Privacy Policy
Effective date: June 14, 2026 Last updated: June 14, 2026
This Privacy Policy explains how GONEW AI S.R.L. ("we", "us", "GoNew.ai") collects, uses, shares, and protects your personal data when you use the GoNew.ai service.
We comply with the EU General Data Protection Regulation 2016/679 ("GDPR") and the Romanian Law 190/2018 on the implementation of GDPR.
1. Data controller
Controller: GONEW AI S.R.L. Legal form: Romanian limited liability company (societate cu răspundere limitată) Registered office: Str. Ing. Alexandru Iacovache nr. 5, bl. 1, sc. 1, et. 6, ap. 46, sector 5, București, Romania Trade Registry: J2026036912005 (EUID: ROONRC.J2026036912005) Tax ID (CUI): 54835213 Administrator: Dan Agapie Privacy contact: privacy@gonew.ai
We do not currently have a designated Data Protection Officer (DPO) as we are below the GDPR threshold for mandatory DPO designation. The privacy@gonew.ai mailbox is monitored by the administrator.
2. What personal data we collect
| Category | Examples | When collected |
|---|---|---|
| Account data | email address, display name, locale preference | when you sign up |
| CV content (Career Shift only) | full CV text including work history, education, contact details, skills | when you upload a CV |
| Questionnaire answers | role, industry, energy sources/drains, values, hobbies, passions, salary range, location, retraining willingness, optional free-text fields | when you complete intake |
| Pathfinder quiz answers (young adults) | name, age bracket, education status, field of study, interests, "would you rather" choices, dream job, world problems, work environment preference | when you complete intake |
| AI-generated reports | career paths, LinkedIn profile drafts, cover letter templates | generated by the AI based on your inputs |
| Payment data | last 4 digits of card, billing country, payment status | when you upgrade to premium (full card data is handled by Stripe, not by us) |
| Usage data | pages visited, actions taken, errors encountered | automatically while using the Service |
| Device data | IP address (truncated), browser type, OS, screen size | automatically while using the Service |
| Feedback | ratings, optional text feedback on reports | when you submit feedback |
3. How we use your data — purposes and legal bases
For each purpose below, we identify the GDPR legal basis (Article 6 GDPR):
3.1 To provide the Service — Performance of a contract (Art. 6(1)(b))
- Generating career reports from your CV and answers
- Storing your sessions so you can return to them
- Processing premium payments
3.2 To improve the Service — Legitimate interest (Art. 6(1)(f))
- Analyzing aggregated, de-identified usage patterns
- Iterating on AI prompts based on aggregated feedback signals
- Debugging errors and improving reliability
3.3 To communicate with you — Performance of a contract or Consent (Art. 6(1)(b) or (a))
- Sending transactional emails (account confirmations, payment receipts, report-ready notifications)
- Sending marketing emails (only if you have opted in; you can opt out anytime)
3.4 To comply with legal obligations — Legal obligation (Art. 6(1)(c))
- Tax and accounting records (Romanian fiscal law)
- Responding to lawful government or court requests
3.5 To protect our rights and prevent abuse — Legitimate interest (Art. 6(1)(f))
- Detecting fraud, abuse, and security threats
- Enforcing our Terms of Service
4. CV processing — specific notice
When you upload a CV for Career Shift, the file is:
- Stored in encrypted cloud storage operated by our provider (Supabase, EU region).
- Parsed to extract text content using a local PDF-parsing library.
- Sent to Anthropic's Claude API (data processor) which structures the data into skills, roles, education, etc. Anthropic does not retain or train on this data (see Section 6).
- Used as input to generate your career report.
By default:
- The original CV file is retained for 30 days for free accounts, then automatically deleted.
- For premium users, the CV file is retained for the lifetime of your account (delete on request).
- The parsed CV data (structured JSON, not the original document) is retained alongside your session record so you can revisit your report.
You can request immediate deletion at any time (Section 8).
5. AI processing — specific notice
Your CV content, questionnaire answers, and other intake data are sent to Anthropic's Claude API for AI processing.
What Anthropic does:
- Processes the input to generate a response
- Does NOT use API inputs to train their AI models (per Anthropic's API data usage policy)
- Stores the data temporarily for safety review purposes only (typically deleted within 30 days)
Data sent: the contents of the prompt — which includes your CV text, intake answers, and any free-text fields you provided.
Data NOT sent: your name (unless contained in your CV), your email, your account credentials, or your payment information.
Where Anthropic processes data: primarily in the United States. Data transfers to the US are protected by Standard Contractual Clauses approved by the European Commission (see Section 7).
For more information about Anthropic's data practices, see https://www.anthropic.com/privacy.
6. Sharing your data
We share your personal data only with the following categories of recipients:
6.1 Data processors (act on our behalf)
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Anthropic, PBC | AI processing (CV parsing, report generation) | USA | Standard Contractual Clauses |
| Supabase Inc. | database + authentication + file storage | EU region for data at rest | Standard Contractual Clauses (US parent) |
| Vercel Inc. | hosting infrastructure (EU edge regions) | EU edge nodes + US control plane | Standard Contractual Clauses |
| Stripe Payments Europe Ltd. | payment processing | Ireland (EU) | EU-based |
| Resend (Resend, Inc.) | transactional and marketing email | USA | Standard Contractual Clauses |
| Plausible Analytics | privacy-friendly web analytics (no cookies, no personal data) | EU (Germany) | EU-based |
All processors are bound by data processing agreements (DPA) requiring confidentiality, security, and GDPR compliance.
6.2 Other parties
- Tax authorities, courts, regulators: when legally required (e.g., tax records, lawful information requests).
- Professional advisors (lawyers, accountants): under confidentiality, on a need-to-know basis.
- Acquirers (in case of merger or acquisition): we would notify you before any such transfer.
We do NOT sell your personal data. We do NOT share your CV or generated reports with advertisers or recruiters.
7. International data transfers
Some of our processors (Anthropic, Stripe, Vercel control plane, Resend) are based in the United States. Transfers of your personal data to the US are protected by:
- EU Commission Standard Contractual Clauses (SCCs) signed with each processor
- Supplementary technical measures (encryption in transit and at rest)
You can request a copy of the relevant SCCs by emailing privacy@gonew.ai.
8. Your rights under GDPR
You have the following rights regarding your personal data. To exercise any of these, email privacy@gonew.ai. We will respond within 30 days (extendable by 60 days if the request is complex; we will notify you if so).
| Right | What it means |
|---|---|
| Access (Art. 15) | Request a copy of the personal data we hold about you |
| Rectification (Art. 16) | Ask us to correct inaccurate or incomplete data |
| Erasure (Art. 17) | Ask us to delete your data ("right to be forgotten") |
| Restriction (Art. 18) | Ask us to pause processing while we verify a concern |
| Portability (Art. 20) | Request your data in a machine-readable format (JSON) |
| Object (Art. 21) | Object to processing based on legitimate interest, including marketing |
| Withdraw consent (Art. 7) | Withdraw any consent you previously gave |
| Lodge a complaint | File a complaint with the Romanian Data Protection Authority (ANSPDCP — www.dataprotection.ro) or your local authority |
How to delete your account
The fastest way to exercise your right of erasure: go to Account Settings → Delete Account in the application. This will:
- Delete your profile, sessions, CV files, generated reports, and feedback
- Anonymize related records that must be retained for legal reasons (e.g., payment records for tax compliance)
- Send you a confirmation email when complete (typically within 7 days)
Alternatively, email privacy@gonew.ai requesting account deletion.
9. Data retention
We retain personal data only as long as needed for the purposes it was collected:
| Data | Retention period |
|---|---|
| Account data (email, profile) | Until you delete your account |
| CV files | 30 days for free accounts; lifetime of account for premium |
| Parsed CV data (structured) | Lifetime of account |
| Session intake data | Lifetime of account |
| Generated reports | Lifetime of account |
| Payment records | 10 years (Romanian tax law requirement) |
| Aggregated/anonymized usage analytics | Indefinite (no longer personal data) |
| Email marketing list | Until you unsubscribe |
| AI generation logs | 12 months (for cost tracking and debugging) |
After retention periods expire, data is automatically deleted or fully anonymized.
10. Children's data
The Service is intended for users aged 16 and older.
For users aged 16–17 using Pathfinder, we collect minimal data appropriate to the service. We recommend that parents or guardians are aware of their child's use, even though GDPR does not require parental consent for users 16+ in Romania.
We do not knowingly collect data from children under 16. If you believe a child under 16 has provided us with data, email privacy@gonew.ai immediately and we will delete the data.
11. Security
We use commercially reasonable security measures to protect your data, including:
- Encryption in transit (TLS 1.2+) for all communications
- Encryption at rest for stored CVs and databases (provided by Supabase)
- Access controls: only authorized personnel can access the production database, and only on a need-to-know basis
- Row Level Security: the database enforces user-level isolation so one user cannot access another user's data
- Audit logs: AI API calls and admin actions are logged for security review
- Regular updates: dependencies and infrastructure are kept current with security patches
In the event of a data breach affecting your personal data, we will notify the relevant supervisory authority (ANSPDCP) within 72 hours and notify affected users without undue delay, as required by GDPR.
12. Cookies and similar technologies
We use a minimal set of cookies. See our Cookie Notice for details.
In summary:
- Strictly necessary cookies (authentication session): always on, no consent needed
- Analytics: handled by Plausible, which uses NO cookies and collects NO personal data
- No advertising or tracking cookies
13. Automated decision-making and AI
The career suggestions, LinkedIn content, and other outputs generated by the Service are produced by an AI system (Claude, by Anthropic).
This is not automated decision-making with legal or similarly significant effect under Article 22 GDPR. The output is informational — you make the actual career decisions yourself. No employment, financial, or other significant outcome is determined automatically by the system.
You have the right to:
- Receive an explanation of how the AI generates suggestions (see /how-it-works on our website)
- Disregard any AI suggestion at your discretion
- Provide feedback on AI output (which we use to improve the system)
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be announced via email (for account holders) and/or a prominent notice on the Service at least 14 days before they take effect.
The "Last updated" date at the top reflects the most recent change.
15. Contact
Data controller: GONEW AI S.R.L. Privacy email: privacy@gonew.ai General contact: hello@gonew.ai Postal address: Str. Ing. Alexandru Iacovache nr. 5, bl. 1, sc. 1, et. 6, ap. 46, sector 5, București, Romania
To file a complaint with the Romanian Data Protection Authority: ANSPDCP — Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București, Romania anspdcp@dataprotection.ro www.dataprotection.ro