1. Overview
HighPassCV is a destination-aware CV-building service. It allows users to create an account, maintain a reusable Master Profile, select an application destination, generate a read-only CV preview, and download PDF or Word files.
HighPassCV does not sell personal data. At launch, HighPassCV does not use advertising cookies, behavioural advertising, or third-party analytics.
This policy should be read with our Terms of Service and Cookie and Browser Storage Policy.
2. Data controller
HighPassCV is operated by the following data controller:
- Legal name: Glofare OÜ
- Registry code: 17351459
- Registered address: Ehitajate tee 140-220, 13517 Tallinn, Harju maakond, Estonia
- Country of establishment: Estonia
- Privacy and support email: amirhosenzakeri@gmail.com
- Data Protection Officer: no DPO has been appointed. Privacy requests should be sent to the email above.
3. Personal data we process
Account and security data
- Email address, user ID, account-creation time, and email-confirmation status.
- Authentication, password-reset, session, and security-event information.
Master Profile and CV data
- Name, professional title, contact details, city, and country.
- Education, work experience, projects, publications, skills, and languages.
- Professional summary and other information the user chooses to provide.
- An optional profile photo stored in a private storage bucket.
Application and document data
- Selected country, city, university, faculty, programme, degree level, and document type.
- Draft metadata, selected template, rule-resolution details, and destination-compliance results.
- Records that a PDF or Word export occurred. The downloaded file is generated for the user and is not ordinarily stored as a public file by HighPassCV.
Support and technical data
- Support-form information, correspondence, and information necessary to investigate a request.
- Browser, device, IP-address, request, security, and error information generated by hosting and infrastructure providers.
- Browser-storage values used for authentication, preferences, and unfinished local drafts.
Paid plans are not available at launch. HighPassCV does not currently collect payment-card data or subscription payments.
4. Purposes and legal bases
- Provide the service and perform the user agreement: account access, profile storage, destination selection, previewing, and document export.
- Legitimate interests: service security, fraud and abuse prevention, debugging, support, product reliability, and protecting legal rights.
- Legal obligations: responding to lawful requests, data-protection rights, and obligations applying to the operator.
- Consent: where the user voluntarily uploads optional information or where future non-essential cookies or communications require consent.
Users should not add unnecessary special-category data, identity-document numbers, payment-card details, or other sensitive information to a CV or support request.
5. CV generation and destination guidance
HighPassCV combines Master Profile data with a template and destination-guidance record. Programme-specific official instructions take priority over general country or university guidance.
PDF and Word downloads are produced for the user. The service may keep export metadata and a compliance snapshot, such as which sections were present, which rule was used, and whether warnings or blockers were detected. Compliance snapshots do not intentionally store the full text of the user's CV.
HighPassCV does not make automated decisions that create legal or similarly significant effects. Admissions, employment, and funding decisions are made independently by third parties.
6. Service providers and recipients
HighPassCV uses service providers only where reasonably necessary to operate the service:
- Supabase: authentication, PostgreSQL database, row-level access controls, and private file storage.
- Netlify: website hosting, content delivery, security, deployment, and support-form processing.
- Cloudflare cdnjs: delivery of the Font Awesome interface-icon stylesheet. A request to the CDN may include technical data such as an IP address and browser information.
HighPassCV may also disclose data to professional advisers, public authorities, courts, or other recipients where required by law or reasonably necessary to protect rights, users, and the service.
HighPassCV does not sell personal data and does not share CV content with advertisers.
7. International data transfers
Some providers may process data in countries outside Estonia or the European Economic Area. Where required, HighPassCV relies on recognised transfer mechanisms, contractual safeguards, provider commitments, and appropriate security measures.
8. Data retention
- Account, Master Profile, drafts, and export metadata: retained while the account is active and deleted or anonymised when the account is deleted, unless a longer period is required for security or legal reasons.
- Profile photo: retained until the user removes it or the account is deleted.
- Local support drafts: remain only in the user's browser until cleared by the user or browser settings.
- Support messages: normally retained for up to 24 months after the request is closed, unless a longer period is necessary for a dispute, security incident, or legal obligation.
- Security and infrastructure logs: normally retained for up to 12 months, subject to the provider's documented security and retention practices.
- Backups: deleted data may remain in protected rotating backups for up to 90 days before being overwritten.
HighPassCV may retain limited records where necessary to establish, exercise, or defend legal claims, comply with law, or prevent repeated abuse.
9. Security
Security measures include HTTPS, private storage for profile photos, database row-level security, authenticated access controls, restricted database functions, security headers, and separation between public pages and private account data.
No online service can guarantee absolute security. Users should use a strong unique password, protect their email account, and report suspected unauthorised access.
10. Your privacy rights
Subject to applicable law, users may request access, correction, deletion, restriction, portability, or an objection to certain processing. Where processing is based on consent, consent may be withdrawn for future processing.
Account Settings provide an account-data export. Verified deletion and other privacy requests may be sent from the account email address to amirhosenzakeri@gmail.com .
HighPassCV may request information necessary to verify identity and protect the account before responding.
11. Cookies and browser storage
At launch, HighPassCV uses only storage necessary for authentication, security, preferences, and user-requested functionality. HighPassCV does not use advertising or behavioural-analytics cookies.
Details are provided in the Cookie and Browser Storage Policy .
12. Children
HighPassCV is intended for users aged 16 or older. A user below 16 should not create an account without the involvement and permission of a parent or legal guardian where required by applicable law.
13. Changes to this policy
This policy may be updated when the service, providers, processing activities, or legal requirements change. Material changes may be announced through the website or account email.
14. Contact and complaints
- Controller: Glofare OÜ
- Registry code: 17351459
- Address: Ehitajate tee 140-220, 13517 Tallinn, Harju maakond, Estonia
- Email: amirhosenzakeri@gmail.com
Users also have the right to complain to the competent data-protection authority. In Estonia, the supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).