CV Bright (“CV Bright”, “we”, “our” or “us”) respects your privacy. This Privacy & Data Protection Policy explains how we collect, use, disclose, store and protect personal data when you use cvbright.com, our account areas, Company services, application programming interfaces (“APIs”), AI-assisted CV tools, inquiry forms and connected services.
This policy is intended to comply with applicable UK data protection and electronic communications law, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (“PECR”). The EU GDPR may also apply where CV Bright offers services to, or monitors the behaviour of, individuals in the European Economic Area.
CV Bright is normally the data controller for personal data collected directly through the CV Bright website, individual user accounts, payments, Company inquiries, customer support and service administration. This means CV Bright determines why and how that data is processed.
For certain Company or Agency API services, the business customer may be the data controller for personal data it submits about its own staff, candidates, clients or other individuals, and CV Bright may act as its data processor. In those circumstances, the business customer is responsible for having a lawful basis and providing any required privacy information to those individuals. Where required, the parties will enter into appropriate data-processing terms or a Data Processing Addendum.
The information collected depends on how you use CV Bright.
CVs can sometimes contain sensitive or special-category personal data, such as health, disability, racial or ethnic origin, religious beliefs, trade-union membership or sexual orientation. Please avoid uploading sensitive information unless it is genuinely necessary. If you upload personal data about another person, you confirm that you are authorised to do so and have provided any required privacy information.
| Purpose | Typical personal data | UK GDPR lawful basis |
|---|---|---|
| Create and secure accounts, authenticate users and manage sessions | Email, authentication identifiers, password information, security logs | Performance of a contract; legitimate interests in account and platform security |
| Provide CV analysis, rewriting, cover letters, job tracking, analytics and downloads | CV content, job information, prompts, generated content and usage data | Performance of a contract or steps requested before entering a contract |
| Review Company inquiries, verify organisations and provision Company access | Company, contact, inquiry, verification and account data | Steps requested before entering a contract; performance of a contract; legitimate interests in fraud prevention and service administration |
| Process payments, subscriptions, receipts, invoices, cancellations and refunds | Billing identifiers, plan, amount, email and transaction status | Performance of a contract; legal obligation; legitimate interests in financial administration and fraud prevention |
| Operate and secure Company APIs, enforce limits and rotate keys | API credentials, usage counters, logs, tier and security events | Performance of a contract; legitimate interests in service security, abuse prevention and reliability |
| Send transactional and service communications | Email address, inquiry status, account and payment information | Performance of a contract; legitimate interests; legal obligation where applicable |
| Improve performance, troubleshoot faults and prevent misuse | Technical, usage, error and security information | Legitimate interests in improving, protecting and maintaining the service |
| Comply with tax, accounting, legal and regulatory duties | Transaction, account, complaint and audit information | Legal obligation; establishment, exercise or defence of legal claims where applicable |
| Send optional marketing | Email and communication preferences | Consent, or legitimate interests where legally permitted and subject to PECR |
Where we rely on legitimate interests, we consider whether the processing is necessary, proportionate and reasonably expected, and balance our interests against your rights. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out lawfully.
CV Bright uses AI services to analyse text and generate feedback, summaries, cover letters and related content. Information submitted for an AI feature may be transmitted to an AI service provider, such as OpenAI, to produce the requested response.
We do not sell personal data. We disclose personal data only where necessary, lawful and proportionate, including to service providers acting under contractual or equivalent safeguards.
Service providers may process only the information reasonably necessary for their role and are subject to their own security, privacy and contractual obligations.
Some providers may process personal data outside the United Kingdom. Where a restricted international transfer occurs, CV Bright will use an available lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, or another safeguard permitted by UK data protection law. We may also carry out transfer-risk assessments and apply additional technical or organisational protections where appropriate.
CV Bright uses cookies, browser storage and similar technologies that are necessary for functions such as authentication, session security, account preferences and fraud prevention. These essential technologies cannot always be disabled without affecting the service.
CV Bright will not intentionally place non-essential analytics, advertising or tracking technologies before obtaining consent where PECR requires it. If non-essential technologies are introduced, users will be given a clear way to accept, reject and later change their choices.
You can also control browser cookies or local storage through your browser settings, although deleting essential storage may sign you out or reset preferences.
Transactional emails—such as inquiry confirmations, account verification, password resets, billing notices and service-security messages—are not marketing and may be sent where necessary to provide or protect the service.
We will send promotional marketing only where permitted by law. Where consent is required, you can withdraw it using the unsubscribe method provided or by contacting info@cvbright.com. Opting out of marketing does not stop essential service communications.
We retain personal data only for as long as reasonably necessary for the purpose collected, to provide the service, meet legal duties, resolve disputes, prevent fraud and maintain security. Retention is determined by the type of record, account status, legal requirements and risk.
Where deletion is requested, we will remove or anonymise applicable data unless retention is required or permitted by law. Anonymised information that no longer identifies an individual may be retained for statistics, security and service improvement.
We use reasonable technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include HTTPS, access controls, password hashing, secret and API-key controls, role restrictions, logging, backups, service-provider security controls and monitoring.
No internet service can guarantee absolute security. You are responsible for using a strong password, protecting account and API credentials, signing out of shared devices and notifying us promptly of suspected unauthorised access.
Subject to legal conditions and exemptions, you may have the right to:
Send requests to info@cvbright.com. We may ask for information reasonably necessary to verify identity and protect accounts. We normally respond without undue delay and within one month. Where legally permitted, a complex request may take longer, and we will explain the extension.
Please contact us first at info@cvbright.com so that we can investigate. We will acknowledge and handle data protection complaints without undue delay, keep the complainant appropriately informed and explain the outcome.
You also have the right to complain to the UK supervisory authority:
Information Commissioner’s Office (ICO)
Website: ico.org.uk/make-a-complaint
Telephone: 0303 123 1113
We maintain procedures to investigate and respond to suspected personal data breaches. Where a breach is likely to create a risk to individuals’ rights and freedoms, we will notify the ICO as soon as possible and, where feasible, within 72 hours after becoming aware of it. Where the risk is high, we will also notify affected individuals without undue delay, unless an applicable legal exception applies.
CV Bright is intended primarily for people aged 16 or over. A person under 16 should use the service only with appropriate parent or guardian involvement and in accordance with the Terms. We do not knowingly seek to collect personal data from children under 13 without valid parental authorisation where consent is the applicable lawful basis. If you believe a child has provided data improperly, contact us so that we can investigate and take appropriate action.
Where an account-deletion feature is available, users may use it to request deletion. Requests may also be sent to info@cvbright.com. Deletion may not be immediate for information that must be retained for payments, legal obligations, fraud prevention, disputes, security records or restricted backups.
CV Bright may link to third-party websites or services. Their processing is governed by their own privacy notices, and CV Bright is not responsible for third-party content or privacy practices.
We may update this policy when our services, providers, legal obligations or data practices change. The latest version will be published on this page with a revised effective date. Where a change materially affects users, we may provide an additional notice through the website or by email.
When you use CV Bright Pathways, we may process information in addition to the general account and AI data described above. This can include target careers, qualifications or skills, answers provided to Pathways questions, generated routes and roadmaps, skills-gap information, milestones, goal status, archived or achieved routes, generation allowance and usage, plan entitlement, reminder preferences and timestamps associated with Pathways activity.
We use this information to provide the requested Pathways service, maintain plan allowances and saved roadmaps, personalise the user's own Pathways workspace, deliver requested reminders and protect the service from misuse. The typical lawful bases are performance of a contract or steps requested before entering a contract, together with legitimate interests in security, administration and service reliability.
For CV Bright Pathways for Education, we may process Institution application and verification information such as Institution name, type, address, website, work email/domain, applicant contact details, requested student capacity, application status, review notes, verification results and audit events.
To assess eligibility and reduce fraud, CV Bright may carry out automated and manual checks using information supplied by the applicant together with public or official sources. Checks may include website and domain information, email-domain and DNS/MX indicators, duplicate records, the Office for Students register, Get Information about Schools (GIAS), Companies House or other relevant public registers. Verification results may support an approval, rejection or manual-review workflow. Where a human review or override is available, authorised CV Bright administrators may consider the wider application context before a final operational decision.
Where an Institution workspace is used, CV Bright may process workspace and membership information including Institution identifiers, package and capacity, owner and staff names/emails, staff role and status, invitation records, student names/emails, cohort assignments, invitation and membership status, student access state, seat usage and limited Pathways engagement information needed to operate the Education dashboard.
Education analytics may include aggregate or account-level operational measures such as whether a student is connected, Pathways generation counts, active goal counts, milestone completion counts, monthly allowance usage and last-active timestamps. The purpose is to help the authorised Institution administer seats and understand use of the Institution-funded service. Access is restricted according to workspace roles and permissions.
Institutions are responsible for deciding which staff and students should be added and for having an appropriate lawful basis, authority and privacy information for personal data they submit. Depending on the processing activity, the Institution may act as controller and CV Bright may act as processor on its documented instructions. CV Bright may separately act as an independent controller for account security, fraud prevention, billing, legal compliance, service administration and its own operational records.
Education customers may use Pathways with students who are under 16. Where this occurs, the Institution must ensure that its use of the Service is lawful, age-appropriate and supported by any notices, authority, consent or parent/guardian involvement required for the particular setting. CV Bright uses account verification, invitation controls, role-based workspace permissions and Institution-managed access to reduce unauthorised use.
A student who creates or uses a personal CV Bright account remains subject to the eligibility provisions in the Terms. Institution-funded access is linked to the relevant Institution membership and may end or change when that membership or Institution licence changes.
For individual Pathways and Education Institution billing, we may process Stripe customer and subscription identifiers, checkout-session and invoice identifiers, selected package, billing cycle, plan start/end dates, cancellation-at-period-end status, payment-failure information, recovery/grace-period timestamps, Enterprise offer/activation status and related billing audit events. We use this information to activate paid entitlements, apply package capacity, reconcile payments, manage cancellations, support payment recovery, prevent duplicate activation and maintain financial records.
For Enterprise, CV Bright may also retain approved student/staff capacity, indicative and final reviewed pricing, request status, review history and activation timestamps. Browser-entered values are not treated as authoritative for final Enterprise billing; the server-side approved commercial record is used to control activation.
CV Bright may process email addresses, invitation identifiers, expiry timestamps, verification state, reminder schedule and delivery/audit information in order to send and secure account verification, password-reset messages, secure sign-in links, Institution staff invitations, student invitations, Pathways reminders, billing notices and other operational communications.
These messages are transactional rather than promotional where they are necessary to provide, secure or administer the requested Service. Repeated authentication or recovery messages may be subject to cooldown controls designed to reduce abuse and unwanted email.
For all inquiries regarding these Terms or the operation of the Service, please contact:
CV Bright Support
Email: info@cvbright.com
Website: https://cvbright.com
Registered Address: London, United Kingdom