← Back

Privacy Policy

Version 1.0 — June 2026
The Italian version is legally prevailing. The English summary is for convenience only.

What Astaris does with your data

Astaris is a career intelligence platform for European professionals. You upload your CV, answer a short Q&A, and our AI builds a structured profile that helps you understand where your career can go and which companies match your ambitions.

We process your data to deliver this service. We do not sell your data. We do not use your data for advertising.

Data we collect

Your CV file and the structured information extracted from it (work experience, education, skills, languages). Your career preferences and goals, as you share them during onboarding. After you register, if you have uploaded a CV, we use AI to rewrite and improve your CV text to produce an optimised version stored in your profile and accessible only to you — this optimised version is not shared with companies and does not affect matching.

Personality traits (OCEAN model) — optional, saved only with your explicit consent

If you choose to explore your personality, Astaris uses the OCEAN model (Big Five: Openness, Conscientiousness, Extraversion, Agreeableness, Neuroticism). This happens in two steps under a single consent you give once, at signup: a short set of preliminary signals collected during onboarding, and an optional 10-question deep-dive. From the deep-dive, Astaris generates a personality profile and a durable personality archetype, which are saved in your profile.

Because some personality dimensions can indirectly reveal sensitive information, Astaris treats your OCEAN scores and archetype as special-category data under Article 9 GDPR, and processes them only on the basis of your explicit consent under Article 9(2)(a) GDPR. This is the only basis we rely on for this data.

Your OCEAN scores and archetype exist for your own self-knowledge only. They are never shared with companies in any form, never used in job matching or compatibility scoring, and never affect your visibility to employers — not before and not after you accept an interview.

You can withdraw this consent at any time from your profile settings, without affecting your account or your matching. On withdrawal we stop using your personality data immediately and permanently delete your OCEAN scores, preliminary signals and archetype within 30 days. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.

We also collect standard technical data: session tokens (including `astaris_last_active`, a timestamp stored in sessionStorage to maintain session state), IP address (for security), and anonymised usage events to improve the product.

Who we share data with

Companies using Astaris to find candidates see a partial profile (first name, experience, skills, a compatibility score). Your OCEAN personality scores and archetype are not included in any data visible to companies. Companies only receive your full contact details after you explicitly accept their interview invitation.

We use Supabase (database and storage), Google Gemini (AI processing), and Cloudflare (hosting). All operate as data processors under GDPR Art. 28 agreements. Data is processed in or transferred to the EU/US under Standard Contractual Clauses.

AI-generated outputs

Astaris uses AI systems (Google Gemini, with Anthropic Claude as a fallback) to extract your career profile from your CV, generate career path analysis, and calculate job match scores. These outputs influence your visibility to companies. You can review and correct all AI-extracted profile data before it is saved. You can request human review of any AI-generated output by writing to privacy@astaris.io. No candidate is permanently excluded from the platform through a fully automated process without the possibility of review.

Your rights

You have the right to access, correct, delete, and export your data. You can withdraw your personality (OCEAN) consent at any time without affecting your account. To exercise any right, write to privacy@astaris.io. We respond within 30 days.

You can also file a complaint with your national data protection authority — in Italy: Garante per la Protezione dei Dati Personali.

Data retention

Your CV file is deleted after 12 months of inactivity. Your profile is kept until you delete your account, plus 30 days for operational backups. OCEAN scores and archetype are deleted within 30 days of consent withdrawal. Job match history is anonymised after 24 months.

Data controller

Astaris — Milan, Italy

privacy@astaris.io