1. Who We Are
HospitalityCV is operated by Epicurean Digital Consultants Ltd, a company registered in England and Wales.
- Company number: 16622200
- Registered address: 30 Durham Road, Wimbledon West, London SW20 0TW
- Email: privacy@hospitalitycv.co.uk
- Phone: +44 7496 766792
2. What Data We Collect
- Account information: Your name, email address, and password (hashed). If you sign in with Google, we receive your name, email address, and profile picture from Google.
- CV data: The information you provide when building your CV, including work history, education, skills, certifications, and any other details you enter into our questionnaire.
- Payment data: If you purchase a paid plan, Stripe (our payment processor) collects your card details. We do not store your card details. We store your Stripe customer ID and transaction records.
- Usage data: Pages visited, features used, CV generations completed, and timestamps.
- Device and browser data: IP address, browser type, device type, operating system, and screen resolution (collected via Google Analytics 4, only with your consent).
3. How We Use Your Data
- To provide and operate the service: Creating your account, generating your CV using AI, storing your CVs, and processing payments. Legal basis: Performance of a contract (UK GDPR Article 6(1)(b)).
- To send transactional emails: Account confirmation, password resets, and service updates. Legal basis: Performance of a contract.
- To improve the service: Analysing usage patterns and performance metrics (only with your analytics consent). Legal basis: Consent (UK GDPR Article 6(1)(a)).
- To send marketing communications: Career tips and product updates (only if you opted in during registration). Legal basis: Consent. You can unsubscribe at any time.
- To comply with legal obligations: Maintaining financial records, responding to lawful requests. Legal basis: Legal obligation (UK GDPR Article 6(1)(c)).
4. AI Processing
Your CV data is processed by OpenAI's API (GPT-4.1-mini) to generate CV content. This involves sending your questionnaire answers to OpenAI's servers for processing. OpenAI does not use data submitted via their API to train their models (as per OpenAI's API data usage policy). The AI-generated content is returned to our servers and stored in your account.
5. Who We Share Your Data With
- Supabase Inc. (USA): Database hosting and authentication. Data processing agreement in place. Data transferred under UK-US data bridge adequacy framework.
- OpenAI Inc. (USA): AI CV generation. API data only (not used for training). Data transferred under UK-US data bridge adequacy framework.
- Stripe Inc. (USA): Payment processing. Stripe is PCI-DSS Level 1 certified. Data transferred under UK-US data bridge adequacy framework.
- Google LLC (USA): Analytics (GA4), only with your consent. OAuth authentication. Data transferred under UK-US data bridge adequacy framework.
- Vercel Inc. (USA): Website hosting. Data processing agreement in place.
We do not sell your personal data to any third party. We do not share your data with any party not listed above.
6. Data Retention
- Active accounts: Data retained for the duration of your account.
- Deleted accounts: All personal data and CV content deleted within 30 days. Anonymised usage statistics may be retained.
- Payment records: Retained for 7 years as required by UK tax law (HMRC).
- Analytics data: Retained for 14 months (GA4 default).
7. Your Rights
Under the UK GDPR, you have the right to:
- Access: Request a copy of all personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your data ("right to be forgotten").
- Restriction: Request that we limit how we use your data.
- Portability: Request your data in a machine-readable format.
- Object: Object to processing based on legitimate interests.
- Withdraw consent: Withdraw consent for analytics or marketing at any time.
To exercise any of these rights, email privacy@hospitalitycv.co.uk. We will respond within 30 days.
8. Cookies
Essential cookies: Required for the site to function (authentication sessions). These are set automatically.
Analytics cookies: Google Analytics 4. Only set if you give consent via our cookie banner. You can change your preferences at any time by clicking "Cookie Settings" in the footer.
See our full Cookie Policy for details.
9. Children
HospitalityCV is not intended for individuals under 16 years of age. We do not knowingly collect data from children under 16.
10. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes by email or by a notice on our website. The "Last updated" date at the top reflects the most recent revision.
11. Complaints
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk/make-a-complaint
- Phone: 0303 123 1113
12. Contact Us
Epicurean Digital Consultants Ltd
30 Durham Road, Wimbledon West, London SW20 0TW
Email: privacy@hospitalitycv.co.uk
Phone: +44 7496 766792