Privacy Policy

Last updated: 13 July 2026

1. Who we are

CiiVSOFT Foundry ("Foundry", "we", "us") is a job asset creation and optimisation service operated by CiiVSOFT Limited, a company registered in England and Wales under company number 09061018, whose registered office is at HLB House, 68 High Street, Tarporley, Cheshire, CW6 0AT. CiiVSOFT Limited is registered with the Information Commissioner's Office under registration number ZA087037.

For the personal data described in this policy, CiiVSOFT Limited is the data controller.

Our Data Protection Officer is Adam Butwilowski, Chief Executive Officer. Contact: privacy@ciivsoft.com or by post to the address above.

This Privacy Policy applies to CiiVSOFT Foundry only. A separate Privacy Policy governs CiiVSOFT Select and our candidate screening products, available at ciivsoft.com/privacy.

2. The short version

Foundry is a business-to-business tool that works with employer and job information only: your employer value proposition, hiring manager kickoff briefs and job postings. Foundry does not collect, store or process candidate or applicant data of any kind, and it makes no automated decisions about individuals. The only personal data we handle is the account information of the business users who sign up, and any incidental personal details (such as a hiring manager's name) contained in documents customers choose to upload.

3. What we collect

Account data

Customer content

Usage data

This website sets no analytics or advertising cookies. The application uses only cookies that are strictly necessary for signing in and operating the service.

4. What we deliberately do not collect

If a document you upload happens to contain personal data (for example, a named hiring manager in a briefing note), you remain responsible for having a lawful basis to share it, and we process it only to provide the service.

5. Why we process data (lawful bases)

PurposeLawful basis (UK GDPR)
Providing the service under our agreement with your businessContract (Article 6(1)(b))
Billing, accounting and tax recordsLegal obligation (Article 6(1)(c))
Service security, abuse prevention and product improvementLegitimate interests (Article 6(1)(f))
Service emails about your accountContract; marketing communications only with consent

6. AI processing

Foundry uses large language models to generate and audit job content. AI model access is provided via Amazon Bedrock, a managed service within Amazon Web Services. All AI processing takes place within our AWS infrastructure — no data is transmitted to external AI model providers. The content processed by AI consists of your employer and job information (EVP data, kickoff briefs, job postings). It contains no candidate data. We do not use your content to train AI models.

7. Who we share data with

We use a small number of subprocessors to run the service, each under a data processing agreement:

SubprocessorPurpose
Amazon Web Services, Inc.All infrastructure, hosting, database, authentication, and AI model access via Bedrock. The entire Foundry production environment operates within AWS. No data is transmitted outside AWS for the purpose of providing the service.
Stripe, Inc.Subscription billing and payment processing. Stripe processes payment card data directly and is PCI DSS compliant.

We do not sell personal data. We do not share customer content with third parties for their own purposes.

8. International transfers

Where a subprocessor processes data outside the UK, we rely on adequacy regulations or the International Data Transfer Agreement / Addendum with appropriate safeguards. Details of specific transfer mechanisms are available on request by contacting privacy@ciivsoft.com.

9. Retention

You may request deletion of your personal data at any time by contacting privacy@ciivsoft.com. Where deletion is not possible — for example where we are required by law to retain records — we will explain why.

10. Security

All data is encrypted in transit and at rest. Access to production systems is restricted, logged and reviewed. Customer accounts are isolated from one another at the database level. In the event of a personal data breach affecting your data, we will notify you within 48 hours of becoming aware of it, where required by law.

11. Your rights

Under UK GDPR you have the right to: access the personal data we hold about you; have inaccurate data corrected; request erasure; restrict or object to processing; and receive your data in a portable format. To exercise any of these rights, contact privacy@ciivsoft.com with the subject line "Privacy Rights Request." We will respond within one calendar month.

You also have the right to complain to the Information Commissioner's Office at ico.org.uk.

12. Changes

We will post any changes to this policy on this page and update the date above. Material changes will be notified to account holders by email at least 30 days before taking effect.