Privacy Policy

Last updated: April 2025

Introduction

At Jobstelo (“we,” “our,” or “us”), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.

Jobstelo is operated from Cardiff, United Kingdom. We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, the EU General Data Protection Regulation (EU GDPR) for users based in the European Economic Area. By using Jobstelo, you agree to the collection and use of information in accordance with this policy.

Information We Collect

Account Information

When you create an account, we collect:

  • Full name and email address
  • Password (stored as a one-way hash; we cannot read it)
  • Subscription and billing status

Career Documents and Content

To provide our Career Tools features, we process:

  • CVs and resumes you upload
  • Job descriptions you provide
  • Cover letters and personal statements generated
  • Interview responses (text and voice, if using voice features)

Career Hub Data

Our Career Hub features store data you actively enter to track your professional progress:

  • Activity logs, including titles, dates, notes, reflections, and sentiment ratings
  • Work goals, including titles, descriptions, target dates, action steps, sub-tasks, and progress notes
  • Career Growth Profile, including current role, target role, skills, career biography, and timeline
  • Progress reports, including titles, date ranges, and any AI-generated or manually edited summaries you save

Usage Data

We automatically collect:

  • IP address and device information
  • Browser type and version
  • Pages visited and features used
  • Time and date of visits

Lawful Basis for Processing (UK & EU GDPR)

We process your personal data under the following lawful bases:

  • Contract performance: processing necessary to provide the services you signed up for, including account management, CV analysis, interview simulation, and Career Hub features.
  • Legitimate interests: we have a legitimate interest in keeping our services secure, preventing fraud, improving our platform, and sending transactional notifications about your account and goals.
  • Consent: for optional marketing communications. You can withdraw consent at any time by unsubscribing or adjusting your notification preferences in your account settings.
  • Legal obligation: where we are required to process data to comply with applicable law.

How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain our services
  • Process and analyse your documents and career data using AI technology
  • Generate personalised cover letters, interview questions, and career insights
  • Power your Career Hub, including activity tracking, goal management, and progress reports
  • Send goal step reminders, completion notifications, and activity nudges
  • Improve and personalise your experience
  • Communicate with you about updates, support, and (with consent) promotions
  • Process payments and manage subscriptions
  • Detect and prevent fraud and security issues
  • Comply with legal obligations

AI Processing

Our services use artificial intelligence to analyse documents, simulate interviews, generate content, and produce career summaries. Important points about our AI processing:

  • Your data is transmitted securely and encrypted in transit
  • We use advanced AI technology to deliver key features. Any data shared is used solely to provide the requested functionality and is processed in line with applicable data protection and privacy standards.
  • We do not use your personal documents or career data to train AI models
  • AI-generated content (summaries, cover letters, interview feedback) is for your personal use only
  • You retain ownership of all documents you upload and content generated from them
  • AI-generated progress summaries are labelled clearly and you can edit or delete them before sharing

Data Sharing and Third-Party Processors

We do not sell your personal information. We share your data only with trusted third-party service providers (“data processors”) who support essential platform functions such as payment processing, infrastructure hosting, email delivery, and AI-powered features. These providers are contractually bound to process your data solely on our behalf and in accordance with this policy.

All third-party services we use adhere to industry-standard security and data protection practices.

We may also disclose your information where required by law, court order, or to protect the rights, safety, or property of Jobstelo or others. In the event of a merger, acquisition, or sale of assets, your data may be transferred to a successor entity under equivalent protections.

International Data Transfers

Some of our third-party processors are based outside the UK and European Economic Area (EEA), including in the United States. Where data is transferred internationally, we ensure adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner’s Office (ICO) or the European Commission, or reliance on adequacy decisions. By using our services, you acknowledge that your data may be processed in these jurisdictions.

Data Security

We implement appropriate technical and organisational security measures to protect your information:

  • SSL/TLS encryption for all data in transit
  • Encrypted database storage for sensitive data
  • Secure, one-way password hashing (we cannot read your password)
  • JWT-based authentication with short-lived tokens
  • Access controls limiting data access to authorised personnel only
  • Regular security reviews

While we strive to protect your information, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security. If you suspect any unauthorised access to your account, please contact us immediately at security@jobstelo.com.

Data Retention

We retain your personal data for as long as your account is active or as necessary to provide services. You can request deletion of your account and data at any time. After account deletion:

  • Personal account information is deleted within 30 days
  • Uploaded documents, activity logs, goals, and career data are permanently deleted
  • Anonymised, aggregated usage data may be retained for service improvement
  • Some data may be retained for a limited period where required by law or for legitimate security purposes

Your Rights Under UK & EU GDPR

As a data subject, you have the following rights regarding your personal data:

  • Right to access: request a copy of the personal data we hold about you
  • Right to rectification: request correction of inaccurate or incomplete data
  • Right to erasure (“right to be forgotten”): request deletion of your personal data
  • Right to data portability: request your data in a structured, machine-readable format
  • Right to object: object to processing based on legitimate interests or for direct marketing
  • Right to restrict processing: request that we limit how we use your data in certain circumstances
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at privacy@jobstelo.com. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk, or with your local data protection authority if you are based in the EEA.

Cookies and Tracking

We use the following types of cookies:

  • Strictly necessary cookies: required for authentication and keeping you logged in. These cannot be disabled
  • Preference cookies: remember your settings and notification preferences
  • Analytics cookies: help us understand how our services are used so we can improve them. No personally identifiable information is shared with analytics providers

You can control non-essential cookies through your browser settings. Disabling cookies may affect authentication and some features of our services.

Children’s Privacy

Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@jobstelo.com and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting the updated policy on this page with a revised “Last updated” date. Where required by law, we will seek your consent before applying changes that affect how we use your personal data.

Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us: