Privacy policy
Your data, in plain English.
Last updated: 29 May 2026
Who we are
theHRkey is an AI-native HR & resourcing practice operated by Ali Akeel, sole trader, based in the United Kingdom. We are the data controller for any personal data you submit through this site. Reach us at info@thehrkey.com.
What we collect
- Contact details you give us in the chatbot or forms (name, email, phone, company).
- Your CV if you upload one — file + extracted text + AI-derived classification.
- Job applications we generate or send on your behalf.
- Anonymous analytics (page views, referrer, device class), only if you've consented to analytics cookies.
- Essential session data (login session, chat session id) needed to make the site work.
Why we collect it
- To answer your enquiry and route it to the right practitioner.
- To match your CV against live job openings (if you upload one).
- To generate tailored applications you've explicitly asked us to produce.
- To run our HR / resourcing services for clients who instruct us.
- To improve the agentic pipelines that power the site, using only data you've consented to share.
Lawful basis (UK GDPR)
- Consent — analytics cookies, marketing emails, sharing your CV with named employers.
- Contract — providing the services you've engaged us for.
- Legitimate interest — answering your enquiry, securing the site, fraud prevention.
Who we share data with
- Named employers — only with your explicit per-application consent, never speculatively.
- Sub-processors that run the site: Google (Gemini API — your CV text is processed but not used to train Google's models per Gemini API terms); NameCheap (hosting); our email provider for transactional mail.
- Nobody else. We do not sell, rent or share your data with advertisers, data brokers, or other agencies.
How long we keep it
- Chat transcripts: 24 months, then deleted.
- CVs and classifications: until you delete them, or 24 months after your last login, whichever is sooner.
- Application records: 6 years (for accounting/tax compliance) where money changed hands; 24 months otherwise.
- Anonymous analytics: 14 months (Google Analytics default).
Your rights
Under UK GDPR you have the right to:
- Access a copy of the data we hold about you
- Correct anything wrong
- Delete it (right to erasure)
- Export it in a portable format
- Object to processing or withdraw consent at any time
- Complain to the ICO
Email info@thehrkey.com with the request — we'll respond within one calendar month.
Security
The site runs over TLS. Passwords are hashed with bcrypt (cost 12). CVs are stored above the web root so they can't be served accidentally. Database backups are encrypted at rest. We don't keep payment card data — that lives with our payment processor.
Cookies
See the cookie policy for the full list and how to change your mind.
Changes to this policy
If we make material changes we'll flag them on the homepage for at least 14 days and email anyone who has an account.