Last updated 11 August 2026
Quantfinance.work is a service of N-Sigma Capital AG, 6317 Oberwil bei Zug, Switzerland. N-Sigma Capital AG is the controller of the data described here, under the Swiss Federal Act on Data Protection (nLPD) and, where it applies to you, the GDPR.
For anything concerning your personal data, including any request under this policy, write to operations@n-sigmacapital.com. We answer within 30 days.
What we deliberately do not want. We do not ask for, and do not need, your photograph, date of birth, civil status, nationality, or any information about your health, religion, or political or trade-union membership. Please remove these from your CV before uploading it. If they are present anyway, they are not used.
Almost all of it you give us yourself — when you create an account, set your preferences, upload a CV, or write to us. The CV is optional: the service works without one, with scoring switched off.
A little we collect automatically — the pages you view and the features you use, as described under Cookies & analytics, plus the server logs needed to run the site securely.
Some of what we hold is about other people, and reaches us through you or through employers. Two cases, and only two:
If you upload data about other people. When you import your connections we assume you are entitled to do so and that the file is accurate. We never contact anyone in it.
If you are one of those people and would like your details removed, write to operations@n-sigmacapital.com and we will remove them — you do not need an account with us to ask.
Your CV is used for exactly four things, each of which you trigger yourself:
We do not use your CV for anything else. We do not contact you about roles. We do not send your CV, your name or your identity to employers, recruiters or headhunters. We do not sell or rent your data, and we do not use it for advertising. Neither we nor our AI providers train any model on it. You apply to employers yourself, directly, on their own site — we are an information tool, not a recruitment or placement service.
Swiss law does not make us pick a basis the way the GDPR does: under the nLPD, processing by a private company is lawful unless it breaches your personality rights, and where it would, we need a justification — your consent, a contract with you, or an overriding interest. Because this policy also follows the GDPR where the GDPR applies to you, the table names both.
| What | Why we may | GDPR, where it applies |
|---|---|---|
| Your account and job-search preferences | Necessary to provide the service you signed up for | Art. 6(1)(b) — performance of a contract |
| Your CV, the profile extracted from it, and every analysis you run on it | Your express consent, given before the first upload and withdrawable at any time | Art. 6(1)(a) — consent |
| Your imported LinkedIn connections — data about people who are not our users | Our and your legitimate interest in showing you who you already know at a firm. Those people cannot consent, so the use is kept minimal: shown only to you, never sent onward, never used to contact them | Art. 6(1)(f) — legitimate interests |
| Invoices and credit history | Swiss accounting law requires us to keep them for ten years | Art. 6(1)(c) — legal obligation |
| Security logs, and preventing abuse of the service | Our legitimate interest in keeping the service running and secure | Art. 6(1)(f) — legitimate interests |
| Google Analytics | Your consent, given on the cookie banner and never assumed | Art. 6(1)(a) — consent |
Where we rely on a legitimate interest you may object; where we rely on consent you may withdraw it, and withdrawing is as easy as giving. Both are under Your rights.
We do not rely on any special category of data — health, religion, trade-union membership and the like. We ask you to keep them out of your CV, and before anything is sent to an AI provider we automatically strip direct identifiers and the fields we can recognise, including contact details, date of birth, address, nationality and civil status. That filter is pattern-based and cannot catch everything a free-text CV might contain, which is why the request to leave such information out matters.
We score postings against your CV automatically. That score is a suggestion to you, not a decision about you: it does not determine whether you are hired, no employer ever sees it, and nobody is accepted or refused because of it.
If you would like a human to review how your CV was scored, write to us and we will look at it and explain the result.
Only the providers we need in order to run the service. They act on our instructions under contract and may not use your data for their own purposes.
| Recipient | What they receive | Where |
|---|---|---|
| An external AI system | CV text and job-posting text, to produce the analyses above | United States |
| Stripe | payment details — we never see or store your card | United States / Ireland |
| Resend | your email address, to send account emails | United States |
| Google Analytics | usage data only, and only if you consent — never your CV | United States |
| Umami | usage data, on our own server — no third party involved | Finland (EEA) |
| Our hosting provider | runs the server holding the database — no access to your CV, which is encrypted | Helsinki, Finland (EEA) |
Sending your CV and job-posting text to this AI system is lawful under data-protection law (Swiss FADP and the EU GDPR): it is covered by a contract that requires the provider to keep your data strictly confidential, use it only to produce your analyses on our instructions, and never for its own purposes.
Transfers outside Switzerland are made only under safeguards recognised by Swiss law. For our AI provider that is a data processing agreement incorporating the European Commission's standard contractual clauses, adapted for Switzerland: the Swiss Federal Act on Data Protection applies, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC), and Swiss law and Swiss courts govern. That agreement also contractually forbids our provider from training any model on your data.
We should be straightforward about what those clauses can and cannot do. They bind the provider and give you enforceable rights, but they cannot override the law of the country the data sits in — they do not, for instance, prevent a lawful access request by a US authority. They narrow the risk substantially; they do not reduce it to zero. That is one of the reasons the CV is the only document that leaves the EEA, and only while an analysis you started is running.
If we add or change an AI provider — including any located outside the United States — we update this policy, and we ask for your consent again before your CV is processed under the new arrangement. Your existing consent does not carry over to a new arrangement.
We ask you twice, each time next to the thing it concerns rather than in one bundle:
We record which wording you were shown and when, so that both of us can establish later what was agreed. You can withdraw your CV consent at any time by deleting your CV, which is as easy as giving it was.
| Data | Kept for |
|---|---|
| CV, extracted profile and every analysis derived from them | Until you delete it — immediately, from your profile |
| The copy our AI provider holds while running an analysis | Up to 30 days on their servers, encrypted, then deleted automatically |
| Everything belonging to a closed account | Erased within 30 days of closure |
| Account and billing records | 10 years, as Swiss accounting law requires |
| Analytics data | 14 months |
| Sign-in times and approximate locations | 12 months |
Your CV and any API keys you store are encrypted at rest with AES-256-GCM, and all traffic to the site is encrypted in transit.
Your data is stored on servers in Helsinki, Finland — inside the European Economic Area, which Switzerland recognises as providing adequate data protection. Your account, your CV and everything derived from it stay there. The only data that leaves the EEA is what is sent to the providers listed above while an analysis you asked for is running.
So that you can recover your account if you forget your password, the encryption keys are held on our servers rather than derived from your password. This means our authorised staff are technically able to access your stored CV; we do so only when necessary to provide a feature you asked for or to keep the service running securely — never for any other purpose.
Sign-in locations. When you sign in we record the time, roughly how long the session lasted, and an approximate location — country and city — so we can notice a sign-in that does not look like you and spot a shared or stolen password. We do not store your IP address: it is turned into that approximate location as your request is handled and then discarded. The lookup runs on our own server against a local database, so your address is never sent to anyone. The location is approximate and often names your provider’s city rather than yours. Only our administrator can see it, we keep it for 12 months, and it is erased with your account.
Like any company, we cannot promise that a security breach is impossible; some residual risk is unavoidable, and we would rather say so than imply otherwise.
If a data breach ever occurs that is likely to result in a high risk to you, we notify the FDPIC as soon as possible, and we tell you directly where you need to act.
You may at any time:
Write to operations@n-sigmacapital.com. You may also complain to the FDPIC in Switzerland, or to your local supervisory authority if you are in the EU or EEA.
Location lookups use the IP-to-City Lite database by DB-IP, licensed under CC BY 4.0.
Strictly-necessary cookies. A session cookie keeps you signed in, and a small cookie remembers your cookie choice. These are required for the site to work, so they need no consent.
Umami, without cookies. Our own analytics on our own server — no third party, nothing shared, no cookies, no tracking across other sites. Each visit records the pages viewed, the referring site, your browser, device and language, and an approximate location (country, region, city) worked out from your IP address. We do not store your IP address — it is used for that lookup and discarded. Not linked to your account. Kept 14 months.
Google Analytics — only with your consent. If you accept, we use Google Analytics 4 to understand how visitors find and use the site so we can improve it. It sets cookies and processes usage data, including online identifiers and a truncated IP address, in the United States under the Data Privacy Framework. We enable IP anonymisation, never use it for advertising, and never send it your CV. These cookies are set only if you click "Accept" on our cookie banner, and never before. You can change or withdraw that choice at any time via Cookie settings.
If we change how we use your data, we update this page and — where the change affects what you consented to — ask you again rather than assuming your earlier answer still stands.