Privacy Policy

We process personal data in line with the EU General Data Protection Regulation (GDPR) and other applicable privacy laws. This Privacy Policy explains what information we collect, why we collect it, how we protect it, and the rights available to individuals whose data we process.

1. Data controller

CVlization is responsible for the processing of personal data described in this policy. If we act as a processor on behalf of your company, we process data only according to the instructions in our agreement.

2. Categories of personal data

We collect and process the following categories of data:

  • Account data: name, business email, company, role, preferred language, authentication details, profile photo (optional).
  • Usage data: app activity logs, device/browser metadata, IP address, timestamps, feature interactions, support tickets.
  • Candidate data: CVs, employment history, skills, feedback, status updates, notes, and interview outcomes provided by our customers.
  • Communication data: emails, chat messages, call notes, and meeting information exchanged with our team.

We generally do not request sensitive personal data (e.g., health, ethnicity). If your organisation uploads such information, you remain responsible for ensuring appropriate legal grounds and safeguards.

3. Legal bases for processing

We rely on different legal bases depending on the context:

  • Contractual necessity: to provide, maintain, and support the platform.
  • Legitimate interests: to secure the service, prevent abuse, understand usage trends, and improve features.
  • Consent: for optional communications, marketing emails, or when you request AI-driven suggestions requiring additional processing.
  • Legal obligations: to comply with bookkeeping, tax, and regulatory requirements.

4. How we use the data

We use personal data to:

  • Authenticate users and provide secure access to the platform.
  • Deliver core functionality: candidate management, matching, analytics, messaging, and collaboration.
  • Respond to support requests, track incidents, and provide customer success services.
  • Send service notices, product updates, and billing information.
  • Analyse aggregate usage to improve reliability, user experience, and product strategy.

We never sell personal data. We do not use candidate data uploaded by our customers to build unrelated commercial products.

5. Subprocessors and international transfers

We engage carefully selected subprocessors for hosting, email delivery, analytics, and payment processing. All subprocessors sign data processing agreements and provide adequate safeguards (EU Standard Contractual Clauses or equivalent). A current list of subprocessors is available on request.

When transferring data outside the European Economic Area, we rely on lawful mechanisms such as SCCs, the UK International Data Transfer Agreement, or adequacy decisions. We monitor regulatory developments and update safeguards accordingly.

6. Data retention

We retain personal data for the duration of the customer contract and for a reasonable period thereafter to comply with legal obligations, resolve disputes, or enforce agreements. You may request deletion of candidate records at any time through in-app tools or by contacting us. Backups are purged on a rolling schedule.

7. Security measures

CVlization implements technical and organisational safeguards including encryption in transit, access controls, role-based permissions, secure development practices, audit logging, regular penetration testing, and employee training. Incident response procedures are in place to notify customers of any data breach without undue delay.

8. Your privacy rights

Depending on your jurisdiction, you may have the right to access, rectify, delete, restrict, or port your personal data, and to object to certain processing activities. To exercise these rights, please contact us at privacy@cvlization.com. We will respond within the timelines required by law and may ask for additional information to verify your identity.

9. Cookies and tracking technologies

We use essential cookies to maintain sessions and security. With consent, we may use analytics cookies to understand product usage and improve features. You can manage cookie preferences through your browser settings or via in-app controls where available.

10. Children’s data

The platform is intended for professional use and not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us so we can delete it.

11. Updates to this policy

We may update this Privacy Policy to reflect legal requirements or service changes. We will post revisions with a new “Last updated” date and notify customers of material changes via email or in-app alerts.

12. Contact

For privacy-related questions, requests, or complaints, reach out to privacy@cvlization.com. You may also lodge a complaint with your local data protection authority if you believe our processing infringes applicable laws.