Privacy Policy
Last updated: 29 Jul 2026
1. Who We Are
Mentum ("we", "us", or "our") is the data controller responsible for your personal data.
- Contact email: privacy@mentumjobs.com
- Data protection enquiries: dpo@mentumjobs.com
Mentum operates as a sole trader pre-launch. We have not designated a formal Data Protection Officer under UK GDPR Art. 37 — the processing volume and single-developer pre-launch posture do not currently trigger the mandatory-designation thresholds in Art. 37(1). The dpo@mentumjobs.com alias is the de-facto routing for DPO-style enquiries and the audit-trail channel for formal rights requests. Operationally, privacy@mentumjobs.com and dpo@mentumjobs.com route to the same human. The canonical contact page with response-time commitments per channel is at /contact.
2. Data We Collect
We collect the following categories of personal data depending on how you use our platform:
Account Data
- Full name, email address, password (stored as a secure hash)
- Authentication identifiers from third-party providers (Google, LinkedIn) if you choose to sign in via OAuth
Profile Data (Candidates)
- Phone number, postcode, profile photograph
- LinkedIn profile URL
- Curriculum Vitae (CV) — uploaded as PDF, DOCX, or RTF
- Work history: job titles, company names, duration, industries
- Education: institution names, qualifications, fields of study, grades, years
- Skills and professional interests
- Availability and scheduling preferences
- Career preferences, notes, and desired/unwanted career paths
Eligibility Declarations (Candidates)
Many roles carry hard requirements — a driving licence, a DBS check or a security clearance, a professional registration, a specific qualification, or availability for night, weekend or early-and-late shifts. Against a fixed list of 41 such requirements, you can tell us whether you hold it, do not hold it, are working towards it, or are willing to obtain it. Every answer is self-declared, every question is optional, and each one can be left unanswered.
- What we use them for. We check your declarations against the requirements an employer has marked essential on a job. The lawful basis is performance of our contract with you — Art. 6(1)(b).
- What they change. Only an explicit “no” against a requirement the employer marked essential hides that job from you, and hides you from that job's employer. No other answer filters anything, and a question you have left unanswered never filters anything.
- What employers see. An employer sees a collapsed status — Confirmed, In progress or Not confirmed — for the requirements on their own job, and nothing more. A “no” reaches them as Not confirmed, which is indistinguishable from a question you never answered.
- Your control. Your answers are included in your data export, are deleted when you delete your account, and can be cleared back to unanswered at any time from your profile.
Profile Data (Employers)
- Company name and profile information
- Job listings including descriptions, salaries, and requirements
Accessibility and Inclusion Data
- Visa sponsorship requirements, disability confidence preferences, equal opportunity employer filters, and reasonable adjustments preferences
Communication Data
- Chat messages exchanged between matched candidates and employers
AI-Generated Data
- Match scores, career recommendations, enhanced career insights, culture fit assessments, and skill analytics generated by our AI systems
Technical Data
- Authentication tokens, session data, and browser-generated identifiers necessary for platform functionality
3. How and Why We Use Your Data
| Purpose | Lawful Basis (UK GDPR) |
|---|---|
| Account creation and management | Contract performance — Art. 6(1)(b) |
| Job matching, AI scoring, and career recommendations | Contract performance — Art. 6(1)(b); Legitimate interest — Art. 6(1)(f) |
| Checking your eligibility declarations against the requirements an employer has marked essential on a job | Contract performance — Art. 6(1)(b) |
| Communication between matched candidates and employers | Contract performance — Art. 6(1)(b) |
| Platform analytics and improvement | Legitimate interest — Art. 6(1)(f) |
| Legal compliance and fraud prevention | Legal obligation — Art. 6(1)(c) |
| Sending service notifications (match updates, messages) | Contract performance — Art. 6(1)(b) |
4. Special Category Data
Where you choose to provide accessibility and inclusion preferences (such as disability confidence requirements or reasonable adjustment needs), this may constitute special category data under UK GDPR Art. 9. We process this data solely on the basis of your explicit consent (Art. 9(2)(a)), which you provide when you voluntarily enter these preferences. You may withdraw this consent at any time by removing these preferences from your profile, or by contacting us.
5. Who We Share Your Data With
Matched Employers
When you are matched with a job, the employer associated with that job may see your profile information. You can control what employers see using our Privacy & Anonymity Settings, which allow you to hide your name, photo, contact details, company names, and institution names from employers.
Third-Party Service Providers
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Supabase (supabase.com) | Database hosting (PostgreSQL), authentication, file storage | United States | Standard Contractual Clauses (SCCs), encryption at rest and in transit |
| Google (Gemini AI) | Standard AI scoring narrative, CV parsing, extraction, classification, persona generation and embeddings | United States / Global | Google Cloud Data Processing Agreement, SCCs, enterprise-grade security |
| OpenAI (GPT-5.6 Luna) | Premium Career Advisor and interview-practice responses, Enhanced Insights, CV optimisation, Career Compass recommendations and trajectory, employer hiring advice and job-description generation. Existing data-minimisation and consent controls continue to apply. | Provider/account dependent | Requests set store=false; API data is not used for model training unless the organisation opts in, and Mentum does not opt in. The production DPA, transfer mechanism and account retention controls must be evidenced before activation. |
| postcodes.io | UK postcode geocoding for location-based job matching | United Kingdom | Public data only (postcodes); no personal data transmitted |
| SendGrid (Twilio) | Transactional and marketing email delivery (match notifications, password resets, onboarding) | United States | Twilio Global Data Processing Agreement, SCCs, TLS encryption |
| Nominatim / OpenStreetMap | Location search geocoding for job search by city or region | European Union | Public API. The geocoding request is sent directly from your browser to OpenStreetMap — Mentum does not act as an intermediary and does not store the query. |
| Sentry (Functional Software) | Application error monitoring and debugging | United States | Sentry DPA, SCCs. PII scrubbing applied before transmission: emails, phone numbers, and authentication headers are automatically redacted. |
| Adzuna Ltd | Inbound daily job-feed ingestion (employer-side job postings) | United Kingdom | Inbound flow only. No candidate or user personal data is transmitted from Mentum to Adzuna. |
| UK Education and Skills Funding Agency (DfE Apprenticeships Service) | Inbound apprenticeship-vacancy feed | United Kingdom (Crown infrastructure) | Inbound flow only. No candidate or user personal data is transmitted from Mentum to the DfE. |
| Additional inbound job-feed sources (Jooble, Reed, Teaching Vacancies, NHS Jobs, Guardian Jobs, university job boards, direct-employer ATS boards) | Inbound daily job-listing ingestion | United Kingdom / provider-dependent | Inbound flow only — no candidate or user personal data is transmitted to them. |
| Coursera / Impact (Impact.com affiliate network) | Affiliate learning-course links. When you click a course link, Mentum's backend resolves the Impact click-tracking chain server-side and redirects your browser to Coursera. | United States | Server-side redirect. Mentum forwards only your browser's User-Agent and a minted click identifier to Impact — no name, email, or profile data is shared. Affiliate-network agreement in place. |
| Hosting and platform infrastructure (Railway, GitHub, Redis provider, ClamAV) | Application hosting, build / deploy, source-code and CI, caching, and optional malware scanning | United States and the United Kingdom | Standard Contractual Clauses where data is transferred outside the United Kingdom; encryption at rest and in transit; transient request handling (no persistent customer data at rest on Railway or GitHub). The complete list with hosting region and DPA status is at /legal/subprocessors. |
The complete, always-current sub-processor list — including the contractual transfer mechanism and external attestations for each vendor — is published at /legal/subprocessors.
We do not sell your personal data to any third party. We do not share your data with advertisers.
6. International Data Transfers
Several of our third-party service providers process your data outside the United Kingdom and European Economic Area — principally in the United States. The processors involved, their locations, and the data each receives are listed in the table in Section 5 above (and, in full, at /legal/subprocessors). Where such a transfer occurs, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office
- UK International Data Transfer Agreement (IDTA) where applicable
- Supplementary technical measures including encryption in transit (TLS 1.2+) and at rest
7. How Long We Keep Your Data
The table below is the high-level summary. For the per-table breakdown — including the database table, the trigger that starts the retention clock, and the destruction mechanism — see Mentum's Data Retention Schedule, which is the audit-grade reference.
| Data Type | Retention Period |
|---|---|
| Active account data | Retained while your account is active. |
| Inactive candidate accounts | After 24 months without sign-in, your candidate account is automatically deactivated. After 36 months without sign-in, identifying personal data (name, email, phone, LinkedIn, location, photo, CV) is automatically pseudonymised; the anonymous row may be retained for aggregate analytics. |
| Deleted account data | Erased from our live database synchronously when you submit the deletion request. Encrypted Supabase backups roll off within a 7-day rotation window. A limited statutory record of your consent decisions is retained for 7 years (UK GDPR Art. 17(3)(e)) and any breach-register entry is retained indefinitely (UK GDPR Art. 33), as set out in the Data Retention Schedule. |
| Chat messages | Message content is replaced with a retention notice 12 months after the associated match closes, and in all cases no later than 36 months after the message was sent. The surrounding metadata (sender, timestamp, match reference) is preserved as part of the employer's hiring record. |
| Eligibility declarations | Retained until you delete your account. They are included in your data export, and you can clear any answer back to unanswered at any time from your profile. |
| AI-generated insights | Retained while your account is active; deleted upon account deletion. Advisor conversations are also deleted after 24 months of inactivity. |
| Audit and security logs | Retained between 6 and 24 months depending on log type. Data access logs are retained for 24 months; application audit logs and security events for 12 months; LLM cost telemetry for 6 months. See the Data Retention Schedule for the per-table breakdown. |
| Notifications | Read notifications are retained for 6 months; unread notifications for 12 months. Notification preferences and push subscriptions are retained until you opt out or delete your account. |
| Job listing data (employer) | Active jobs are auto-deactivated after 90 days with no active matches. Inactive jobs are hard-deleted 12 months after deactivation, provided no active matches remain. |
For erasure-window and statutory-carve-out detail (consent records retained for 7 years, breach register retained indefinitely), see §§ 8 and 9 of the Data Retention Schedule.
8. Your Rights
Under the UK GDPR and Data Protection Act 2018, you have the following rights:
- Right of access (Art. 15) — Request a copy of the personal data we hold about you
- Right to rectification (Art. 16) — Ask us to correct inaccurate or incomplete data
- Right to erasure (Art. 17) — Request deletion of your personal data ("right to be forgotten")
- Right to data portability (Art. 20) — Receive your data in a structured, commonly used, machine-readable format
- Right to restrict processing (Art. 18) — Ask us to limit how we use your data
- Right to object (Art. 21) — Object to processing based on legitimate interest
- Rights related to automated decision-making (Art. 22) — See section 9 below
9. Automated Decision-Making and AI
Mentum uses artificial intelligence to generate match scores between candidates and jobs, produce career recommendations, and create enhanced career insights. These AI-generated outputs are provided as informational aids and do not constitute sole automated decision-making that produces legal or similarly significant effects.
Employers make their own hiring decisions. Match scores and AI insights are one input among many. You have the right to:
- Request an explanation of how your match score was calculated
- Request human review of any AI-generated assessment
- Contest an AI-generated outcome by contacting us at privacy@mentumjobs.com
10. Cookies
By default we use strictly essential cookies only, to keep you logged in and maintain your session security. We offer an optional first-party analytics preference that is off by default: if you enable it in Cookie Settings, product-usage events are sent only to Mentum's own backend — never to a third-party analytics provider. We use no third-party analytics or marketing cookies. For the full per-key record and to change your choice, see our Cookie Policy.
11. How to Exercise Your Rights
You can exercise your data rights in the following ways:
- In-app settings: Update your profile, privacy preferences, and notification settings directly in your account
- Account deletion: Use the account deletion feature in your settings to permanently erase your data
- Data export: Download your data in a portable format from your settings
- Email: Contact us at privacy@mentumjobs.com for any data rights request. We will respond within one month of receiving your request, as required by UK GDPR Art. 12(3).
We may ask you to verify your identity before processing your request to protect your data from unauthorised access.
12. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK supervisory authority:
- Information Commissioner's Office (ICO)
- Website: ico.org.uk/make-a-complaint
- Telephone: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
We encourage you to contact us first at privacy@mentumjobs.com so we can try to resolve your concern directly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify you via email and/or an in-app notification
- Where required by law, seek your renewed consent
We encourage you to review this policy periodically to stay informed about how we protect your data.
Related: Terms of Service | Cookie Policy