GDPR Policy
Your data protection rights under the General Data Protection Regulation and UK Data Protection Act 2018
Effective Date: 1st October 2025
Last Updated: 7th March 2026
DoviLearn Global Education Ltd, trading as CVSense, is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy outlines your rights and our responsibilities regarding data protection.
This GDPR policy applies to all users of the CVSense platform, including Job Seekers who use our CV creation, SmartMatch, Apply Assist, and Browser Extension services, and Recruiters who use our recruitment, CV screening, candidate management, and job posting services.
Data Controller
Company: DoviLearn Global Education Ltd (trading as "CVSense")
Company Number: 15697688
Registered Office: 124 City Road, London, United Kingdom, EC1V 2NX
Contact: privacy@cvsense.co.uk
Lawful Basis for Processing Personal Data
We process your personal data under the following lawful bases:
(a) Consent: For AI processing, email communications, analytics, and optional features where you have opted in.
(b) Legitimate Interest: For service improvement, fraud prevention, and security measures.
(c) Legal Obligations: To comply with applicable laws and regulations.
(d) Contract Performance: To provide our CV creation and job application services.
(d1) Consent (Expert Apply Assist Service): Where Job Seekers enrol in the Expert Apply Assist Service, we process their Personal Data based on their express consent to apply for jobs on their behalf, create and manage email addresses for application purposes, and utilise the CVSense platform and AI Technology to carry out these activities.
(e) Contract Performance (Recruiter Services): To provide job posting, CV screening, candidate scoring, application management, and related recruitment services to Recruiters.
(f) Legitimate Interest (Recruiter Data Processing): For the processing of Candidate Data uploaded by Recruiters through Screening Projects, where the Recruiter has a legitimate interest in evaluating candidates for employment purposes.
Your Data Protection Rights
Under GDPR, you have the following rights regarding your personal data:
1. Right of Access
Request copies of your personal data and information about how we process it.
2. Right to Rectification
Request correction of inaccurate or incomplete personal data.
3. Right to Erasure
Request deletion of your personal data in certain circumstances.
4. Right to Restrict Processing
Request limitation of processing in specific situations.
5. Right to Data Portability
Request transfer of your data to another service provider.
6. Right to Object
Object to processing based on legitimate interests or direct marketing.
7. Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent.
8. Right to Complain
Lodge a complaint with the Information Commissioner's Office (ICO).
To exercise your rights: Contact us at privacy@cvsense.co.uk with your request. We will respond within one month of receiving your request.
Recruiter-Specific GDPR Considerations:
Recruiters who use CVSense for Recruiters should note the following additional GDPR considerations:
(a) Data Controller Responsibility: When Recruiters upload Candidate Data (e.g., third-party CVs for screening), they act as independent Data Controllers for that data and are responsible for having a lawful basis to process it, including obtaining necessary consents.
(b) Data Processor Role of CVSense: CVSense acts as a Data Processor when processing Candidate Data on behalf of Recruiters. We process such data only in accordance with Recruiter instructions and applicable data protection law.
(c) Data Subject Rights Facilitation: CVSense will assist Recruiters in responding to data subject access requests, rectification requests, and erasure requests relating to Candidate Data processed through the Platform.
(d) Privacy Notices: Recruiters are responsible for providing appropriate privacy notices to candidates whose data they upload to or process through CVSense, including informing candidates that AI-powered tools will be used to analyse their CVs.
(e) Automated Decision-Making: CVSense's AI-powered candidate scoring and ranking constitutes profiling under Article 22 of the UK GDPR. Recruiters must ensure they do not rely solely on automated processing for decisions that produce legal effects concerning candidates. Human review of AI recommendations is required before making employment decisions.
(f) Data Protection Impact Assessments: Recruiters using bulk CV screening services may need to conduct Data Protection Impact Assessments (DPIAs) where required by the UK GDPR. CVSense will provide reasonable cooperation in connection with any such assessment.
AI and Large Language Model Processing and Your Data
CVSense uses Artificial Intelligence (AI), including Large Language Models (LLMs) and Natural Language Processing (NLP), to provide suggestions and recommendations for your CV and job applications. Here's what you need to know:
(a) AI and Large Language Model processing is based on your explicit consent.
(b) All system-generated content is advisory and requires your review.
(c) You can withdraw consent for AI and Large Language Model processing at any time.
(d) Your content is processed securely and in accordance with data protection laws.
(e) In Recruiter Services, Artificial Intelligence (AI), including Large Language Models (LLMs) and Natural Language Processing (NLP), is used to analyse candidate CVs, generate match scores, extract skills and qualifications, and produce candidate summaries. This processing constitutes profiling under the UK GDPR.
(f) Recruiters must ensure that automated AI analysis is supplemented with human review before making any employment decisions. CVSense AI outputs are advisory only and must not form the sole basis for rejecting or selecting candidates.
Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms:
(a) We will notify you within 72 hours of becoming aware of the breach.
(b) The notification will include the nature of the breach and potential consequences.
(c) We will provide information about steps taken to address the breach.
(d) We will notify the Information Commissioner's Office (ICO) as required by law.
Children's Privacy Protection
We take special care to protect children's privacy:
(a) Our services are not directed at children under 16 years of age.
(b) Users must be at least 16 years old to create an account.
(c) If we become aware that we have collected data from a child under 16 without parental consent, we will delete such information.
(d) Parents or guardians may contact us to request deletion of their child's data.
Data Retention
We retain your personal data in accordance with our data retention policies:
(a) Account data is retained while your account is active.
(b) After account closure, personal data is deleted within a reasonable timeframe.
(c) Some data may be retained for legal compliance or legitimate business purposes.
(d) Anonymised data may be retained for research and service improvement.
(d1) Data collected under the Expert Apply Assist Service, including application records and managed account credentials, is retained for the duration of the service and for two (2) years following service termination or withdrawal.
(e) Recruiter account data is retained while the account is active and for three (3) years after closure.
(f) Candidate Data uploaded through Screening Projects is retained for two (2) years from the date of upload, unless the Recruiter requests earlier deletion.
(g) Credit and billing transaction records are retained for seven (7) years in accordance with UK accounting and tax obligations.
(h) Job posting data and associated application records are retained for three (3) years from the vacancy closing date.
International Data Transfers
When transferring personal data outside the UK/EEA, we ensure adequate protection through:
(a) Adequacy decisions by the UK or European Commission.
(b) Standard Contractual Clauses (SCCs).
(c) Other appropriate safeguards as required by law.
Contact Information
Data Protection Enquiries
Email: privacy@cvsense.co.uk
Post: Data Protection Officer, DoviLearn Global Education Ltd, 124 City Road, London, EC1V 2NX
Complete Terms of Service
This GDPR Policy forms part of our comprehensive Terms of Service. For complete information about our data processing practices, privacy policies, and service terms, please refer to our full Terms of Service.
This GDPR Policy was last updated on 7th March 2026
© 2026 DoviLearn Global Education Ltd. Company Number: 15697688