Version 1.0 — 12 September 2026
1. Who we are
Padgrad Ltd is the data controller for the personal data described in this notice. We are a company registered in England and Wales (company number 17365449) with our registered office at 20 Wenlock Road, London, England, N1 7GU.
- Data protection contact: privacy@padgrad.com
- EU representative (GDPR Art. 27): Not yet appointed — we will publish the representative's name and address here before we actively offer services to people in the EU. In the meantime, contact privacy@padgrad.com and we will deal with your request directly
- ICO registration: Pending — published once the data protection fee is paid (we pay the statutory data protection fee)
If you are a customer of PadCount (our business expense-tracking product), we act as a processor for the employee and financial data your organisation puts into PadCount, and as a controller for your account, billing and marketing data. The business terms and data processing addendum govern that relationship; this notice covers the parts where we are the controller.
2. The personal data we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account and identity | name, email address, password hash, Google account identifier (if you sign in with Google), account status, language preference | you |
| Profile and education | phone number, location/country, degrees and qualifications, universities, grades, work history, skills, career interests, volunteer interest | you |
| Your documents | CVs and CV text, cover letters, generated drafts | you / generated by our AI features at your request |
| Job-search activity | saved and viewed jobs, applications you log, rejection outcomes you record, interview practice sessions, career quiz answers, heatmap and pattern analyses derived from your records | you / derived from your activity |
| Payments | Stripe customer and payment identifiers, transaction history, credits balance. We never receive or store your card number | Stripe |
| Communications | support messages, complaints, emails we send you and their engagement, feedback | you / our systems |
| Technical | IP address, approximate location derived from IP (country-level, via GeoIP), device and browser information, session identifiers, error and security logs | your device |
| Cookies and similar | see the Cookie Policy — including analytics and session-replay data collected only with your consent | your device |
| PadCount business data | company name and slug, VAT number, tax year end, expense and revenue entries, uploaded receipt images, team member names and roles, invite records | your organisation and its staff |
We do not ask for, and do not want, special category data (for example health, ethnicity, religion, trade union membership, sexual orientation, biometrics). CVs sometimes contain this information incidentally. Please remove anything of that kind before uploading.
We do not intentionally collect data from under-18s — see section 11.
3. Why we use it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Creating and running your account, providing the features you ask for, generating CV checks/cover letters/interview practice at your request | Performance of a contract (Art. 6(1)(b)) |
| Job matching, personalised listings, relevance ranking and the indicative match/predictive score | Legitimate interests (Art. 6(1)(f)) — giving you useful results rather than an unranked list. We have carried out and documented a balancing test |
| Sending you the job digest and other service emails you opted into | Consent (Art. 6(1)(a)) for marketing. Service/transactional messages (verification, receipts, security) rely on contract or legitimate interests |
| Analytics, product improvement, error monitoring | Consent where cookies or session recording are involved (Cookie Policy); otherwise legitimate interests in running a working, secure service |
| Security, fraud prevention, abuse prevention, rate limiting, enforcing our terms | Legitimate interests and, where relevant, legal obligation |
| Taking payment, accounting, tax and VAT records | Contract and legal obligation (Art. 6(1)(c)) |
| Handling complaints, rights requests and legal claims | Legal obligation and legitimate interests in defending claims |
| Referral programme administration | Contract / legitimate interests, with consent where required for marketing communications |
Automated decisions. We use automated processing to score, rank and analyse your job-search activity (for example match scores, and patterns in the applications and rejections you log). Where such processing could have a significant effect on you, you have the rights set out in section 8 — including the right to be informed, to make representations, to obtain human intervention and to contest the outcome. We do not use solely automated decision-making to make final decisions about you or anyone else.
4. Artificial intelligence features
Our AI-assisted features use third-party models — currently DeepSeek and OpenAI — alongside our own logic. When you use them, the content you submit (for example your CV text, a job description, your cover letter draft or your interview answers) is sent to those providers so they can return a result.
We are required to be straight with you about this:
- What we send: the minimum content needed for the feature — your input text plus the instructions for the task. We do not send your password or payment details.
- Who receives it: DeepSeek (China) and OpenAI (United States). Both act as our processors under written terms.
- Where it is processed: outside the UK — see section 6.
- Retention by providers: as set out in their enterprise terms and our contract with them.
- Human review: our AI output is a draft for you to review and edit. You are never obliged to accept it, and you may ask us to review it.
We do not use your CV, your documents or your interview answers to train our own models. We do not sell your personal data. We do not share your CV with employers unless you actively apply for a role and the application route requires it.
5. Who we share personal data with
We share personal data only as needed, and only with parties bound by written contracts:
| Recipient | Purpose | Location |
|---|---|---|
| Google Cloud (Cloud SQL, Cloud Run, Cloud Storage) | hosting, database, receipt storage | EEA (europe-west1) |
| Stripe | payments, subscriptions, billing | US / EU |
| Amazon Web Services (SES), Resend | transactional and digest email delivery | US / EEA |
| DeepSeek | AI features (see section 4) | China |
| OpenAI | AI features (see section 4) | United States |
| Microsoft Clarity | analytics and session recording, only after you consent | US |
| Scraping/data providers | collection of publicly available job listings | varies |
| Professional advisers (accountants, insurers, lawyers) | where necessary | UK |
| Regulators and law enforcement | where we are legally required | UK/EU/other |
| A buyer or successor | if our business (or this product) is sold or reorganised | UK/other |
We do not sell your personal data, and we do not share it for third-party advertising.
For PadCount: your organisation's data is visible to the members your organisation invites, and to us as processor. We do not use it for our own purposes beyond providing and securing the service.
6. International transfers
Some of our providers are outside the UK/EEA. Where we transfer personal data to a country without UK adequacy regulations, we rely on the ICO International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with a documented transfer risk assessment (a "data protection test" under the Data (Use and Access) Act 2025).
| Transfer | Safeguard |
|---|---|
| EEA (Google Cloud europe-west1) | Covered by UK adequacy regulations for the EEA |
| United States (OpenAI, Stripe, Microsoft, AWS, Resend) | IDTA/UK Addendum + risk assessment; or the UK Extension to the EU–US Data Privacy Framework where the provider is certified |
| China (DeepSeek) | No adequacy determination. IDTA/UK Addendum + a transfer risk assessment, and additional measures where needed. |
You can ask us for a summary of the safeguards we rely on at privacy@padgrad.com.
7. How long we keep it
| Data | Retention |
|---|---|
| Account, profile, documents | while your account is active, then 12 months after closure or last activity, then deleted |
| Application and rejection records | 24 months from the date you log them |
| AI inputs and outputs | 30 days, unless kept longer to resolve a support request you have raised |
| Cookies and analytics | as set out in the Cookie Policy |
| Payment, tax and accounting records | 6 years from the end of the relevant financial year (legal requirement) |
| Receipt images and PadCount financial data | per your organisation's instructions; deleted on termination in line with the data processing addendum |
| Security and audit logs | 12 months |
| Complaints and legal files | 6 years (limitation period) |
We keep data only as long as we need it. Retention schedules are reviewed annually.
8. Your rights
You have the right to:
- Be informed — via this notice and the AI Transparency Notice;
- Access a copy of your personal data;
- Rectify inaccurate data (much of it you can edit yourself in your account);
- Erase your data where we no longer need it;
- Restrict how we use it;
- Object to processing based on legitimate interests, including profiling and direct marketing (marketing objections are absolute — we stop);
- Data portability — receive your data in a structured, machine-readable format, or have it sent to another provider where technically feasible;
- Withdraw consent at any time, without affecting what we did before;
- In relation to automated decisions that significantly affect you: be told about the decision, make representations, obtain human intervention, and contest the outcome.
How to exercise them: email privacy@padgrad.com. We will respond within one month — we may extend by two further months for complex requests and will tell you if we do. We do not charge for rights requests. We may ask you to verify your identity. You can also delete much of your data yourself in settings.
If you are unhappy with our response, you can complain to:
| Jurisdiction | Regulator |
|---|---|
| UK | Information Commissioner's Office — ico.org.uk · 0303 123 1113 |
| Kenya | Office of the Data Protection Commissioner (ODPC) — odpc.go.ke |
| Nigeria | Nigeria Data Protection Commission (NDPC) — ndpc.gov.ng |
| Uganda | Personal Data Protection Office (PDPO) — pdpo.go.ug |
| EU | Your national supervisory authority (for example the DPC in Ireland, or the authority where you live) |
9. Marketing
We send marketing (job digest, product news, referral prompts) only with your consent. We ask for that consent separately at registration with an unticked box, and you can withdraw at any time using the unsubscribe link in every email or in your settings. Withdrawing marketing consent does not stop essential service emails (verification, receipts, security, major service changes).
If you have bought something from us, we may occasionally send you information about similar products. You can always tell us to stop, and we will.
10. Security
We take the security of your data seriously and use appropriate technical and organisational measures, including: encryption in transit, hashed passwords (argon2), access controls and role separation, unique credentials for privileged systems, audit logging, regular backups, patched infrastructure, and least-privilege access to production data. Receipt images and documents are stored in access-controlled cloud storage.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware and tell you directly where the risk is high.
11. Children
Our services are for people aged 18 and over. We do not knowingly collect data from under-18s. If you believe a child has created an account, contact privacy@padgrad.com and we will investigate and delete the account.
[NOTE — compliance decision required: if you choose to allow 16–17 year olds, you must implement an age declaration, high-privacy defaults, no behavioural advertising or profiling of minors, no session recording of minors, and full alignment with the ICO's Children's Code. The ICO has shown what happens otherwise — Reddit was fined £14.47m in February 2026 for inadequate age assurance, no lawful basis and no DPIA.]
12. Cookies
Our Cookie Policy lists the cookies and similar technologies we use, what they are for, and how to accept, reject or withdraw. Non-essential cookies and session recording are set only after you consent.
13. Changes
If we make a material change to how we use your personal data, we will update this notice, change the version date, and notify you by email or in-product notice before the change takes effect.
14. Contact
Padgrad Ltd · 20 Wenlock Road, London, England, N1 7GU · privacy@padgrad.com