Search for a "GDPR-compliant AI resume tool" today and you will find a long list of European companies. Look at their infrastructure stack and you will find OpenAI, AWS us-east-1, and Azure West US. The company is in Europe. The data is not. That gap matters more than most people realise — and it is why we built Job-Agent the way we did.
What "GDPR-compliant" actually requires
GDPR compliance has two distinct layers that are easy to conflate. The first is organisational: a data processing agreement, a privacy policy, a named DPO, breach notification procedures. Most companies handle this. The second layer is harder: the actual data transfer rules. Under GDPR Articles 44-49, personal data can only leave the EU under specific conditions — an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules. When a European company sends your resume to an LLM hosted in Virginia, they are triggering a cross-border data transfer. Whether it is lawful depends on their DPA. Whether it is what you signed up for is a different question.
The practical problem: most people uploading a CV to a "GDPR-compliant" tool have no idea their data is being processed by a US-based model. The privacy policy mentions it, somewhere, in the data sub-processors section. Nobody reads it.
Why your CV is especially sensitive
A resume contains a dense concentration of personal data: full name, contact details, home city, employment history with dates and employer names, education, sometimes age-inferrable information, sometimes health or family context in a cover letter. It is exactly the data profile that GDPR classifies as requiring careful handling. The irony is that resume tools — the category most people trust with this data — have historically been among the least careful about where it goes.
If you are a senior professional applying to roles at regulated companies — finance, healthcare, defence — your employment history itself may be considered sensitive. The companies you worked for, the roles you held, the technologies you used: all of it is in the document you are uploading to a third-party AI service.
The EU AI Act adds another layer
The EU AI Act, which entered force in August 2024, classifies AI systems used in employment and recruitment as high-risk. That classification comes with obligations around transparency, documentation, and human oversight. Tools that analyse resumes or score candidates sit squarely in this category. Using a non-EU LLM for this task does not make you automatically non-compliant — but it creates a more complex accountability chain. When something goes wrong, you want the data to have stayed in a jurisdiction with clear rules and enforcement.
What EU-sovereign actually means
EU-sovereign means every layer of the stack is EU-based — not just the company's registered address. For Job-Agent, that means:
The LLM: Mistral Small — built by Mistral AI, a French company founded in Paris in 2023. The model runs on Scaleway Generative APIs, operated from French data centres. Mistral has published its weights, has no dependence on US cloud infrastructure for inference, and is governed by French and EU law.
The infrastructure: Scaleway — a French cloud provider operating exclusively in EU regions. Our production database, object storage, and container runtime all run in the Paris data centre. No data transits through US regions at any point in the pipeline.
The result: when you upload your CV and a job description to Job-Agent, the entire analysis — Stage 1 (JD parsing), Stage 2 (candidate scoring), Stage 3 (resume generation) — runs within the EU. Your data does not leave. Not to OpenAI. Not to AWS. Not to anywhere outside French jurisdiction.
Why we made this choice
The honest answer is that we did not want to build a tool we would not use ourselves. We are based in Europe. Our users are mostly European professionals applying to European roles. The data they trust us with is sensitive. Routing it through US infrastructure because GPT-4 is marginally easier to integrate felt like the wrong trade-off.
The technical trade-off is real: Mistral Small is a 24-billion-parameter model, not a 200-billion-parameter one. We have invested significantly in prompt engineering, multi-call pipeline architecture, and deterministic post-processing to get reliable results from a smaller, EU-native model. We think the results are good. We also think knowing where your data goes is worth slightly more engineering work on our end.
What this means for you
If you are applying to roles in the EU and you care about where your personal data goes — or if your employer has data handling policies that govern what tools you can use — Job-Agent is the only ATS resume analysis tool we are aware of where the LLM, the inference infrastructure, and the database all sit inside the EU. Not just the company. The actual compute.
We are not the only option for AI resume tailoring. We are probably the only option if genuine data sovereignty matters to you.
