Privacy Policy
Last updated: 2026-07-03
This policy describes how Progressa processes users' personal data under Regulation (EU) 2016/679 (GDPR). To exercise your rights or for any question, contact: [privacy contact to be added before publication].
1. Data controller
The data controller is Progressa. Full details (legal name, address, VAT) will be listed here. For privacy matters: [privacy contact to be added before publication].
2. Data we process
Account data: name, email, password (hashed). Content you upload or generate: CV, applications, notes, tasks, STAR stories, questions, AI prompts and outputs, readiness score. Technical data: logs, IP address, session data, timestamps.
Please do not enter special-category data (Art. 9 GDPR) — e.g. health, union membership, religion, political opinions — or unnecessary third-party data, unless strictly necessary.
3. Purposes and legal bases
Providing the service (account, tracker, story bank, AI features): performance of the contract (Art. 6.1.b). Security, abuse prevention and technical logs: legitimate interest (Art. 6.1.f). Analytics cookies: consent (Art. 6.1.a). Marketing: separate, revocable consent.
We do not use your content (CV, stories, prompts) to train AI models without your separate, explicit consent.
4. Providers and processors
We rely on providers acting as processors or independent controllers: Google (Gemini AI), Vercel (hosting and file storage), Neon (database), Upstash (rate limiting), PostHog (analytics, only with consent), Jina and Clearbit/DiceBear (enrichment/images). An up-to-date sub-processor list is available on request.
5. International transfers
Some providers may process data outside the European Economic Area (e.g. the USA). In such cases we rely on appropriate safeguards under Arts. 44-49 GDPR (e.g. Standard Contractual Clauses and/or Data Privacy Framework). TODO(legal): confirm per provider.
6. Retention
We keep data for as long as needed to provide the service and while your account exists. On account deletion, data is deleted or anonymized within defined periods, subject to legal obligations. TODO(legal): define exact periods for inactive accounts, logs and backups.
7. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability (Arts. 15-22 GDPR). You can export or delete your data from profile settings, or via the contact above ([privacy contact to be added before publication]). You also have the right to lodge a complaint with your data protection authority.
8. Security
We apply appropriate technical and organizational measures (password hashing, HTTPS, access control, rate limiting, encryption in transit). In case of a data breach posing a risk to your rights, we will make the notifications required by Arts. 33-34 GDPR.