Privacy Policy
Effective Date: March 2026 · Last updated: April 2026
At Resumelyn, accessible at resumelyn.com, your privacy is a core priority. This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights as a data subject under the General Data Protection Regulation (GDPR).
1. Data Controller
The data controller responsible for your personal data is Resumelyn, operated by an independent developer based in the Netherlands. Contact: hello@resumelyn.com
As a company based in the Netherlands and operating within the European Union, Resumelyn fully complies with the GDPR (Regulation (EU) 2016/679). Resumelyn is the Data Controller as defined under GDPR Art. 4(7).
2. Information We Collect
When you register or use Resumelyn, we may collect the following categories of data:
- Account data: email address, name, authentication method (email/password or Google OAuth).
- Professional data: CV content, work history, education, skills provided via uploads or our CV builder.
- Profile data: display name, professional bio, public profile information, and any profile photo you upload.
- Usage data: credit balance, optimization history, session data for security and fraud prevention.
- Billing data: transaction references provided by DodoPayments. We do not store payment card data.
- Job Applicant data: CV/Resume files, cover letters, and contact information submitted via the "Work With Us" portal for recruitment purposes.
3. Legal Basis for Processing (GDPR Art. 6)
We process your personal data under the following legal bases:
Contract Performance (Art. 6(1)(b))
Account creation and management, CV optimization, cover letter generation, user authentication, and transactional emails (e.g. password reset, account confirmation). This is the primary legal basis for the operation of the Resumelyn service.
Explicit Consent (Art. 6(1)(a))
Inclusion in the Exclusive Talent Pool. This is always opt-in and separate from the main service. You may withdraw this consent at any time without affecting your main account.
Legitimate Interest (Art. 6(1)(f))
Aggregate, anonymized site analytics to understand how users interact with the platform, improve features, and prevent abuse.
4. Exclusive Talent Pool
If you explicitly check the “Add me to the Exclusive Talent Pool” box during sign-up or in your profile settings, you grant Resumelyn permission to share your optimized CV and professional profile with our network of vetted hiring partners and recruiters.
- Scope: Talent Pool profiles may be shared with recruiters globally, with a primary focus on EU-based hiring partners. Where profiles are shared with non-EU recruiters, appropriate safeguards (Standard Contractual Clauses) are in place.
- Retention: Your Talent Pool data is retained until you request removal. It is not automatically deleted when your account is closed unless you request it separately.
- Opt-out: You may request removal from the Talent Pool at any time by emailing hello@resumelyn.com. Removal from the Talent Pool does not affect your Resumelyn account or any other service features.
5. Data Retention Policy
| Data Type | Retention Period |
|---|---|
| Account data | While the account is active; deleted within 30 days of a deletion request. |
| CVs uploaded and optimized | While the account is active. |
| Job applicant data ("Work With Us") | Maximum 12 months from the date of submission, unless requested otherwise. |
| Talent Pool profile | Until you request removal via hello@resumelyn.com. |
| Email and activity logs | Maximum 12 months. |
6. Sub-processors and Third Parties
We use the following third-party providers that process personal data on our behalf. Each is contractually bound to handle data securely and in compliance with GDPR:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, authentication and file storage | Account data, CVs, profile data (Row Level Security enforced) |
| Resend | Transactional emails (password reset, account confirmations) | Email address only |
| DodoPayments | Payment processing | Billing data only. No CV or account content is shared. |
| MercadoPago | Payment processing for Argentine users | Billing data only. No CV or account content is shared. |
| OpenAI | AI CV optimization and cover letter generation | CV content and job description submitted for optimization (not stored by OpenAI per API terms) |
7. Data Transfers Outside the EEA
Some of our sub-processors (including Supabase, Resend, and DodoPayments) may store or process data outside the European Economic Area (EEA). Where this occurs, such transfers are carried out under Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring that your data receives an adequate level of protection equivalent to that guaranteed within the EEA.
8. Security
We implement strict security measures to protect your personal data, including database-level Row Level Security (RLS) via Supabase, ensuring that users can only access their own data. Passwords are cryptographically hashed and are never readable by our team. All data is transmitted over encrypted HTTPS connections.
9. Cookies and Tracking
Resumelyn uses the following types of cookies:
- Session cookies: Strictly necessary for authentication. These are set by Supabase to maintain your logged-in session and expire when you close your browser or log out.
- Functional cookies: Used to remember temporary user preferences (e.g. referral tracking for the duration of a session).
We do not use third-party advertising cookies, retargeting pixels, or cross-site tracking technologies. No cookie consent banner is required for strictly necessary cookies under the ePrivacy Directive. If analytics cookies are introduced in the future, explicit consent will be requested before they are activated.
10. Your Rights under GDPR
As a data subject, you have the following rights. To exercise any of them, email us at hello@resumelyn.com. We will respond within 30 days.
- Right to access: Request a copy of all personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request complete deletion of your account and all associated data.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interest.
- Right to withdraw consent: Withdraw consent for Talent Pool participation at any time, without affecting your access to the main service.
11. Right to Lodge a Complaint
If you believe your data is being processed in violation of GDPR, you have the right to lodge a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens
12. Legal Basis and Consent
The primary legal basis for processing your data at Resumelyn is contract performance (GDPR Art. 6(1)(b)). We process only the data that is necessary to deliver the service you signed up for. We do not rely on generalized consent as a basis for standard account and service-related data processing.
Consent is reserved specifically for:
- Inclusion in the Exclusive Talent Pool, which is always explicit, opt-in, and separate.
- Any analytics cookies beyond strictly necessary session cookies.
By using Resumelyn, you acknowledge that you have read and understood this Privacy Policy. This does not substitute the explicit, separate consent required for the Talent Pool or optional cookies.
13. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy at any time. For material changes that significantly affect how your data is processed, we will notify you by email at least 14 days before the change takes effect. Your continued use of Resumelyn after receiving such notification constitutes your acceptance of the updated policy.
14. Contact
For any privacy-related questions or to exercise your rights, contact us at: hello@resumelyn.com
