Privacy Policy
This document is a working draft. It has not been reviewed by a qualified GDPR and AI-law attorney. It will be published in final form before Astaris opens to the public. If you have questions before that date, write to [email protected].
What Astaris does with your data
Astaris is a career intelligence platform for European professionals. You upload your CV, answer a short Q&A, and our AI builds a structured profile that helps you understand where your career can go and which companies match your ambitions.
We process your data to deliver this service. We do not sell your data. We do not use your data for advertising. OCEAN personality scores — if you choose to complete them — are for your personal insight only and are never shared with companies.
Data we collect
Your CV file and the structured information extracted from it (work experience, education, skills, languages). Your career preferences and goals, as you share them during onboarding. Optional: a personality self-assessment (OCEAN model, 5 dimensions) — only if you explicitly consent.
We also collect standard technical data: session tokens, IP address (for security), and anonymised usage events to improve the product.
Who we share data with
Companies using Astaris to find candidates see a partial profile (first name, experience, skills, a compatibility score). They only receive your full contact details after you explicitly accept their interview invitation.
We use Supabase (database and storage), Google Gemini (AI processing), and Cloudflare (hosting). All operate as data processors under GDPR Art. 28 agreements. Data is processed in or transferred to the EU/US under Standard Contractual Clauses.
Your rights
You have the right to access, correct, delete, and export your data. You can withdraw your personality (OCEAN) consent at any time without affecting your account. To exercise any right, write to [email protected]. We respond within 30 days.
You can also file a complaint with your national data protection authority — in Italy: Garante per la Protezione dei Dati Personali.
Data retention
Your CV file is deleted after 12 months of inactivity. Your profile is kept until you delete your account, plus 30 days for operational backups. OCEAN scores are deleted within 72 hours of consent withdrawal. Job match history is anonymised after 24 months.