RemakeCV

GDPR, data retention and where CVs are stored

How RemakeCV handles candidate personal data: what is stored, for how long, who controls it, and how to configure retention for your agency.

Candidate CVs are personal data and your agency is the data controller; RemakeCV processes them on your instructions. Stored CVs are deleted automatically after a per-company retention period, which defaults to 30 days. CV storage can also be switched off entirely, in which case nothing is retained after processing.

Note:

This page explains how the product behaves so you can configure it correctly. It is not legal advice. Your retention periods and lawful basis are decisions for your own DPO or legal adviser.

Who is the controller?

Your agency. You decide which candidates to process, for what purpose, and how long to keep the results. RemakeCV acts as a processor, handling that data on your instructions.

Practically, this means the obligations that sit with you include:

  • Having a lawful basis for processing candidate data
  • Telling candidates their CV will be reformatted and shared with clients
  • Honouring subject access, rectification and erasure requests
  • Setting and enforcing a retention period

How long are CVs kept?

Stored CVs are deleted automatically. A retention window is applied per company and defaults to 30 days from when a CV was last updated. When the window passes, both the stored file and its database record are permanently removed — not archived, not soft-deleted.

SettingDefaultEffect
Retention window30 days from last updateFile and record permanently deleted
CV storage disabledNothing retained at all; no CV history
Temporary preview files24 hoursDeleted automatically
Warning:

This is the fact most often needed for a client security questionnaire or a DPO review: RemakeCV does not retain candidate CVs indefinitely by default. If your agency needs a longer or shorter window than 30 days, email support@remakecv.com — it is configurable per company, but only we can change it.

Two practical consequences:

  • A CV you processed six weeks ago is gone. Download anything you need to keep into your own systems, or your ATS.
  • Retention is not a substitute for your own records. RemakeCV is a formatting step, not an archive.

What does RemakeCV store?

DataStored?
The uploaded CV fileOnly if CV storage is enabled, and only within the retention window
Extracted structured dataSame — including the original pre-edit extraction alongside your edits
Candidate name, latest employer, latest roleWith the stored CV record, for search in history
Your templates and company settingsYes
User accountsYes
Credit usage logsYes — user, company and timestamp, for billing
Warning:

Disabling CV storage removes CV history as well. Consultants must download the formatted CV before leaving the page, because there is nothing to come back to. Make sure the team knows before you change the setting.

How do I handle an erasure request?

If a candidate asks you to delete their data:

  1. Locate the CV in your history

    Note the candidate and roughly when it was processed.

  2. Email support@remakecv.com

    There is no self-serve delete in the product today, so erasure requests come to us. We will confirm deletion of the stored record and the underlying file.

  3. Delete your own copies

    Anything you downloaded, sent to a client, or filed in your ATS sits outside RemakeCV and is yours to handle. This is usually the larger part of the request.

Note:

If the CV is older than your retention window it has already been deleted automatically, and there is nothing left for us to remove.

Does anonymisation make data non-personal?

Not automatically, and this is a common misconception. Removing a name does not make data anonymous under GDPR if the person remains identifiable from what is left — and a detailed career history is often identifying on its own.

Treat anonymised CVs as pseudonymised personal data unless you have specifically assessed otherwise. They are a bias-reduction tool, not a get-out from data protection obligations.

Where is data processed?

For details of hosting, sub-processors and the AI providers involved in processing, see security and sub-processors. If you need a signed Data Processing Agreement, email support@remakecv.com.

Frequently asked questions

Is RemakeCV a data controller or a data processor?
A processor. Your agency decides which CVs to process and why, which makes you the controller. RemakeCV processes them on your instructions.
How long does RemakeCV keep candidate CVs?
Stored CVs are deleted automatically after a per-company retention window, which defaults to 30 days from last update. Both the file and its record are permanently removed. The window is configurable — email support@remakecv.com.
Can I turn off CV storage entirely?
Yes. CV storage is a company-level setting. With it disabled, processed CVs are not retained at all — which also means there is no CV history to return to.
Can I delete a specific CV myself?
Not today. There is no self-serve delete, so erasure requests go to support@remakecv.com. CVs older than your retention window have already been deleted automatically.
Are candidate CVs used to train AI models?
No. CVs are processed to produce your formatted document and are not used as training data.

Related articles

Was this page helpful?

Last updated . Still stuck? Email support@remakecv.com or book a call.