Last updated: 28 May 2026
Introduction
ExactMatchCV is a platform offered by Sereanae Gestion SASU, that attaches great importance to the confidentiality, integrity and security of the personal data entrusted to it by its users.
This Privacy Policy explains how ExactMatchCV processes personal data when you visit the website, create an account, use ExactMatchCV, manage resumes, applications, job searches and alerts, subscribe to a paid plan, or contact us.
ExactMatchCV is a web application designed to help job seekers manage their job search workflow, create and improve resumes, adapt resumes to job postings, track applications, search for job offers, and use artificial intelligence features to generate suggestions, translations, evaluations and resume adaptations.
ExactMatchCV only processes personal data that is necessary for the provision, security, improvement and administration of the ExactMatchCV service, or where processing is required by law.
1. Data controller
The data controller is:
Serenae Gestion Publisher of ExactMatchCV.com France 2 Place Jean V Bureau 3, 44000 Nantes contact@exactmatchcv.com
For any question relating to this Privacy Policy or the processing of your personal data, you may contact ExactMatchCV at the address above or by email at: privacy@exactmatchcv.com.
2. Scope of this Privacy Policy
This Privacy Policy applies to the personal data processed by ExactMatchCV in connection with:
- the public website ExactMatchCV.com;
- the user account and authentication system;
- the ExactMatchCV web application;
- resume creation, import, editing, versioning, optimization, translation and export;
- job application tracking;
- job search and job alerts;
- billing, subscriptions and payments;
- artificial intelligence features;
- technical logs, cookies, local browser storage and audience measurement;
- platform administration and support.
This Privacy Policy does not apply to websites, services or platforms operated by third parties, even where they are accessible through links or integrations from ExactMatchCV. Such third parties process personal data under their own responsibility and in accordance with their own privacy policies.
3. Main principles
ExactMatchCV processes personal data in accordance with Regulation (EU) 2016/679, known as the General Data Protection Regulation or GDPR.
In particular, ExactMatchCV undertakes to:
- process personal data lawfully, fairly and transparently;
- collect personal data for specified, explicit and legitimate purposes;
- limit the data collected to what is necessary for the relevant purposes;
- keep personal data accurate and, where necessary, up to date;
- retain personal data only for as long as necessary;
- protect personal data using appropriate technical and organisational measures;
- respect the rights granted to data subjects under the GDPR.
4. Personal data processing carried out by Serenae Gestion
4.1 Public website visits and audience measurement
When you visit the public website without being signed in to an account, ExactMatchCV may process technical and navigation data in order to operate the website, measure its audience and improve its performance.
| Item | Description |
|---|---|
| Categories of data | Technical and navigation data, such as IP address or truncated IP address where applicable, browser and device information, page views, referring pages, navigation events, language preferences and information necessary to establish aggregated statistics. |
| Purpose | To operate the website, measure audience, improve navigation, detect anomalies and optimise the performance of the public website. |
| Legal basis | Legitimate interest of ExactMatchCV in measuring its audience and improving its website, Article 6(1)(f) GDPR. |
| Recipients | Serenae Gestion. Audience measurement is carried out using Umami, hosted by Serenae Gestion. The data collected for this audience measurement is not shared with third parties and is not cross-referenced with other data. |
| Retention | Raw data or session-level data is retained for a maximum of thirteen months. Anonymous or aggregated statistics may be retained for a maximum of twenty-five months, then deleted or irreversibly anonymised. |
These measurements are configured to produce only anonymous or aggregated statistics, without individual tracking of your browsing beyond what is necessary for the operation and improvement of the website.
4.2 Account creation, authentication and session management
When you create an account or sign in to ExactMatchCV, ExactMatchCV processes account and authentication data.
| Item | Description |
|---|---|
| Categories of data | Account and login data, such as name, email address, password-related data, authentication provider, language and market preferences, profile picture where applicable, user identifier, role information, session data and security tokens. |
| Purpose | To create and manage your account, authenticate you, maintain your session, secure access to the platform, prevent fraud and CSRF attacks, enable automatic reconnection, personalise language and market preferences. |
| Legal basis | Performance of the contract between you and Serenae Gestion, Article 6(1)(b) GDPR, for account access and use of the service. Legitimate interest, Article 6(1)(f) GDPR, for fraud prevention, security and protection of the platform. |
| Recipients | Serenae Gestion. Google may also receive data where you choose to use Google sign-in. |
| Retention | Account data is retained for as long as your account remains active. After twenty-four months of inactivity, ExactMatchCV may notify you that the account will soon be disabled or deleted. If no response is received within thirty days, the data is deleted or anonymised, except where retention is required for legal, accounting, security or dispute-management purposes. After account deletion by the user, data is deleted or anonymised within thirty days, subject to the same exceptions. |
Passwords are not stored in plain text and will never be requested outside the official ExactMatchCV authentication interface.
4.3 Email verification, password reset and transactional emails
ExactMatchCV processes certain account data to send transactional emails related to the security and operation of your account.
| Item | Description |
|---|---|
| Categories of data | Identification and communication data, such as email address, account identifier, verification or password reset tokens, date and time of request, and technical delivery metadata. |
| Purpose | To verify your email address, secure account creation, allow password reset, send job alerts and other transactional messages necessary for the operation of the service. |
| Legal basis | Performance of the contract, Article 6(1)(b) GDPR. Legitimate interest in securing the service, Article 6(1)(f) GDPR. |
| Recipients | ExactMatchCV and Brevo, acting as email delivery provider. |
| Retention | Email verification tokens are retained for a maximum of seven days. Password reset tokens are retained for a maximum of one hour. Transactional email delivery logs are retained for a maximum of twelve months to ensure delivery, security and troubleshooting. |
4.4 Reusable personal profile for resumes
ExactMatchCV allows you to create a reusable personal profile to pre-fill resumes and maintain consistency across resume versions and exports.
| Item | Description |
|---|---|
| Categories of data | Profile and contact data, such as name, email address, telephone number, location, professional websites or social profiles, nationality, driving licence information and preferred job-search market. |
| Purpose | To pre-fill resumes, reuse profile information across multiple resume versions, improve consistency between resumes and applications, and personalise the service by market or country. |
| Legal basis | Performance of the contract, Article 6(1)(b) GDPR. |
| Recipients | Serenae Gestion. |
| Retention | Data is retained for as long as your account remains active or until you delete or modify the relevant profile data. After account deletion, it is deleted or anonymised within thirty days, subject to technical backups and applicable legal obligations. |
4.5 Resume creation, editing, versioning and export
ExactMatchCV processes resume data to allow users to create, edit, organise, optimise, translate, version and export resumes.
| Item | Description |
|---|---|
| Categories of data | Resume content and metadata, such as professional experience, education, skills, languages, certifications, projects, publications, volunteering, awards, custom sections, resume titles, versions, templates, language, export metadata and update history. |
| Purpose | To store and edit resumes, create specialised versions, optimise resumes for applicant tracking systems, translate resumes, export resumes in PDF or ODT format, generate resumes adapted to a job posting or application, and preview resumes in the browser. |
| Legal basis | Performance of the contract, Article 6(1)(b) GDPR. |
| Recipients | Serenae Gestion. Mistral AI may receive relevant resume data where you use AI-powered features. |
| Retention | Resume data is retained for as long as your account remains active or until you delete the relevant resume or version. After account deletion, it is deleted or anonymised within thirty days, subject to technical backups and applicable legal obligations. Export files generated on demand are retained only for the time necessary for download and for a maximum of twenty-four hours. |
You are responsible for ensuring that the resume information you provide is accurate and that you do not include unnecessary sensitive data.
4.6 Resume import
ExactMatchCV allows you to import an existing resume in PDF, DOCX or ODT format in order to extract and reuse its content.
| Item | Description |
|---|---|
| Categories of data | Imported resume data, such as the uploaded file, file metadata, extracted text and processing status or error messages. |
| Purpose | To extract resume information automatically, simplify resume creation and allow you to reuse an existing resume. |
| Legal basis | Performance of the contract, Article 6(1)(b) GDPR. |
| Recipients | Serenae Gestion. |
| Retention | Parsed content is retained as part of your resume data. Original imported files are deleted after extraction, and no later than within twenty-four hours. In case of import failure or where temporary retention is necessary for technical troubleshooting, they may be retained for a maximum of seven days. |
4.7 Job application tracking
ExactMatchCV allows you to create, manage and track job applications.
| Item | Description |
|---|---|
| Categories of data | Application tracking data, such as job title, company, application date and status, notes, job posting URL, job description, associated resume, evaluation scores, adaptation review, comments and suggestions. |
| Purpose | To track your job application pipeline, associate the correct resume with the correct job posting, maintain your application history, improve resumes based on job postings, and measure resume relevance before and after optimisation. |
| Legal basis | Performance of the contract, Article 6(1)(b) GDPR. |
| Recipients | Serenae Gestion. Mistral AI may receive relevant data where you use evaluation or adaptation features. |
| Retention | Application data is retained for as long as your account remains active or until you delete or archive the relevant application. Deleted application data is removed or anonymised within thirty days, unless retention is required for security, legal or dispute-management purposes. |
Free-text notes may contain personal data. You should avoid adding unnecessary sensitive information about yourself or third parties.
4.8 Job search, recent searches and job alerts
ExactMatchCV provides job search and alert features.
| Item | Description |
|---|---|
| Categories of data | Job search and alert data, such as search keywords, selected locations, filters, sorting preferences, recent searches, job alert settings, alert status, notification history and job offer information returned by external job sources. |
| Purpose | To search and filter job offers, create personalised job alerts, retrieve recent searches, and manage bookmarked or set-aside job offers through application logic. |
| Legal basis | Performance of the contract, Article 6(1)(b) GDPR, for job search and alerts requested by the user. Legitimate interest, Article 6(1)(f) GDPR, for maintaining recent searches and improving service usability, subject to user controls where applicable. |
| Recipients | Serenae Gestion, France Travail for job offer search features where applicable, geo.api.gouv.fr for location resolution, and Brevo for email job alerts. |
| Retention | Job alert settings are retained until you delete the alert, disable the alert or close your account. Job alert delivery logs are retained for a maximum of twelve months. Recent searches are retained for a maximum of ninety days and may also be stored locally in your browser. |
Where job search data is obtained from third-party sources such as France Travail, such third parties may also process data in accordance with their own legal terms and privacy policies.
4.9 Billing, subscriptions and payments
If you subscribe to a paid plan, ExactMatchCV processes billing and subscription data. Payment operations are handled through Stripe.
| Item | Description |
|---|---|
| Categories of data | Billing and subscription data, such as subscribed plan, subscription status, billing frequency, renewal information, Stripe customer and subscription identifiers, limited payment method details, billing contact details, invoice information and payment history. |
| Purpose | To manage subscriptions, process payments, issue invoices, manage plan limits and quotas, provide customer support and comply with accounting obligations. |
| Legal basis | Performance of the contract, Article 6(1)(b) GDPR, for subscription and payment management. Compliance with legal obligations, Article 6(1)(c) GDPR, for accounting, tax and invoicing obligations. Legitimate interest, Article 6(1)(f) GDPR, for managing payment incidents and disputes. |
| Recipients | Serenae Gestion, Stripe, accounting and legal advisors where applicable, competent authorities where required by law. |
| Retention | Billing and accounting records are retained for the legal retention period applicable to accounting documents, generally ten years from the end of the relevant financial year under French law. Payment card data is processed by Stripe; ExactMatchCV does not intend to store full card numbers. |
4.10 Artificial intelligence features
ExactMatchCV includes AI-powered features, including resume suggestions, PDF metadata generation, resume translation, resume-to-job evaluation and generation of tailored resume versions.
| Item | Description |
|---|---|
| Categories of data | Data submitted to or generated by AI features, such as resume content, job descriptions, application context, target language or market, prompts, AI-generated outputs and technical usage metadata. |
| Purpose | To provide resume suggestions, reformulation, translation, resume-to-job evaluation, resume adaptation to a job posting, generation of document metadata, monitoring of AI usage and cost control. |
| Legal basis | Performance of the contract, Article 6(1)(b) GDPR, where AI processing is necessary to provide the feature requested by the user. Legitimate interest, Article 6(1)(f) GDPR, for usage monitoring, cost control, debugging and abuse prevention. |
| Recipients | ExactMatchCV and Mistral AI, acting as AI service provider. Mistral AI’s Data Processing Addendum is available here: https://legal.mistral.ai/terms/data-processing-addendum |
| Retention | AI input and output data may be retained as part of your resume, application or service history where necessary to provide the feature; they then follow the retention period applicable to the relevant resume, application or content. Technical AI usage logs are retained for a maximum of twelve months for monitoring, cost control, quota management, security and troubleshooting. |
ExactMatchCV does not use AI features to make legally binding decisions about you. AI outputs are provided to assist you. You remain responsible for reviewing, validating and correcting any AI-generated content before using it in a job application.
You should not submit unnecessary sensitive data to AI features.
4.11 Analysis of service use by signed-in users, administration and platform supervision
When you create an account and use the ExactMatchCV service, ExactMatchCV may process certain data relating to your use of the service in order to operate the platform, supervise its use, understand how features are used, diagnose technical issues, strengthen security and improve the service.
| Item | Description |
|---|---|
| Categories of data | Administration and usage data, such as user account information, role information, account activity, pages or features used, actions performed in the interface, errors encountered, usage paths, usage volumes, number of resumes and applications, quotas consumed, AI usage events, token consumption, estimated costs, provider configuration and platform statistics. |
| Purpose | To operate and supervise the platform, manage quotas, understand the effective use of the service, identify friction points, diagnose technical issues, correct malfunctions, administer users, monitor AI costs, prevent abuse, ensure service reliability and prioritize functional developments. |
| Legal basis | Performance of the contract constituted by the ExactMatchCV Terms and Conditions, Article 6(1)(b) GDPR, which the user accepts when creating their account. These processing activities are necessary for the provision, operation, maintenance, security and continuous improvement of the Service. |
| Recipients | Serenae Gestion. Mistral AI may receive AI-related data where necessary for the relevant AI feature. |
| Retention | Detailed administration and usage logs are retained for a maximum of twelve months. Aggregated or pseudonymised statistics used for service improvement may be retained for a maximum of twenty-five months. Access to the administration interface must be strictly limited to authorised personnel. |
These processing activities are distinct from audience measurement on the public website. They concern use of the Service by a signed-in or identifiable user after account creation.
4.12 Security, fraud prevention and technical logs
ExactMatchCV processes technical data to secure the platform and maintain service reliability.
| Item | Description |
|---|---|
| Categories of data | Technical and security data, such as IP addresses, connection logs, user agents, authentication events, session identifiers, security tokens, error logs, API activity metadata and security events. |
| Purpose | To secure the platform, detect anomalies, prevent fraud, protect against unauthorised access, maintain availability, debug errors and ensure the proper functioning of the service. |
| Legal basis | Legitimate interest of ExactMatchCV in securing its service and users’ data, Article 6(1)(f) GDPR. Legal obligation, Article 6(1)(c) GDPR, where retention of certain logs is required by applicable law. |
| Recipients | Serenae Gestion, hosting and infrastructure providers where applicable, security providers where applicable, competent authorities where legally required. |
| Retention | Technical and security logs are retained for a maximum of twelve months. In case of an incident, abuse, fraud, security threat or dispute, strictly necessary elements may be archived with restricted access for a maximum of five years, unless a legal obligation requires a different period. |
4.13 Customer support and communications
If you contact ExactMatchCV for support or information, ExactMatchCV processes the data necessary to handle your request.
| Item | Description |
|---|---|
| Categories of data | Support and communication data, such as name, email address, account information, content of messages, attachments or screenshots you provide, technical context, URL or debugging information where collected, date and time of the request and support history. |
| Purpose | To respond to support requests, troubleshoot issues, provide assistance, improve the service and maintain a support history. |
| Legal basis | Performance of the contract, Article 6(1)(b) GDPR, where the request relates to your use of the service. Legitimate interest, Article 6(1)(f) GDPR, for general enquiries, troubleshooting and service improvement. |
| Recipients | ExactMatchCV and Brevo where support communications are handled by email. |
| Retention | Support data is retained for the time necessary to process the request, then for three years from the last exchange, unless longer retention is required for dispute management or legal obligations. |
5. Cookies and local browser storage
ExactMatchCV uses cookies and browser storage technologies to operate the service.
5.1 Cookies
The platform may use:
- language preference cookies;
- authentication cookies;
- CSRF protection cookies;
- session cookies;
- interface preference cookies;
- audience measurement cookies or similar technologies, where applicable.
Strictly necessary cookies are used to provide the service and secure your session. They do not require consent where they are essential to the operation of the service.
Audience measurement on the public website is carried out using Umami hosted by Serenae Gestion. It is configured to produce only anonymous or aggregated statistics, without individual tracking of your browsing beyond what is necessary for the operation and improvement of the website. The data collected for this audience measurement is not shared with third parties and is not cross-referenced with other data.
5.2 Local storage and session storage
Certain information may be stored locally in your browser, including:
- resume creation drafts;
- job search state;
- resume adaptation or tailoring review data.
This local storage allows the platform to improve usability and avoid losing temporary work.
Deleting data from your ExactMatchCV account may not automatically delete data already stored locally in your own browser. You can delete such data by clearing your browser storage or using browser settings.
6. Recipients and processors
Personal data may be accessed or processed by the following categories of recipients, strictly within the limits necessary for their role:
- ExactMatchCV and authorised personnel;
- hosting and infrastructure providers, where services are provided by third parties;
- Google, where you choose Google sign-in;
- Stripe, for payments, checkout, subscription management and customer portal;
- Brevo, for transactional emails, job alerts and email communications;
- France Travail, for job offer search features where applicable;
- geo.api.gouv.fr, for location resolution;
- Mistral AI, for artificial intelligence features;
- support or customer communication tools, if implemented;
- accounting, legal or technical advisors where necessary;
- public authorities, courts or regulators where required by law.
Technical services operated directly by Serenae Gestion, including the application backend and internal platform services, are considered part of ExactMatchCV and are not listed as separate recipients.
ExactMatchCV selects service providers that provide sufficient guarantees regarding security, confidentiality and GDPR compliance. Where required, ExactMatchCV enters into data processing agreements with its processors in accordance with Article 28 GDPR.
Mistral AI’s Data Processing Addendum is available at: https://legal.mistral.ai/terms/data-processing-addendum
7. International transfers
Some service providers may process personal data outside the European Economic Area.
Where personal data is transferred outside the European Economic Area to a country that does not benefit from an adequacy decision, ExactMatchCV ensures that appropriate safeguards are implemented, such as:
- standard contractual clauses adopted by the European Commission;
- additional technical and organisational measures where necessary;
- verification of the provider’s transfer mechanisms and security commitments.
The exact list of international transfers and safeguards should be maintained in Serenae Gestion’s internal processor register and made available where required.
8. Data retention
ExactMatchCV retains personal data only for as long as necessary for the purposes for which it was collected.
As a general rule:
| Data category | Retention principle |
|---|---|
| Account data | Retained while the account is active. After twenty-four months of inactivity, notification then disabling or deletion/anonymisation after thirty days without response. After account deletion by the user, deletion or anonymisation within thirty days, unless legal, accounting, security or dispute-management retention applies. |
| Resume, profile and application data | Retained while the account is active or until deleted by the user. After account deletion, deletion or anonymisation within thirty days, subject to technical backups and applicable legal obligations. |
| Technical backups | Progressive purge within a maximum of ninety days after effective deletion from the active database. |
| Imported resume files | Deleted after extraction, no later than within twenty-four hours. In case of failure or technical troubleshooting, retained for a maximum of seven days. |
| PDF/ODT export files | Temporary retention strictly necessary for download, no later than twenty-four hours after generation. |
| Job alerts | Retained until the alert is deleted, disabled or the account is closed. Delivery logs retained for a maximum of twelve months. |
| Recent searches | Retained for a maximum of ninety days. Some data may be stored locally in the user’s browser. |
| Public website audience measurement | Raw data or session-level data retained for a maximum of thirteen months. Anonymous or aggregated statistics retained for a maximum of twenty-five months, then deleted or irreversibly anonymised. |
| Usage data of signed-in users | Detailed logs retained for a maximum of twelve months. Aggregated or pseudonymised service-improvement statistics retained for a maximum of twenty-five months. |
| AI usage logs | Retained for a maximum of twelve months for monitoring, troubleshooting, cost control, quota management and security. AI content retained in a resume or application follows the retention period of the relevant resume or application. |
| Technical and security logs | Retained for a maximum of twelve months. In case of an incident, abuse, fraud, security threat or dispute, restricted archiving of necessary elements for a maximum of five years, unless a legal obligation requires a different period. |
| Billing and accounting records | Retained for the applicable legal retention period, generally ten years from the end of the relevant financial year under French law. |
| Payment card data | Full payment card numbers are not stored by ExactMatchCV. Limited transaction data necessary for billing follows the accounting-record retention period. |
| Support requests | Retained for the time necessary to process the request, then three years from the last exchange, unless longer retention is necessary for dispute management or compliance with a legal obligation. |
Where data is no longer necessary, it is deleted, anonymised or archived with restricted access where retention is required by law or necessary for legal claims.
9. Security measures
ExactMatchCV implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These measures may include, depending on the relevant processing:
- authentication and session protection;
- CSRF protection;
- access control and role-based administration;
- limitation of administrative access to authorised personnel;
- secure password storage;
- secure communication protocols;
- logging and monitoring of security events;
- separation of environments where applicable;
- contractual safeguards with processors;
- minimisation of data sent to third-party services;
- regular review of technical and organisational measures.
No system is completely secure. Users must also take appropriate steps to protect their account, including using a strong password, keeping credentials confidential and signing out from shared devices.
10. Your rights
In accordance with the GDPR, you have the following rights regarding your personal data:
- right of access, Article 15 GDPR;
- right to rectification, Article 16 GDPR;
- right to erasure, Article 17 GDPR;
- right to restriction of processing, Article 18 GDPR;
- right to data portability, Article 20 GDPR;
- right to object, Article 21 GDPR;
- right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects, Article 22 GDPR;
- right to withdraw consent at any time, where processing is based on consent, Article 7(3) GDPR;
- right to define instructions concerning the fate of your personal data after death, where applicable under French law.
To exercise your rights, you may contact ExactMatchCV at:
privacy@exactmatchcv.com
For security reasons, ExactMatchCV may ask you to provide additional information to confirm your identity before processing your request.
ExactMatchCV will respond to your request within the time limits provided by the GDPR.
You also have the right to lodge a complaint with the French data protection authority:
Commission Nationale de l’Informatique et des Libertés (CNIL) 3 Place de Fontenoy TSA 80715 75334 Paris Cedex 07 France https://www.cnil.fr
11. Consent withdrawal and preferences
Where processing is based on your consent, you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Where available, you may manage certain preferences directly from your ExactMatchCV account, including job alert preferences, account settings and communication preferences.
12. Data provided by the user
ExactMatchCV is designed for job-search and resume-management purposes. You should only provide data that is relevant to these purposes.
In particular, you should avoid including unnecessary sensitive data in your resumes, notes, job applications, imported files or AI prompts, such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation, unless strictly necessary and voluntarily provided by you.
If you include personal data relating to third parties, you are responsible for ensuring that you are authorised to do so.
13. Children
ExactMatchCV is not intended for children. The service is intended for users who are legally capable of entering into a contract or who use the service under the supervision and responsibility of a legal representative where applicable.
ExactMatchCV does not knowingly collect personal data from children without appropriate authorisation.
14. Changes to this Privacy Policy
ExactMatchCV may update this Privacy Policy from time to time, in particular to reflect changes in the service, legal requirements, processors or data processing operations.
Where changes are material, ExactMatchCV may inform users by any appropriate means, such as email, in-app notification or website notice.
15. Change history
| Date | Changes |
|---|---|
| 8 June 2026 | Clarification of data collected after sign-in to the user account and details on retention periods. |
| 28 May 2026 | Initial version of the ExactMatchCV Privacy Policy. |