Back to the schools offer
Security and student data
Students trust their school with their job search. This page explains what we process, who sees what, and how access is controlled.
Data we process
- Account data: name and email address used to sign in.
- CV content a student uploads to localize it for a country.
- Applications a student logs or records with the extension: company, role, country, contract type, status and dates.
Who sees what
- The careers service sees who is enrolled in its school.
- It sees a student’s applications only if that student turned sharing on, and never their CV, letters or job ad texts.
- Aggregated statistics hide any group of fewer than 5 students; there is no student scoring or ranking.
- Students can turn sharing off at any time.
Access control
- Every school’s data is isolated: access is resolved from the user’s membership, never from what the browser sends.
- Invitations are single-use, expire after 30 days and only work for the email address they were sent to; only a hash of each link is stored.
- Advisor and admin roles are separate; detailed exports are reserved to admins.
- Sensitive actions (exports, viewing a student’s applications, consent changes) are recorded in an audit log.
Subprocessors
TopCV relies on these providers to run the service:
- Clerk — sign-in and account management
- Vercel — application hosting
- Prisma Postgres — database
- Amazon Web Services S3 (eu-west-1, Ireland) — file storage
- OpenAI — CV localization
- Resend — transactional email
- Stripe — payments for individual customers only
GDPR roles
The school is the data controller for its students; TopCV acts as a processor. Hosting regions and transfer safeguards for each subprocessor are documented in the data processing agreement signed with each school. Deletion requests can be sent through the contact page.