Effective date: 6 July 2026 Version: 1.2
Introduction
This Privacy Policy explains how Sireda AB, the company operating Civium, collects, uses, stores, and protects personal data. It also describes your rights under applicable data protection laws, including the General Data Protection Regulation (GDPR).
Sireda AB operates Civium and acts as the data controller for personal data processed through the platform. Sireda AB is a Swedish limited company registered in Sweden (organisation number 559589-4899), with its registered office in Gothenburg, Sweden.
Civium is not intended for children under 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data through the platform, please contact us at privacy@mycivium.com so we can delete it.
Data We Collect
We collect the following types of personal data:
- Account data such as email address
- Authentication flow data: during sign-in via Magic Link, a temporary record associating your email address with a cryptographic token reference is created and automatically deleted within 15 minutes when the link is used or expires
- Preference data, including selected roles, skills, and organizations
- Derived profile data, such as skills and experience extracted from your CV, and a mathematical embedding vector (a numerical representation of your CV used internally for job matching)
- Subscription and billing metadata required for account access and invoicing
- Technical and usage data used for security, diagnostics, and reliability, including IP addresses, browser and device type (from request user-agent), request timestamps, and application error diagnostics
- Consent and legal acceptance records, including records of your acceptance of billing terms, and — where you are located in the EU, EEA or UK — the withdrawal waiver required by applicable consumer law, together with the version of Terms of Service and Privacy Policy in effect at the time of acceptance, a hash of your IP address and browser information recorded at the moment of acceptance for the purpose of demonstrating valid consent under applicable law
How We Use Data
We use personal data to:
- Provide job matching and related account features
- Process CV data to extract relevant skills and experience
- Send user-selected email notifications and match digests based on your preferences
- Operate subscriptions, payments, and account lifecycle flows
- Maintain platform security and prevent abuse
- Comply with legal and regulatory obligations
We use automated processing to analyze your CV and generate a profile used for matching job opportunities. See the Automated Processing section below for more detail.
Communications
We send service-related emails, such as account updates and subscription information. Optional notifications, such as match alerts and digests, are only sent based on your preferences and can be adjusted or disabled at any time.
Legal Basis (GDPR)
We process personal data on the following legal bases, mapped to each purpose:
| Purpose | Legal basis |
|---|---|
| Account creation and authentication | Contract performance |
| Job matching and recommendations (subscribed users) | Contract performance |
| Job matching preview for registered users prior to subscription | Legitimate interests (demonstrating service value; steps preparatory to a potential subscription contract) |
| CV parsing and profile extraction | Contract performance |
| Sending optional match alerts and digests | Consent |
| Google Ads conversion tracking | Explicit consent (Consent Mode v2) |
| Service-related communications | Contract performance / Legitimate interests |
| Fraud prevention and platform security | Legitimate interests |
| Diagnostics and reliability monitoring | Legitimate interests |
| Accounting and invoicing records | Legal obligation |
| Storing consent and legal acceptance records | Legal obligation |
| Compliance with legal requests | Legal obligation |
Automated Processing and Profiling
Civium uses automated systems to analyze your profile data (including extracted skills, experience, and stated preferences) and rank job opportunities based on relevance to your profile.
- What is automated: Matching score calculation and opportunity ranking.
- Data used: Derived profile data, preference selections, and available job listings.
- Effect on you: Determines the order and selection of job opportunities shown to you. This affects recommendation ordering only.
- No legally significant decisions: This processing does not produce legal effects or similarly significant effects on you. Civium does not make automated decisions about employment, access to services, or creditworthiness.
- Concerns: You may contact us at privacy@mycivium.com to raise concerns about your profile data, matching inputs, or recommendation quality.
Data Sharing
We do not sell personal data.
We may share data with the following categories of service providers and third parties:
- Cloud infrastructure and authentication (Amazon Web Services, including AWS Cognito) — Hosts application data, processing, and user authentication in the EU (eu-north-1, Stockholm region). API requests are routed through AWS CloudFront, a content delivery and security network, using edge nodes restricted to EU and North American locations for DDoS protection and request security screening (AWS WAF). No personal data content is stored in CDN edge nodes; all personal data storage remains in eu-north-1. As part of operational resilience, daily snapshots of account data are written to an encrypted S3 bucket within the same AWS region (eu-north-1). These snapshots are retained for up to 35 days and are used solely for disaster recovery purposes. Upon account deletion, your data is removed from active systems immediately; backup copies are automatically purged within 35 days.
- AI processing (AWS Bedrock, Amazon Web Services, eu-west-2 London region) — Processes CV text to extract skills and experience, and generates embedding vectors used for job matching. CV text is transmitted to foundation models (Amazon Nova Lite and Amazon Titan Embed Text v2) hosted within the EU (eu-west-2). No raw CV files are stored by this service; only the derived profile attributes are retained by Civium. For operational monitoring, Civium retains Bedrock invocation metadata (model used, timestamp, processing duration, and token counts) for up to 90 days. No CV text or content is included in these logs.
- Payment processor (Stripe) — Handles subscription billing. Stripe acts as an independent data controller for payment data and processes it under its own privacy policy and PCI-DSS compliance.
- Email delivery (Amazon SES — Amazon Web Services) — Delivers transactional and notification emails on our behalf. Email content and recipient addresses are processed within the EU (eu-north-1) consistent with our primary AWS infrastructure.
- Analytics provider (Plausible Analytics) — Privacy-friendly, cookieless analytics. Plausible does not use cookies and is configured to avoid storing personally identifiable analytics data, including full IP addresses.
- Conversion tracking provider (Google Ads, Google LLC) — Tracks conversion events (trial signups, feature preview access) for advertising campaign optimization. Google acts as an independent data processor and uses cookies only when you have consented to marketing cookies. See Google's Privacy Policy for details on how Google processes this data.
- Competent authorities — Where required by applicable law.
Where providers process personal data on our behalf, they do so under contractual safeguards.
International Data Transfers
Our primary infrastructure is hosted within the European Economic Area (EEA) on Amazon Web Services in the Stockholm region (eu-north-1).
Certain service providers (including Stripe and AWS global services) may process data in countries outside the EEA, including the United States. This includes AWS CloudFront and AWS WAF, which process API request metadata (including IP addresses) through edge and configuration infrastructure in the United States for security screening purposes. Where such transfers occur, appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or adequacy decisions as applicable.
Cookies and Conversion Tracking
Essential Cookies
We use essential cookies required for authentication and session security. These cookies are necessary for the service to function and cannot be disabled. They are processed on the basis of contract performance.
Optional Marketing Cookies
We use Google Ads conversion tracking to measure key events (trial signups, feature preview access) for advertising optimization. These cookies are optional and only set when you explicitly consent to "marketing cookies" in your consent preferences.
Legal basis: Your explicit consent (Consent Mode v2) Data processor: Google LLC Purpose: Measure conversions for ad campaign optimization Duration: Depends on your consent withdrawal and Google's retention policies
Privacy-Friendly Analytics
We use Plausible Analytics, a privacy-friendly analytics tool that does not use cookies and is configured to avoid storing personally identifiable analytics data, including full IP addresses.
For more details, including how to manage your preferences, see our Cookie Policy.
Data Retention
We retain personal data only as long as necessary for the purposes described in this policy:
- Magic Link authentication records — Temporary sign-in records (email address and cryptographic token reference) are automatically purged within 15 minutes when the sign-in link is used or expires.
- CV files — Original CV files are deleted from active processing systems after extraction is complete, subject to short-lived operational backups or recovery systems where applicable.
- Derived profile data (extracted skills, experience) — Retained for as long as your account is active.
- Account and subscription data — Retained for the duration of your account and for up to 3 years after account closure for dispute resolution purposes.
- Invoices and billing records — Retained for 7 years in accordance with Swedish accounting law (Bokföringslagen).
- Consent records (billing consent, withdrawal waiver, and related metadata) — Retained for 7 years to demonstrate compliance with legal obligations.
- Operational logs — Retained for 90 days for security and diagnostics purposes.
- Account data export snapshots — Daily operational snapshots of account data (email address, account status, group membership) are retained for up to 35 days for disaster recovery purposes. A rolling "latest" snapshot is overwritten daily and expires within 2 days if not refreshed. Accounts deleted before a snapshot runs are not included in subsequent snapshots.
- AWS Backup snapshots — Encrypted database snapshots taken as part of AWS Backup policies may retain copies of your personal data for up to 35 days after account deletion, after which they are automatically purged by lifecycle policy. These snapshots are stored in encrypted form, are inaccessible to Civium services during that window, and are not used for any operational purpose.
- Inactive trial accounts — May be deleted after 6 months of inactivity.
- Match history in exports — May be limited to recent activity.
Your Rights
Depending on your location and applicable law, you have the right to:
- Right to Access — Request a copy of all personal data we hold about you.
- Right to Rectification — Correct any inaccurate or incomplete data.
- Right to Erasure — Request deletion of your personal data ("right to be forgotten").
- Right to Data Portability — Export your data in a machine-readable format.
- Right to Object — Object to the processing of your personal data, in particular where processing is based on legitimate interests (Article 21 GDPR).
- Right to Restrict Processing — Request that we limit how we use your data.
- Right to Withdraw Consent — Where processing is based on your consent (such as sending optional match alerts and digests), you may withdraw that consent at any time by adjusting your notification preferences in your account settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Exercising Your Rights
You can exercise your rights through your account settings or by contacting us at privacy@mycivium.com. We will respond without undue delay and ordinarily within one month, subject to extensions permitted by applicable law.
Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. As Sireda AB is registered in Sweden, the lead supervisory authority is:
Integritetsskyddsmyndigheten (IMY) Website: imy.se
You may also contact the supervisory authority in your country of residence.
Data Security
We implement appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, and controlled access to systems.
Changes to This Policy
We may update this Privacy Policy from time to time. If significant changes are made, we will notify users through the platform or by email where appropriate.
Contact
For privacy-related questions, data protection inquiries, or requests, contact us at privacy@mycivium.com.