Legal
Agency Privacy Policy
Effective date: 31 May 2026
1. Overview
This Agency Privacy Policy explains how SyncCV Agency collects, uses, stores, shares, protects, and deletes personal data for agency.synccv.store and the SyncCV Agency service.
SyncCV Agency is designed for recruitment businesses creating branded, privacy-aware candidate CV submissions. It includes automated privacy checks before AI-assisted drafting, but those checks are safeguards rather than a guarantee that every item of personal data will be detected.
This policy describes the processing we carry out for agency users, candidate documents, billing, security, support, and legal compliance under applicable UK data protection law, including the UK GDPR, the Data Protection Act 2018, and, where relevant, the Privacy and Electronic Communications Regulations.
2. Controller and Processor Roles
For agency account administration, billing, security, support, legal compliance, analytics where used, and service operations, the SyncCV owner/operator acts as controller.
For candidate CVs, candidate references, role briefs, client instructions, agency branding, and generated candidate outputs processed on the Customer's instructions, the Customer is normally the controller and SyncCV acts as processor.
The Agency Data Processing Addendum explains the processor terms that apply to Customer-controlled candidate data.
3. Personal Data We Collect
- ●Agency account data: user names, business email addresses, authentication identifiers, workspace details, roles, permissions, and account settings.
- ●Agency billing data: Stripe customer ID, subscription ID, plan, payment status, invoices, transaction metadata, and billing correspondence. We do not store full card details.
- ●Candidate and document data: candidate CV source files, role brief source files, extracted text processed during generation, candidate references, generated CV outputs, match analysis, quality checks, filenames, timestamps, and download choices.
- ●Branding and business data: agency name, logos, colours, contact details, footer text, and related output settings.
- ●Technical and security data: IP address, device and browser information, request logs, session data, security logs, error logs, and cookie consent choices.
- ●Support and communications data: messages, contact details, issue descriptions, and records of support interactions.
4. How We Use Personal Data
- ●To create and administer agency workspaces, user access, authentication, and permissions.
- ●To upload, extract, privacy-check, process, generate, store, preview, download, and support agency CV outputs.
- ●To process subscriptions, invoices, payment status, failed-payment handling, refunds, chargebacks, taxes, and billing support.
- ●To secure the service, prevent fraud, investigate misuse, enforce terms, and protect users, candidates, customers, and the platform.
- ●To respond to support requests, legal notices, rights requests, and operational communications.
- ●To maintain and improve reliability, performance, redaction quality, and user experience using logs and analytics, with consent where required for non-essential cookies.
- ●To comply with legal, tax, accounting, regulatory, court, law-enforcement, or professional obligations.
5. Lawful Bases Where We Are Controller
- ●Performance of contract: account creation, workspace access, billing, support, and service delivery to agency users.
- ●Legitimate interests: service security, fraud prevention, product improvement, support administration, legal protection, and business-to-business communications.
- ●Legal obligation: tax, accounting, regulatory, court, law-enforcement, and compliance records.
- ●Consent: non-essential cookies, analytics, or marketing communications where consent is required.
6. Candidate Data Processed for Agencies
Where we process candidate data for a Customer, the Customer decides what candidate data to upload, why it is processed, who may access it, whether it is shared with clients, and how long it should be retained, subject to the service controls available.
Customers must give candidates appropriate privacy information and identify a lawful basis before using SyncCV Agency with candidate material.
Uploaded source CVs and role briefs are stored in the Customer's agency workspace after generation unless deleted through available product controls, expiry processes, or an agreed deletion request.
Candidate outputs may contain professional information such as employers, roles, dates, education, skills, sectors, achievements, projects, and candidate references because those details may be necessary for useful recruitment documents.
7. AI Processing and Automated Decision-Making
SyncCV Agency uses AI-assisted drafting to generate candidate CV content and role-alignment material. It does not itself make hiring, rejection, shortlisting, salary, immigration, or background-checking decisions.
Generated scores, summaries, and role-fit language are decision-support material only. Agency users must review outputs before use and must not treat them as a final decision about a candidate.
Customers using AI in recruitment should explain relevant use to candidates and keep human review, fairness, accuracy, and bias controls in their own recruitment process.
8. Special Category and Criminal-Offence Data
Candidate CVs and role documents may contain sensitive information such as health information, disability information, trade union membership, ethnicity, religion, sexual orientation, political opinions, or criminal-offence information.
SyncCV Agency is not intended for unnecessary sensitive-data processing. Customers should remove sensitive information before upload unless it is lawful, necessary, proportionate, and covered by the required UK GDPR and Data Protection Act 2018 conditions.
9. Sharing Personal Data
We do not sell candidate CV data. We share personal data only where needed to operate, secure, improve, support, bill, or legally protect the service.
- ●Cloud hosting, storage, authentication, and deployment providers, including Firebase/Google Cloud and Vercel.
- ●AI processing providers, including Google Gemini or equivalent providers used for generation and analysis.
- ●Payment providers, including Stripe, for checkout, subscriptions, billing portal access, invoicing, refunds, tax, and fraud prevention.
- ●Email, support, analytics, monitoring, logging, and consent-management providers where enabled.
- ●Professional advisers, insurers, auditors, legal representatives, regulators, courts, public authorities, or law-enforcement bodies where necessary.
10. International Transfers
Some providers may process personal data outside the United Kingdom. Where restricted transfers occur, we rely on appropriate safeguards such as UK adequacy regulations, UK-approved standard contractual clauses, international data transfer agreements or addenda, provider data-processing terms, or other lawful transfer mechanisms.
11. Retention
- ●Agency account and workspace records are kept while the account is active and for a reasonable period afterwards where needed for legal, billing, security, support, or dispute purposes.
- ●Candidate source files, role brief source files, generated outputs, and agency document records are retained according to service functionality, Customer instructions, deletion requests, backup cycles, and legal or security needs.
- ●Billing and transaction records are retained as needed for tax, accounting, fraud-prevention, chargeback, and legal purposes.
- ●Security, audit, and error logs are retained for a limited period appropriate to investigation, reliability, legal, and security needs.
- ●Backups may retain data for a limited period before deletion is technically completed.
12. Security
We use technical and organisational measures designed to protect personal data, including account-based access controls, server-side ownership checks, encrypted transport, provider-managed encryption at rest, private storage controls, audit logging, and no-store caching for sensitive download responses.
No internet service is completely secure. Customers are responsible for managing authorised users, using strong authentication, limiting workspace access, and reporting suspected compromise promptly.
13. Cookies and Analytics
We use strictly necessary cookies and similar technologies to operate the site, authenticate users, remember security settings, and provide requested features.
Where non-essential analytics, advertising, or similar technologies are used, we seek consent where required by PECR and UK GDPR standards. You can manage cookies through available cookie controls and browser settings.
14. Rights Requests and ICO Complaints
Agency users may have rights to access, correct, erase, restrict, object, request portability, withdraw consent, and complain to the UK Information Commissioner's Office, subject to legal conditions and exemptions.
Candidate rights requests about candidate data in an agency workspace should normally be directed to the Customer as controller. Where we receive a candidate request relating to Customer-controlled data, we may refer it to the Customer or assist the Customer under the Data Processing Addendum.
You can contact us through the SyncCV Agency contact page. We may need to verify identity before responding. You also have the right to complain to the ICO at ico.org.uk.
15. Changes
We may update this Agency Privacy Policy to reflect changes in the service, providers, law, regulator guidance, security practices, or business operations. Material changes will be notified by updating this page and, where appropriate, by additional notice inside the service.