PRIVACY POLICY

Last Updated: March 12, 2025

  1. INTRODUCTION
    Welcome to A smart CV (“we,” “our,” or “us”). We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
    A Smart CV is an AI-powered platform that allows users to store their career history and generate tailored CVs and cover letters for specific job applications. Given the nature of our service, we understand the importance of handling your personal information with the utmost care and transparency.
    This Privacy Policy complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and The Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR).
  2. INFORMATION WE COLLECT
    We collect and process the following types of personal data:
    2.1 Account Information:
    • Name, email address, and password
    • Contact information (phone number, address)
    • Login and authentication details
    2.2 Professional Information:
    • Employment history
    • Skills and qualifications
    • Educational background
    • Professional achievements
    • Career objectives
    • Special category data where the Customer has volunteered this, it is never requested
    2.3 Job Application Information:
    • Job descriptions and requirements
    • Target roles and companies
    • Generated CVs and cover letters
    2.4 Usage Information:
    • Device information (IP address, browser type)
    • Log data and usage statistics
    • Cookies and similar tracking technologies
  3. HOW WE USE YOUR DATA
    We use your personal data for the following purposes:
    3.1 Service Provision:
    • To create and maintain your account
    • To store your professional information securely
    • To generate tailored CVs and cover letters using AI technology
    • To provide customer support and respond to inquiries
    3.2 Service Improvement:
    To analyse usage patterns and optimise our platform<
    To develop new features and improve existing ones
    To troubleshoot technical issues
    3.3 Communications:
    • To send service-related notifications
    • To provide updates about our platform
    • To respond to your requests and inquiries
    3.4 Marketing Communications:
    • To send you information about our services, features, and offers that may be of interest to you
    • To notify you about updates, improvements, or similar services we offer
    3.5 Legal and Security:
    • To comply with legal obligations
    • To enforce our Terms of Service
    • To detect and prevent fraudulent activities
  4. LEGAL BASIS FOR PROCESSING
    Under UK data protection law, we process your personal data based on one or more of the following legal grounds:
    4.1 Contract Performance: Processing necessary to deliver our services and fulfil our contractual obligations to you.
    4.2 Legitimate Interests: Processing that serves our legitimate business interests (such as improving our services) while respecting your rights and interests. Whenever we rely on this legal basis, we will balance our interests against your rights and freedoms.

    Soft Opt-in for Marketing:
    As an existing customer, we may send you marketing communications about our own similar products and services based on the ‘soft opt-in’ provision under the Privacy and Electronic Communications Regulations (PECR). This means that:
    • We will only send marketing communications about our own products and services that are similar to those you have already purchased or enquired about
    • We will provide you with a clear and simple opportunity to opt out of such communications in every message we send
    • We will respect your decision if you choose to opt out at any time
    You can opt out of these marketing communications at any time by:
    • Clicking the ‘unsubscribe’ link included in every marketing email
    • Updating your communication preferences in your account settings
    • Contacting us directly at info@asmartcv.com

    4.3 Consent: Processing based on your explicit consent, which you can withdraw at any time by contacting us or using the opt-out mechanisms we provide.
    4.4 Legal Obligation: Processing required to comply with UK laws and regulations.

  5. DATA SHARING AND THIRD PARTIES
    We may share your information with the following categories of third parties:
    5.1 Service Providers:
    • Cloud storage providers – Digital Ocean
    • AI processing services – OpenAI, Anthropic, Google Gemini
    • 3rd party suppliers (software development agency & website management agency) – Provanta AI, Inca Creative Enterprises Ltd
    • Payment processors – Stripe
    • Analytics services – Google Analytics, MailChimp
    5.2 With Your Consent: We may share your information with third parties when you explicitly consent to such sharing.
    5.3 Legal Requirements: We may disclose your information if required by law, regulation, or legal process.We do not sell or rent your personal data to third parties for marketing purposes.
  6. DATA SECURITY
    We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
    These measures include:
    • Encryption of data in transit and at rest
    • Secure user authentication
    • Regular security assessments
    • Restricted access to personal data
    • Secure data backupsWhile we strive to protect your personal information, no security system is impenetrable. We cannot guarantee the absolute security of your data transmission or storage.
  7. DATA RETENTION
    In accordance with UK data protection laws, we retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including:
    • While your account remains active
    • As needed to provide our services
    • As required to comply with UK legal obligations, including tax and accounting requirements
    • As necessary to establish, exercise, or defend legal claims
    Our specific retention periods are as follows:
    • Account information: For the duration of your account plus 6 years for legal claims
    • Job application data: For the duration of your subscription account plus 6 months
    • Generated CVs and cover letters: For the duration of your subscription account plus 6 months
    • Usage data: 26 months from collection (for analytics purposes)
    • Payment information: 7 years (as required by UK tax laws)When you delete your account, we will delete or anonymise your personal data within 30 days, unless specific legal requirements prevent us from doing so. In such cases, we will securely store your data and isolate it from any further processing until deletion is possible.
  8. YOUR RIGHTS
    Under UK data protection law, specifically the UK GDPR and Data Protection Act 2018, you have the following rights:
    8.1 Right of Access:You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of your request (which can be extended by up to two additional months if necessary due to complex or numerous requests). We will need to verify your identity, and will provide your personal data if we are legally able to.
    8.2 Right to Rectification: You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
    8.3 Right to Erasure (Right to be Forgotten): You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
    8.4 Right to Restriction of Processing: You have the right to request restriction of processing of your data in certain circumstances, including when you contest the accuracy of the data or when processing is unlawful.
    8.5 Right to Data Portability: You have the right to request the transfer of your data in a structured, commonly used, machine-readable format to you or to another controller.
    8.6 Right to Object: You have the right to object to processing based on legitimate interests, including profiling, and for direct marketing purposes.
    8.7 Rights Related to Automated Decision Making and Profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects.
    8.8 Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw that consent at any time.We will respond to all legitimate requests within one month. If your request is particularly complex or you have made several requests, it may take us longer, but we will keep you informed of any delays.To exercise these rights, please contact us at info@asmartcv.com.
  9. COOKIES AND TRACKING TECHNOLOGIES
    Our website uses cookies and similar tracking technologies to enhance your browsing experience and provide certain functionality. In accordance with UK law, including the Privacy and Electronic Communications Regulations (PECR), we use the following types of cookies:
    9.1 Essential Cookies: Required for basic website functionality. These cookies do not require consent under UK law.
    9.2 Analytical/Performance Cookies: Help us understand how visitors interact with our website by collecting and reporting information anonymously. These cookies require consent.
    9.3 Functional Cookies: Enable enhanced functionality and personalisation. These cookies require consent.
    9.4 Targeting Cookies: These cookies may be set through our site by our advertising partners to build a profile of your interests and show you relevant adverts on other sites. These cookies require consent.When you first visit our website, we will present you with a cookie banner allowing you to accept or decline non-essential cookies. You can also manage your cookie preferences through your browser settings at any time.For more detailed information about the specific cookies we use, their purposes, and how to control them, please refer to our separate Cookie Policy.
  10. CHILDREN’S PRIVACY
    Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us, and we will take steps to delete such information.
  11. CHANGES TO THIS PRIVACY NOTICE
    We may update this Privacy Notice from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on our website with a revised “Last Updated” date. We encourage you to review this policy periodically.
  12. DATA CONTROLLER AND DATA PROTECTION OFFICER
    A smart CV is the data controller responsible for your personal data.We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this Privacy Policy and our data protection compliance. Our DPO can be contacted for any privacy-related queries:
    Email: info@asmartcv.comWe are registered as a data controller with the UK Information Commissioner’s Office (ICO).
    Our registration number is 00019656833.
  13. CONTACT US
    If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:A smart CV
    82A James Carter Road
    Mildenhall
    IP28 7DEEOr email: info@asmartcv.com
  14. COMPLAINTS
    If you are not satisfied with our response to your privacy concern, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO), which is the UK’s supervisory authority for data protection issues:Information Commissioner’s Office
    Wycliffe House
    Water Lane
    Wilmslow
    Cheshire
    SK9 5AFTelephone: 0303 123 1113
    Website: www.ico.org.ukWe would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.