Privacy Notice
Last Updated: October 13, 2025
1. Who We Are
Pathleader operates the pathleader.ai platform, an AI-powered job-matching service that helps job seekers find the perfect employment opportunities while they relax. Our platform integrates with multiple job boards to provide intelligent, personalized job recommendations.
Data Controller: Pathleader
Contact: privacy@pathleader.ai
Website: pathleader.ai
The purpose of this Privacy Notice is to inform you of how we process your personal data and ensure you that your personal data is managed with care and transparency. You should always feel safe when you share personal data with Pathleader, and we continuously work on implementing necessary technical and organizational security measures.
Our privacy notice is designed to meet the requirements of various international data protection laws and regulations, including the General Data Protection Regulation (GDPR). However, in some cases, local laws may impose additional obligations or restrictions.
2. Information We Collect
We collect and process the following categories of personal data:
2.1 Account Registration Data
- Name and email address
- Password (stored in encrypted form)
- IP address and device information
2.2 CV/Resume and Professional Information
- Complete CV/resume content (work history, education, skills, contact details)
- Career progression and professional experience
- Academic qualifications and achievements
- Professional skills and competencies
- Career objectives and preferences
2.3 Job Search and Matching Data
- Job search queries and preferences
- Saved job listings and applications
- Job matching results and interactions
- Platform usage patterns and preferences
2.4 AI Career Counseling Data
- Career-related questions and conversations
- Professional development inquiries
- Guidance requests and responses
- Career counseling session history
2.5 Cover Letter Generation Data
- Job descriptions and application requirements
- Generated cover letters and application materials
2.6 Payment and Subscription Data
- Payment method details and billing information
- Subscription plan and payment history
- Transaction records and billing address
2.7 Support and Communication Data
- Support tickets and email communications
- Feedback and survey responses
- Technical support interactions
2.8 Technical and Usage Data
- Device information and browser type
- IP address and approximate location (country/region)
- Platform usage analytics and performance data
- Cookie and tracking data (where consented)
3. Purpose, Legal Basis, and Categories of Processing
3.1 Legal Bases for Processing Personal Data
Contractual Obligation (Article 6(1)(b)): When we process your personal data to fulfill an agreement we have entered, or are preparing to enter, with you as a user
Legitimate Interest (Article 6(1)(f)): When we have an interest in processing your personal data for a specific purpose and have assessed that our purpose is justified
Legal Obligation (Article 6(1)(c)): When we process your personal data to comply with legal requirements applicable to our operations
Consent (Article 6(1)(a)): For processing that requires your active consent, where we explicitly request your approval
3.2 Data Processing Purposes Table
| Purpose | Data Categories | Legal Basis |
|---|---|---|
| Core Service Delivery | Account data, CV/resume content, job preferences | Contractual Obligation |
| AI Search | Professional information, skills, career history | Contractual Obligation |
| AI Career Counseling | Career questions, professional background, conversation history | Contractual Obligation |
| Cover Letter Generation | CV content, job descriptions, professional information | Contractual Obligation |
| Payment Processing | Payment information, billing details, subscription data | Contractual Obligation / Legal Obligation |
| Service Improvement | Anonymized usage patterns and feedback | Legitimate Interest |
| Marketing Communications | Email address and communication preferences | Consent |
| Platform Security | Login data, device information, IP address | Legitimate Interest |
4. Automated Decision-Making and AI Processing
AI Fairness Commitment: We regularly audit our AI systems for bias and discrimination to ensure fair job matching regardless of your background, gender, age, or other protected characteristics.
4.1 AI Search
Our platform uses artificial intelligence to analyze your CV and match you with suitable job opportunities. This automated processing involves:
- Logic: AI algorithms compare your skills, experience, and preferences with job requirements from integrated job boards
- Significance: Job recommendations directly influence your job search and career opportunities
- Your Rights: You can request human review of any job match, opt-out of automated matching, and access information about how decisions are made
4.2 AI Career Counseling
Our AI career counselor provides automated advice based on your professional background and career questions:
- Logic: Natural language processing analyzes your career situation and provides personalized guidance
- Significance: Career advice may influence your professional development decisions
- Your Rights: You can request clarification on any advice given and opt-out of AI counseling
4.3 Safeguards and Your Rights
For all automated decision-making, you have the right to:
- Request human intervention and review
- Express your point of view and contest decisions
- Receive explanations about the logic and significance of automated processing
- Opt-out of automated processing where possible
5. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
5.1 Technical Measures
- End-to-end encryption for data transmission (TLS 1.3)
- Encryption at rest for all stored data
- Secure API communications with service providers
- Regular security monitoring and vulnerability assessments
5.2 Organizational Measures
- Role-based access controls and multi-factor authentication
- Staff training on data protection procedures
- Regular security audits and incident response procedures
- Privacy by design in system architecture
5.3 Data Processing Agreements
All service providers are bound by comprehensive data processing agreements ensuring GDPR compliance.
6. Data Sharing and Recipients
6.1 AI Model Training - What We Don't Do
We do not use your personal data to train our AI models or improve third-party AI systems. Your CV content, career information, and conversations remain private and are never used to enhance AI models for other users or external purposes.
6.2 Service Providers
We share data with trusted service providers who help us deliver our services:
- EU-based Database and Authentication Providers: Database, storage, and authentication services
- AI Processing Services: AI processing for job matching, career counseling, and cover letter generation
- EU-based Payment Processing Services: Payment processing and subscription management
- EU-based Frontend Hosting and Content Delivery Services: Frontend hosting and content delivery
- Backend Hosting and API Services: Backend hosting and API services
6.3 Legal Requirements
We may share data when required to:
- Comply with legal obligations
- Respond to lawful requests from authorities
- Protect our rights and prevent fraud
- Ensure platform security and safety
7. International Data Transfers
Some of our service providers are located outside the EU/EEA:
Countries with Adequacy Decisions:
For transfers to countries the European Commission has deemed to provide adequate protection, we rely on these adequacy decisions.
Countries without Adequacy Decisions:
For transfers to other countries, we implement appropriate safeguards including:
- Data Processing Agreements with all service providers
- Standard Contractual Clauses approved by the European Commission
- Additional technical and organizational security measures
8. Your Rights Under GDPR
You have the following rights regarding your personal data:
8.1 Right of Access
Request a copy of the personal data we hold about you and information about how it's processed.
8.2 Right to Rectification
Request correction of inaccurate or incomplete personal data.
8.3 Right to Erasure
Request deletion of your personal data in certain circumstances, including when you withdraw consent.
8.4 Right to Restrict Processing
Request limitation of processing your personal data in certain situations.
8.5 Right to Data Portability
Request transfer of your data to another service in a machine-readable format.
8.6 Right to Object
Object to processing based on legitimate interests or for direct marketing purposes.
8.7 Automated Processing Rights
Right not to be subject to solely automated decision-making and to request human intervention.
8.8 Withdraw Consent
Where processing is based on consent, you can withdraw it at any time.
How to Exercise Your Rights:
Contact us at support@pathleader.ai or use the data management tools in your account dashboard. We will respond within 30 days (or notify you of any extension required).
9. Data Retention
We retain your personal data as follows:
User Content Data (30 days after account deletion):
- CVs, resumes, and cover letters
- Job matches and recommendations
- Career counseling conversations
- Interview preparation materials
Business Records (12 months after account deletion):
- Support tickets and communications
- Usage analytics (anonymized)
- Account activity logs
- Service improvement data
Legal Requirements (as mandated by law):
- Payment and billing records (7 years)
- Tax documentation (7 years)
- Other legally required records (as specified by applicable law)
Active Account Data: While your account remains active, we retain data necessary to provide our services. Upon account deletion, the retention periods above apply.
Early Deletion: We may delete data earlier if it's no longer needed for the specified purpose or upon your request where legally permissible.
10. Cookies
We use only essential cookies that are strictly necessary for our platform to function properly. These cookies:
- Enable basic website functionality and navigation
- Maintain your login session and authentication
- Ensure platform security and prevent fraud
- Remember your language and accessibility preferences
No consent is required for these essential cookies as they are necessary to provide the service you have requested. We do not use analytics, marketing, or tracking cookies.
You can disable cookies through your browser settings, but this may affect the functionality of our platform.
11. Children and Minors
We assume that all personal data provided in connection with our services is provided by individuals legally capable of entering into agreements with us. If you are a minor in your jurisdiction of residence, you may not use our services without the consent of your parent or legal guardian.
Age Requirements:
- Under 13: Our service is not intended for children under 13 years of age
- Ages 13-16: In the EU, parental consent may be required depending on your country's laws (in Sweden, the digital consent age is 13)
If we become aware of usage of our service from minors without appropriate consent, we will delete their data to the fullest extent possible, which may mean we will have to delete the account in question.
12. Updates to This Notice
We may update this Privacy Notice periodically to reflect changes in our practices or legal requirements. We will:
- Post the updated notice on our website with a new "Last Updated" date
- Notify you of material changes via email or platform notification
- For significant changes affecting your rights, we may seek your consent where required
We encourage you to review this notice regularly to stay informed about how we protect your data.
13. Additional Rights and Information
13.1 California Consumer Privacy Act (CCPA)
California Residents: Under the California Consumer Privacy Act (CCPA), you have the right to know what personal information we collect, request deletion, and opt-out of data sales (note: we do not sell personal data). Contact us through the details below to exercise these rights.
13.2 Our Commitment to AI Transparency
We use artificial intelligence to provide personalized career guidance and job matching. We regularly assess our AI systems for potential discriminatory impacts and bias. Our AI processing is designed to be fair, transparent, and beneficial to all users regardless of background.
13.3 Legitimate Interests Assessment
Where we rely on legitimate interests as a legal basis, we have conducted balancing tests to ensure our interests do not override your rights and freedoms. You can request details of these assessments by contacting us.
14. Contact Us
For privacy-related questions or to exercise your rights:
Email: privacy@pathleader.ai
Subject Line: "Privacy Request" or "Data Subject Rights"
Response Time: We will respond to your privacy requests within 30 days (or notify you of any extension required).
Complaints: You have the right to lodge a complaint with your local data protection authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten - IMY).
This Privacy Notice demonstrates our commitment to data protection and compliance with GDPR. We continuously review and update our practices to ensure the highest standards of privacy protection while helping you find your perfect job with confidence and peace of mind.
© 2025 Pathleader. All rights reserved.