MatchPack privacy

What is stored, for how long, and who remains responsible.

This page describes the current MatchPack product. It is product information, not legal advice. Your agency remains the controller for candidate data and must establish its own lawful basis, candidate notice and client-sharing instructions.

Source file handling

An uploaded PDF or DOCX is used to extract text. The original file is not retained as a downloadable source. MatchPack stores the vacancy text, structured candidate data, contact-reduced version, analysis, evidence references, revisions and approval information needed for review.

Retention and deletion

New Agency subscriptions use a 90-day content retention setting by default. The owner may select 30, 90, 180, 365 days in settings. Content expiry covers candidate data, vacancy text, evidence references, revisions and derived CV content. billing, subscription, payment and non-content usage records remain where required for administration and allowance auditing.

Contact-reduced is not anonymous

The contact-reduced output clears known name and contact fields and removes recognisable contact-like text. Employers, schools, projects and rare combinations may still identify a person. Review both full and contact-reduced PDF/DOCX files before client sharing.

Roles and access

Owners manage settings, templates, team members and deletion. Editors create and change work. Reviewers inspect evidence and approve. Viewers have read access. Remove access promptly when a team relationship ends.

Current verification status

Processors and subprocessors

Depending on deployment, MatchPack may use providers for AI processing, payments, login email and hosting/PostgreSQL. Legal entity, processing region, transfer mechanism and contract status must be checked against current provider contracts before live candidate use. WerkCV does not infer those facts from a hostname or environment variable.

Swipe horizontally to view all columns.

CategoryPurposeVerification status
OpenAIAI-assisted extraction and vacancy-evidence analysisdeployment verification required
Dodo PaymentsAgency subscription checkout and payment statusdeployment verification required
Configured email providerLogin-code deliverydeployment verification required
Configured hosting/PostgreSQL providerAccount, MatchPack and revision storagedeployment verification required

DPA request

Review the current documents before live use.

Current status: legal review required. Request the current processor details and DPA through contact@werkcv.nl. Until the required information and contracts have been checked for your use case, use fictional or properly authorised CVs for testing.