Privacy Policy

Last updated: 7th August 2025

Effective Date: 7th August 2025

At Profilewise Ltd. ("Company", "we", "us", or "our"), we are committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, and protect your information when you use our recruiting platform and services.

1. Information We Collect

1.1 Information You Provide

When you create an account or use our service, we collect:

  • Account Information: Name, email address, password
  • Job Requirements: Job descriptions, requirements, and preferences you upload
  • Payment Information: Billing details processed through Stripe (we do not store your card details)
  • Communications: Messages you send to us for support or feedback

1.2 Candidate Information

Our service analyzes publicly available professional information, which may include:

  • Professional Profiles: Names, job titles, work experience, education
  • Skills and Qualifications: Listed skills, certifications, languages
  • Location Information: Professional location details
  • Public Posts: Professional announcements and career updates

1.3 Technical Information

We automatically collect:

  • Usage Data: How you interact with our service
  • Device Information: Browser type, operating system, IP address
  • Analytics: Website performance data through Vercel Analytics
  • Cookies: Essential cookies for authentication and service functionality

2. How We Use Your Information

2.1 Service Provision

  • Matching candidates with your job requirements using AI analysis
  • Providing candidate recommendations and compatibility scores
  • Sending email notifications about new matches
  • Managing your account and billing

2.2 Legal Basis for Processing

We process your data based on:

  • Contract Performance: To provide the services you've subscribed to
  • Legitimate Interests: To improve our service and analyze publicly available professional information for legitimate recruiting purposes
  • Legal Compliance: To comply with applicable laws and regulations
  • Consent: For marketing communications (where applicable)

2.3 Service Improvement

  • Improving our matching algorithms and AI technology
  • Analyzing service usage to enhance user experience
  • Developing new features and capabilities

3. Data Sharing and Third Parties

3.1 Service Providers

We share data with trusted third-party providers who help us operate our service:

  • Payment Processing: Stripe for secure payment handling
  • Cloud Infrastructure: MongoDB and cloud servers for data storage
  • AI Services: OpenAI and OpenRouter for candidate analysis and matching
  • Analytics: Vercel Analytics for website performance monitoring

International Transfers: Some of our service providers may process data outside the UK/EU. We ensure appropriate safeguards are in place for any international data transfers in accordance with UK GDPR.

3.2 We Do Not Sell Your Data

We never sell, rent, or trade your personal information to third parties for their marketing purposes.

3.3 Legal Requirements

We may disclose information when required by law, court order, or to protect our rights and safety.

4. Data Retention

Our Retention Policy:

  • Your Account Data: Retained while your account is active and for 30 days after deletion
  • Matched Candidates: Stored indefinitely to provide ongoing service
  • Unmatched Candidates: Automatically deleted within 24 hours
  • Payment Records: Retained as required by applicable financial regulations

You can delete your job profiles and associated matches at any time through your account settings.

5. Your Rights Under UK GDPR

As a data subject, you have the following rights:

Right of Access

Request a copy of the personal data we hold about you

Right to Rectification

Request correction of inaccurate or incomplete data

Right to Erasure

Request deletion of your personal data in certain circumstances

Right to Restrict Processing

Request limitation of how we process your data

Right to Data Portability

Request transfer of your data to another service

Right to Object

Object to processing based on legitimate interests

To exercise any of these rights, please contact us at josh@profilewise.co.uk. We will respond within one month of receiving your request.

6. Candidate Data Rights

If you are a job seeker whose information appears in our system, you have the same rights listed above. We are committed to full compliance with data protection laws and will:

  • Promptly delete your information upon request
  • Correct any inaccuracies in your data
  • Provide you with a copy of information we hold about you
  • Explain how we obtained and use your information

7. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption of data in transit and at rest
  • Secure authentication and access controls
  • Regular security monitoring and updates
  • Limited access to personal data on a need-to-know basis

Data Breach Notification

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant authorities within 72 hours as required by law.

8. Cookies and Tracking

8.1 Essential Cookies

We use essential cookies for:

  • User authentication and security
  • Maintaining your session and preferences
  • Providing core service functionality

8.2 Analytics

We use Vercel Analytics to understand how our website is used and to improve performance. This helps us enhance your experience with our service.

9. Marketing Communications

We may send you marketing communications about our services if:

  • You have given explicit consent, or
  • You are an existing customer and the communications relate to similar services

You can unsubscribe from marketing emails at any time by clicking the unsubscribe link in any email or contacting us directly.

10. Children's Privacy

Our service is not intended for anyone under 18 years old. We do not knowingly collect personal information from children under 18. If we discover we have collected such information, we will delete it immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through our service at least 30 days before they take effect. Your continued use of our service after changes take effect constitutes acceptance of the updated policy.

12. Complaints and Supervisory Authority

If you have concerns about how we handle your personal data, please contact us first at josh@profilewise.co.uk. We are committed to resolving any privacy concerns promptly.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection matters: ico.org.uk

13. Contact Information

Data Controller: Profilewise Ltd.

Email: josh@profilewise.co.uk

For all privacy-related inquiries, data subject requests, and concerns

By using Profilewise, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and use of your information as described herein.