Privacy & Data Protection
Last updated: 3 July 2026
cvitae is used by job seekers around the world, so we handle personal information according to the strictest applicable standard rather than a single country's rules. In practice, that means aligning with South Africa's Protection of Personal Information Act (POPIA), the EU/UK's General Data Protection Regulation (GDPR), and the US's California Consumer Privacy Act (CCPA) — all of which share the same core principles below. Here's how we put that into practice, wherever you're signing up from.
Consent first
You decide what goes into your CV and when to publish it.
Secure data
Your data is stored on Supabase with row-level security and encryption.
Privacy controls
Your contact details stay hidden until you approve a request.
1. Purpose specification
We collect personal details, such as your employment history, email address, and phone number, for one purpose: to help you build a professional CV and share it securely with prospective employers.
2. The contact-reveal flow
In line with the data-minimisation principle common to POPIA, GDPR, and CCPA alike, our contact-reveal flow lets you publish your CV online without exposing your email address or phone number. When a recruiter requests access:
- We email you the requester's name, company, and phone number.
- Your contact details are shared only once you tap Approve.
- The secure link we send the recruiter expires automatically after 7 days.
3. Access and deletion rights
You can review, update, or delete your personal details at any time from your dashboard. Deleting a CV or your profile permanently removes that information from our databases.
4. Privacy contact
For any questions about how we handle your data — including requests directed to our POPIA Information Officer, our GDPR representative, or under any other applicable law — contact our team at privacy@cvitae.co.za.