Privacy Policy Overview
Effective Date: May 29, 2025
This Privacy Policy describes how UNFRAMED LTD (Company No. 17379534), a company incorporated in England and Wales, with its registered office at 66 Paul Street, London, England, United Kingdom, EC2A 4NA ("X-Unframed," "we," "us," or "our"), collects, uses, stores, shares, and protects Personal Data through its Software as a Service platform and associated website (collectively, the "Service"). For customers in the Gulf, the contracting entity is X Unframed Establishment (Commercial Registration No. 7049407336, 4925 Bakr Kamal Street, 8444 Al Narjis District, Riyadh 13333, Kingdom of Saudi Arabia).
We are committed to protecting your privacy and ensuring compliance with all applicable data protection laws and regulations, including but not limited to the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and, for customers contracting with X Unframed Establishment, the Personal Data Protection Law of the Kingdom of Saudi Arabia (Saudi PDPL), as well as any other relevant local regulations.
Important: This Privacy Policy forms an integral part of our Terms of Service. By accessing or using the Service, you confirm that you have read, understood, and agreed to this Privacy Policy. If you disagree with any part of this Privacy Policy, you may not access the Service.
Interpretation and Definitions
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Our Roles in Data Processing
Understanding our roles is crucial for determining responsibilities and rights under data protection laws.
When We Are the Data Controller
We act as the Data Controller when we collect and process Personal Data directly from our Customers (e.g., your business contact details, billing information, user account credentials, and usage data). In this capacity, we determine the purposes and means of processing this data and are responsible for ensuring compliance with data protection laws.
When We Are the Data Processor
We act as a Data Processor when we process Personal Data (primarily Candidate data) that You, our Customers, upload or provide to the Service. In this scenario, You (the Customer) are the Data Controller for this Candidate data, and we process it strictly on your documented instructions.
Personal Data We Collect
We collect Personal Data in different ways, depending on your interaction with our Service and whether we act as a Data Controller or Data Processor.
When We Are the Data Controller (Customer Data)
- — Profile information (name, email, professional details)
- — Resume and portfolio content
- — Job preferences and career goals
- — Communication with other users and our support team
Information We Collect Automatically
- — Usage data and platform interactions
- — Device information and browser type
- — IP address and general location
- — Cookies and similar tracking technologies
How We Use Your Information
We use your information to provide and improve our services, match you with relevant opportunities, and ensure a safe, personalized experience.
- — Connect talent with employers through matching
- — Personalize job recommendations and platform experience
- — Improve our algorithms and platform functionality
- — Provide customer support and respond to inquiries
- — Ensure platform security and prevent fraud
Legal Basis for Processing
For processing Personal Data where X-Unframed is the Data Controller, we rely on the following legal bases:
Performance of a Contract
We process your Personal Data when it is necessary for the performance of a contract with you, such as when you subscribe to our Service, create an Account, or use specific features.
- — Managing your Account and subscription
- — Providing access to Service features
- — Processing payments and billing
Legitimate Interests
We may process your Personal Data for our legitimate business interests, provided these interests do not override your fundamental rights and freedoms.
- — Improving and developing our Service
- — Ensuring security and preventing fraud
- — Conducting internal analytics and research
Consent
Where required by law, we will obtain your explicit consent for certain processing activities, such as sending you marketing communications. You have the right to withdraw your consent at any time.
Legal Obligation
We may process your Personal Data when it is necessary to comply with a legal obligation to which we are subject (e.g., tax laws, reporting requirements, or responding to lawful requests from public authorities).
Note: For processing Personal Data where X-Unframed is the Data Processor (i.e., Candidate Data), the legal basis for processing is determined by You (the Customer), the Data Controller. We process this data solely on your instructions and as outlined in our agreement.
International Data Transfers
As X-Unframed operates globally and utilizes international service providers, your Personal Data may be transferred to, stored, and processed in countries outside the United Kingdom, the European Economic Area, and the Kingdom of Saudi Arabia, including where our servers or service providers are located.
Important: These countries may have data protection laws that are different from those in the United Kingdom, the European Economic Area, or the Kingdom of Saudi Arabia. When we transfer Personal Data outside those territories, we implement appropriate safeguards to ensure a similar level of protection.
Safeguards We Implement
Specific Note: For transfers to the United States, where no adequacy decision is in place, we rely on Standard Contractual Clauses and supplementary measures. For transfers between UNFRAMED LTD in the United Kingdom and X Unframed Establishment in the Kingdom of Saudi Arabia, we rely on appropriate safeguards such as Standard Contractual Clauses.
Data Security
We implement industry-standard security measures to protect your information.
Technical Safeguards
- — End-to-end encryption
- — Secure data centers
- — Regular security updates
- — Access controls and monitoring
Administrative Safeguards
- — Employee privacy training
- — Limited access protocols
- — Regular security audits
- — Incident response procedures
Your Rights
You have full control over your personal information.
Data Retention
We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
Customer Data (Controller Role)
Candidate Data (Processor Role)
Factors Affecting Retention Periods
- — Legal and regulatory requirements
- — Ongoing legal proceedings or investigations
- — Legitimate business needs
- — Data subject requests and preferences
- — Technical limitations and backup systems
- — Industry best practices and standards
Secure Deletion: When Personal Data is no longer needed, we securely delete or anonymize it using industry-standard methods to ensure it cannot be recovered or reconstructed.
Children's Privacy
Age Restriction: Our Service is not intended for individuals under the age of 18 ("Children"), unless a different age threshold applies under the applicable laws of the Data Subject's jurisdiction. We do not knowingly collect Personal Data from Children.
Our Commitment
- — We do not knowingly collect, use, or disclose Personal Data from Children
- — We do not knowingly allow Children to create accounts
- — We do not direct our marketing or advertising to Children
If We Discover Child Data
If we become aware that we have collected Personal Data from a child under 16, we will:
- — Delete the information as quickly as possible
- — Terminate the associated account
- — Take steps to prevent future collection
Parents and Guardians: If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without verification of parental consent, we take steps to remove that information from our servers.
Changes to This Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top.
We will notify You via email and/or a prominent notice on Our Service, prior to the change becoming effective, for material changes.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page. Your continued use of X-Unframed after any changes indicates your acceptance of the updated policy.
Data Breach Notification
Our Commitment: In the event of a personal data breach, we will notify the relevant Supervisory Authority without undue delay, and where feasible, within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
Authority Notification
We will notify the appropriate Supervisory Authority (such as the UK Information Commissioner's Office or the competent European Union supervisory authority) within the required timeframe.
- — Nature of the breach and categories of data affected
- — Approximate number of data subjects affected
- — Likely consequences and measures taken
Data Subject Notification
Where applicable, we will also notify affected Data Subjects in accordance with the requirements of UK GDPR, EU GDPR and, for customers contracting with X Unframed Establishment, Saudi PDPL.
- — Clear description of the breach in plain language
- — Contact details for further information
- — Recommended measures to mitigate adverse effects
Prevention and Response: We maintain comprehensive incident response procedures and continuously monitor our systems to prevent data breaches and respond effectively if they occur.
Assignment and Transfer
The Company may assign, transfer, novate, or otherwise transfer its rights and obligations under these Terms, in whole or in part, to any affiliated entity, successor entity, or entity resulting from a corporate restructuring, merger, reorganisation, or change of jurisdiction, without prior notice to or consent from you.
Such assignment or transfer shall not affect the rights and obligations you have under these Terms, which shall continue to be enforceable against the assignee or successor entity in the same manner as against the Company.
In the event of any such assignment, transfer, or change of jurisdiction, any Personal Data held by the Company shall be handled in accordance with applicable data protection laws and the provisions of this Privacy Policy.
Your Rights: You may not assign, transfer, or delegate any of your rights or obligations under these Terms without our prior written consent. Any attempted assignment in violation of this provision shall be void.
Billing Entity and Payment Processing
The Company reserves the right to change the billing entity, invoicing entity, and/or payment processor used to provide the Services at any time, without prior notice or consent, provided that such change does not materially affect the terms of your subscription or payment obligations.
Such changes may include, but are not limited to, the use of a different legal entity within the Company's group of companies to issue invoices and collect payments, or the engagement of a different third-party payment processor.
Any change in billing entity shall not alter the amount, currency, or frequency of your payments, unless otherwise agreed upon or required by applicable law.
Notice: Where practicable, we will provide you with reasonable notice of any material changes to our billing arrangements. Your continued use of the Service following any such change constitutes your acceptance of the new billing entity or payment processor.
Contact Us
Have questions about our privacy practices? We're here to help.
We'll respond to privacy-related inquiries within 48 hours.
