Privacy Policy
Our data commitments
1. Controller
The data controller is Patrik Duch s.r.o. (IČO: 24091090), with its registered office at Sládkova 372/8, Moravská Ostrava, 702 00 Ostrava, Czech Republic. Data Protection Officer: privacy@atsmate.app.
ATS Mate processes all personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and applicable Czech data protection laws. The competent supervisory authority is the Czech Office for Personal Data Protection (ÚOOÚ).
2. Data We Collect
2.1 Data you provide
- Account data — name, email address, hashed password
- Resume content — work experience, education, skills, personal statement and any text you enter into the builder
- Payment data — processed by Stripe; we store only a tokenised reference and plan tier, never your full card number
- Support correspondence — emails and feedback submissions
2.2 Data collected automatically
- Device & browser — User-Agent string, screen resolution, OS
- Network — IP address (for security, rate limiting, bot protection)
- Usage — pages visited, features used, timestamps
- Cookies — see our Cookie Policy
3. Legal Basis (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Providing the service (resume builder, PDF export) | Contract performance |
| Payment processing via Stripe | Contract performance |
| Account security & fraud prevention | Legitimate interest |
| Anonymised service improvement | Legitimate interest |
| Transactional emails (verification, reset, renewal) | Contract performance |
| Legal compliance (tax records) | Legal obligation |
4. How We Use Your Data
- Operate, maintain and improve ATS Mate
- Authenticate your identity and manage sessions (HttpOnly cookies)
- Process payments via Stripe
- Send transactional emails (account verification, password reset, renewal reminders)
- Detect and prevent abuse, bots and security threats
- Generate anonymised, aggregate analytics (no individual tracking)
What we will never do with your data:
- Sell, rent, licence or share it with recruiters, employers, agencies or job boards
- Train AI, machine-learning, or language models on your resume content
- Display advertising or share data with ad networks
- Profile you for purposes beyond operating the service
- Make it available in any “resume database” searchable by third parties
4b. Shared Resume Links & Analytics
When you create a shareable resume link, visitors to that link are tracked for your benefit. Specifically, we collect:
- Timestamp of the visit
- Visitor’s device type and browser (User-Agent)
- Approximate geographic location (derived from IP, not stored individually)
- View count
This data is visible only to you in your Share Links dashboard. It is never shared with third parties. The visitor does not create an account and we do not track them beyond the single page view. Nobody sees your resume unless you choose to share the link — the analytics exist to help you understand who did.
5. Data Storage & Location
Your resume data stays in the EU. Our application servers, frontend and database are hosted on Hetzner infrastructure in Europe. All data is encrypted in transit via TLS.
Stripe (payments) is a US-based processor. Payment data may pass through US infrastructure. This transfer is covered by Standard Contractual Clauses (SCCs). However, your resume content and personal profile data never leave EU servers.
6. Data Retention
- Active accounts — retained while your account is active.
- Deleted accounts — 30-day export window, then permanent erasure. Anonymised analytics and legal records (invoices) may be retained as required by law.
- Security logs (IP, User-Agent) — 90 days maximum, then purged.
7. Third-Party Processors
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Stripe | Payment processing | Card info (direct to Stripe), plan tier | US (SCCs) |
| Database hosting | Primary database | All account & resume data | EU |
We keep the processor list minimal. No analytics providers, no ad networks, no tracking pixels. If we add a processor, we update this table and notify you.
8. Security
We implement defence-in-depth security:
- bcrypt password hashing with per-user salt
- HttpOnly, Secure, SameSite cookies for session management
- CSRF double-submit token protection on all state-changing requests
- Rate limiting and automated bot detection with IP banning
- Content Security Policy (CSP), HSTS with preload, X-Content-Type-Options
- XSS and SQL injection middleware
- All data encrypted in transit via TLS
To report a vulnerability, see our security.txt. We appreciate responsible disclosure.
9. Your Rights (GDPR / CCPA)
You have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — delete your data (“right to be forgotten”)
- Portability — export your data in structured, machine-readable format (PDF, JSON)
- Restriction — restrict processing in certain circumstances
- Objection — object to processing based on legitimate interest
- Withdraw consent — where processing is based on consent
- Do Not Sell (CCPA) — we do not sell personal data, period
Submit a request via our Data Request form or email privacy@atsmate.app. We respond within 14 days (GDPR allows 30). You may also lodge a complaint with your local supervisory authority (CZ: UOOU).
10. Children
ATS Mate is not intended for children under 16. We do not knowingly collect data from children. Contact privacy@atsmate.app if you believe a child has provided data to us.
11. Changes
This policy is versioned (current: v1.0). Material changes require 30 days’ email notice with a plain-language summary. Changes that expand data usage require your explicit consent. Previous versions remain archived.
12. Contact
Data Protection Officer: privacy@atsmate.app
Company: Patrik Duch s.r.o.
Registered Address: Sládkova 372/8, Moravská Ostrava, 702 00 Ostrava, Czech Republic
Company ID (IČO): 24091090