Privacy Policy.
DestinAI is built around your career data. This document explains, in plain language, what we collect, why, and the rights you keep over it.
Data we collect
Account credentials (email, hashed password, optional country of residence) are collected at registration. During use, we record your conversation transcripts with the AI counselor and your swipe-assessment responses. These are converted into anonymised trait vectors and matched against global standard frameworks (such as ISCED, ISCO, O*NET, and ESCO).
Lawful basis · GDPR
Processing is grounded in your explicit consent at registration (Article 6(1)(a) GDPR) for the AI matching service, and on legitimate interest for security and abuse-prevention logs. You may withdraw consent at any time without affecting the lawfulness of prior processing.
EU AI Act compliance
DestinAI is classified under the EU AI Act as a limited-risk system providing vocational guidance. We do not make automated decisions with legal effect. Every match is a recommendation accompanied by transparent reasoning that you can audit, accept, or discard.
Sub-processors
We use OpenAI (text-embedding-3-small, hosted in EU regions) as a strictly secured embedding pipeline. OpenAI is bound by a Data Processing Addendum that prohibits use of your data for training their underlying models.
Retention & deletion
You have the absolute Right to be Forgotten under GDPR Article 17. Account deletion may be requested in Settings; all personal data, conversation transcripts, and derived vectors are purged within 72 hours (primary) and 30 days (backups).
Your rights
You may access, export, rectify, restrict, or delete your data at any time. Contact [email protected] or use Settings → Data. You may also lodge a complaint with your national Data Protection Authority.