Career Visibility Healthcheck

Privacy Policy

1. Who we are

This website (the Site), published at careerpaths.uk and at any development or staging address we operate, loyaltyMATTERS Ltd ("we", "us", "our") is the controller of the personal data described in this policy. We are registered in England and Wales under company number 04824426, with registered office at 104 Station Parade, Harrogate, North Yorkshire, HG1 1HQ. CareerPaths, Career Visibility Software and Cath are our brands and products.

We are registered with the Information Commissioner's Office under registration number Z1141240.

Contact for privacy matters: [email protected], or write to us, loyaltyMATTERS Ltd,104 Station Parade, Harrogate, North Yorkshire, HG1 1HQ.

2. What this policy covers

This policy explains how we handle personal data when you:

- visit our website, read our content or use Cath on our site;

- contact us, book a demo or make an enquiry;

- download a guide, template or checklist;

- complete our Career Visibility Healthcheck;

- act as an administrative, billing or technical contact for a customer organisation;

- receive marketing from us; or

- apply for a job with us, or act as a contact at one of our suppliers or partners.

Not covered: personal data held inside a customer's CareerPaths tenant — employee profiles, skills and competency attainment, career goals, development plans, 1:1 agendas and Cath conversations within the platform. Our customer is the controller of that data; we process it under the Data Processing Agreement in our Trust Pack. If you are an employee of one of our customers and want to know how your career data is handled, ask your employer, or contact us and we will refer your request to them.

3. The personal data we collect

Information you give us. Name, job title, organisation, work email, work phone (where you provide it), your organisation's website and careers page URLs, approximate employee numbers, the challenges you tell us you're facing, and anything else you include in an enquiry, form, email or call.

Career Visibility Healthcheck. Your answers to the ten questions, the score they produce, and the email address you give us if you ask for your results. The questions are about your organisation's careers content and practices — we don't ask for personal data about your employees, and you shouldn't include any.

Account data. Sign-up details, configuration choices and administrative contact details for customer organisations.

Billing data. Billing contact details, purchase and subscription records. Card payments are processed by Stripe; we do not store card numbers.

Cath conversations on our own website. The questions asked and answers given, and technical metadata. Please don't enter confidential or special category information into Cath.

Technical and usage data. IP address, device and browser type, operating system, referring source, pages viewed, time on page, and interactions with our content, collected via cookies and similar technologies (see Annex A).

Communications. Emails, form submissions, call notes, meeting notes and demo records, and whether you opened or clicked our emails.

Recruitment data, where you apply to work with us: application, CV, right-to-work and interview records.

We do not seek special category data (health, race, religion, trade union membership, sexual orientation, biometric data) in any of the above, and ask that you do not send it to us.

4. Where we get it

Directly from you; automatically as you use our site; from your colleagues (where someone at your organisation introduces you); from your organisation's public website and public careers content (for the Career Visibility Healthcheck, and for research before a meeting); from publicly available professional sources such as company websites, LinkedIn and Companies House, where we are researching organisations that may benefit from our services; and from our suppliers and partners (for example event organisers where you visited our stand and agreed to be contacted).

Business contact information from third-party sources

Where we believe an organisation may benefit from our services, we obtain limited business contact information about relevant people there — typically name, job title, work contact details and organisation details — from reputable business-data providers, and from public professional sources such as company websites and LinkedIn. We use this information only to make relevant business-to-business contact about our services. When we first contact you, we tell you where your details came from, and you can object to further contact at any time — one objection stops all our marketing to you, permanently.

5. Why we use it, and our lawful basis

| What we do | Data used | Lawful basis |

|---|---|---|

| Respond to enquiries, demo bookings and questions | Contact, organisation, enquiry content | Legitimate interests (responding to a request about our services); steps towards a contract |

| Deliver a requested resource, or your Career Visibility Healthcheck results · Contact, organisation, Healthcheck answers and score · Consent for the results email; legitimate interests for the resource itself |

| Provide and administer customer accounts · Account, configuration, contact · Performance of a contract |

| Take payment and keep financial records | Billing, transaction records | Performance of a contract; legal obligation (tax) |

| Provide support and service communications | Contact, account, correspondence | Performance of a contract; legitimate interests |

| Send marketing about our services to business contacts | Contact, organisation, engagement data | Legitimate interests (B2B direct marketing), subject to your right to object at any time; consent where required by law |

| Improve our website, content and products | Usage, analytics, Cath question logs, aggregated Healthcheck findings | Legitimate interests (understanding what our audience needs) |

| Publish benchmark and research content | Aggregated, anonymised data only | Not personal data once anonymised; legitimate interests up to the point of anonymisation |

| Keep our site and systems secure, prevent fraud and misuse | Technical, access and audit logs | Legitimate interests (security); legal obligation |

| Recruit staff | Application data | Legitimate interests; steps towards a contract; legal obligation (right to work) |

| Establish, exercise or defend legal claims; comply with law | As relevant | Legal obligation; legitimate interests |

Where we rely on legitimate interests we have assessed that our interest does not override your rights; you can ask us for the assessment, and you can object at any time (see section 9).

Marketing, specifically. If you download a resource, request a Review, book a demo or otherwise engage with us as a business contact, we will send you related content and follow-up about our services. Every marketing email has an unsubscribe link, and unsubscribing takes effect across all our marketing regardless of how you first reached us. We do not sell or rent your details to anyone. 

Cookies and consent. Non-essential cookies (analytics, marketing) are used only with your consent, given through our cookie banner and changeable at any time. See Annex A.

6. Cath, AI and automated processing

Where you use Cath on our website, your question and the minimum relevant content from our knowledge base are sent to our AI provider to generate an answer, and the exchange is logged in our systems. Our AI provider's commercial terms do not use customer content to train their models, and we do not use it to train any model of our own. We hold the provider's data processing terms and will share the relevant extract on request. We review these logs to improve our content and answers.

We do not use automated decision-making producing legal or similarly significant effects about you, and we do not profile you in any way that produces such effects. We do score and prioritise business enquiries to manage sales follow-up; this affects only how quickly a human contacts you and does not deny you any service. 

7. Who we share it with

Suppliers who process data on our behalf, under written contract and only on our instructions: hosting, email delivery, CRM and marketing automation, analytics, AI provider, payment processing (Stripe), error monitoring, e-signature and support tooling. The suppliers relevant to the *product* are listed in our Sub-Processor Register in the Trust Pack. 

- Professional advisers — accountants, lawyers, insurers — where necessary.

- Authorities and third parties where required by law, or to establish, exercise or defend legal claims.

- A buyer or successor if we sell or reorganise our business, subject to appropriate protections.

We never sell your personal data.

8. International transfers and where data is held

Our production platform and its data are hosted in the United Kingdom, as described in the Data Residency Statement in our Trust Pack. Where you enable AI features, some processing takes place outside the UK; our Sub-Processor Register sets out where, and the transfer mechanism that applies. Some of the suppliers we use for our own website and marketing may process data outside the UK. Where that happens, we rely on UK adequacy regulations or the UK International Data Transfer Agreement/Addendum (or EU Standard Contractual Clauses as applicable), with additional safeguards where needed. You can ask us for details of the safeguards in place.

9. How long we keep it

| Data | Retention |

|---|---|

| Enquiries and prospect records where no relationship develops | 24 months from last meaningful contact, then deleted or anonymised |

| Career Visibility Healthcheck responses and reports | 24 months, then deleted or anonymised; aggregated benchmark data retained indefinitely in anonymised form |

| Marketing contacts | Until you unsubscribe or 24 months of no engagement, whichever is sooner; suppression records kept indefinitely to honour your opt-out |

| Customer account and contract records | Duration of the contract plus 6 years |

| Billing and tax records | 6 years, as required by law |

| Cath conversation logs on our website | 12 months |

| Website analytics | 14 months (or as set in the tool) |

| Unsuccessful job applications | 6–12 months |

10. Your rights

You have the right to: be informed about how we use your data; request a copy of it; have inaccurate data corrected; have data erased in certain circumstances; restrict processing; object to processing based on legitimate interests, and to direct marketing at any time; receive certain data in a portable format; and withdraw consent where we rely on it.

To exercise any of these, email [email protected]. We will respond within one month. There is normally no charge.

If you are unhappy with how we've handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office — ico.org.uk, 0303 123 1113 — but we would appreciate the chance to address it ourselves.

If your request relates to data held inside a customer's CareerPaths tenant, we will refer you to that organisation, who is the controller.

11. Children

Our website and our commercial services are aimed at organisations and their professional representatives, not children, and we do not knowingly collect personal data from children through this site.

12. Security

We protect personal data with measures including encryption in transit and at rest, access controls, two-factor authentication, audit logging of security-sensitive workflows, and supplier due diligence. Our product security measures are described in full in the Trust Pack. No transmission over the internet is completely secure, so we cannot guarantee absolute security, but we do maintain procedures to deal with any suspected breach and will notify you and the ICO where we are legally required to do so.

13. Changes to this policy

We may update this policy from time to time. The current version is always published here, and we will note the date of the last update. This policy was last updated on 7th September 2026.

chevron-down