Placeholder text — not legal advice. This document describes how the platform currently behaves, but it has not been reviewed by a lawyer. It must be completed and approved by qualified counsel before public launch.
Privacy notice
Last updated: 18 August 2026
1. Who we are
Qualifyed operates a two-sided hiring platform that introduces candidates and companies only when stated requirements are met. For candidate data we act as a data controller; when a candidate sends their CV to a company, that company becomes an independent controller of the data it receives.
[Placeholder — insert legal entity name, registered address and contact details.]
2. Data we collect
- Candidates: name, email address, phone number, CV file and its parsed contents, work history and skills, languages, seniority, location, work authorisation and visa needs, compensation expectations, and search preferences.
- Companies and recruiters: contact name and work email, company details, and the requirements of each mandate posted.
- Usage data: sign-in timestamps, last-activity timestamps, match and application events, and security logs (including IP address for abuse prevention).
3. Why we use it and on what basis
- To match candidates and mandates, and to deliver a CV when a candidate chooses to send it — performance of a contract.
- To keep availability information accurate (activity tracking, reconfirmation emails) — legitimate interests.
- To prevent abuse, fraud and unauthorised access, and to maintain audit records — legitimate interests and legal obligation.
- Special-category data is not requested. Please do not include it in your CV or free-text fields.
4. Who sees your data
A candidate's profile, CV, contact details and compensation expectations are shown to a company only after the candidate sends their CV to that company. Companies never browse the candidate pool directly, and no candidate data is public.
We use service providers for hosting, database, email delivery, geocoding and AI-based CV parsing. [Placeholder — list processors and their locations before launch.]
5. Recruiter access window
Access a company receives to a CV ends at the earliest of:
- 90 days after the CV was sent;
- immediately, if the candidate marks themselves as no longer looking; or
- immediately, if the candidate is reported as placed by another company (the company that reported the hire keeps its own record).
After that point the company retains only the outcome record of the application, not the candidate's CV or contact details.
6. Retention
- Accounts are not hard-deleted. On request, an account is anonymised: name, contact details, CV file and free-text fields are stripped and the login is retired, while hiring outcome and event records are retained for the companies involved and for our own audit obligations.
- Dormant candidate profiles are anonymised automatically after 24 months without activity.
- Application records are archived 24 months after they were sent, and are no longer visible to either side.
- Security and audit logs are retained for [placeholder — confirm period] and contain identifiers, not CV content.
7. Your rights
You can download everything we hold about you and request anonymisation at any time from the "Privacy & your data" panel in your dashboard. You may also ask us to correct data, object to or restrict processing, and complain to your local supervisory authority. [Placeholder — insert privacy contact address.]
8. International transfers and security
Data is transmitted over HTTPS and stored with access controls enforced at the database level. Where data is transferred outside the EEA or UK we rely on standard contractual clauses. [Placeholder — confirm hosting regions and transfer mechanisms.]
9. Changes
We will notify registered users of material changes to this notice.
See also our data processing addendum.