Privacy Policy

Last updated: 1 January 2025

Works Well ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

Works Well is the data controller for personal data processed through this website. If you have any questions about this policy or wish to exercise your rights, please contact us at privacy@workswelljobs.co.uk.

2. What Data We Collect

We collect data you provide directly, including:

  • Account information: name, email address, password (hashed)
  • Profile information: employment history, CV information, job preferences
  • Community content: forum posts, replies, reports
  • Communications: emails you send us

We also collect data automatically when you use our service, including IP address, browser type, pages visited, and referral source. This data is collected via Plausible Analytics, which is privacy-friendly and GDPR-compliant.

3. How We Use Your Data

We use your personal data to:

  • Provide and improve the Works Well service
  • Match you with relevant job opportunities
  • Send job alert emails where you have opted in
  • Moderate the community forum
  • Comply with our legal obligations

4. Legal Basis for Processing

We process your data on the following legal bases:

  • Contract: processing necessary to provide the service you signed up for
  • Legitimate interests: fraud prevention, service security, analytics
  • Consent: marketing communications and analytics cookies

5. Data Sharing

We do not sell your personal data. We share data only with:

  • Supabase — database and authentication hosting (EU servers)
  • Vercel — website hosting
  • Resend — transactional email delivery
  • Stripe — payment processing (employer billing only)
  • Plausible — privacy-friendly, cookieless analytics

6. Data Retention

We retain your account data for as long as your account is active. You may delete your account at any time from your account settings, which will permanently delete your personal data within 30 days.

7. Your Rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Object to processing based on legitimate interests
  • Data portability (receive your data in a structured format)
  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, email privacy@workswelljobs.co.uk. We will respond within 30 days.

8. Cookies

We use only essential cookies required to operate the service (authentication). We use Plausible Analytics which operates without cookies. See our Cookie Policy for full details.

9. Contact and Complaints

If you have a concern about how we handle your data, please contact privacy@workswelljobs.co.uk. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.