Privacy Policy
Effective Date:
19 June 2026
Controller: Uptomic SRL, a Belgian private limited liability company (SRL), Rue Belliard 40, 1040 Brussels, Belgium
Contact: [email protected]
1. Overview
This Privacy Policy explains how Uptomic SRL ("Uptomic", "we", or "us") collects, uses, and protects your information when you sign up for, access, or use Uptomic.
This policy is intended to explain our privacy practices under the EU General Data Protection Regulation (GDPR), the Belgian Data Protection Act, and other data-protection requirements that may apply to our service.
Controller and privacy contacts
Uptomic is operated by Uptomic SRL, a Belgian private limited liability company (SRL). Privacy questions, data-rights requests, and data-protection correspondence should be sent to [email protected].
Uptomic has not appointed a Data Protection Officer at this time. Uptomic SRL is established in the European Union, so an EU representative under Article 27 GDPR is not required. If our legal obligations change, we will update this policy accordingly.
2. Data We Collect
We collect the following categories of information:
Account and contact data
- Name, email address, and optional professional details when signing up or using the service.
- Account credentials and preferences.
- Uptomic requires an account to sign up, log in, or use saved features.
Uploaded content and career data
- CVs, documents, feedback reports, and information you voluntarily upload to your Career Vault.
- Career goals, job preferences, and AI interaction history.
- Job descriptions or text you submit for task-level analysis.
This content is processed to generate the requested analysis and may be stored, depending on your preferences. Please avoid uploading sensitive personal information unless it is directly relevant to the service you request.
Technical and usage data
- Device type, IP address, browser type, and product usage patterns.
- Application logs, AI trace metadata, and session activity for debugging, security, and reliability.
Communication data
- Feedback, survey responses, or session recordings, only with your consent.
- Support or contact messages.
3. How We Use Your Data
We process data to:
- Provide and improve the service and personalized AI outputs.
- Manage account access, early access, and user communications.
- Analyze aggregated or pseudonymized usage data to enhance application performance.
- Notify users of major updates, future releases, or public launch opportunities.
- Ensure security, compliance, and platform integrity.
We do not sell your personal data or share it with third parties for cross-context behavioral advertising.
4. AI Use of Your Data
Our AI systems use your uploaded data solely to provide personalized insights, job recommendations, and related services.
We integrate the principles of our AI Use Statement:
- Data is encrypted at rest and in transit.
- Your Career Vault is private and user-owned.
- Data is not used to train third-party AI models.
- AI access is limited to retrieval and contextual processing to serve you directly.
- You may review, edit, export, or delete your data at any time.
Job descriptions you submit are used only to generate the analysis you request. They are processed securely through our application infrastructure. We do not use these inputs to train any AI models.
Uptomic provides recommendations and generated materials to support your own career decisions. We do not use AI outputs to make solely automated decisions about you that produce legal or similarly significant effects.
Uptomic performs profiling to generate recommendations, match opportunities, estimate salary ranges, score fit, rank jobs or career paths, and personalize career guidance. These activities are intended to support your own review and do not produce legal or similarly significant effects without human review.
Salary estimates are informational only and are not guarantees of future earnings. Job recommendations are based on available data and may not reflect every opportunity in the market. Uptomic provides informational career guidance and does not provide legal, financial, employment, immigration, or professional-licensing advice.
We maintain internal governance, vendor review, logging, human oversight, and privacy controls intended to support compliance with applicable AI, privacy, and consumer-protection requirements. These controls are reviewed as our AI features, vendors, and legal obligations evolve.
5. Legal Bases for Processing (GDPR)
We rely on the following legal bases:
- Consent for early access, analytics, or communications.
- Performance of a contract to create accounts and deliver the service you request.
- Legitimate interest to maintain security, debug issues, and improve platform functionality.
- Legal obligation where required by law.
6. Data Retention
We retain personal data only as long as needed for the purposes described in this policy, unless a longer period is required for security, fraud prevention, dispute resolution, tax, accounting, or legal compliance.
| Data category | Typical retention period |
|---|---|
| Account and profile data | Until account deletion, plus up to 90 days to complete deletion from active systems. |
| Career Vault content and uploaded documents | Until you delete the content or your account, unless retained longer at your direction. |
| Job descriptions and task-level inputs | Temporarily for the requested analysis, unless you save, export, or attach them to your account. |
| AI interaction logs and trace metadata | Up to 30 days for debugging, quality, abuse prevention, and reliability, unless saved by you. |
| Security, audit, and application logs | Up to 12 months where needed for security, fraud prevention, and service integrity. |
| Support tickets, feedback, and communications | Up to 24 months after the last interaction, unless a longer period is needed for dispute handling. |
| Billing, tax, and legal records | Up to 7 years, or longer if required by applicable law. |
| Backups | Deleted or overwritten on routine backup cycles, typically within 90 days. |
If an access program ends and you do not continue using the application, we will notify you before deletion or transition where required.
7. Data Sharing and Processors
We use trusted third-party providers and infrastructure vendors to operate Uptomic, deliver account access, process AI requests, send transactional emails, analyze product usage, and maintain platform security. These providers process personal data only as needed to provide services to Uptomic and are subject to data-processing terms, transfer safeguards, or equivalent contractual protections where required by law.
Uptomic consumes job-market data from external job-search and market-data sources, but we do not send your CV, profile, account data, or uploaded career content to those job-search data sources for their own processing.
Uptomic subprocessors
| Category | Provider | Purpose | Location |
|---|---|---|---|
| Cloud hosting / platform | Railway | Application hosting, PostgreSQL database, Redis, and internal object storage / MinIO. | EU primary hosting; Railway operations may involve US transfers under DPA/SCCs. |
| DNS / edge / hosting | Cloudflare | DNS, edge routing, security, Cloudflare Pages static-site hosting, and hosted public-site assets. | Global network; transfers covered by Cloudflare DPA/SCCs. |
| Authentication and account management | Clerk | User sign-up, login, sessions, account metadata, and identity management. | US, with DPF/SCC transfer safeguards. |
| AI processing | OpenRouter and approved routed model providers, which may include OpenAI, Anthropic, Google, Meta, Mistral, and other providers available through OpenRouter. | Resume parsing, career-path generation, job/profile matching, document generation, and other AI responses. | US / international, with SCCs where applicable. |
| AI/web research | Perplexity | Market, salary, company, and career research where live web grounding is used. | US / international. |
| Location services | Mapbox | Location autocomplete, geocoding, commute, and distance calculations. | US / international, with DPA/SCCs. |
| Email delivery | Resend | Transactional and system email delivery. | US, with DPA/SCCs. |
| Source control / deployment operations | GitHub | Code hosting, CI/CD, and deployment workflow metadata. | US / international. |
Clerk acts as Uptomic's subprocessor for authentication under GDPR Article 28. All authentication data is encrypted, stored securely, and subject to Clerk's Data Processing Addendum and Standard Contractual Clauses.
Uptomic may use self-hosted analytics, observability, and error-reporting software inside its controlled hosting environment. Those tools support product analytics, operational debugging, AI trace auditing, and reliability; they are not separate third-party subprocessors unless Uptomic uses an externally hosted version of the service.
Data transfers outside the EU rely on applicable safeguards, including DPAs, DPF participation, and Standard Contractual Clauses where required.
Uptomic maintains an internal list of approved AI providers and reviews provider use as features change. We will update this policy or a dedicated subprocessor page if our AI subprocessors materially change.
8. Your Rights
Under GDPR, you have the right to:
- Access and obtain a copy of your data.
- Request correction or deletion.
- Withdraw consent at any time.
- Object to processing or request restriction.
- Data portability, receiving your data in a structured format.
To exercise these rights, contact [email protected].
You may also lodge a complaint with your local data-protection supervisory authority. We may need to verify your identity before completing access, deletion, correction, or portability requests.
9. US State Privacy Rights
Depending on where you live, including if you are a California resident, you may have rights to know what personal information we collect, access or delete personal information, correct inaccurate information, receive a portable copy of certain information, opt out of sale or sharing for cross-context behavioral advertising, limit certain uses of sensitive personal information, and avoid discrimination for exercising privacy rights.
Uptomic does not sell personal information and does not share personal information for cross-context behavioral advertising. To exercise applicable US state privacy rights, contact [email protected]. Authorized agents may submit requests where permitted by law, subject to verification.
10. Security Measures
We apply industry-standard encryption, including AES-256 and TLS, access controls, and auditing.
Access to personal data is limited to authorized personnel.
No system is entirely risk-free, but we continuously monitor and improve our security posture.
Clerk manages authentication and session tokens for Uptomic. Clerk uses encryption, salted hashing, and session-token management to protect login credentials. Uptomic does not store your raw passwords or authentication secrets.
Railway provides the primary hosted application environment, database, cache, and internal object storage. Cloudflare provides public-site hosting, edge routing, DNS, and security controls. Self-hosted observability tools are used to monitor reliability, debug errors, and audit AI model calls.
If a security incident affects your personal information, we will notify affected users and regulators where required by applicable law.
11. International Transfers
Uptomic primarily hosts production application data in the EU. Some subprocessors operate global infrastructure or may process data in the US or other countries, including Clerk, Cloudflare, OpenRouter and routed model providers, Perplexity, Mapbox, Resend, and GitHub. Where required, we rely on European Commission Standard Contractual Clauses, Data Processing Agreements, DPF participation, and additional safeguards to protect your data.
12. Children's Data
The service is not intended for children under 16.
We do not knowingly collect children's data.
If such data is found, it will be deleted promptly.
13. Changes to This Policy
We may update this policy to reflect service or legal changes.
If updates are material, we will notify you by email or in-app notice before they take effect.
14. Contact
For any data-protection questions or GDPR requests:
Email: [email protected]
Address: Uptomic SRL, Rue Belliard 40, 1040 Brussels, Belgium
Supervisory authority: the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit)