Privacy Policy
Effective date: 1 January 2025
CareerAI is committed to protecting your personal data. This policy explains how we collect, use, and safeguard your information.
✓ GDPR & UK GDPR Compliant
1. Data We Collect
We collect the following categories of personal data:
Account Information: Your name, email address, and password when you register.
Profile & CV Data: Information you provide in your profile, including your CV, work history, education, skills, salary expectations, and job preferences.
Usage Data: Information about how you use the Service, including pages visited, features used, job searches performed, and applications submitted.
Device & Technical Data: Your IP address, browser type and version, device identifiers, operating system, and referral source.
Communication Data: Records of your communications with us, including support queries.
Payment Data: If you subscribe to a paid plan, payment is processed by our third-party provider (Stripe). We store only a tokenised reference and the last four digits of your payment card; we never store full card details.
We collect this data when you register, use the Service, correspond with us, or when you grant us permission to access third-party accounts (e.g., LinkedIn).
2. How We Use Your Data
We use your personal data to:
• Provide and improve the CareerAI Service, including AI job matching, resume optimisation, and auto-apply features.
• Create and manage your account.
• Process subscription payments.
• Send you transactional emails (e.g., application confirmations, account notifications).
• Send you marketing communications where you have given consent or we have a legitimate interest.
• Analyse usage to improve our AI models and Service quality.
• Comply with legal obligations and enforce our Terms of Service.
• Prevent fraud and ensure the security of the Service.
Our legal bases for processing are: performance of a contract (providing the Service), legitimate interests (improving the Service), compliance with legal obligations, and your consent (where applicable).
4. Data Retention
We retain your personal data for as long as necessary to provide the Service and for legitimate business purposes:
• Account data is retained for the duration of your account and for 90 days after deletion (to allow recovery of inadvertent deletions).
• CV and profile data is deleted when your account is deleted.
• Usage logs are retained for 13 months.
• Payment records are retained for 7 years to comply with UK financial regulations.
You can request deletion of your account and personal data at any time (see GDPR Rights below).
5. Your GDPR Rights
If you are based in the UK or European Economic Area, you have the following rights under GDPR and UK GDPR:
Right of Access: Request a copy of the personal data we hold about you.
Right to Rectification: Request correction of inaccurate or incomplete personal data.
Right to Erasure: Request deletion of your personal data ("right to be forgotten"), subject to certain exceptions.
Right to Restrict Processing: Request that we limit how we use your personal data.
Right to Data Portability: Receive your personal data in a structured, machine-readable format.
Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent: Where processing is based on consent, withdraw that consent at any time.
To exercise any of these rights, contact us at privacy@careerai.io. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
6. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:
CareerAI Limited
Data Protection Officer
Email: privacy@careerai.io
Address: 1 Harbour Exchange Square, London, E14 9GE, United Kingdom
This Privacy Policy was last updated on 1 January 2025.