Privacy policy
Last updated: October 7, 2026
Coach Career IA is a private career agent: privacy is the product. This page explains what data we process, why, for how long, with whom, and how to exercise your rights (General Data Protection Regulation, GDPR).
Data controller
DD TECH CONSULT (NextSeed-AI), —. Contact for your data: contact@nextseed-ai.org.
Data processed, feature by feature
- Account: email address, preferred language, creation and login dates, version of the terms accepted. No password: you sign in with a single-use link.
- Career Memory: experiences (job title, dates, level, employer described by its sector and size, never by name), achievements, skills, supporting documents (encrypted on our servers) and guard rails (salary, locations, remote work, contract types, excluded sectors and companies, the latter encrypted).
- Identity vault: your name, contact details, the real names of your employers and your original CV are encrypted in your browser with a key derived from your passphrase. The server only stores encrypted data that it cannot read; neither the passphrase nor the key is ever sent to it.
- Imports: the CV, LinkedIn export or public GitHub profile you import are analysed to offer you a draft Career Memory, which you review and validate before anything is saved.
- AI coach: your conversations with the coach and the suggestions it makes to you.
- Opportunities and alerts: the job postings selected for you, their score and explanation, your reactions; email alerts are only sent if you turn them on, and every email contains an unsubscribe link.
- Anonymous card, outreach and negotiation: your anonymous card, the messages sent to companies after your approval, the contact address of the person you specify, the replies received and your negotiation mandate (encrypted).
- Identity reveal: only the fields you choose to reveal to a company, accessible through a revocable link that expires after 30 days.
- Subscription: plan taken, subscription status and renewal date, payment provider identifiers. We never see or store your card number.
- Company accounts: the member’s professional email address, the organisation’s name, website, sector, size and country, published job postings and related payments.
- Technical logs: technical identifiers, counters and errors, with no personal content (no email, no name, no text you entered).
Legal bases
- Performance of a contract (article 6.1.b GDPR): account, Career Memory, vault, imports, coach, opportunities, outreach and identity reveals that you request, subscription, company workspace.
- Consent (article 6.1.a): email alerts, which you can withdraw at any time from the settings or the unsubscribe link.
- Legitimate interest (article 6.1.f): security of the service, abuse prevention, moderation of job postings and organisations, technical logs.
- Legal obligation (article 6.1.c): retention of accounting records relating to payments.
Retention periods
- Account, Career Memory, vault and coach data: for as long as the account exists. Deleting the account immediately erases all this data and all your files; backup copies disappear within 30 days at most.
- Login link: 15 minutes, single use. Login session: 30 days, revoked when you sign out.
- Anonymous card links: 30 days. Data revealed in an identity reveal: 30 days, then automatically purged.
- Company job postings: published for 30 days then closed; kept for as long as the organisation exists.
- Accounting records relating to payments: 10 years (article L123-22 of the French Commercial Code).
Recipients and processors
Your data is never sold or rented. A company only receives what you have approved: a message, your anonymous card, or the fields you choose to reveal. Our processors act only on our instructions:
- Mistral AI (France, hosted in the European Union): language model used for imports, the coach, opportunity explanations and message drafts. We do not train any model with your data.
- Email delivery (—): login links, alerts and messages to companies.
- Hosting (Hostinger International Ltd): virtual private server located in the European Union, which hosts the application and the database.
- Payment: payments are simulated during the test phase: no payment data is collected. When payments open, Stripe Payments Europe (Ireland) will process them.
- Geocoding: city names (never your identity) are sent to the IGN Géoplateforme (France) and to OpenStreetMap Nominatim to calculate distances.
- GitHub: only if you import a GitHub profile, to read its public information.
Hosting and transfers
Data is hosted and processed in the European Union. We do not transfer your data outside the European Union; if a provider were to do so, it would only be with the safeguards provided for by the GDPR (standard contractual clauses of the European Commission).
Security
Passwordless login, revocable sessions, AES-256 encryption of sensitive fields and supporting documents, identity vault end-to-end encrypted in your browser, data access limited to your account, logs free of personal data.
Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw your consent, and the right to give directions on what happens to your data after your death.
- Export all your data (JSON file) from your account settings.
- Delete your account and all its data, at any time, from the settings.
- Correct your information directly in your workspace (Career Memory, guard rails, identity).
- For any other request: contact@nextseed-ai.org. We reply within one month.
If you believe your rights are not being respected, you can lodge a complaint with the CNIL (the French data protection authority, Commission nationale de l’informatique et des libertés).
Changes
This policy may change as the service evolves. The update date appears at the top of the page; in the event of a significant change, we will inform you the next time you sign in.