CV30

BUN VENIT 👋

Cum vrei să arate?

Alege un stil și plimbă-te prin meniu în dreapta ca să vezi diferența pe fiecare zonă.

O poți schimba oricând — apasă butonul colorat ✦ din bara de sus, lângă selectorul de limbă.

// PREVIEW LIVE · TEMA BRUTALIST · APASĂ ÎN MENIU ↓

CV30
Ce vrei să postezi?
POSTEAZĂ
CV30
Graduation Kit
CV30
Skip to content

Privacy Policy

Jump to section

Document version: 3.0

This version fully replaces version 2.4.

This policy explains what data about you CV30 uses, why, who we give it to, how long we keep it and what rights you have. It applies to the CV30 mobile app and to the cv30.app website (together, the “Platform”). The policy exists in Romanian and in English; the Romanian version is the reference version.

This policy informs you; it does not ask for your consent. At sign-up we only ask you to confirm that you have read it. Where we need your consent (for example for the newsletter), we ask for it separately, and section 12 shows you how to withdraw it.

This policy does not apply to the admin.cv30.app administration dashboard, nor to the company websites business.cv30.co and b2b.cv30.co: these are not for users of the Platform, and the data processing that takes place there is not described in this document. The older websites cv30.web and user.cv30.co are being closed.

0. IN SHORT

Who we are. CV30 WORLDWIDE GROUP SRL, based in Bucharest. We decide what data we use and why, so we are the “controller” of your data. You can write to us at contact@cv30.co.

What is public. Your name, photo, username (@), city, faculty and class, your studies (including those we filled in from Student Kit orders), experience, skills, career plan, ideal job (including the desired salary, if you fill it in), links to social networks, your gender (if you filled it in and have not hidden it) and who you follow. Anyone can see them, and your profile can appear in Google. Also public are posts and comments in the main feed, listings on the Board (Avizier), map pins (with your name and photo), contributions to “Let's Talk” (the theme of the month) and XoXo posts; posts can also appear in Google, XoXo posts excepted.

What we do not show. Your e-mail, phone number and date of birth do not appear on your profile unless you choose to show them; technically, however, other signed-in accounts can read them (section 2.2). Private messages are seen only by the people in the conversation and, in exceptional cases, by the team (section 2.5). Group posts are not private: they also appear on your public profile (section 2.4).

XoXo is not anonymous. Other users see only your pseudonym, notifications included. CV30, however, knows who wrote each post, and moderators see the author's name and e-mail (section 2.6).

Artificial intelligence. An automatic filter (OpenAI) checks the texts and photos that are published and can reject or hide content before any person sees it (section 2.14). “Let's Talk” recordings are transcribed with Google Gemini, and the draft of the monthly summary is written with Claude (Anthropic), both through OpenRouter. Skill suggestions are produced on our server: your studies and experience reach OpenAI through it, and OpenAI does not retain them.

What you see and who sees you. What appears in the feed and on the Board depends on your groups and on your university, faculty and class; on the Board, so does the order of the listings. The CV30 team and the accounts we give this right to can target posts at certain groups of students, for example freshers or graduates of a faculty; the CV30 team can also target notifications, and companies can target their jobs and promotions on the Board. We calculate your academic status automatically.

Statistics. We record how you use the Platform (which areas you open, how long you stay, which posts you see, what you search for), linked to your account. We do not show other users what you have read or what you have searched for (section 2.15). The mobile app also sends statistics to Google Firebase, without your e-mail address. We do not ask for your consent for cookies or for statistics: we put nothing on your device beyond what is strictly necessary for the Platform to work and a session identifier used to measure our own audience (section 13).

Providers. We work with providers such as Supabase, Cloudflare, Google, OpenAI and SendMachine. Some of them process data in the USA (sections 7 and 8).

Deleting your account. You delete your account in the app or on the website, and your personal data is erased by anonymisation: your name, e-mail, phone number, photos and the other details that identify you are removed, and whatever remains published no longer appears under your name and photo (section 10).

Minimum age: 16. At sign-up you declare that you are at least 16. We do not verify age; we rely on your declaration.

Your rights. You can ask for a copy of your data, or for it to be corrected, deleted, restricted or transferred, and you can complain to the ANSPDCP. Write to us at contact@cv30.co. The answer is free and usually comes within one month at most (section 11).

Your right to object
You can object at any time, on grounds relating to your particular situation, to the use of your data based on our legitimate interest, for example to content targeting, to the calculation of your academic status and to statistics. You can also object at any time to direct marketing; we then stop, without asking for reasons. Write to us at contact@cv30.co. Details in section 11.2.

1. WHO WE ARE AND HOW TO CONTACT US

The controller of your data is CV30 WORLDWIDE GROUP SRL, with its registered office in Bucharest, District 1, 26 G-ral Barbu Vlădoianu Street, attic, room 1, tax identification code 33994135, registered with the Trade Register under no. J40/588/2015 (“CV30”, “we”).

For any question or request about your data, write to us at contact@cv30.co. By post: CV30 WORLDWIDE GROUP SRL, 26 G-ral Barbu Vlădoianu Street, attic, room 1, District 1, Bucharest, Romania. Phone: +40 311 096 740.

We have appointed a data protection officer (DPO), on an outsourced basis: Adrian Chira, through ELFER S.R.L., with its registered office in Cluj-Napoca, 17 Câmpeni Street, apt. 5, Cluj County, registered with the Trade Register under no. J2025053083002, tax identification code RO52181570. Write to them at contact@cv30.co, marked “for the attention of the data protection officer”. You may contact the DPO directly about any matter relating to the processing of your data and to the exercise of your rights (art. 38(4) GDPR).

Two terms we use: the controller is whoever decides why and how the data is used (here, CV30). A processor is a provider that processes data for us, following our instructions, for example the company that hosts our database.

2. WHAT DATA WE USE, WHY AND ON WHAT LEGAL BASIS

Below you will find, for each feature of the Platform, what data we use, why and on what legal basis. The legal bases in Regulation (EU) 2016/679 (“GDPR”) that we rely on are:

Legal basisWhat it means
Contract (art. 6(1)(b))The data without which we cannot provide the service you asked for when you created your account.
Legitimate interest (art. 6(1)(f))An interest of ours or of others, which we name each time. We have weighed each such interest against your rights, and you can ask us for the assessment at contact@cv30.co. You can object (section 11.2).
Consent (art. 6(1)(a))Your agreement, which you can withdraw at any time (section 12).
Legal obligation (art. 6(1)(c))What the law requires of us, for example to answer the authorities.

2.1. Account and sign-in

Data: your e-mail address; first and last name; your username (@), which we suggest and you can change; your password, if you choose to set one (kept by the authentication provider only in irreversibly encrypted form); an internal identifier (for old accounts and for accounts created in the app, made of your first name, last name and a number), which is technically visible on your posts; your role (student or employee); the account creation date; the sign-in session, kept on your device. If you sign in with Google or Apple, we receive from them your name, your e-mail address (with Apple it may be a relay address, that is, an address generated by Apple that hides your real one) and, from Google, your profile photo. The sign-in codes sent by e-mail are valid for 10 minutes, accept a limited number of attempts, and we keep them only as a cryptographic fingerprint (an encoded form from which the code can no longer be read).

WhyLegal basis
Creating the account, signing in and account e-mails (access codes, password reset, security)Contract
Keeping proof that you accepted the Terms and Conditions, that you expressly accepted the clauses in section 26 of the Terms, that you declared you are at least 16 and that you confirmed that you read this policy: the date, time, version of the documents and where you signed up (app or website)Legitimate interest: to be able to prove what you accepted and when

For accounts created before September 2026 we reconstructed this record from the account creation date; we do not know which version of the documents was accepted then.

2.2. Your profile: what is public and what is not

Data: your city and, if you wish, your profile and cover photo, description, an introduction video, gender, date of birth, phone number, a contact e-mail, links to Facebook, Instagram and X (Twitter), your job title and company, your CV file.

InformationWho sees it
Name, profile and cover photo, username (@), description, introduction video, job title, company, faculty, level and classAnyone, including visitors without an account. Your profile has a public address (cv30.app/u/…) and can be indexed by search engines, for example Google.
Studies (including those we filled in, section 2.3), work experience, skills, career plan (including financial and personal goals) and ideal job (including the minimum and maximum desired salary)Anyone, including visitors without an account
City and links to social networksAnyone, including visitors without an account, for as long as you do not hide it. The app has the “hide location” and “hide social networks” options: while they are on, the information no longer appears on your public profile and is no longer served through the Platform's technical interface either.
GenderHidden by default. While it is hidden, your gender appears neither on the public profile page on the website nor through the Platform's technical interface. It appears only if you choose to show it.
E-mail, phone number, date and year of birthHidden by default: we do not show them on your profile, neither in the app nor on the website, unless you choose to show them. We also switched all existing profiles to “hidden”.
The “I live in a dorm” marker, your employment type and whether you are subscribed to the newsletterWe do not show them on your profile.
Dorm coordinates, CV file, identity data, XoXo pseudonymWe do not show them on the public profile.
Who you follow and who follows youAnyone

Warning: “hidden” means that we do not pass the information on, not that it becomes secret. The “hide location”, “hide gender” and “hide social networks” switches stop the information from being served to other accounts, not merely from being displayed. The rest of what you fill in stays stored with us and, at present, other signed-in accounts can read it through the technical means of the Platform. If you do not want us to hold a piece of information at all, delete it from your profile.

WhyLegal basis
Showing your name, city, faculty and class on your profile, so that others can find youContract
Showing the optional information you choose to fill inConsent: you withdraw it by deleting the information from your profile or hiding it, where that option exists
Indexing of the public profile and of public posts by search engines, including through the site map (sitemap) that search engines readLegitimate interest: so that colleagues and employers can find you and so that we bring visitors to the Platform. There is no no-index setting: if you do not want your profile and your public posts to reach search engines, write to us at contact@cv30.co and we will handle the request manually (section 11.2). Pages that a search engine has already saved are removed by asking that search engine directly to delete them.

2.3. Your studies, groups and academic status

Data: university, faculty, specialisation, study cycle and class (graduation year); your education history (institution, degree, field, period, description). We do not ask for your year of study: we calculate it from your class.

Studies filled in by us. For more than 72,000 people with an account we filled in the education history from the student kit orders (Student Kit) placed between 2020 and 2024, matched by e-mail address. We deduced the start year and the length by convention: usually 4 years for a bachelor's degree, 2 for a master's and 6 for a doctorate. For some accounts we also deduced the class. Under each such study it says where it comes from. These studies appear on your public profile, like any others. The deductions may be wrong: you can correct them in profile editing or ask us to delete them.

Groups. Based on your university, faculty, class and level we automatically add you to the matching groups.

Academic status. We calculate it automatically from your class and your declared cycle: fresher (first year of a bachelor's degree), student, graduate (your class has finished), master's student, doctoral student or unknown. We switch the academic year on 1 July, so you become a “fresher” about three months before classes start. Accounts created before 1 January 2022 are considered graduates, whatever they declared at the time, except those that entered a class that has not finished. You see the label (fresher, graduate, master's or doctorate) on your own profile; other users do not see it. We use the status for content targeting (section 5). If the label does not fit, fill in or correct your class in profile editing; if it is still wrong, write to us at contact@cv30.co and we will correct it.

WhyLegal basis
Automatically adding you to university, faculty and class groupsContract
Filling in the education history and class from Student Kit ordersLegitimate interest: so that you have a complete profile and end up in the right groups
Public display of the studies we filled inLegitimate interest: so that you have a complete profile and so that colleagues and employers can find you. You did not choose to publish them: you can correct them at any time in profile editing, and if you do not want them to appear at all, you can ask us to delete them by writing to contact@cv30.co (section 11.2).
Calculating academic status and showing the labelLegitimate interest: to show you content suited to your stage of studies

2.4. Posts, comments, reactions and groups

Data: the content you publish (text, photos, video, music, GIFs, stickers, polls, quizzes), comments, likes, saves, shares, the posts you hide (“Not interested”), your answers to polls and quizzes, who you follow, who you block, the words you choose to mute and your requests to administer a group.

Who sees it. What is published in the main feed and in the open areas (“Let's Talk”, XoXo, the Board, the map) can be seen by anyone, including visitors without an account, and posts can be indexed by search engines. Posts in a group and posts with a chosen audience appear in the feed only to the members of the group or to the chosen audience. However, they appear to anyone, including without an account, in the list of posts on your public profile and on the post's separate page (cv30.app/post/…), and the site map can pass them to search engines. They are not technically protected as private either, so do not post in a group anything you would not want to become public. Comments and reactions are seen together with the post. Your answers to polls and quizzes are linked to your account; the author sees the results, and technically anyone can find out how each account answered. Only you see your blocks and muted words.

You can delete a post or a comment at any time. The post disappears from the Platform, and the attached files (photos, video, recordings) are deleted from the file server together with it; the same happens when you delete your account. If you delete a comment that has replies, its text is no longer shown, but it stays stored and technically accessible, so that the thread does not break.

WhyLegal basis
Publishing and displaying content, comments, reactions, groups, follows and blocksContract

2.5. Private messages

Data: the text of messages, attached files, reactions, read receipts, the time sent, edits, replies and forwards, message requests and, where applicable, the listing the conversation started from.

Messages are seen only by the members of the conversation. The CV30 team has no routine access to them. It can access them only in exceptional cases, such as an abuse report or a legal request. Access through our incident procedure is logged; direct database access by technical administrators is not logged. Private messages do not go through the automatic moderation filter.

You can edit a message within the first 15 minutes and you can delete a message you sent at any time; the message also disappears for the others. The attached file, however, stays on the file server. Attached files are stored at addresses that are hard to guess, but anyone with the direct link can open them.

The push notification for a new message contains the sender's name and the text of the message. It passes through the notification services (Google Firebase Cloud Messaging, Apple Push Notification service, OneSignal) and through Cloudflare's servers, where it is written to the technical logs. If you do not want the text of your messages to pass through these services, turn off push notifications in your phone's settings or in the Platform's settings.

WhyLegal basis
Sending and displaying messagesContract
The team's exceptional access to a reported conversationLegitimate interest: user safety and investigating abuse
Access at an authority's requestLegal obligation

2.6. XoXo, the pseudonymous area

In XoXo you post, by default, under an automatically generated pseudonym, which you can change; you can also choose to post under your own name. XoXo is not anonymous. Within the XoXo area, other users see only the pseudonym. The same holds for notifications: if you comment on a XoXo post, the author sees your alias, not your real name. CV30 does, however, keep the link between the pseudonym and your account. Moderators and administrators see the author's name and e-mail address when they review a report or a flagged post. We use this link for moderation, to stop abuse and to answer the authorities' legal requests.

Your pseudonym hides you from other users: your real name is not displayed and is not served through the Platform's technical interface either, which returns the alias alone. That is not anonymity: we keep the link between pseudonym and account, moderators see the author, the alias is the same on all your posts, and the way you write can make you recognisable. Treat the area as a public one: do not write there anything you would not want linked to your name.

Anyone can read XoXo posts, including without an account. Every post goes through the automatic filter before publication (section 2.14). XoXo posts have no page of their own on the website (cv30.app/post/…), do not appear in the site map and do not appear in the website search. Your pseudonym and posts remain after your account is deleted.

Do not write in XoXo things about other people that you would not say under your own name, especially about their health, intimate life or orientation (section 2.19). If someone wrote about you, report the post or write to us.

WhyLegal basis
Posting under a pseudonymContract
Keeping the link between pseudonym and account, for moderation and to stop abuseLegitimate interest: the safety of other users and accountability for content
Disclosing the author to an authority that legally requests itLegal obligation

2.7. Let's Talk (theme of the month)

Data: your contribution (text, audio or video recording, so your voice and, for video, your image), reactions, participation, the automatic transcript and the monthly summary.

Contributions are public, including for visitors without an account, and the audio and video files are on our public file server. After you upload a recording, we send it through OpenRouter to the Google Gemini model, which transcribes it; we keep the transcript next to the contribution. Once a month, the team generates a draft summary: the texts, the transcripts, at most three comments by other users on each contribution and the first and last names of the contributors are sent through OpenRouter to the Claude model (Anthropic). The team reviews the draft before publication. The published summary, the winners and the hosts of the theme are public.

If you delete a contribution, the audio or video file is deleted from the file server together with it, along with its transcript; the same happens when you delete your account.

WhyLegal basis
Publishing the contributionContract
Automatic transcription and the draft summaryLegitimate interest: to make contributions easy to go through and to summarise the month's discussion. The transcription and the draft go through OpenRouter, to the Google Gemini and Claude (Anthropic) models; we have data processing agreements with these providers (section 7.2), and transfers outside the European Economic Area are described in section 8.

2.8. The Board (Avizier), jobs and applications

Data: your listing (title, description, image, details), the chosen audience, the contact details you choose to include (phone, WhatsApp, Instagram, e-mail or application link), views and saves.

Listings are public, including for visitors without an account. For a personal listing you can choose whether everyone sees it or only your faculty colleagues; companies can choose the audience of their jobs and promotions using the criteria in section 5. These choices concern display only: technically, listings are accessible to anyone. Anyone who sees a listing sees its contact details; you include them at your own responsibility and can remove them at any time by editing the listing. A closed or expired listing is no longer shown, but stays stored. When you delete your account, we take your listings down together with the contact details in them (section 10).

Applying for a job. When you apply, the Platform opens your e-mail app with a message prepared for the employer. You send the message yourself, directly; CV30 does not see it and does not pass on your CV. We only record that you pressed “Apply” (the listing, your account and the time), so that we can show the company aggregate statistics.

WhyLegal basis
Publishing and displaying listingsContract
Counting views and presses of “Apply”, for listing statisticsLegitimate interest: to show those who publish how their listings perform

2.9. Map, location and dorm

Map pins. The title, description, coordinates and type of the pin, your name and initials, who pressed “Going” and requests to change the category. Pins are public, together with your name and photo. An expired pin is no longer shown, but stays stored until you delete it.

Searching for an address. In the app, the text you type goes directly from your phone to OpenStreetMap, which turns it into coordinates.

Device location. We read it only if you give us permission and only in three situations. (1) When you press the location button on the map or when you choose a place for a pin, a post or a listing: the location stays on the device and centres the map; if you save the pin or the listing at that place, the saved coordinates become public. (2) In contests with a zone: the device itself calculates whether you are in the zone. (3) In the map hunt and for prizes that are collected at a specific place: we send the server the phone's coordinates at that moment, and the server only calculates whether you are in the zone. We do not keep the coordinates. We do, however, keep the result, that is, the fact that you unlocked a zone or claimed a prize, with the date and time. This shows that you were in that zone at that moment.

Dorm (optional). The “I live in a dorm” marker and, if you wish, the dorm's coordinates. In the app we use them to show you listings in your area. The coordinates are not public; the “I live in a dorm” marker can technically be read by anyone (section 2.2). You can delete them from your profile at any time.

WhyLegal basis
Showing pins and participation (“Going”)Contract
Reading the device location, when you use a feature that needs it (the location button, choosing a place, zone games, prizes collected at a place)Contract. We read the location only if you have given location permission, which you can withdraw at any time in your phone or browser settings.
Keeping the result of zone games (unlocked zone, claimed prize, date and time)Contract
Listings in your dorm's areaConsent; you withdraw it by deleting the data from your profile

2.10. Events, contests, prizes and Coins (Bănuți)

Events. When you register we use your name, e-mail address, company, a PIN code, the status of your registration and check-in, the date of the invitation and of acceptance, and who invited you. We check eligibility for some events automatically from your profile (section 5). Organisers, their co-administrators and the people who scan at the entrance see your name, e-mail, company and the status of your registration and check-in. We send invitations by e-mail. We do not show participants' names publicly; the organiser can show or hide how many there are.

Guest lists. We may upload to the Platform guest lists with names, e-mail addresses and companies, to which we send invitations. The lists come from the event organiser, who chooses whom to invite, and only the CV30 team uploads them, after the organiser confirms in writing that it has the right to use that data and that it has informed the people on the list. We use the list only to send the invitations and to keep track of registrations for that event. If you ended up on a guest list and do not want to receive invitations, write to us at contact@cv30.co.

The QR code on your profile contains your account identifier and does not change. Show it only at check-in and do not publish it.

Contests and prizes. We keep your participation, the prize won, the claim code, who validated the prize and when. For the treasure hunt in comments we also keep the key phrase and the time of the first comment; this data, including the key phrase, can technically be read by anyone. For the map hunt we keep the unlocked zones and the prizes claimed, with the person who scanned. For prizes we send you an e-mail with your name and a QR code. If the value of a prize exceeds the non-taxable threshold set by law (currently 600 lei), we ask you for your full name, personal identification number (CNP) and address, so that we can withhold and declare the tax. The legal basis is our legal obligation, and we keep this data for as long as accounting and tax law require. You can take part in prize contests only if you are at least 18 years old; the rule is set out in the Terms and Conditions. If a contest has its own rules, those apply first.

Coins and rewards. The points ledger (amount, reason, source, who granted them, any notes), your balance and the exchange of points for rewards (voucher code, cost, status, who handed over the reward).

WhyLegal basis
Registration, check-in, contests, prizes, Coins and rewardsContract
Inviting the people on guest listsLegitimate interest: to invite to the event the people chosen by the organiser. If the invitation promotes a brand's event, we send it only to people who have consented to commercial messages (art. 12 of Law no. 506/2004). Every invitation contains a link to this policy.

2.11. Companies, “I work here” and recommendations

“I work here”. The company, your account, the status of the request (pending, confirmed or rejected) and the dates. The request is seen by those who can approve it (the company's administrators and the CV30 team), and notifications about the request name the people involved. On your public profile we show only your confirmed link to the company; pending and rejected requests do not appear there.

Other data. The companies you follow; your visits to company pages (how many, the first and last visit); the recommendations you write about a company, with your name, photo, role, start date, text and rating, which are public; a company verification request, if you make one.

WhyLegal basis
Company pages, approving requests, follows, recommendationsContract
Counting visits to company pagesLegitimate interest: statistics for companies and for us

2.12. Notifications

Data: your device's notification identifier (token), the platform, the app version, the language and the last activity; your notification settings; delivery events (sent, accepted, opened); the text of notifications, which contains the name of whoever took the action (for example “X commented on your post”). We send e-mail notifications through SendMachine.

How they start. In the app, push notifications start only if you allow them on your phone. On the website, at sign-up, all notification types are switched on. E-mail notifications are switched on by default. You can turn them off in the Platform's notification settings, and push notifications also in your phone's settings.

Through notifications we also send you announcements about campaigns, partners' events and student kits, sometimes targeted at certain groups of students (section 5), as well as notifications and digests about new posts. By e-mail you get them only if you ticked the checkbox described in section 2.13. For push you have a separate switch for promotional announcements in the Platform's notification settings: if you allowed notifications on your phone, the switches for kits and campaigns (Chill Pack, Students Kit) are on from the start, and if you turn the promotional announcements switch off we no longer send you such announcements by push, not even those addressed to all users. You turn them off in the Platform's notification settings, or by turning off notifications in your phone's settings. The Platform's notification settings are also where you choose whether you want to hear about the student kits (Chill Pack, Students Kit) and whether you want digests about new posts. You can change your mind at any time, from there.

WhyLegal basis
Account and security e-mailsContract
Push notifications about your account and its activityLegitimate interest: so that you find out in time what is happening in your account. You get them only if you allowed notifications on your phone; you turn them off in your phone's settings or in the Platform's settings.
E-mail notifications about activity in your account (likes, comments, shares, follows, mentions)Legitimate interest: so that you find out what is happening in your account; you can turn them off at any time in the notification settings
Announcements about campaigns, partners' events and kits, and notifications and digests about new posts, by e-mail or pushConsent by e-mail (and art. 12 of Law no. 506/2004): only if you ticked the checkbox in section 2.13. For push: legitimate interest — you have a separate switch for promotional announcements, on from the start if you allowed notifications on your phone, which you can turn off at any time (section 2.12).
Measuring the delivery and opening of notificationsLegitimate interest: to know whether notifications arrive and are useful

2.13. Newsletter and commercial messages

When you create your account we ask you separately, through an unticked checkbox, whether you want to receive by e-mail news from CV30 and offers from the partners and brands we work with. The checkbox is optional: the account is created without it too. We record your answer (yes or no), with the date, time, policy version and where you signed up (app or website).

We add you to the newsletter contact list only if you ticked the checkbox. We send the e-mail provider your e-mail address and your first and last name. We send nothing else, and we do not update the list every time you change your profile (section 7.2).

How to unsubscribe. Every newsletter has an unsubscribe link and shows CV30 as the sender. You can also write to us at contact@cv30.co. The unsubscribe is recorded by the e-mail provider and is synchronised with the Platform, and your address is not sent back to the list, whatever you change in your profile. In the Platform's settings you have a newsletter switch, from which you can subscribe and unsubscribe at any time. If you nevertheless receive the newsletter after you unsubscribed, write to us at contact@cv30.co. What happens to your address on the list when you delete your account is explained in section 10.

WhyLegal basis
Sending the newsletter by e-mailConsent (and art. 12 of Law no. 506/2004)
Keeping proof of consent to the newsletterLegal obligation: we must be able to prove consent (art. 7(1) GDPR)
Keeping a refusal, a withdrawal of consent and an unsubscribeLegitimate interest: not to send you the newsletter if you do not want it

2.14. Content moderation and reports

Automatic filter. The text and photos of posts, comments, listings (including the contact details in them), pins, “Let's Talk” contributions and XoXo posts are sent to OpenAI, which assesses whether they seem to break the rules (for example violence, hate, sexual content, harassment). We do not send your name, but the text may contain personal data. We keep only the scores and the category, not the content sent. Private messages do not go through the filter. We also compare uploaded photos with an internal list of fingerprints of known illegal images.

Before publication. In areas where checking before publication is switched on (in XoXo, always), content is checked before it is saved. If the filter considers it prohibited, it is not saved and not published: you see a message and can rephrase it. This is an automated decision. No person sees the rejected content and, because we do not keep it, we cannot re-examine it later. You can rephrase it and publish it again. If you think the filter got it wrong, write to us at contact@cv30.co with the text you wanted to publish and a person from the team will answer you. We consider that the rejection does not significantly affect you within the meaning of art. 22 GDPR, because it concerns a single post, which you can rephrase, not your account.

After publication. In areas where the filter does not check before publication, content is published, and the filter can hide it, flag it or show it less often automatically, before any person sees it. On the Board, gigs, searches for flatmates or study mates, offers and jobs are checked before publication, as in XoXo. In the main feed, a post with at least five unresolved reports is no longer shown, and in XoXo a single unresolved report takes the post out of the main feed, until it is checked. Other cases flagged by the filter or reported by users go to moderators, that is, people from the team, who decide whether to remove the content, hide it or leave it. Moderators can also review automated decisions and reverse them; filter flags that nobody reviews within 7 days are closed automatically, and the content goes back to normal display. Moderators may receive alerts in an internal channel (Slack), with the content identifier and the category. We do not suspend accounts automatically: a person from the team decides on a suspension. If we blocked or hid your content, you can ask for a review directly in the Platform, through the appeal option next to the content, or at contact@cv30.co; a moderator decides. If we suspended your account, write to us at contact@cv30.co. The setting is made for each area separately and can change: in some areas content is checked before publication, in others the filter applies its verdict on its own; if you want to know which setting an area has, write to us at contact@cv30.co. For any moderation decision you can also go to court or file a complaint with ANCOM, Romania's digital services coordinator.

Reports. When you report something, we keep your account, what you reported, the reason and your description. Moderators see who reported, and the report also reaches the contact@cv30.co inbox, with your e-mail address. We also keep a record of each user's reports, to limit abusive reporting.

WhyLegal basis
Automatic filtering, automatic hiding after reports, reviewing reports, removing content, suspensions, appealsLegitimate interest: user safety and enforcing the Platform's rules
Receiving notices about illegal content, stating reasons for moderation decisions and notifying the authorities where necessaryLegal obligation (Regulation (EU) 2022/2065 on digital services)

2.15. Usage statistics and error reports

What we record, linked to your account: the areas you open, the last screen and the time spent; sessions; the posts shown and opened, how long you read them and how far you scroll; how much of each video you watch; the full text of your searches, where you search and how many results you get; which notifications you open; which banners you see and how many times; which listings you see, when you press “Apply” and which company pages you visit; the app version; whether we asked you for a review in the app store. We also record where you first came from: the source, medium and campaign in the link, the domain of the website you came from, the page or link you entered through and the platform. We keep none of this on your device: it stays only in the memory of the app or of the browser tab, until you create an account, and it is lost if you close the tab or the app before that. Also on the website we record errors (the error message and details, the page address, the browser type).

We use them mainly in aggregate reports (by area, period and group of users), but the data stays linked to your account, and the team can consult it in internal dashboards. We do not show other users what you have read, what you have searched for or how long you spent on a page. The author of a poll or a quiz sees the results.

Mobile app. Error reports go to Google Firebase Crashlytics: your account identifier, the device's technical data and the error details. Statistics go to Google Analytics for Firebase: automatically collected events (first open, sessions, screens), the app identifier, the approximate location derived from your IP address and, from us, your account identifier, university, faculty, city, company and whether you are a student. Your e-mail address does not reach Google Analytics, and the app no longer reads the Android advertising identifier. The statistics in the app rely on our legitimate interest in understanding how the Platform is used, not on your consent; you can object at any time by writing to us at contact@cv30.co (section 11.2). If you have an older version of the app, it may keep sending your e-mail address and the advertising identifier until you update it; we have deleted data of this kind sent earlier from Google Analytics.

The “Send report” button. If you press it after an error in the app, you send us by e-mail the error details, the device model, the operating system, the app version, your account identifier and your e-mail address. In rare cases, the app sends such a report automatically, for example when it cannot open the app store page.

WhyLegal basis
Understanding how the Platform is used, measuring the audience, choosing which features we improve, finding out through which channels users arriveLegitimate interest: to improve and develop our service. We do not ask for your consent, because we neither write nor read anything on your device for this purpose (section 13). You can object (section 11.2).
Error reports and the report you sendLegitimate interest: to fix errors and keep the Platform stable

2.16. Security and abuse prevention

Data: your IP address and, at sign-in, your e-mail address, used to limit the number of attempts (we keep them between a few seconds and 10 minutes); the technical logs of our hosting providers (IP address, browser, pages accessed) and of our server functions (sometimes including your e-mail address); a cryptographic fingerprint of your IP address, kept for 30 minutes, and the address of the link you opened before installing the app, kept for 7 days, so that we can take you to the right content after installation; the record of the team's access (who used which permission and when).

WhyLegal basis
Protecting accounts and the Platform against abuse, investigating incidents, controlling the team's accessLegitimate interest: the security of the Platform and its users

2.17. Identity verification

Identity verification. We do not verify identity with an ID card or a selfie. We do not ask you for such documents and we do not keep such data.

2.18. Support, legal obligations and defending rights

When you write to us, we use your e-mail address, your name and what you write, so that we can answer you. We use the data strictly needed to answer authorities that legally request it, to keep accounting records (for example for prizes) and to defend ourselves in a complaint or a dispute. We also keep the correspondence about requests regarding your data.

WhyLegal basis
Answering your messages and requestsContract or, if you do not have an account, legitimate interest: to be able to answer you
Answers to authorities, accounting records, records of data requestsLegal obligation
Establishing, exercising or defending a legal claimLegitimate interest: to be able to defend our rights

2.19. Sensitive data

We do not ask you for data about health, religion, ethnic origin, political opinions, sexual orientation or intimate life, and we do not infer it from what you publish. If you write such information about yourself in a post, a listing or a public recording, we display it because you chose to make it public (art. 9(2)(e) GDPR). We do not use the voice or face in recordings to recognise people.

Do not publish such information about other people, not in XoXo, not on the Board and not anywhere else. If someone has published sensitive information about you, report the content or write to us at contact@cv30.co.

3. WHERE WE GET THE DATA FROM

Most data is given to us by you or results from the way you use the Platform. Some comes from other sources:

SourceWhat data
Other usersMentions, comments, photos or posts about you (including in XoXo), messages, reports, listings that contain your data, the approval or rejection of an “I work here” request, invitations
Google or Apple, if you sign in with themYour name, e-mail address (with Apple it may be a relay address) and, from Google, your profile photo
Event organisers and the people who scan at the entranceGuest lists (name, e-mail, company), check-in status, prizes handed over (section 2.10)
Old student kit orders (2020–2024)University, faculty, specialisation, level and locality, from which we filled in the education history and class (section 2.3)
Public company registers and targetare.roCompany data (name, tax code, address), which may include the names of some people, for example directors
Us, by calculationAcademic status, year of study, automatic groups, the audience you belong to for targeting, moderation scores, Coins balance

If you do not have a CV30 account, we may still have data about you: if you were put on a guest list, if a user mentioned you or wrote about you, or if a listing contains your contact details. You have the same rights as users (section 11). Write to us at contact@cv30.co.

4. WHAT IS MANDATORY AND WHAT IS OPTIONAL

On the website, students also choose their university, faculty and specialisation, and employees their company. In the app you can skip the step about studies or about your job; if you choose a faculty, you must also choose the cycle and class. At sign-up you must tick that you are at least 16, that you accept the Terms and Conditions — including, expressly, the clauses in section 26 of the Terms — and that you have read this policy. Without this data we cannot create the account. The age declaration is required at sign-up, the same on the website and in the app (section 14).

The rest is optional: a password, photo, description, gender, date of birth, phone number, social networks, studies and experience, CV, dorm, location permission, notifications, newsletter. Without them the account works, but some features do not: without a faculty you do not get into the faculty's groups, without location permission you cannot take part in zone games, and some events ask for your phone number or gender.

5. AUTOMATED PROCESSING AND PROFILING

Profiling means that a system automatically uses data about you to draw conclusions or to decide what you see. On the Platform, this happens here:

WhatHow it worksLegal basis
Main feedThe order does not depend on your profile: pinned posts come first, then new posts and those with many reactions, comments, saves, shares and views. Your profile only decides what you see: posts from your groups, without the posts you hid, without blocked accounts and companies and without posts targeted at an audience you are not part of.Contract, for showing the feed; legitimate interest, for targeting (below)
The BoardListings are filtered and ordered by your university, faculty, specialisation, year, class and groups and by how new they are; in the app, also by city. We use your dorm's area only if you filled it in, based on your consent (section 2.9).Legitimate interest: so that you see the listings relevant to you first
Targeting of content and notificationsThe CV30 team and the accounts we give the right to publish in the main feed can choose who sees a post; the CV30 team can also choose who receives a push notification, and companies who sees their jobs and promotions on the Board. The criteria are academic status, university, faculty, class, city, year of study and final year; for listings, also an area on the map. The criteria do not include gender or date of birth. Whoever publishes sees how many people they would reach. You can limit a personal listing to your faculty colleagues.Legitimate interest: so that content suited to your stage of studies and your city reaches you.
Academic statusCalculated from your class and your declared cycle (section 2.3)Legitimate interest (section 2.3)
Event eligibility and zone checks in gamesThe system automatically checks profile fields (for example your faculty) or whether you are in the required zoneContract
Automated moderationThe filter can reject content before publication and, in some areas, hide it, flag it or show it less often after publication; reports can automatically hide a post (section 2.14)Legitimate interest (section 2.14)

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (art. 22 GDPR). These processing operations decide what you see, in what order, who sees what you publish and whether a post passes the filter or stays displayed. They do not suspend your account and do not block your access to the Platform. The automated checks at events and for prizes can prevent you from registering or from claiming a prize. If this happened to you, write to us: a person from the team checks again, you can express your point of view and you can contest the result.

You can object to profiling based on our legitimate interest (section 11.2). We always honour an objection to the targeting of commercial content. There is no button for this in the app or on the website. Write to us at contact@cv30.co and tell us what you object to, and a person from the team handles the request manually, within the time limit in section 11. We reply telling you what we have stopped and, if there is something we cannot stop, why.

6. ARTIFICIAL INTELLIGENCE

We use artificial intelligence models from external providers in four places:

FeatureWhat we send and to whomLegal basis
Moderation filterThe text and photos of published content, without your name, to OpenAILegitimate interest: user safety
Skills suggestionsYour studies and experience (institutions, degrees, periods, job titles, employers, descriptions), to OpenAI. The request leaves from our servers, not from your phone, automatically, when you open the skills screen, and OpenAI does not keep the request.Legitimate interest: to suggest suitable skills to you.
Transcribing “Let's Talk” contributionsThe audio or video recording, to the Google Gemini model, through OpenRouterLegitimate interest (section 2.7)
Draft of the monthly “Let's Talk” summaryThe texts, transcripts, a few comments and the first and last names of contributors, to the Claude model (Anthropic), through OpenRouter. The team reviews the draft before publication.Legitimate interest (section 2.7)

OpenRouter does not always send the request directly to Anthropic or Google: it can also send it to the cloud providers that host the model (for example Amazon Web Services or Google Cloud).

All the artificial intelligence providers above work for us under a data processing agreement: they may use what we send them only to give us the answer we asked for, not for their own purposes. That does not mean the data disappears immediately: the provider that answers may keep the request for a time, according to the settings of our account and its own rules. For the models we reach through OpenRouter, the rules of the provider that hosts the model also apply.

The filter assesses the content, not the person. We do not use artificial intelligence to draw conclusions about your health, religion, origin or intimate life, nor to refuse you access to your account.

7. WHO ELSE RECEIVES YOUR DATA

7.1. People and organisations that see data about you

Other users and the public see what is public, under the rules in section 2. Event organisers, their co-administrators and the people who scan at the entrance see registration and check-in data (section 2.10). A company's administrators see “I work here” requests. The CV30 team (moderators and administrators) has role-based access, only to what it needs for its task. Authorities receive data only when they legally request it. Our advisers (lawyers, accountants, auditors) receive it only when needed and are bound by confidentiality.

Brands and clients for whom we run campaigns receive only aggregate statistics: how many people saw a campaign, how many reacted, how many took part, by group of users. We do not send them your name, your e-mail address or any other data that identifies you. The only exception is at events: the organiser, their co-administrators and the people who scan at the entrance see the registration and check-in data (section 2.10).

Employers receive nothing from us. When you apply for a job, you send the message yourself, from your own e-mail.

7.2. Providers that work for us (processors)

We have a data processing agreement (art. 28 GDPR) with every provider in the table below. They use your data only for what we ask them to do, not for their own purposes, and they are bound by confidentiality. For each one we say what it does, what data it receives and where the data goes.

ProviderWhat it does and what data it receivesWhere, and with what safeguard
Supabase Pte. Ltd. (Singapore)The database, authentication, server functions, real-time messaging. It receives all account and content data and the IP address on requests to the server.The data is stored in the EU (Frankfurt). Support and some sub-processors may be outside the EU. Standard contractual clauses.
Cloudflare, Inc. (USA)Hosting the website, file storage (photos, video, audio recordings, documents), the content delivery network, notification queues, technical logs. It receives the IP address and browsing data, uploaded files and the content of notifications.Global network, including the USA; uploaded files sit in Cloudflare storage spaces that are not limited to a region in the European Union. DPF and standard contractual clauses.
Upstash, Inc. (USA)Limiting the number of requests, against abuse. It receives the IP address and, at sign-in, the e-mail address.The region configured with the provider; it may be outside the European Union. DPF and standard contractual clauses.
OpenAI Ireland Ltd., together with OpenAI, L.L.C. (USA)The moderation filter and skills suggestions (section 6)USA. The data processing agreement is with OpenAI Ireland Ltd., which passes the data on to OpenAI, L.L.C. in the USA, under standard contractual clauses.
OpenRouter, Inc. (USA)Relays requests to the Claude (Anthropic) and Google Gemini models (rows below) and receives the same dataUSA. Data processing agreement and standard contractual clauses.
Anthropic PBC (USA), through OpenRouterThe draft of the monthly “Let's Talk” summary: texts, transcripts, comments, contributors' first and last namesUSA. The request may reach Anthropic or the cloud providers that host the model (for example Amazon Web Services or Google Cloud), as OpenRouter chooses. The transfer relies on standard contractual clauses.
Google LLC (Gemini), through OpenRouterTranscribing “Let's Talk” recordings (the voice and, for video, the image)USA, through Google AI Studio or Google Cloud, as OpenRouter chooses. DPF and standard contractual clauses.
Google LLC (Firebase Cloud Messaging)Push notifications: the device identifier and the text of the notification, including the sender's name and the text of private messagesUSA. DPF and standard contractual clauses.
Apple Inc. (Apple Push Notification service)Delivering notifications on iPhone: the device identifier and the text of the notificationUSA. DPF.
OneSignal, Inc. (USA)Push notifications, as a fallback (our previous provider): the account and device identifiers, the text of the notification. It still keeps old device records, from the time when it was our main provider. We delete them when we close our account with this provider; we have no date set.USA. DPF and standard contractual clauses.
Google LLC (Firebase Crashlytics)Error reports from the mobile app: the account identifier, device data, error detailsUSA. DPF and standard contractual clauses.
Google LLC (Google Analytics for Firebase)Statistics from the mobile app (section 2.15), without the e-mail address and without the Android advertising identifierUSA. DPF and standard contractual clauses.
SendMachine S.R.L. (Romania)Sign-in e-mails, e-mail notifications, prizes, invitations, reports to the team and the newsletter. It receives the e-mail address, the name and the content of the message; in the newsletter list, also profile data (section 2.13).Romania. Data processing agreement in place. If the processing goes outside the European Economic Area, the safeguards in that agreement apply.
Branch Metrics, Inc. (USA)Links for campaign invitations, for sharing articles and for invitations to people who scan. It receives the e-mail address of the person invited to a campaign and the title, description and image of the shared article. The links generated here are no longer used in the app or on the website, but the request still goes out to the provider.USA. DPF and standard contractual clauses.
Google Workspace (Google Ireland Ltd. or Google Cloud EMEA Ltd.)The team's e-mail, including contact@cv30.co: your messages to us, content reports and error reports, with the e-mail address and the account identifierEU and USA. DPF and standard contractual clauses.
Slack Technologies, LLC (USA)Internal moderation alerts: the type and identifier of the flagged content, the verdict, the category. No author name and no content text. The alerts go out only when the alert channel is switched on at our end.USA. DPF and standard contractual clauses.

7.3. Signing in with Google or Apple

If you sign in with Google or Apple, you authenticate directly with them. Google Ireland Ltd. and Apple Distribution International Ltd. decide on their own how they use your data (they are independent controllers), under their own policies. From them we receive your name, your e-mail address and, from Google, your profile photo.

7.4. Services loaded directly by the app or the browser

Some content is loaded directly from its provider onto your device, not through our servers. The provider receives your IP address and data about your browser or device, and sometimes what you search for. These providers use the data under their own rules; with most of them we have no data processing agreement.

ProviderWhat forWhat else it receives, and where
OpenStreetMap FoundationMaps and address searchThe map area shown (which roughly shows where you are, if the map is centred on you) and the text of the address searched for. United Kingdom (adequacy decision), through a global delivery network.
CARTO (CartoDB Inc.)The map background on the websiteThe map area shown. USA.
Google LLC (Tenor)GIFsIn the app, the search text. On the website, the search goes through our servers, but the GIFs load directly from Google. USA.
Giphy, Inc.GIFs in the mobile appThe search text. USA.
Apple (iTunes)Searching for and listening to music previewsIn the app, the search text; on the website, the search goes through our servers. USA.
Google (YouTube) and VimeoVideos embedded in posts, in the mobile app (they do not load on the website)They may set their own cookies, which they use for statistics, for playback preferences and, in YouTube's case, for advertising. USA.
DiceBearIllustrated avatarsThe avatar options chosen. EU or global.
unpkgThe map library in the mobile appGlobal.
goQR.me (Foundata GmbH)The QR code image in the prize e-mailThe prize code; the request comes from your e-mail app. Germany.
targetare.roCompany name autocompleteThe text you type. Romania.

8. TRANSFERS OUTSIDE THE EUROPEAN ECONOMIC AREA

Some providers process data outside the European Economic Area (EEA): in the USA, in Singapore (Supabase Pte. Ltd., the entity we have the contract with; the data is stored in Frankfurt) and in the United Kingdom (OpenStreetMap). The safeguards we use are: the European Commission's adequacy decisions (art. 45 GDPR), that is, decisions by which the Commission has found that a country or, in the USA, a company certified under the EU–US Data Privacy Framework (“DPF”) protects data as well as the EU does (we use them for the United Kingdom and for certified US companies); and standard contractual clauses (art. 46(2)(c) GDPR), that is, a model contract approved by the Commission, by which the provider undertakes to protect data as in the EU. The safeguard for each provider is given in the table in 7.2.

Where it says “DPF and standard contractual clauses”, the transfer relies on the provider's DPF certification; the standard contractual clauses in the contract apply only if the certification or the DPF decision ends.

For the services in 7.4, your device connects directly to the provider, which may be outside the EEA. We are jointly responsible with the provider for this connection; the provider is responsible for what it then does with the data. Some of these providers are DPF-certified, others are not; with most of them we have no agreement, so we cannot impose on them the safeguards in 7.2. The connection is made the moment their content loads: for example when a map is shown, when you search for a GIF, or when you open the image of a prize code in your e-mail.

You can ask us for the list of providers outside the EEA and a copy of the safeguards used, at contact@cv30.co.

9. HOW LONG WE KEEP DATA

We keep data for as long as we need it for the purpose for which we collected it. Where we do not yet have automatic deletion, we say so openly.

DataHow long we keep it
Account and profileFor as long as you have an account. When you press “Delete account”, in the app or on the website, we delete them (section 10). Accounts you no longer use stay stored: for now we have no automatic deletion for inactivity. If we introduce one, we will e-mail you first, so that you can keep your account.
Posts, comments, reactions, listings, pinsUntil you delete them. Expired listings and pins are no longer shown, but stay stored. A comment that has replies stays stored even after you delete it (section 2.4). When you delete your account, your posts and comments stay displayed but without your name and photo, and the attached files are deleted (section 10).
Private messagesUntil the sender deletes them or the conversation is deleted. After your account is deleted they remain in the others' conversations. Attached files stay on the file server even after the message is deleted: the rule is that we keep them for as long as the message exists, but the deletion does not happen automatically. We delete them on request, at contact@cv30.co, and they are deleted when you delete your account.
“Let's Talk” contributions (text, audio, video, transcript)Until you delete them; the audio and video files are deleted together with the contribution (section 2.7). They are also deleted when you delete your account.
Device locationWe do not keep it. We keep only the result of zone games (unlocked zone, claimed prize, with the date and time). We keep it for as long as the campaign is running and for as long as prizes can still be claimed or challenged. For now we do not delete it automatically, so old results stay stored.
Dorm coordinatesUntil you delete them from your profile or until you delete your account.
Sign-in codeValid for 10 minutes; replaced at the next request
IP address and e-mail used for limiting attemptsBetween a few seconds and 10 minutes
IP address fingerprint and link address, for links to the appFingerprint: 30 minutes. Link address: 7 days.
Device notification identifierWe delete it after 180 days of inactivity. In the app, the phone's identifier is also deleted when you sign out.
Notifications in your account and delivery eventsFor now we do not delete them automatically, so they stay stored. We want to keep them only for as long as they are useful to you in your account's notification history, and to delete the rest periodically; until that deletion runs, we cannot give you a period.
Usage statistics (areas, sessions, posts seen, video, searches, banners, errors, first visit)The criterion: we keep them tied to your account for as long as you have an account and for as long as we need in order to see how the Platform is used, and after that we keep only the aggregate figures, from which nobody can be identified. For now we have no automatic deletion, so older records stay stored. We delete them on request, if you write to us at contact@cv30.co.
Data in Google Analytics for Firebase and CrashlyticsFor as long as is configured with the provider: the period we set in the Google Firebase console, separately for Analytics and for Crashlytics. You can ask us for the current period at contact@cv30.co.
Reports, filter verdicts and moderation actions2 years. Those related to child safety we keep for longer: for as long as the police, the prosecutor's office or a court may ask us for them in a case about the incident, and for as long as we need them in order to stop it happening again. For now we have no fixed period for them and we do not delete them automatically.
Suspensions, team roles and access logsFor now we do not delete them automatically. We keep suspensions for as long as we need in order to apply the measure and to explain it to you if you challenge it. We keep team roles for as long as the person holds the role and for a period afterwards, so that it can be checked who did what. We keep access logs for as long as we need them for security checks.
Coins, rewards, contest entries and prizesFor as long as you have an account, so that we can show you your balance and your history; accounting data, for as long as the law requires. For now we do not delete them automatically. When you delete your account, your Coins balance, unused vouchers and their history are lost (section 10).
Event registrations, check-ins, invitations and guest lists (including data of people without an account)For now we do not delete them automatically. After the event, we keep registrations and check-ins for as long as we need them to settle a complaint or a prize claim. Guest lists and the data of people without an account we keep only for as long as they are needed for that event. If you are on a guest list and you do not have an account with us, you can ask us to delete your data at contact@cv30.co.
“I work here” requests, company recommendations and company verification requestsFor now we do not delete them automatically. Approved requests stay for as long as you are linked to that company. Rejected and pending requests we keep only for as long as we need them to be able to explain the decision. Recommendations you write about a company stay published until you ask us to delete them. You can ask us to delete a request or a recommendation at contact@cv30.co.
Proof of acceptance of the Terms, of the policy and of consent to the newsletterFor as long as you have an account. After the account is deleted we keep the proof for as long as a dispute about your use of the Platform can arise, that is the general limitation period of 3 years (art. 2517 of the Civil Code). For now, deletion does not happen automatically.
Newsletter list (SendMachine)Until you unsubscribe. After you unsubscribe we keep only the address, marked as unsubscribed, so that we do not add you to the list again. Deleting your account does not remove you from the list (section 2.13).
Messages sent to contact@cv30.coFor as long as we need to deal with what you wrote to us and, after that, for a possible dispute: as a rule 2 years, and requests about your data, 3 years. For now we do not delete messages from the mailbox automatically.
Identity verification dataSection 2.17
Database backupsThey are made by the database provider (Supabase), for the period configured in our account with them. The backups are overwritten in turn, and deleted data disappears from them as they are overwritten.
Technical logs of the hosting providers and of the server functionsFor as long as the providers keep them (Cloudflare, including for the notification service, and Supabase), for the period configured in our accounts with them.
Data needed for a dispute or for a legal obligationAs long as the law requires: usually 3 years from the moment a claim can be made (the general limitation period, art. 2517 of the Civil Code), plus the length of the proceedings; accounting documents, as long as Accounting Law no. 82/1991 requires.

We may keep aggregate statistics, from which no one can be identified any more, with no time limit.

10. DELETING YOUR ACCOUNT

How to ask for deletion. In the app: Settings, then “Delete account”. On the website: cv30.app/settings/delete-account, where you confirm by typing the word DELETE (ȘTERGE on the Romanian site). You can also write to us at contact@cv30.co, from your account's address.

What happens when you press “Delete account”. We actually delete the data that identifies you, by anonymising your account. We delete the sign-in account, so you can no longer log in, and we empty your profile: your name, photo, e-mail, phone number, date of birth, studies, experience, skills, career plan, ideal job and the other fields you filled in. We delete your identity document and selfie, if you uploaded them, the files you uploaded, including the photos and files attached to your posts and those for “Let's Talk”, and the notification identifiers of your phones. We withdraw your listings, together with the contact details in them. We also clear the copies of your name kept elsewhere: map pins, campaign lists, company testimonials and the text of the notifications other users have already received. Your public page on the website (cv30.app/u/…) is no longer shown, and your profile no longer appears in the app.

What remains after deletion. Your posts and comments stay displayed, but without your name and photo; if you ask for deletion within the first 14 days after signing up, we delete those as well. The messages you sent in other people's conversations also stay, with the other participants, as do your XoXo posts, which are shown under a pseudonym. Of your studies we keep only the faculty and the graduation year, as statistical data, without your name. We may keep only the data we need for a legal obligation or for a dispute (section 9). If you need help, or want to check what was deleted, write to us at contact@cv30.co from your account's address; we answer within one month at most (section 11.3).

At providers and in backups. When you delete your account, we also remove your contact from SendMachine and from OneSignal; in SendMachine only the address remains, marked as unsubscribed, so that we do not add you to the list again. You can also unsubscribe yourself, through the link at the end of every e-mail. The data sent to Google Firebase is deleted through the retention period configured there (sections 2.15 and 9). If we have passed your data on to other recipients, we ask them to delete it as well, under the conditions in section 11.3. In the database backups, the data disappears when the backups are overwritten (section 9).

11. YOUR RIGHTS AND HOW TO EXERCISE THEM

You have the rights below. For any of them, write to us at contact@cv30.co. Some you can exercise directly in the Platform.

11.1. What rights you have

RightWhat it means and how you exercise it on CV30
AccessTo find out whether we process data about you, what data, why, who we give it to and how long we keep it, and to receive a copy. You can see most of the data in your profile and your settings. We do not yet have a data download button: write to us and we will send you the copy by e-mail.
RectificationTo have us correct wrong or incomplete data. You can correct the data in your profile yourself, including the studies we filled in, in profile editing. For the rest, write to us.
ErasureTo have us delete data, for example when it is no longer needed, when you withdraw your consent or when you object and we have no stronger reason. You can delete your account directly in the Platform, in the app or on the website (section 10). If you created your account when you were a minor, you can ask for the data collected then to be deleted, even if you have since turned 18. We can refuse deletion only when the law allows it, for example when we need data for a legal obligation or for a dispute.
RestrictionTo have us temporarily stop using the data, for example while we check whether it is correct or whether your objection is justified. Write to us.
PortabilityTo receive the data you gave us, in a structured, machine-readable format, or to have us send it to another controller. It applies to data processed on the basis of the contract or of your consent. Write to us.
ObjectionSection 11.2
Withdrawing consentAt any time, as easily as you gave it (section 12). What we did before the withdrawal remains lawful.
Automated decisionsNot to be subject to a decision based solely on automated processing that significantly affects you and, if such a decision exists, to ask for human intervention, to express your point of view and to contest it (section 5)
ComplaintTo the ANSPDCP (section 11.4) or to the data protection authority of the EU country where you live, where you work or where you believe your rights were infringed
CourtYou can go to court if you believe we have infringed your rights

11.2. Your right to object

You can object at any time, on grounds relating to your particular situation, to the use of your data based on our legitimate interest, for example: targeting of content and notifications, profile-based filtering of the Board, the calculation of academic status, filling in studies from orders, usage statistics, indexing of your profile and posts. We stop, unless we have compelling legitimate grounds that override them (that is, reasons stronger than your interests, for example the safety of other users) or we need the data for a dispute. You can object at any time to direct marketing, including profiling carried out for that purpose; we then always stop, without asking for reasons. Write to us at contact@cv30.co; for the newsletter, also use the unsubscribe link.

11.3. How we handle your request

Write to us from your account's e-mail address, so that we know it is you; if you write from another address, we may ask you for an additional, proportionate confirmation. We do not ask for a copy of your identity document, unless we have no other way to identify you. The answer is free and comes without undue delay, within one month at most. If the request is complex or we receive many requests, we may extend the deadline by two more months and we will tell you within the first month. If we refuse a request, we tell you why and that you can complain to the ANSPDCP or go to court. If we delete or correct data at your request, we also inform the recipients to whom we disclosed that data, unless this proves impossible or involves disproportionate effort. On request, we tell you who these recipients are. Requests about your data also go to contact@cv30.co, where the CV30 team handles them; we do not have a separate address for them.

11.4. Complaint to the ANSPDCP

National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, postal code 010336, Bucharest, Romania; phone +40.318.059.211 or +40.318.059.212; e-mail anspdcp@dataprotection.ro; website www.dataprotection.ro, where you will also find the complaint form.

12. YOUR CONSENTS AND HOW TO WITHDRAW THEM

We ask for your consent only for what is optional. Withdrawing it does not affect what we lawfully did before.

What forHow you give consentHow you withdraw it
Newsletter by e-mailYou tick the optional checkbox at sign-upThe newsletter switch in the Platform's settings, the unsubscribe link in every e-mail, or an e-mail to contact@cv30.co; unsubscribing is synchronised with the newsletter list.
Promotional announcements and notifications and digests about new posts (e-mail, push)For e-mail, you tick the box when you sign up (section 2.13). For push, promotional announcements have their own switch in the notification settings, separate from the one for notifications about new posts (section 2.12)In the Platform's notification settings or through the link in the e-mail
Dorm locationYou fill in the field in your profileYou delete the field from your profile
Optional profile informationYou fill it in and, where applicable, choose to show itYou delete or hide it in profile editing

Push notifications and device location also depend on your phone's or browser's permissions, which you can withdraw at any time in the settings.

We do not ask for your consent for cookies, for statistics or for anything else stored on your device: we put nothing there that would require consent (section 13). The consents above are the only ones we ask you for.

Accepting the Terms and Conditions is not consent within the meaning of the GDPR, but the conclusion of the contract with us. Confirming that you have read this policy is not consent either: the policy informs you.

13. COOKIES, DEVICE STORAGE AND SDKS

Law no. 506/2004 (art. 4) requires your consent before we store or read information on your device, except for what is strictly necessary for the service you asked for. Below you will find what we store, why and for how long.

We do not ask for your consent for anything we store, because we store nothing that would require it. What stays on your device is only what is strictly necessary for the Platform to work or what remembers a choice you made — the sign-in session, the language, the theme, display preferences — plus a session identifier used solely to measure the audience of our own service, which disappears when you close the tab. Where you came from we keep only in memory, until you create an account — nothing stays on your device (section 2.15). We do not read the Android advertising identifier and we do not set advertising cookies. Videos in posts load from youtube-nocookie.com and with dnt=1, the variants without tracking cookies.

You can delete the data saved on your device at any time from your browser's or your phone's settings (section 13.5). If you want us to stop sending the statistics from the app, write to us at contact@cv30.co and we will stop (section 11.2).

13.1. Cookies of the cv30.app website

CookiePurposeDuration
sb-… (Supabase session)Keeps you signed inUp to 400 days; deleted when you sign out
cv30-localeRemembers the language you chose1 year
cv30-skinRemembers the visual theme you chose1 year
cv30-bwRemembers the black-and-white variant of the theme1 year
cv30-skin-chosenRemembers that you have already chosen the theme, so that we do not show you the choice again1 year
cv30-feed-modeRemembers the feed display mode you chose1 year

These cookies are strictly necessary or remember a choice you made, so they do not require consent (art. 4(6) of Law no. 506/2004). They are all first-party cookies of cv30.app, which other websites cannot read. The website does not set advertising cookies.

13.2. Other data saved by the website in the browser

KeyPurposeDuration
cv30-telemetry-session and cv30-telemetry-session-start (sessionStorage)The session identifier and start time, for usage statisticsUntil you close the tab
cv30:elig-fix:… (sessionStorage)Takes you back to an event registration after you complete your profileUntil you close the tab

13.3. The mobile app

The app keeps on your phone: the sign-in session, the language, the theme, the icon you chose, which guides and announcements you have seen, post drafts, recent searches, and a queue of notification events. It does not keep first-open data on your phone: where you came from stays only in memory, until you create an account (section 2.15). It also uses these Google components: Firebase Cloud Messaging (push notifications), Firebase Crashlytics (error reports), Google Analytics for Firebase (statistics, section 2.15) and Google Sign-In; on iPhone, also Sign in with Apple. On Android, the app no longer requests the permission to read the advertising identifier.

13.4. Third-party content

Maps, GIFs and the other services in section 7.4 load directly from their providers, which receive your IP address. In the mobile app, videos embedded in posts load directly from the providers, but from youtube-nocookie.com (YouTube) and with dnt=1 (Vimeo) — the variants without tracking cookies, which do not require your consent. The providers receive your IP address and the device's technical data, under their own rules. On the website, these videos do not load.

13.5. How to delete or block them

On the website you can delete cookies and saved data in your browser settings (for example the option to clear browsing data or the settings for cookies and site data) and you can block third-party cookies. If you delete the session cookie, you will be signed out. In the app, the session is deleted when you sign out, and the other data, including cookies set by embedded videos, when you uninstall the app or clear its data in your phone's settings. On Android you can reset or delete the advertising identifier in your phone's Google settings.

14. MINORS

The Platform is only for people who are at least 16. From the age of 16, the GDPR (art. 8) allows you to give consent yourself where processing is based on consent, for example for the newsletter. Romanian law has not set a different age, so the GDPR threshold of 16 applies.

Being at least 16 is a rule written in the Terms and Conditions, which you take on when you create your account. At sign-up you tick a box confirming that you are at least 16. We do not ask for documents for this purpose and we do not verify your age by any other means.

We do not knowingly collect data from people under 16. If you are a parent or guardian and you think a child under 16 has created an account, write to us at contact@cv30.co. When we see an account whose date of birth shows an age under 16, we write to the account's address and ask for the date to be corrected; if it is not corrected within 14 days, we delete the account together with everything it published. We do not delete straight away, because a mistyped date would delete an adult's account. We also check the dates of birth already entered that show an age under 16.

We have no different settings for users aged 16 and 17: their profile is public and can receive targeted content, like everyone else's. If you created your account when you were a minor, you can ask at any time for the data collected then to be deleted. Under the Terms and Conditions, XoXo and prize contests are only for people who are at least 18: that is a rule you have to follow, not a technical filter, because we do not verify age.

15. DATA SECURITY

We use: encrypted connections (HTTPS) between your device and the Platform; role-based team access, with a record of how permissions are used; access to the text of private messages only for the members of the conversation and, in exceptional cases, for the team (section 2.5), although attached files are accessible to anyone with the link; sign-in codes kept only as a cryptographic fingerprint, valid for 10 minutes and with a limited number of attempts; limits on the number of requests, against abuse.

No measure removes the risk completely. If a personal data breach may affect your rights, we notify it to the ANSPDCP within 72 hours and, if the risk to you is high, we also inform you, as the GDPR requires.

16. CHANGES TO THIS POLICY

The version of the policy is given at the beginning. When we change it, we publish the new version here.

If the change is significant (a new purpose, a new category of recipients, a change in how you exercise your rights), we write to you by e-mail before it applies: at least 15 days in advance, or at least 30 days if the change is to your disadvantage. If the change concerns something for which we asked for your consent, we ask for your consent again only for that.

The version in force is always published at cv30.app/privacy.

16.1. What changed compared with version 2.4

We rewrote the policy from scratch, based on a review of the Platform's code.

New: the summary at the beginning; XoXo; “Let's Talk”; academic status, automatic groups and content targeting; studies filled in from Student Kit orders; events, contests, prizes and Coins; companies; moderation and reports; artificial intelligence; sensitive data; security; old data; data sources; what is mandatory; account deletion; consents and how to withdraw them; device storage and the components in the app; changes to the policy; the data protection officer (sections 1 and 17).

Corrected: automated moderation (content rejected before publication is not held for a person, and some measures after publication are automatic); statistics (they are linked to the account, and the app sends data to Google Analytics); data retention (we removed the 24-month promise, for which there is no automatic deletion); the order of the feed (it does not depend on the profile); providers (entities, locations and the data they receive; we added Google Workspace, Apple Push Notification service, Google Fonts and Slack); applying for jobs (CV30 does not receive the CV); the visibility of group posts; messages (they are not deleted together with the account); social networks on the profile; the map (we no longer turn GPS coordinates into addresses); minimum age (16 is the GDPR threshold); the website's cookies.

17. CONTACT

For questions about this policy or about your data:

E-mail: contact@cv30.co

Address: CV30 WORLDWIDE GROUP SRL, 26 G-ral Barbu Vlădoianu Street, attic, room 1, District 1, Bucharest, Romania

Phone: +40 311 096 740

Data protection officer (DPO): Adrian Chira, through ELFER S.R.L. — contact@cv30.co, marked “for the attention of the data protection officer”

Supervisory authority: the ANSPDCP (section 11.4).