Privacy Notice

Effective Date: June 22, 2025 | Last Updated: May 26, 2025

1. Who We Are

Pathleader operates the pathleader.ai platform, an AI-powered job-matching service that helps job seekers find the perfect employment opportunities while they relax. Our platform integrates with multiple job boards to provide intelligent, personalized job recommendations.

Data Controller: Pathleader

Contact: privacy@pathleader.ai

Website: pathleader.ai

The purpose of this Privacy Notice is to inform you of how we process your personal data and ensure you that your personal data is managed with care and transparency. You should always feel safe when you share personal data with Pathleader, and we continuously work on implementing necessary technical and organizational security measures.

Our privacy notice is designed to meet the requirements of various international data protection laws and regulations, including the General Data Protection Regulation (GDPR). However, in some cases, local laws may impose additional obligations or restrictions.

2. Information We Collect

We collect and process the following categories of personal data:

2.1 Account Registration Data

  • Name and email address
  • Password (stored in encrypted form)
  • IP address and device information

2.2 CV/Resume and Professional Information

  • Complete CV/resume content (work history, education, skills, contact details)
  • Career progression and professional experience
  • Academic qualifications and achievements
  • Professional skills and competencies
  • Career objectives and preferences

2.3 Job Search and Matching Data

  • Job search queries and preferences
  • Saved job listings and applications
  • Job matching results and interactions
  • Platform usage patterns and preferences

2.4 AI Career Counseling Data

  • Career-related questions and conversations
  • Professional development inquiries
  • Guidance requests and responses
  • Career counseling session history

2.5 Cover Letter Generation Data

  • Job descriptions and application requirements
  • Generated cover letters and application materials

2.6 Payment and Subscription Data

  • Payment method details and billing information
  • Subscription plan and payment history
  • Transaction records and billing address

2.7 Support and Communication Data

  • Support tickets and email communications
  • Feedback and survey responses
  • Technical support interactions

2.8 Technical and Usage Data

  • Device information and browser type
  • IP address and approximate location (country/region)
  • Platform usage analytics and performance data
  • Cookie and tracking data (where consented)

3. Purpose, Legal Basis, and Categories of Processing

3.1 Legal Bases for Processing Personal Data

Contractual Obligation (Article 6(1)(b)): When we process your personal data to fulfill an agreement we have entered, or are preparing to enter, with you as a user

Legitimate Interest (Article 6(1)(f)): When we have an interest in processing your personal data for a specific purpose and have assessed that our purpose is justified

Legal Obligation (Article 6(1)(c)): When we process your personal data to comply with legal requirements applicable to our operations

Consent (Article 6(1)(a)): For processing that requires your active consent, where we explicitly request your approval

3.2 Data Processing Purposes Table

PurposeData CategoriesLegal Basis
Core Service DeliveryAccount data, CV/resume content, job preferencesContractual Obligation
AI SearchProfessional information, skills, career historyContractual Obligation
AI Career CounselingCareer questions, professional background, conversation historyContractual Obligation
Cover Letter GenerationCV content, job descriptions, professional informationContractual Obligation
Payment ProcessingPayment information, billing details, subscription dataContractual Obligation / Legal Obligation
Service ImprovementAnonymized usage patterns and feedbackLegitimate Interest
Marketing CommunicationsEmail address and communication preferencesConsent
Platform SecurityLogin data, device information, IP addressLegitimate Interest

4. Automated Decision-Making and AI Processing

AI Fairness Commitment: We regularly audit our AI systems for bias and discrimination to ensure fair job matching regardless of your background, gender, age, or other protected characteristics.

4.1 AI Search

Our platform uses artificial intelligence to analyze your CV and match you with suitable job opportunities. This automated processing involves:

  • Logic: AI algorithms compare your skills, experience, and preferences with job requirements from integrated job boards
  • Significance: Job recommendations directly influence your job search and career opportunities
  • Your Rights: You can request human review of any job match, opt-out of automated matching, and access information about how decisions are made

4.2 AI Career Counseling

Our AI career counselor provides automated advice based on your professional background and career questions:

  • Logic: Natural language processing analyzes your career situation and provides personalized guidance
  • Significance: Career advice may influence your professional development decisions
  • Your Rights: You can request clarification on any advice given and opt-out of AI counseling

4.3 Safeguards and Your Rights

For all automated decision-making, you have the right to:

  • Request human intervention and review
  • Express your point of view and contest decisions
  • Receive explanations about the logic and significance of automated processing
  • Opt-out of automated processing where possible

5. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

5.1 Technical Measures

  • End-to-end encryption for data transmission (TLS 1.3)
  • Encryption at rest for all stored data
  • Secure API communications with service providers
  • Regular security monitoring and vulnerability assessments

5.2 Organizational Measures

  • Role-based access controls and multi-factor authentication
  • Staff training on data protection procedures
  • Regular security audits and incident response procedures
  • Privacy by design in system architecture

5.3 Data Processing Agreements

All service providers are bound by comprehensive data processing agreements ensuring GDPR compliance.

6. Data Sharing and Recipients

6.1 AI Model Training - What We Don't Do

We do not use your personal data to train our AI models or improve third-party AI systems. Your CV content, career information, and conversations remain private and are never used to enhance AI models for other users or external purposes.

6.2 Service Providers

We share data with trusted service providers who help us deliver our services:

  • EU-based Database and Authentication Providers: Database, storage, and authentication services
  • AI Processing Services: AI processing for job matching, career counseling, and cover letter generation
  • EU-based Payment Processing Services: Payment processing and subscription management
  • EU-based Frontend Hosting and Content Delivery Services: Frontend hosting and content delivery
  • Backend Hosting and API Services: Backend hosting and API services

6.3 Legal Requirements

We may share data when required to:

  • Comply with legal obligations
  • Respond to lawful requests from authorities
  • Protect our rights and prevent fraud
  • Ensure platform security and safety

7. International Data Transfers

Some of our service providers are located outside the EU/EEA:

Countries with Adequacy Decisions:

For transfers to countries the European Commission has deemed to provide adequate protection, we rely on these adequacy decisions.

Countries without Adequacy Decisions:

For transfers to other countries, we implement appropriate safeguards including:

  • Data Processing Agreements with all service providers
  • Standard Contractual Clauses approved by the European Commission
  • Additional technical and organizational security measures

8. Your Rights Under GDPR

You have the following rights regarding your personal data:

8.1 Right of Access

Request a copy of the personal data we hold about you and information about how it's processed.

8.2 Right to Rectification

Request correction of inaccurate or incomplete personal data.

8.3 Right to Erasure

Request deletion of your personal data in certain circumstances, including when you withdraw consent.

8.4 Right to Restrict Processing

Request limitation of processing your personal data in certain situations.

8.5 Right to Data Portability

Request transfer of your data to another service in a machine-readable format.

8.6 Right to Object

Object to processing based on legitimate interests or for direct marketing purposes.

8.7 Automated Processing Rights

Right not to be subject to solely automated decision-making and to request human intervention.

8.8 Withdraw Consent

Where processing is based on consent, you can withdraw it at any time.

How to Exercise Your Rights:

Contact us at support@pathleader.ai or use the data management tools in your account dashboard. We will respond within 30 days (or notify you of any extension required).

9. Data Retention

We retain your personal data as follows:

User Content Data (30 days after account deletion):

  • CVs, resumes, and cover letters
  • Job matches and recommendations
  • Career counseling conversations
  • Interview preparation materials

Business Records (12 months after account deletion):

  • Support tickets and communications
  • Usage analytics (anonymized)
  • Account activity logs
  • Service improvement data

Legal Requirements (as mandated by law):

  • Payment and billing records (7 years)
  • Tax documentation (7 years)
  • Other legally required records (as specified by applicable law)

Active Account Data: While your account remains active, we retain data necessary to provide our services. Upon account deletion, the retention periods above apply.

Early Deletion: We may delete data earlier if it's no longer needed for the specified purpose or upon your request where legally permissible.

10. Cookies

We use only essential cookies that are strictly necessary for our platform to function properly. These cookies:

  • Enable basic website functionality and navigation
  • Maintain your login session and authentication
  • Ensure platform security and prevent fraud
  • Remember your language and accessibility preferences

No consent is required for these essential cookies as they are necessary to provide the service you have requested. We do not use analytics, marketing, or tracking cookies.

You can disable cookies through your browser settings, but this may affect the functionality of our platform.

11. Children and Minors

We assume that all personal data provided in connection with our services is provided by individuals legally capable of entering into agreements with us. If you are a minor in your jurisdiction of residence, you may not use our services without the consent of your parent or legal guardian.

Age Requirements:

  • Under 13: Our service is not intended for children under 13 years of age
  • Ages 13-16: In the EU, parental consent may be required depending on your country's laws (in Sweden, the digital consent age is 13)

If we become aware of usage of our service from minors without appropriate consent, we will delete their data to the fullest extent possible, which may mean we will have to delete the account in question.

12. Updates to This Notice

We may update this Privacy Notice periodically to reflect changes in our practices or legal requirements. We will:

  • Post the updated notice on our website with a new "Last Updated" date
  • Notify you of material changes via email or platform notification
  • For significant changes affecting your rights, we may seek your consent where required

We encourage you to review this notice regularly to stay informed about how we protect your data.

13. Additional Rights and Information

13.1 California Consumer Privacy Act (CCPA)

California Residents: Under the California Consumer Privacy Act (CCPA), you have the right to know what personal information we collect, request deletion, and opt-out of data sales (note: we do not sell personal data). Contact us through the details below to exercise these rights.

13.2 Our Commitment to AI Transparency

We use artificial intelligence to provide personalized career guidance and job matching. We regularly assess our AI systems for potential discriminatory impacts and bias. Our AI processing is designed to be fair, transparent, and beneficial to all users regardless of background.

13.3 Legitimate Interests Assessment

Where we rely on legitimate interests as a legal basis, we have conducted balancing tests to ensure our interests do not override your rights and freedoms. You can request details of these assessments by contacting us.

14. Contact Us

For privacy-related questions or to exercise your rights:

Email: privacy@pathleader.ai

Subject Line: "Privacy Request" or "Data Subject Rights"

Response Time: We will respond to your privacy requests within 30 days (or notify you of any extension required).

Complaints: You have the right to lodge a complaint with your local data protection authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten - IMY).

This Privacy Notice demonstrates our commitment to data protection and compliance with GDPR. We continuously review and update our practices to ensure the highest standards of privacy protection while helping you find your perfect job with confidence and peace of mind.

© 2025 Pathleader. All rights reserved.