Last updated · 22 May 2026

Privacy Policy

This is the privacy notice for this personal CV website. It explains, in plain language, what data is processed when you visit, what legal basis applies under the EU General Data Protection Regulation (GDPR), and what rights you have.

1. Who is responsible

The data controller under Art. 4(7) GDPR is:

Hannes Krengel
hannes.krengel@gmail.com

2. What data is processed

a) Server logs

When you load any page, the hosting infrastructure (Lovable / Cloudflare) receives standard request data such as your IP address, user-agent, the URL requested, and a timestamp. This data is processed on the legal basis of legitimate interest (Art. 6(1)(f) GDPR) to deliver and secure the site.

b) Job-ad projection feature

If you use the "drop your job ad" feature on the homepage, the following is sent to the server and stored in a database hosted in the EU:

  • the URL or text of the job ad you submit,
  • the AI-generated projection (predicted role, fit score, skills, narrative),
  • a short random share token used to build the share URL,
  • a timestamp.

No email or other contact information is required to use this feature. Legal basis: your consent (Art. 6(1)(a) GDPR), given by submitting the form. The projection text is generated by an AI provider (Google / OpenAI via the Lovable AI Gateway); the job ad text is transmitted to that provider for the sole purpose of generating the response.

c) Local storage in your browser

To remember the last projection between page reloads, the site stores three keys in your browser's sessionStorage: cv:projection, cv:shareToken, and cv:projectionExpanded. These are strictly necessary for the feature to work, are not cookies, do not leave your device, and are cleared automatically when you close the tab.

d) No tracking

This site does not use advertising cookies, analytics scripts, tracking pixels, social-media plugins, or fingerprinting.

3. Recipients and transfers

Data is processed by the following processors acting on our behalf under Art. 28 GDPR:

  • Lovable AB (Sweden, EU) — hosting and database.
  • Cloudflare, Inc. (USA) — CDN and edge runtime.
  • Google LLC / OpenAI LLC (USA) — AI model inference for the projection feature only.

Transfers to the USA rely on the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses.

4. How long data is kept

  • Server access logs: up to 30 days by the hosting provider.
  • Job-ad projections: kept until you request deletion (see your rights below). The share URL is unguessable; the projection is not indexed.
  • sessionStorage entries: until you close the browser tab.

5. Your rights under the GDPR

You have the right to:

  • access your data (Art. 15),
  • have it rectified (Art. 16),
  • have it erased (Art. 17),
  • restrict or object to processing (Art. 18 & 21),
  • receive a portable copy (Art. 20),
  • withdraw consent at any time, without affecting prior processing.

To exercise any of these, email hannes.krengel@gmail.com. You also have the right to lodge a complaint with your local EU data protection authority (Art. 77).

6. Changes to this notice

This notice may be updated to reflect changes to the site or to legal requirements. The "last updated" date at the top of the page always reflects the current version.