🚀 padgrad
Blogu Ingia

Padgrad Ltd · Legal

Privacy Policy

Version 1.0 — 12 September 2026

On this page

  • 1. Who we are
  • 2. The personal data we collect
  • 3. Why we use it, and our lawful basis
  • 4. Artificial intelligence features
  • 5. Who we share personal data with
  • 6. International transfers
  • 7. How long we keep it
  • 8. Your rights
  • 9. Marketing
  • 10. Security
  • 11. Children
  • 12. Cookies
  • 13. Changes
  • 14. Contact

Version 1.0 — 12 September 2026

1. Who we are

Padgrad Ltd is the data controller for the personal data described in this notice. We are a company registered in England and Wales (company number 17365449) with our registered office at 20 Wenlock Road, London, England, N1 7GU.

  • Data protection contact: privacy@padgrad.com
  • EU representative (GDPR Art. 27): Not yet appointed — we will publish the representative's name and address here before we actively offer services to people in the EU. In the meantime, contact privacy@padgrad.com and we will deal with your request directly
  • ICO registration: Pending — published once the data protection fee is paid (we pay the statutory data protection fee)

If you are a customer of PadCount (our business expense-tracking product), we act as a processor for the employee and financial data your organisation puts into PadCount, and as a controller for your account, billing and marketing data. The business terms and data processing addendum govern that relationship; this notice covers the parts where we are the controller.


2. The personal data we collect

CategoryWhat it includesWhere it comes from
Account and identityname, email address, password hash, Google account identifier (if you sign in with Google), account status, language preferenceyou
Profile and educationphone number, location/country, degrees and qualifications, universities, grades, work history, skills, career interests, volunteer interestyou
Your documentsCVs and CV text, cover letters, generated draftsyou / generated by our AI features at your request
Job-search activitysaved and viewed jobs, applications you log, rejection outcomes you record, interview practice sessions, career quiz answers, heatmap and pattern analyses derived from your recordsyou / derived from your activity
PaymentsStripe customer and payment identifiers, transaction history, credits balance. We never receive or store your card numberStripe
Communicationssupport messages, complaints, emails we send you and their engagement, feedbackyou / our systems
TechnicalIP address, approximate location derived from IP (country-level, via GeoIP), device and browser information, session identifiers, error and security logsyour device
Cookies and similarsee the Cookie Policy — including analytics and session-replay data collected only with your consentyour device
PadCount business datacompany name and slug, VAT number, tax year end, expense and revenue entries, uploaded receipt images, team member names and roles, invite recordsyour organisation and its staff

We do not ask for, and do not want, special category data (for example health, ethnicity, religion, trade union membership, sexual orientation, biometrics). CVs sometimes contain this information incidentally. Please remove anything of that kind before uploading.

We do not intentionally collect data from under-18s — see section 11.


3. Why we use it, and our lawful basis

PurposeLawful basis
Creating and running your account, providing the features you ask for, generating CV checks/cover letters/interview practice at your requestPerformance of a contract (Art. 6(1)(b))
Job matching, personalised listings, relevance ranking and the indicative match/predictive scoreLegitimate interests (Art. 6(1)(f)) — giving you useful results rather than an unranked list. We have carried out and documented a balancing test
Sending you the job digest and other service emails you opted intoConsent (Art. 6(1)(a)) for marketing. Service/transactional messages (verification, receipts, security) rely on contract or legitimate interests
Analytics, product improvement, error monitoringConsent where cookies or session recording are involved (Cookie Policy); otherwise legitimate interests in running a working, secure service
Security, fraud prevention, abuse prevention, rate limiting, enforcing our termsLegitimate interests and, where relevant, legal obligation
Taking payment, accounting, tax and VAT recordsContract and legal obligation (Art. 6(1)(c))
Handling complaints, rights requests and legal claimsLegal obligation and legitimate interests in defending claims
Referral programme administrationContract / legitimate interests, with consent where required for marketing communications

Automated decisions. We use automated processing to score, rank and analyse your job-search activity (for example match scores, and patterns in the applications and rejections you log). Where such processing could have a significant effect on you, you have the rights set out in section 8 — including the right to be informed, to make representations, to obtain human intervention and to contest the outcome. We do not use solely automated decision-making to make final decisions about you or anyone else.


4. Artificial intelligence features

Our AI-assisted features use third-party models — currently DeepSeek and OpenAI — alongside our own logic. When you use them, the content you submit (for example your CV text, a job description, your cover letter draft or your interview answers) is sent to those providers so they can return a result.

We are required to be straight with you about this:

  • What we send: the minimum content needed for the feature — your input text plus the instructions for the task. We do not send your password or payment details.
  • Who receives it: DeepSeek (China) and OpenAI (United States). Both act as our processors under written terms.
  • Where it is processed: outside the UK — see section 6.
  • Retention by providers: as set out in their enterprise terms and our contract with them.
  • Human review: our AI output is a draft for you to review and edit. You are never obliged to accept it, and you may ask us to review it.

We do not use your CV, your documents or your interview answers to train our own models. We do not sell your personal data. We do not share your CV with employers unless you actively apply for a role and the application route requires it.


5. Who we share personal data with

We share personal data only as needed, and only with parties bound by written contracts:

RecipientPurposeLocation
Google Cloud (Cloud SQL, Cloud Run, Cloud Storage)hosting, database, receipt storageEEA (europe-west1)
Stripepayments, subscriptions, billingUS / EU
Amazon Web Services (SES), Resendtransactional and digest email deliveryUS / EEA
DeepSeekAI features (see section 4)China
OpenAIAI features (see section 4)United States
Microsoft Clarityanalytics and session recording, only after you consentUS
Scraping/data providerscollection of publicly available job listingsvaries
Professional advisers (accountants, insurers, lawyers)where necessaryUK
Regulators and law enforcementwhere we are legally requiredUK/EU/other
A buyer or successorif our business (or this product) is sold or reorganisedUK/other

We do not sell your personal data, and we do not share it for third-party advertising.

For PadCount: your organisation's data is visible to the members your organisation invites, and to us as processor. We do not use it for our own purposes beyond providing and securing the service.


6. International transfers

Some of our providers are outside the UK/EEA. Where we transfer personal data to a country without UK adequacy regulations, we rely on the ICO International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with a documented transfer risk assessment (a "data protection test" under the Data (Use and Access) Act 2025).

TransferSafeguard
EEA (Google Cloud europe-west1)Covered by UK adequacy regulations for the EEA
United States (OpenAI, Stripe, Microsoft, AWS, Resend)IDTA/UK Addendum + risk assessment; or the UK Extension to the EU–US Data Privacy Framework where the provider is certified
China (DeepSeek)No adequacy determination. IDTA/UK Addendum + a transfer risk assessment, and additional measures where needed.

You can ask us for a summary of the safeguards we rely on at privacy@padgrad.com.


7. How long we keep it

DataRetention
Account, profile, documentswhile your account is active, then 12 months after closure or last activity, then deleted
Application and rejection records24 months from the date you log them
AI inputs and outputs30 days, unless kept longer to resolve a support request you have raised
Cookies and analyticsas set out in the Cookie Policy
Payment, tax and accounting records6 years from the end of the relevant financial year (legal requirement)
Receipt images and PadCount financial dataper your organisation's instructions; deleted on termination in line with the data processing addendum
Security and audit logs12 months
Complaints and legal files6 years (limitation period)

We keep data only as long as we need it. Retention schedules are reviewed annually.


8. Your rights

You have the right to:

  1. Be informed — via this notice and the AI Transparency Notice;
  2. Access a copy of your personal data;
  3. Rectify inaccurate data (much of it you can edit yourself in your account);
  4. Erase your data where we no longer need it;
  5. Restrict how we use it;
  6. Object to processing based on legitimate interests, including profiling and direct marketing (marketing objections are absolute — we stop);
  7. Data portability — receive your data in a structured, machine-readable format, or have it sent to another provider where technically feasible;
  8. Withdraw consent at any time, without affecting what we did before;
  9. In relation to automated decisions that significantly affect you: be told about the decision, make representations, obtain human intervention, and contest the outcome.

How to exercise them: email privacy@padgrad.com. We will respond within one month — we may extend by two further months for complex requests and will tell you if we do. We do not charge for rights requests. We may ask you to verify your identity. You can also delete much of your data yourself in settings.

If you are unhappy with our response, you can complain to:

JurisdictionRegulator
UKInformation Commissioner's Office — ico.org.uk · 0303 123 1113
KenyaOffice of the Data Protection Commissioner (ODPC) — odpc.go.ke
NigeriaNigeria Data Protection Commission (NDPC) — ndpc.gov.ng
UgandaPersonal Data Protection Office (PDPO) — pdpo.go.ug
EUYour national supervisory authority (for example the DPC in Ireland, or the authority where you live)

9. Marketing

We send marketing (job digest, product news, referral prompts) only with your consent. We ask for that consent separately at registration with an unticked box, and you can withdraw at any time using the unsubscribe link in every email or in your settings. Withdrawing marketing consent does not stop essential service emails (verification, receipts, security, major service changes).

If you have bought something from us, we may occasionally send you information about similar products. You can always tell us to stop, and we will.


10. Security

We take the security of your data seriously and use appropriate technical and organisational measures, including: encryption in transit, hashed passwords (argon2), access controls and role separation, unique credentials for privileged systems, audit logging, regular backups, patched infrastructure, and least-privilege access to production data. Receipt images and documents are stored in access-controlled cloud storage.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware and tell you directly where the risk is high.


11. Children

Our services are for people aged 18 and over. We do not knowingly collect data from under-18s. If you believe a child has created an account, contact privacy@padgrad.com and we will investigate and delete the account.

[NOTE — compliance decision required: if you choose to allow 16–17 year olds, you must implement an age declaration, high-privacy defaults, no behavioural advertising or profiling of minors, no session recording of minors, and full alignment with the ICO's Children's Code. The ICO has shown what happens otherwise — Reddit was fined £14.47m in February 2026 for inadequate age assurance, no lawful basis and no DPIA.]


12. Cookies

Our Cookie Policy lists the cookies and similar technologies we use, what they are for, and how to accept, reject or withdraw. Non-essential cookies and session recording are set only after you consent.


13. Changes

If we make a material change to how we use your personal data, we will update this notice, change the version date, and notify you by email or in-product notice before the change takes effect.


14. Contact

Padgrad Ltd · 20 Wenlock Road, London, England, N1 7GU · privacy@padgrad.com


Questions about this page? Email legal@padgrad.com. Report a data protection issue to privacy@padgrad.com.

All legal documents · Company information · Cookie settings

Blogu · Dashibodi · Msaada · Bei
Legal information · Terms & conditions · Privacy policy · Cookie policy · Disclaimer ·

Padgrad Ltd — registered in England and Wales, company number 17365449. Registered office: 20 Wenlock Road, London, England, N1 7GU. Operated by Padgrad Ltd. We are not an employment agency, and we do not provide immigration, legal, tax or financial advice.

Padgrad — kazi za wahitimu, zinalingana na digrii yako