Privacy Policy

Version 2026-09-08 · Effective from September 8, 2026

This policy describes what personal data we process, for what purpose, on what legal basis, who we share it with, and what rights you have over it.

1. Data controller

Nextplacement SpA, tax ID 77.229.797-1, registered at Nueva Providencia 1881, oficina 1201, Providencia, Santiago, Chile.

Privacy contact: privacy@alkemicascend.com

2. What data we process

CategoryData
Account dataEmail address, name, language preference, country.
CVThe file you upload and the text extracted from it: work history, education, competencies, achievements and any personal data you included in the document.
Derived dataAnalyses, diagnostics, scores, reports and materials generated from your CV and your responses.
AssessmentsResponses to purpose, leadership and career-discovery assessments, and interview simulations.
Career targetsTarget role, industry, seniority band and geography that you declare.
Service usageNavigation and usage events, consumption of AI features and their associated cost.
Technical dataError diagnostic information and session data required for authentication.
Third-party professional contactsName, role, company and professional contact information of people you confirm as contacts, obtained from public sources, together with the reference to that source.

We do not request or require sensitive data such as health, ethnic origin, political or trade-union affiliation, or sexual orientation. We recommend you do not include such data in your CV. If you do, it will be protected in the same way as the rest of the document.

3. Why we use it and on what basis

PurposeDataLegal basis
Provide the service: analyse your background and generate guidance and materialsAccount, CV, derived data, assessmentsPerformance of the contract
Manage your account, authentication and operational communicationsAccount, technical dataPerformance of the contract
Make you visible to companies and headhuntersCareer-target derived fieldsYour explicit consent (off by default)
Measure product usage and improve itUsage eventsYour consent (non-essential analytics)
Attribute advertising conversions and optimise campaignsA SHA-256 hash of the email, conversion events, and the advertising cookies _gcl_au and _fbpYour consent (non-essential marketing)
Security, abuse prevention and cost controlTechnical data, AI usageLegitimate interest
Comply with legal and accounting obligationsUsage and cost recordsLegal obligation
Suggest relevant professional contacts at target companiesThird-party professional contactsLegitimate interest

4. Artificial intelligence and processing of your CV

To generate analyses and materials, the content of your CV and your responses are sent to language models operated by OpenAI. This processing is essential to providing the service: without it, the platform cannot function.

We use OpenAI's business interface, whose terms do not provide for the data sent to be used to train their models.

Content generated by artificial intelligence may contain errors or inaccurate statements. See the AI Notice for detail.

VERIFY before publishing: confirm OpenAI's current policy for the contracted plan and processing region. This statement must not be published without checking it; it is one of the claims an executive user will scrutinise most closely.

5. Visibility to companies and headhunters

This feature is off by default. Your profile is not visible to any organisation unless you expressly enable it from the service settings.

When you enable it, authorised organisations can see only the following fields derived from your career target:

  • Target role
  • Industry
  • Seniority band
  • Geography
  • Your chosen visibility level, which defaults to anonymous

Your CV is never shared with third parties. Neither are your name, your email address, your reports, your assessments, nor any other profile data. You can switch visibility off at any time, with immediate effect.

6. Third-party data: suggested professional contacts

When you work on a target company, the service may suggest relevant people within it --- for example, who holds a role you would benefit from speaking to. This section explains how we handle the data of those people, who are not users of the service.

What data, and where it comes from. Suggestions are obtained by searching public sources on the internet. The data is professional in nature: name, role, company and, where the public source includes it, professional contact information. Every suggestion states the source it came from, and that reference is retained alongside the contact if you save it. We do not extract data from LinkedIn or from any other platform whose terms of use prohibit it.

On what basis. We process this data on the basis of legitimate interest: helping a professional identify relevant contacts in their field. We consider that this interest does not unduly override the rights of the people suggested, because the data is professional in nature and publicly sourced, it is processed in a strictly business context, no profiling or automated decision-making is carried out about those people, and it is neither sold nor transferred to third parties.

What is stored and what is not. A suggestion is not stored merely by being shown. It is stored only when you individually confirm it, at which point it becomes part of your own contact list. The service does not build or maintain a database of people who are not users.

For how long. A confirmed contact is retained for as long as you keep it and your account remains active. It is deleted when you delete that contact, or when you delete your account.

Rights of the suggested person. Anyone whose data appears in the service may request access, rectification, objection or deletion by writing to privacy@alkemicascend.com. We will handle those requests within the same timeframes and on the same terms as those of our own users, without requiring them to be a user of the service.

Your responsibility. You decide whether and how to contact that person. That communication is yours, not ours, and is subject to the professional-communications and data-protection rules applicable in your jurisdiction and in that of your recipient.

7. Who we share data with

We do not sell your personal data. We do share data for advertising purposes, only with your consent. We work with the following providers. Most act as processors on our behalf.

For Google Ads and Meta Pixel, Nextplacement SpA acts as joint controller with those providers of the advertising-measurement data collected through those services, under the terms each provider publishes. Google Analytics 4 runs only with your analytics consent and is described in the rows below.

ProviderFunctionData processed
SupabaseDatabase, authentication and file storageAll account, CV and derived data
OpenAILanguage models for generating analyses and materialsCV content, responses and profile context
TavilyWeb search for company and market intelligenceSearch queries that may include your career-target context
VercelApplication hosting and executionData in transit, request logs
PostHogProduct analyticsUsage events --- only with your consent
Google Analytics 4Product and traffic measurementPageviews, device and approximate location, and the _ga cookie --- only with your analytics consent
Google AdsConversion attribution, Enhanced Conversions and campaign optimisationConversion events, the _gcl_au cookie, and a SHA-256 hash of your email --- only with your marketing consent
Meta (Meta Platforms Ireland)Conversion attribution and cross-site measurementPage views and registration conversions, and the _fbp identifier --- only with your marketing consent. We send Meta no email address and no account identifier.
SentryError monitoringDiagnostic data, without personally identifiable information
ResendTransactional email deliveryEmail address and name

When a registration conversion is attributed to Google Ads, we transmit a SHA-256 hash of your email address, trimmed and lowercased, to Google. We never send Google the address itself.

That hash is derived personal data, not anonymised data, because the same address produces the same hash and can therefore still identify you. The rights in section 11 apply to it. It is sent only if you have granted marketing consent, and only for conversion attribution (Enhanced Conversions). If you have not granted marketing consent, or if you withdraw it, no hash is generated.

We may also disclose data when a competent authority lawfully requires it.

8. International transfers

Our providers operate infrastructure outside Chile, principally in the United States and the European Union. By using the service, your data is transferred to and processed in those jurisdictions under the contractual mechanisms each provider makes available.

9. How long we keep your data

DataRetention
CV, uploaded files and derived dataFor as long as your account is active
Account data and assessmentsFor as long as your account is active
After you request account deletionDeleted 7 days after confirmation. Your access is revoked immediately on confirmation.
Usage, cost, audit and error recordsRetained in anonymised form, with no link to your identity

10. Deleting your account

You can request deletion of your account from the service settings. The process is as follows:

  • You request deletion and confirm it through a single-use link sent to your email address.
  • On confirmation, your access to the service is revoked immediately.
  • A 7-day window opens during which you can cancel the request, in case of accidental deletion.
  • After that window, your stored files --- CV, assessment documents and generated documents --- and all your account data, assessments, reports and derived data are permanently deleted.

What is retained and why. Usage records, AI consumption and cost records, audit records and error records are not deleted: they are unlinked from your identity and retained in anonymised form. We need them for accounting, cost control, security and compliance. After deletion, those records can no longer identify you.

11. Your rights

You may exercise the following rights:

  • Access the personal data we process about you.
  • Rectify inaccurate or incomplete data.
  • Request deletion of your data.
  • Object to certain processing and withdraw your consent where processing is based on it.
  • Request a copy of your data in a structured format.

To exercise them, write to privacy@alkemicascend.com. We will respond within the timeframes set by applicable law. If you believe we have not handled your request properly, you may complain to the data protection authority for your jurisdiction.

12. Cookies and similar technologies

We use a small set of cookies. Essential and functional cookies are necessary for the service to operate and do not require consent. Analytics cookies are only activated if you authorise them. Advertising cookies are only activated if you authorise marketing.

CookieTypePurpose
Supabase session cookiesEssentialKeep your session signed in and authenticated
NEXT_LOCALEFunctionalRemember the language you prefer
Active career targetFunctionalRemember which career target you have selected
aa_consentEssentialRemember whether you authorised or declined analytics and marketing
PostHog cookiesAnalyticsMeasure product usage. Activated only with your analytics consent.
Google Analytics cookies (_ga, _ga_*)AnalyticsMeasure product and traffic usage. Activated only with your analytics consent.
_gcl_auAdvertisingAttribute Google Ads conversions across sites. Activated only with your marketing consent.
_fbpAdvertisingAttribute Meta advertising conversions across sites. Activated only with your marketing consent.

You can change or withdraw your analytics and marketing preferences at any time from the service settings. Withdrawing stops these cookies being set again and takes effect immediately.

We do use advertising cookies (_gcl_au and _fbp) to attribute conversions across sites, only with your marketing consent. If you have not yet chosen, or if you decline, those cookies are not set. No advertising cookie is set before consent. We do not sell your personal data.

We do not record your screen or your browsing within the service.

13. Security

We apply database-level data isolation, so each user can access only the information in their own account. Sensitive operations run exclusively on our servers. Administrative access is restricted and logged.

No system is completely invulnerable. If a security breach affecting your personal data occurs, we will notify you in accordance with applicable law.

14. Minors

The service is not directed at people under 18 and we do not knowingly collect data from them. If we identify an account belonging to a minor, we will delete it.

15. Changes to this policy

We may update this policy. Each version has an identifier and an effective date. When a change substantially affects how we process your data, we will inform you and, where appropriate, ask you to accept the new version before continuing.

← Back to home