Privacy Policy
Last updated: 13 July 2026
1. Who we are
CiiVSOFT Foundry ("Foundry", "we", "us") is a job asset creation and optimisation service operated by CiiVSOFT Limited, a company registered in England and Wales under company number 09061018, whose registered office is at HLB House, 68 High Street, Tarporley, Cheshire, CW6 0AT. CiiVSOFT Limited is registered with the Information Commissioner's Office under registration number ZA087037.
For the personal data described in this policy, CiiVSOFT Limited is the data controller.
Our Data Protection Officer is Adam Butwilowski, Chief Executive Officer. Contact: privacy@ciivsoft.com or by post to the address above.
This Privacy Policy applies to CiiVSOFT Foundry only. A separate Privacy Policy governs CiiVSOFT Select and our candidate screening products, available at ciivsoft.com/privacy.
2. The short version
Foundry is a business-to-business tool that works with employer and job information only: your employer value proposition, hiring manager kickoff briefs and job postings. Foundry does not collect, store or process candidate or applicant data of any kind, and it makes no automated decisions about individuals. The only personal data we handle is the account information of the business users who sign up, and any incidental personal details (such as a hiring manager's name) contained in documents customers choose to upload.
3. What we collect
Account data
- Name, work email address and password credentials for your login
- Company name and domain
- Billing contact details processed via our payment provider (we do not store card numbers)
Customer content
- Employer value proposition content (values, benefits, culture, tone of voice)
- Kickoff briefs and documents you upload (job specs, adverts, competency frameworks and similar)
- Job postings you import from your applicant tracking system's public feeds
- Assets generated, edited and audited within the service
Usage data
- Standard server logs (IP address, browser type, pages requested) for security and service operation
This website sets no analytics or advertising cookies. The application uses only cookies that are strictly necessary for signing in and operating the service.
4. What we deliberately do not collect
- No candidate or applicant data. Foundry has no candidate-facing surface and no integration that transfers applicant records.
- No special category data is requested or required by any feature.
- No automated decision-making about individuals takes place in Foundry.
If a document you upload happens to contain personal data (for example, a named hiring manager in a briefing note), you remain responsible for having a lawful basis to share it, and we process it only to provide the service.
5. Why we process data (lawful bases)
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Providing the service under our agreement with your business | Contract (Article 6(1)(b)) |
| Billing, accounting and tax records | Legal obligation (Article 6(1)(c)) |
| Service security, abuse prevention and product improvement | Legitimate interests (Article 6(1)(f)) |
| Service emails about your account | Contract; marketing communications only with consent |
6. AI processing
Foundry uses large language models to generate and audit job content. AI model access is provided via Amazon Bedrock, a managed service within Amazon Web Services. All AI processing takes place within our AWS infrastructure — no data is transmitted to external AI model providers. The content processed by AI consists of your employer and job information (EVP data, kickoff briefs, job postings). It contains no candidate data. We do not use your content to train AI models.
7. Who we share data with
We use a small number of subprocessors to run the service, each under a data processing agreement:
| Subprocessor | Purpose |
|---|---|
| Amazon Web Services, Inc. | All infrastructure, hosting, database, authentication, and AI model access via Bedrock. The entire Foundry production environment operates within AWS. No data is transmitted outside AWS for the purpose of providing the service. |
| Stripe, Inc. | Subscription billing and payment processing. Stripe processes payment card data directly and is PCI DSS compliant. |
We do not sell personal data. We do not share customer content with third parties for their own purposes.
8. International transfers
Where a subprocessor processes data outside the UK, we rely on adequacy regulations or the International Data Transfer Agreement / Addendum with appropriate safeguards. Details of specific transfer mechanisms are available on request by contacting privacy@ciivsoft.com.
9. Retention
- Customer content: retained while your account is active. Following account closure, you retain read-only access for 30 days, after which content may be deleted.
- Account data: retained for the life of the account plus any period required by law for legal and accounting obligations (billing records: 7 years).
- Server logs: retained on a rolling basis for no more than 12 months.
You may request deletion of your personal data at any time by contacting privacy@ciivsoft.com. Where deletion is not possible — for example where we are required by law to retain records — we will explain why.
10. Security
All data is encrypted in transit and at rest. Access to production systems is restricted, logged and reviewed. Customer accounts are isolated from one another at the database level. In the event of a personal data breach affecting your data, we will notify you within 48 hours of becoming aware of it, where required by law.
11. Your rights
Under UK GDPR you have the right to: access the personal data we hold about you; have inaccurate data corrected; request erasure; restrict or object to processing; and receive your data in a portable format. To exercise any of these rights, contact privacy@ciivsoft.com with the subject line "Privacy Rights Request." We will respond within one calendar month.
You also have the right to complain to the Information Commissioner's Office at ico.org.uk.
12. Changes
We will post any changes to this policy on this page and update the date above. Material changes will be notified to account holders by email at least 30 days before taking effect.