CVGenerator

GDPR Compliance

Last updated: April 17, 2026

CV Generator is committed to full compliance with the General Data Protection Regulation (EU) 2016/679.

Data controller

CV Generator Ltd

Email: privacy@cvgenerator.io

Lawful basis for processing

  • Contract: processing your account and CV data is necessary to provide the service you've signed up for.
  • Legitimate interests: anonymized usage analytics to improve the product.
  • Consent: marketing emails, if you opt in.

Your rights under GDPR

Right of access

You can request a copy of all personal data we hold about you.

Right to rectification

You can correct inaccurate data at any time via your account settings.

Right to erasure

You can delete your account and all associated data from your account settings. All data is permanently deleted within 30 days.

Right to restrict processing

You can ask us to stop processing your data while a dispute is resolved.

Right to data portability

You can export your CV content at any time in PDF or JSON format.

Right to object

You can object to processing based on legitimate interests at any time.

Right to withdraw consent

If we process your data based on consent (e.g., marketing emails), you can withdraw consent at any time via the unsubscribe link in any email.

To exercise any right, email: privacy@cvgenerator.io. We will respond within 30 days.

Data transfers

Your data is stored and processed in the EU. Our infrastructure providers (Supabase, Vercel) maintain EU data residency options, which we use for all user data.

Supervisory authority

If you believe we are processing your data unlawfully, you have the right to lodge a complaint with your local data protection authority. In Austria: Datenschutzbehörde (dsb.gv.at).

Data retention

  • Active accounts: data retained for the duration of the account.
  • Deleted accounts: all personal data permanently deleted within 30 days of account deletion.
  • Server logs: retained for 90 days for security purposes, then deleted.

Data breach notification

In the event of a personal data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay.