPR): objecting to processing based on legitimate interest.
  • Right to withdraw consent: to the extent that processing is based on consent, it may be withdrawn at any time, without affecting the lawfulness of processing carried out before its withdrawal.
Self-service account deletion. The account can be permanently deleted by the User, at any time, in the account settings. Deleting the account means permanent erasure of data and documents, with the exception of accounting data (retained for 5 years) and technical logs (up to 12 months).
How to exercise your rights? Simply send an e-mail to hello@eveilo.com describing your request. A response will be provided without undue delay, no later than within 30 days of receiving the request.

The User also has the right to lodge a complaint with the supervisory authority: the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw (uodo.gov.pl), if in the User's opinion the processing of data infringes the provisions of the GDPR.

9Cookies

The eveilo.com Service uses only essential cookies, necessary for the proper functioning of the application:

  • Session cookie: maintains the User's logged-in session; deleted upon logout or session expiry.
  • CSRF cookie: protects against Cross-Site Request Forgery attacks; required by the application framework.

In addition, interface preferences (for example, editor settings) are stored locally in the User's browser, using the localStorage mechanism, and are not sent to the server for analytical purposes.

No analytics and no marketing. The Service does not use analytical or marketing cookies. For this reason no cookie consent banner is displayed: only essential cookies are used, which do not require consent.

Disabling cookies in the browser may make it impossible to log in to the Service and use the account.

10Data security

The Controller applies the following technical and organisational measures to protect personal data:

  • encryption of data transmission using the TLS protocol (HTTPS)
  • storing passwords exclusively as a cryptographic hash (bcrypt algorithm)
  • access control: each User has access exclusively to their own data and documents
  • daily backups with retention of up to 30 days
  • storing data on servers located within the European Union (Finland)
  • software updates and remediation of security vulnerabilities

In the event of a personal data breach that may result in a risk to the rights or freedoms of natural persons, the Controller will notify the President of the Personal Data Protection Office (PUODO) within 72 hours of becoming aware of it, and in the cases provided for by law will also notify the data subjects.

11Changes to this Privacy Policy

The Controller reserves the right to amend this Policy in the event of:

  • changes to the law concerning the protection of personal data
  • a significant change in the scope of the services provided or the technologies used
  • the need to comply with guidelines issued by supervisory authorities

Users holding an account will be informed of significant changes by e-mail at least 14 days before the changes take effect. The message will contain a summary of the changes, the date the new version takes effect and a link to the full text of the new Policy.

The current version of the Policy is always available at https://eveilo.com/polityka-prywatnosci. As subsequent versions are published, the Controller will maintain a version archive, making it possible to review the wording of the Policy in force in the past.

12Contact

In matters concerning the protection of personal data, the exercise of rights under the GDPR and complaints, please contact:

ULTIMO SOLUTIO Katarzyna Bilińska ul. Myszyniec 25, 05-255 Arciechów
E-mail: hello@eveilo.com

Responses to messages are provided within 30 days of receipt. Complaints are handled within 14 days.

Consumers have the option of using out-of-court (amicable) methods of handling complaints and pursuing claims, including the EU online dispute resolution (ODR) platform, available at ec.europa.eu/consumers/odr. The Controller declares its willingness to resolve disputes with Users amicably.

+Change history

Version Effective date Scope of changes
1.0 24 August 2026 Initial version of the eveilo.com Privacy Policy.