Privacy Policy

How Amstel Lab protects your personal data

1. Introduction

Welcome to Amstel Lab ("we," "our," or "us"). We are committed to protecting your privacy and ensuring transparency about how we collect, use, and protect your personal information. This Privacy Policy explains our practices in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.

Amstel Lab
Email: privacy@amstellab.com
Contact: support@amstellab.com

2. Information We Collect

2.1 Personal Information

We collect information you provide directly to us, including:

  • Account Information: Name, email address, password
  • Profile Data: Professional information, skills, work experience
  • Resume Content: Text, formatting, and document data you upload
  • Payment Information: Billing details (processed securely by Stripe)
  • Communication: Messages sent to our support team

2.2 Automatically Collected Information

  • Usage Data: How you interact with our service
  • Device Information: Browser type, operating system, IP address
  • Analytics: Performance metrics and service optimization data

3. How We Use Your Information

3.1 Service Provision

  • Generate and customize resumes using AI technology
  • Process payments and manage your account
  • Provide customer support and respond to inquiries
  • Improve our AI algorithms and service quality

3.2 Legal Bases (GDPR)

  • Contract Performance: Providing our services as agreed
  • Legitimate Interest: Service improvement and security
  • Consent: Marketing communications (where applicable)
  • Legal Compliance: Meeting regulatory requirements

4. Data Processing and AI

Our AI system processes your resume content and job descriptions to create tailored documents. This processing:

  • Occurs on secure servers with encryption in transit and at rest
  • Does not involve human review unless explicitly requested for support
  • Uses your data only for generating your personalized content
  • Does not train our AI models on your personal resume content

5. Data Sharing and Disclosure

5.1 We Do Not Sell Your Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

5.2 Service Providers

We may share data with trusted service providers who assist us:

  • Stripe: Payment processing (see Stripe's privacy policy)
  • Cloud Storage: Secure document storage
  • Analytics: Service performance monitoring

5.3 Legal Requirements

We may disclose information when required by law or to protect our rights and users' safety.

6. Data Retention

  • Account Data: Retained while your account is active
  • Resume Documents: Stored for 3 years or until deletion
  • Payment Records: Kept for 7 years for tax compliance
  • Analytics Data: Anonymized after 24 months

7. User Control and Self-Service Data Management

7.1 Dashboard Controls

You have full control over your data through your dashboard:

  • View Your Data: Access all your stored resumes and account information
  • Delete Resumes: Remove individual tailored resumes at any time
  • Update Information: Modify your profile and account details
  • Download Data: Export your resumes and documents

7.2 Self-Service Deletion

You can delete your tailored resumes directly from your dashboard without contacting support. Each resume has a delete option that permanently removes:

  • The generated resume document
  • Associated processing data
  • Any temporary files created during generation

8. Your Rights Under GDPR

8.1 Data Subject Rights

  • Access: Request copies of your personal data
  • Rectification: Correct inaccurate information
  • Erasure: Delete your data (available through dashboard or by request)
  • Restriction: Limit processing of your data
  • Portability: Receive your data in a structured format
  • Objection: Object to certain types of processing
  • Withdraw Consent: Revoke consent for processing

8.2 Right to Erasure (Right to be Forgotten)

You can exercise your right to erasure in two ways:

  • Self-Service: Delete individual resumes through your dashboard
  • Complete Deletion: Contact us to delete your entire account and all associated data
  • Automatic Processing: Deletion requests are processed immediately for dashboard actions

9. Exercising Your Rights

Dashboard Actions: Most data management can be done directly through your account dashboard, including viewing, updating, and deleting individual resumes.

Contact Requests: For rights requiring our assistance (complete account deletion, data portability, etc.), please contact us at: privacy@amstellab.com

We will respond to requests within 30 days and may require identity verification for security purposes.

10. Data Security

  • Encryption: Data encrypted in transit (TLS) and at rest
  • Access Controls: Limited employee access on need-to-know basis
  • Regular Audits: Security assessments and vulnerability testing
  • Secure Infrastructure: Industry-standard cloud security measures

11. International Data Transfers

Your data may be processed in countries outside the EU. We ensure adequate protection through:

  • Standard Contractual Clauses
  • Adequacy decisions by the European Commission
  • Other appropriate safeguards as required by GDPR

12. Children's Privacy

Our service is not intended for children under 16 years old. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16, we will delete such information promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the updated policy on our website
  • Sending email notifications for significant changes
  • Requiring re-consent where legally required

14. Supervisory Authority

You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not complied with applicable data protection laws.

15. Contact Information

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

  • Email: privacy@amstellab.com
  • Support: support@amstellab.com
  • Data Protection Officer: dpo@amstellab.com
  • Address: Netherlands

Last Updated: August 18, 2025

This policy is effective as of the date listed above.