Privacy Policy

Last updated: 5 June 2026

This Privacy Policy explains how Polynomial OÜ, a company registered in Estonia (registry code on request), operating the CareerPlan brand at careerplan.io ("CareerPlan", "we", "us"), collects and processes your personal data. We are the data controller under the EU General Data Protection Regulation (GDPR). For any privacy question or to exercise your rights, contact support@careerplan.io.

1. Data we collect

2. How we use your data and our legal bases

PurposeLegal basis (GDPR Art. 6)
Provide the service: match jobs to your CV, score and rank them, track applicationsPerformance of a contract
Auto-apply on your behalf (only roles you approve)Consent / contract
Notifications via email or TelegramConsent / legitimate interest
Security, fraud prevention, service improvementLegitimate interest
Billing and taxLegal obligation / contract

3. AI processing is in-house

Matching, scoring, and document generation are performed on our own infrastructure. Your CV and profile are not sent to third-party AI providers (e.g. OpenAI, Google) for these features. This keeps your data within our control.

4. Sharing and sub-processors

We share personal data only as needed to run the service:

We do not sell your personal data.

5. International transfers

We are based in the EU (Estonia) and host primarily within the EU. Where a sub-processor processes data outside the EEA, we rely on adequacy decisions or Standard Contractual Clauses.

6. Retention

We keep your account and CV data while your account is active. You may delete your CV or account at any time; we then delete or anonymise the associated personal data within a reasonable period, except where we must retain certain records (e.g. invoices) to meet legal obligations.

7. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent at any time. To exercise any right, email support@careerplan.io. You also have the right to lodge a complaint with your supervisory authority — in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon).

8. Security

We use technical and organisational measures (encryption in transit, access controls, encrypted storage of sensitive credentials) to protect your data. No system is perfectly secure; please use a strong, unique password.

9. Cookies

We use only cookies/local storage that are strictly necessary for sign-in and core functionality. We do not use advertising trackers.

10. Children

CareerPlan is for users aged 18 and over. We do not knowingly collect data from children.

11. Changes

We may update this policy; the "Last updated" date will change and, for material changes, we will notify you.

Polynomial OÜ · Estonia · operating the CareerPlan brand · support@careerplan.io