RolePact
Sign inCreate account

Privacy notice

Your career data is not inventory.

This notice explains what RolePact stores, why it is used and the controls available to account holders.

Public information · no account required
01

Data we hold

RolePact stores account identity, onboarding and profile information, structured CV content, applications, interview schedules and room chat, decisions, access and security events, notification preferences, reports and support or administrative records.

We do not sell candidate data. We do not provide employers with bulk candidate downloads.

02

Why we use it

  • To authenticate members and protect account-only surfaces.
  • To operate verified role, application, review and interview workflows.
  • To enforce the RolePact standard, investigate reports and secure the service.
  • To meet legal obligations and resolve disputes.
03

Who can see it

Candidates control their profile and CV versions. An employer can see only the submitted CV for an application to its organisation, through an attributed protected view. Interview data is restricted to its application participants. RolePact administrators access records only for verification, safety, support and enforcement.

04

Retention and deletion

Members can request deletion from Account. RolePact delays deletion for seven days so errors can be reversed. Records may be retained where necessary for legal claims, fraud prevention, safety investigations or statutory obligations, then minimised or deleted when the purpose ends.

05

Your controls

Signed-in members can update their display name and preferences, revoke other sessions, download a machine-readable copy of their own data and request or cancel account deletion.

Contact: privacy@rolepact.com. Identity verification may be required before responding to a rights request.

06

Infrastructure and international processing

RolePact is designed for UK use. Production infrastructure providers may process encrypted service data on our behalf under contractual safeguards. The current build keeps development data in local SQLite; production migration is designed for controlled Supabase policies and Cloudflare infrastructure.