For agencies

Agency data and privacy

Last updated 21 September 2026. When you use Smart CV Writer for Agencies you upload other people's CVs. This page explains, in plain language, what happens to them. It sits alongside our general Privacy Policy and How we use AI.

Who is responsible for what

For the candidate data you upload, your agency decides why and how it is used, so you are the controller. Smart CV Writer processes it on your behalf and only to provide the service to you, so we act as your processor. We put a data processing agreement in place with every agency before real candidate data goes in; ask us for it when you request access.

Your own account data (your name, email and login) is different: for that, we are the controller, as described in the Privacy Policy.

What we store

  • Job postings you upload, and the fields we extract from them: title, client, location, budget, requirements.
  • Candidate profiles built from the CVs you upload: name, contact details, current role, summary, skills and work history. We keep the profile, not the original file.
  • Match results: the score and short explanation for each candidate against a vacature.
  • Your agency's branding: logo, accent colour and tagline.
  • Short-lived processing records. While a CV or posting is being read, the result is held briefly so your browser can pick it up. These expire automatically within a day or two.

Your data is separate from every other agency's

  • Everything you upload is visible only to people on your agency's workspace.
  • If two agencies upload the same person's CV, each gets its own separate copy. They are never linked or merged, and neither agency can see the other's.
  • Candidate profiles are not connected to any Smart CV Writer account. Nobody is invited, emailed or contacted because you uploaded their CV.

What the AI does with it

We use AI (Amazon Bedrock) for three things: reading a job posting into structured fields, reading a CV into a candidate profile, and comparing your candidates with a vacature to produce the scores and explanations.

  • It suggests, you decide. Every extracted field is shown to you to review before it is saved, and a match score is a starting point for your own judgement. Nothing is decided about a person automatically.
  • Not used for training. We do not use your data to train any AI model, ours or anyone else's.
  • More detail on where AI touches data: How we use AI.

Where it lives

All storage and processing runs on Amazon Web Services infrastructure in the EU (Paris, eu-west-3): Cognito for logins, DynamoDB for your workspace's data and Bedrock for the AI steps. These are sub-processors acting on our instructions.

What goes into a client shortlist

A shortlist PDF contains each selected candidate's name, current role, location, summary, skills and the reason they match. Their email address and phone number are left out, so a client sees who you recommend while the introduction stays with you.

Removing data

  • A candidate: open their profile and choose Delete. Their profile is removed from your workspace, along with any saved match results that mention them.
  • A vacature: same, from its page.
  • Everything: if you leave, tell us and we will delete your agency's workspace and all the data in it. There is no self-service button for this yet, so it is done by hand.

A candidate who asks you to see, correct or delete what you hold about them should ask you first, as the controller. We will help you act on the request promptly.

How long we keep it

For as long as your agency's workspace exists, unless you delete something sooner. We do not keep copies elsewhere for our own purposes.

Questions

Write to teams@smartcvwriter.com. A person reads every message.

← Back to Smart CV Writer for Agencies