PartnerXPartnerX

Privacy Policy

Last updated: April 2026

1. Who we are

PartnerX is operated by PartnerX Ltd, a company registered in England and Wales. We provide a career management platform for Planning, Project Controls, and PMO professionals.

For the purposes of UK GDPR and the Data Protection Act 2018, PartnerX Ltd is the data controller for personal data collected through this platform.

If you have any questions about this policy or how we handle your data, please contact us at privacy@partnerx.io.

2. What data we collect

We collect the following categories of personal data:

  • Account data: your name and email address when you register.
  • CV and career data: the CV documents you upload, job titles, work history, skills, qualifications, and any other content you enter into the platform.
  • Job tracking data: roles you save, application stages, notes, and outcomes you record inside the platform.
  • Billing data: payment information processed by Stripe. We do not store card details ourselves — Stripe is the data processor for all payment information.
  • Usage data: pages visited, features used, session duration, and similar analytics data collected via PostHog.
  • Technical data: IP address, browser type, device type, and operating system, collected automatically when you use the platform.

3. How we use your data

We use your personal data for the following purposes:

  • To create and maintain your account.
  • To provide the core platform features: CV scoring, CV optimisation, job tracking, and cover letter generation.
  • To process your CV content through AI models (Anthropic Claude) to generate scores, suggestions, and tailored content. This processing is performed server-side only.
  • To process payments and manage your subscription via Stripe.
  • To send transactional emails (account confirmations, password resets) via Resend.
  • To analyse how the platform is used and improve it over time, using PostHog analytics.
  • To comply with legal obligations.

4. Legal basis for processing

We rely on the following legal bases under UK GDPR:

  • Contract: processing your account data and CV content is necessary to deliver the service you signed up for.
  • Legitimate interests: platform analytics, security monitoring, and product improvement.
  • Legal obligation: retaining billing records as required by HMRC and applicable law.

5. Third-party processors

We share data with the following third-party processors, each bound by data processing agreements:

  • Supabase — database, authentication, and file storage (EU-hosted).
  • Anthropic — AI processing of CV content and job descriptions (server-side only; no raw CV data is stored by Anthropic beyond the API request).
  • OpenAI — embedding generation for semantic CV matching (server-side only).
  • Stripe — payment processing and subscription management.
  • Resend — transactional email delivery.
  • PostHog — product analytics (anonymised where possible).
  • Vercel — hosting and edge infrastructure.

We do not sell your personal data to any third party.

6. Data retention

We retain your account and CV data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or tax purposes (typically up to 7 years for billing records).

7. Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure ("right to be forgotten") of your personal data, subject to legal retention requirements.
  • Portability — receive your data in a structured, machine-readable format.
  • Restriction of processing in certain circumstances.
  • Object to processing based on legitimate interests.

To exercise any of these rights, contact us at privacy@partnerx.io. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Cookies

We use essential cookies to keep you signed in and maintain your session. We also use analytics cookies (PostHog) to understand how the platform is used. You can disable non-essential cookies in your browser settings at any time.

9. Security

We implement industry-standard security measures including encrypted data storage, row-level security on the database, HTTPS-only communication, and access controls. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security but we take all reasonable precautions.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the platform. Continued use of PartnerX after changes are posted constitutes acceptance of the updated policy.