Privacy Policy of eveilo.com
NIP: 775 236 91 48 · REGON: 366801676
E-mail for data protection matters: hello@eveilo.com
This Privacy Policy describes the rules for processing personal data on eveilo.com, an online CV and cover letter builder with artificial intelligence features (CV import from files, AI document review, document translations, AI-assisted cover letters). This document has been drawn up on the basis of Regulation (EU) 2016/679 (GDPR), the Polish Act of 18 July 2002 on Providing Services by Electronic Means, the Polish Act of 30 May 2014 on Consumer Rights and the Polish Civil Code.
1Data Controller
The controller of personal data processed in connection with the use of eveilo.com is ULTIMO SOLUTIO Katarzyna Bilińska, ul. Myszyniec 25, 05-255 Arciechów, NIP: 775 236 91 48, REGON: 366801676 (hereinafter: the Controller).
In all matters concerning the protection of personal data, you can contact us at the e-mail address: hello@eveilo.com.
The Controller has not appointed a Data Protection Officer (DPO), as it is not obliged to do so under Article 37 of the GDPR.
2Scope of data processed
Account data
- first name and surname or a name provided by the User
- e-mail address (used for logging in and communication)
- password (stored exclusively as a cryptographic hash, bcrypt algorithm)
- country
- Google account identifier (only when signing in with Google)
Sign-in with Google (optional)
The Service allows optional sign-in via a Google account (provider: Google Ireland Limited). In that case the following data are obtained from Google: e-mail address, first name and surname, and the Google account identifier. Relevant information is displayed below the sign-in button.
Document content entered by the User
The content of the created documents (CVs and cover letters) is entered by the User personally. It may include, in particular: professional experience, education, skills, contact details placed in the document and any other information the User decides to include. The scope of these data depends solely on the User's decision.
Photo (image), optional
The User may voluntarily add a photo to a document. The image is processed solely for the purpose of placing it in the created document and solely on the User's initiative. The photo can be removed in the editor at any time.
Payment data (no card numbers)
In connection with a one-time purchase of Full Access, the following are processed: payment amount and date, declared country, IP address and the country of the payment card. Payment card numbers are not processed or stored by the Controller: card data are handled exclusively by the payment operator (Mollie B.V.).
Technical data and logs
- IP address (also used to determine, on a one-off basis, the default billing country using a local DB-IP geolocation database; the IP address is not transferred to third parties for this purpose, and the user can change the country at checkout)
- browser information (technical server logs)
Newsletter (optional)
- e-mail address and the date of consent to receive the newsletter (voluntary checkbox during registration or in account settings)
3Purposes and legal bases of processing
| Purpose of processing | Legal basis | Scope of data |
|---|---|---|
| Provision of the service: registration and maintenance of the account, document editor, PDF export | Article 6(1)(b) GDPR (performance of a contract) | Account data, document content, photo (if added) |
| Sending the newsletter: information about new features and tips on application documents | Article 6(1)(a) GDPR (consent); consent can be withdrawn at any time in the account settings, without affecting the lawfulness of processing carried out before the withdrawal | E-mail address, date of consent; data processed until the consent is withdrawn |
| Performance of AI features (CV import from files, document review, translations, AI-assisted cover letters) | Article 6(1)(b) GDPR (performance of a contract) | Document content transmitted to the feature at the User's request |
| Handling payments and keeping accounting records | Article 6(1)(c) GDPR (legal obligation, tax and accounting regulations) | Payment data (amount, date, declared country, IP address, card country) |
| Ensuring the security of the Service and keeping technical logs | Article 6(1)(f) GDPR (legitimate interest) | IP address, browser information |
| Handling requests and correspondence (including complaints) | Article 6(1)(f) GDPR (legitimate interest) | E-mail address, content of the request |
| Establishing, pursuing or defending legal claims | Article 6(1)(f) GDPR (legitimate interest) | Account data, payment data, correspondence |
4Data retention periods
| Data category | Retention period |
|---|---|
| Account data and document content (including the photo) | Until the account is deleted by the User (on their own, in the account settings, at any time). Expiry of Full Access does not result in deletion of the account or the documents. |
| Accounting data (payment records) | 5 years, in accordance with tax and accounting regulations |
| Technical logs | Up to 12 months |
| Backups | Up to 30 days (backups made daily, overwritten on a rotating basis) |
After the account is deleted, the User's data are permanently erased, with the exception of accounting data (5 years) and technical logs (up to 12 months). Data may remain in backups for up to 30 days after deletion, after which they are overwritten.
5Data recipients
Personal data may be transferred to the following categories of data recipients:
| Entity | Role | Country |
|---|---|---|
|
Hetzner Online GmbH Industriestr. 25, 91710 Gunzenhausen, Germany |
Application hosting and data storage (server in a data centre in Helsinki) | Germany, server: Finland (EU) |
|
Mollie B.V. Keizersgracht 313, 1016 EE Amsterdam, Netherlands |
Payment operator (BLIK, Przelewy24, payment card); card data held exclusively by the operator | Netherlands (EU) |
| Anthropic PBC | Performance of AI features (generation, translation, document review) via API | USA (details in sections 6 and 7) |
| Google Ireland Limited | Optional sign-in via a Google account | Ireland (EU) |
| E-mail provider Polish e-mail hosting provider |
Handling the domain's e-mail (servers in Poland) | Poland (EU) |
| Accounting office | Accounting services for sales records | Poland (EU) |
| Authorised public authorities | Disclosure of data solely on the basis of and within the limits of the law | Poland (EU) |
Personal data are not sold or shared with third parties for marketing purposes.
6Transfers of data outside the EEA
As a rule, personal data are processed within the European Union (the application servers are located in Finland, e-mail in Poland, payments in the Netherlands).
The only transfer of data outside the European Economic Area concerns the performance of AI features: document content is sent to the Anthropic API (Anthropic PBC, USA) solely for the purpose of performing the function requested by the User (generation, translation, document review).
The transfer is based on: the European Commission's decision on the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses (SCC). Under the commercial terms of the Anthropic API, the transmitted data are not used to train models.
7AI features and data
The Service offers features supported by artificial intelligence: CV import from files, AI document review, document translations into 5 languages (Polish, English, German, French, Spanish) and AI-assisted creation of cover letters.
Document content is sent to the Anthropic API only at the moment the User uses a given feature and only to the extent necessary for its performance (data minimisation principle). Merely storing and editing documents in the Service does not involve transmitting their content to the API.
8User rights
Under the GDPR, the User has the following rights with respect to their personal data:
- Right of access (Article 15 GDPR): obtaining information about the data being processed and a copy of them.
- Right to rectification (Article 16 GDPR): requesting the correction of inaccurate data or the completion of incomplete data.
- Right to erasure (Article 17 GDPR): requesting the erasure of data when they are no longer necessary for the purposes for which they were collected.
- Right to restriction of processing (Article 18 GDPR): requesting the restriction of processing in the cases specified by law.
- Right to data portability (Article 20 GDPR): receiving the data in a structured, commonly used format.
- Right to object (Article 21 GDPR): objecting to processing based on legitimate interest.
- Right to withdraw consent: to the extent that processing is based on consent, it may be withdrawn at any time, without affecting the lawfulness of processing carried out before its withdrawal.
The User also has the right to lodge a complaint with the supervisory authority: the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw (uodo.gov.pl), if in the User's opinion the processing of data infringes the provisions of the GDPR.
9Cookies
The eveilo.com Service uses only essential cookies, necessary for the proper functioning of the application:
- Session cookie: maintains the User's logged-in session; deleted upon logout or session expiry.
- CSRF cookie: protects against Cross-Site Request Forgery attacks; required by the application framework.
In addition, interface preferences (for example, editor settings) are stored locally in the User's browser, using the localStorage mechanism, and are not sent to the server for analytical purposes.
Disabling cookies in the browser may make it impossible to log in to the Service and use the account.
10Data security
The Controller applies the following technical and organisational measures to protect personal data:
- encryption of data transmission using the TLS protocol (HTTPS)
- storing passwords exclusively as a cryptographic hash (bcrypt algorithm)
- access control: each User has access exclusively to their own data and documents
- daily backups with retention of up to 30 days
- storing data on servers located within the European Union (Finland)
- software updates and remediation of security vulnerabilities
In the event of a personal data breach that may result in a risk to the rights or freedoms of natural persons, the Controller will notify the President of the Personal Data Protection Office (PUODO) within 72 hours of becoming aware of it, and in the cases provided for by law will also notify the data subjects.
11Changes to this Privacy Policy
The Controller reserves the right to amend this Policy in the event of:
- changes to the law concerning the protection of personal data
- a significant change in the scope of the services provided or the technologies used
- the need to comply with guidelines issued by supervisory authorities
Users holding an account will be informed of significant changes by e-mail at least 14 days before the changes take effect. The message will contain a summary of the changes, the date the new version takes effect and a link to the full text of the new Policy.
The current version of the Policy is always available at https://eveilo.com/polityka-prywatnosci. As subsequent versions are published, the Controller will maintain a version archive, making it possible to review the wording of the Policy in force in the past.
12Contact
In matters concerning the protection of personal data, the exercise of rights under the GDPR and complaints, please contact:
E-mail: hello@eveilo.com
Responses to messages are provided within 30 days of receipt. Complaints are handled within 14 days.
Consumers have the option of using out-of-court (amicable) methods of handling complaints and pursuing claims, including the EU online dispute resolution (ODR) platform, available at ec.europa.eu/consumers/odr. The Controller declares its willingness to resolve disputes with Users amicably.
+Change history
| Version | Effective date | Scope of changes |
|---|---|---|
| 1.0 | 24 August 2026 | Initial version of the eveilo.com Privacy Policy. |