CV
CV Score

Privacy Policy

Last updated: 26 February 2026

1. Introduction

CV Score ("we", "our", "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and services (the "Service"). We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).

For the purposes of data protection law, CV Score is the data controller responsible for your personal data.

2. Data We Collect

We collect and process the following categories of personal data:

2.1 Account Information

  • Name and email address (provided during registration)
  • Account preferences and settings
  • Subscription and billing information (processed by Stripe)

2.2 CV and Career Data

  • CV documents you upload (PDF, DOCX, TXT files)
  • Extracted text content from your CV
  • Job descriptions you provide for matching
  • Job titles and career information
  • Analysis results, scores, and recommendations
  • Cover letters generated by our AI
  • Interview preparation content

2.3 Technical Data

  • IP address and approximate location
  • Browser type and version
  • Device information and operating system
  • Pages visited and interaction data
  • Session cookies and authentication tokens

3. How We Use Your Data

We process your personal data for the following purposes and legal bases:

PurposeLegal Basis
Providing CV analysis and scoringPerformance of contract
Generating cover letters and interview prepPerformance of contract
Processing payments and subscriptionsPerformance of contract
Sending service-related notificationsLegitimate interest
Improving our AI models and service qualityLegitimate interest
Website analytics and performance monitoringLegitimate interest
Complying with legal obligationsLegal obligation

4. AI Processing

Our Service uses artificial intelligence to analyse your CV and generate content. When you submit your CV for analysis, the text content is processed by our AI systems to generate scores, recommendations, and other outputs. We do not use your personal CV data to train our AI models without your explicit consent. AI-generated content is provided as suggestions and should be reviewed before use.

5. Data Sharing

We do not sell your personal data. We may share your data with the following categories of recipients:

  • Payment processors: Stripe processes your payment information securely. We do not store your full card details.
  • Cloud infrastructure providers: We use secure cloud services to host our application and store your data.
  • AI service providers: CV text is processed through AI APIs for analysis purposes only.
  • Analytics providers: We use privacy-respecting analytics to understand how our Service is used.
  • Legal authorities: We may disclose data if required by law or to protect our legal rights.

6. International Data Transfers

Some of our service providers may process your data outside the United Kingdom. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the Information Commissioner's Office (ICO), or the recipient is in a country with an adequacy decision.

7. Data Retention

We retain your personal data for as long as necessary to provide the Service and fulfil the purposes described in this policy. Specifically:

  • Account data: Retained while your account is active and for 30 days after deletion.
  • CV files and analysis data: Retained while your account is active. You may delete individual analyses at any time.
  • Payment records: Retained for 7 years to comply with UK tax and accounting requirements.
  • Technical logs: Retained for up to 90 days for security and debugging purposes.

8. Your Rights Under UK GDPR

Under the UK GDPR, you have the following rights regarding your personal data:

  • Right of access: You can request a copy of the personal data we hold about you.
  • Right to rectification: You can request correction of inaccurate or incomplete data.
  • Right to erasure: You can request deletion of your personal data ("right to be forgotten").
  • Right to restrict processing: You can request that we limit how we use your data.
  • Right to data portability: You can request your data in a structured, machine-readable format.
  • Right to object: You can object to processing based on legitimate interests.
  • Rights related to automated decision-making: You can request human review of any automated decisions that significantly affect you.

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month, as required by law. If your request is complex, we may extend this by a further two months, but we will inform you of any delay.

9. Cookies and Tracking

We use the following types of cookies:

  • Essential cookies: Required for the Service to function (e.g., authentication session cookies). These cannot be disabled.
  • Analytics cookies: Help us understand how visitors interact with our website. We use privacy-respecting analytics that do not track individual users across websites.

We do not use advertising cookies or share cookie data with third-party advertisers. You can manage cookie preferences through your browser settings.

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption of data in transit (TLS/SSL) and at rest (AES-256)
  • Secure authentication with session management
  • Regular security assessments and monitoring
  • Access controls limiting data access to authorised personnel only
  • Secure cloud infrastructure with industry-standard certifications

While we take all reasonable precautions, no method of transmission over the Internet is 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the ICO within 72 hours as required by law.

11. Children's Privacy

Our Service is not intended for children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that data promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy on our website and, where appropriate, by email. We encourage you to review this policy periodically.

13. Complaints

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk

14. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:

Email: [email protected]
Website: cvscore.uk