For CompaniesFor TalentFor GraduatesPricingComplianceExplore Open JobsPartners
LoginSign Up
For CompaniesFor TalentFor GraduatesPricingComplianceExplore Open JobsPartners
LoginSign Up

Hiring based on proof.

London, United Kingdom

team@x-unframed.com

Product
  • For Companies
  • For Talent
  • Pricing
  • Explore Open Jobs
  • Partners
Company
  • Team
  • Contact
  • Privacy
  • Terms
  • Legal documents
Connect

team@x-unframed.com

© 2026 X-Unframed

TermsPrivacyLegal documents
Legal

Data & Privacy.

04
About this page

How we collect, use, and protect your personal data.

Effective
29 May 2025
Region
London, UK

Quick Navigation

OverviewDefinitionsData RolesData CollectionHow We Use DataLegal BasisInformation SharingInternational TransfersSecurity MeasuresYour RightsData RetentionCookiesChildren's PrivacyPolicy ChangesData BreachAssignment & TransferBilling EntityContact Us

Privacy Policy Overview

Effective Date: May 29, 2025

This Privacy Policy describes how UNFRAMED LTD (Company No. 17379534), a company incorporated in England and Wales, with its registered office at 66 Paul Street, London, England, United Kingdom, EC2A 4NA ("X-Unframed," "we," "us," or "our"), collects, uses, stores, shares, and protects Personal Data through its Software as a Service platform and associated website (collectively, the "Service"). For customers in the Gulf, the contracting entity is X Unframed Establishment (Commercial Registration No. 7049407336, 4925 Bakr Kamal Street, 8444 Al Narjis District, Riyadh 13333, Kingdom of Saudi Arabia).

We are committed to protecting your privacy and ensuring compliance with all applicable data protection laws and regulations, including but not limited to the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and, for customers contracting with X Unframed Establishment, the Personal Data Protection Law of the Kingdom of Saudi Arabia (Saudi PDPL), as well as any other relevant local regulations.

Important: This Privacy Policy forms an integral part of our Terms of Service. By accessing or using the Service, you confirm that you have read, understood, and agreed to this Privacy Policy. If you disagree with any part of this Privacy Policy, you may not access the Service.

Interpretation and Definitions

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Account: A unique account created for You to access Our Service or parts of Our Service.
Smart Services: Any features or functionalities within the Service that utilize artificial intelligence, machine learning, or similar computational techniques to process data, generate content, or provide insights, such as candidate sourcing, screening, matching, resume analysis, and job description generation.
Candidate: An individual whose Personal Data is processed on the Service by a Customer for recruitment purposes (e.g., job applicants, sourced professionals).
Customer ("You" or "Your"): The company or other legal entity on behalf of which an individual is accessing or using the Service for talent acquisition purposes.
Customer Data: All data, information, or content, including but not limited to job descriptions, candidate resumes, communication records, and performance metrics, uploaded, submitted, or otherwise provided by You or on Your behalf to the Service.
Data Controller: The natural or legal person who determines the purposes and means of processing Personal Data. You (the Customer) are the Data Controller for Candidate Personal Data you upload to the Service.
Data Processor: A natural or legal person who processes Personal Data on behalf of the Controller. X-Unframed is the Data Processor for Candidate Personal Data that Customers upload to the Service.
Data Subject: The identified or identifiable natural person to whom Personal Data relates (e.g., a website visitor, a Customer contact, a Candidate).
Personal Data: Any information relating to an identified or identifiable natural person, including identifiers such as name, identification number, location data, online identifier, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity.
Processing: Any operation performed on Personal Data, such as collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure or destruction.
Sensitive Personal Data: Data which directly or indirectly reveals a natural person's racial origin, ethnic origin, political opinions, religious beliefs, criminal record, trade-union membership, biometric data, health data, genetic data, sex life, or sexual orientation.
Service: The X-Unframed SaaS platform and associated website (https://x-unframed.com/), including all features, functionalities, and Smart Services offered therein.
Third-Party Service: Any services or content provided by a third party that may be displayed, included, or made available by the Service.
Usage Data: Data collected automatically from the use of the Service or from the Service infrastructure itself.

Our Roles in Data Processing

Understanding our roles is crucial for determining responsibilities and rights under data protection laws.

When We Are the Data Controller

We act as the Data Controller when we collect and process Personal Data directly from our Customers (e.g., your business contact details, billing information, user account credentials, and usage data). In this capacity, we determine the purposes and means of processing this data and are responsible for ensuring compliance with data protection laws.

When We Are the Data Processor

We act as a Data Processor when we process Personal Data (primarily Candidate data) that You, our Customers, upload or provide to the Service. In this scenario, You (the Customer) are the Data Controller for this Candidate data, and we process it strictly on your documented instructions.

Personal Data We Collect

We collect Personal Data in different ways, depending on your interaction with our Service and whether we act as a Data Controller or Data Processor.

When We Are the Data Controller (Customer Data)

  • — Profile information (name, email, professional details)
  • — Resume and portfolio content
  • — Job preferences and career goals
  • — Communication with other users and our support team

Information We Collect Automatically

  • — Usage data and platform interactions
  • — Device information and browser type
  • — IP address and general location
  • — Cookies and similar tracking technologies

How We Use Your Information

We use your information to provide and improve our services, match you with relevant opportunities, and ensure a safe, personalized experience.

  • — Connect talent with employers through matching
  • — Personalize job recommendations and platform experience
  • — Improve our algorithms and platform functionality
  • — Provide customer support and respond to inquiries
  • — Ensure platform security and prevent fraud

Legal Basis for Processing

For processing Personal Data where X-Unframed is the Data Controller, we rely on the following legal bases:

Performance of a Contract

We process your Personal Data when it is necessary for the performance of a contract with you, such as when you subscribe to our Service, create an Account, or use specific features.

  • — Managing your Account and subscription
  • — Providing access to Service features
  • — Processing payments and billing

Legitimate Interests

We may process your Personal Data for our legitimate business interests, provided these interests do not override your fundamental rights and freedoms.

  • — Improving and developing our Service
  • — Ensuring security and preventing fraud
  • — Conducting internal analytics and research

Consent

Where required by law, we will obtain your explicit consent for certain processing activities, such as sending you marketing communications. You have the right to withdraw your consent at any time.

Legal Obligation

We may process your Personal Data when it is necessary to comply with a legal obligation to which we are subject (e.g., tax laws, reporting requirements, or responding to lawful requests from public authorities).

Note: For processing Personal Data where X-Unframed is the Data Processor (i.e., Candidate Data), the legal basis for processing is determined by You (the Customer), the Data Controller. We process this data solely on your instructions and as outlined in our agreement.

Information Sharing

We never sell your personal information to third parties. Period.

We only share your information in these specific circumstances:

With Your Consent

When you explicitly choose to share information with employers or other users.

Service Providers

With trusted partners who help us operate our platform, under strict confidentiality agreements.

Legal Requirements

When required by law or to protect our users' safety.

International Data Transfers

As X-Unframed operates globally and utilizes international service providers, your Personal Data may be transferred to, stored, and processed in countries outside the United Kingdom, the European Economic Area, and the Kingdom of Saudi Arabia, including where our servers or service providers are located.

Important: These countries may have data protection laws that are different from those in the United Kingdom, the European Economic Area, or the Kingdom of Saudi Arabia. When we transfer Personal Data outside those territories, we implement appropriate safeguards to ensure a similar level of protection.

Safeguards We Implement

Standard Contractual Clauses (SCCs): Implementing the appropriate SCCs approved by the UK Information Commissioner's Office (ICO) or the European Commission for transfers to countries not deemed to provide an adequate level of data protection.
Adequacy Decisions: Relying on adequacy decisions made by the relevant authorities (e.g., the UK government or the European Commission) which recognize that a particular country or framework provides an adequate level of data protection.
Other Legally Approved Mechanisms: Any other valid transfer mechanisms permitted under applicable data protection laws, including supplementary measures in line with UK GDPR and EDPB guidelines.

Specific Note: For transfers to the United States, where no adequacy decision is in place, we rely on Standard Contractual Clauses and supplementary measures. For transfers between UNFRAMED LTD in the United Kingdom and X Unframed Establishment in the Kingdom of Saudi Arabia, we rely on appropriate safeguards such as Standard Contractual Clauses.

Data Security

We implement industry-standard security measures to protect your information.

Technical Safeguards

  • — End-to-end encryption
  • — Secure data centers
  • — Regular security updates
  • — Access controls and monitoring

Administrative Safeguards

  • — Employee privacy training
  • — Limited access protocols
  • — Regular security audits
  • — Incident response procedures

Your Rights

You have full control over your personal information.

Access & Download: Request a copy of all personal information.
Correct & Update: Update or correct any inaccurate information.
Delete: Request deletion of your account and data.
Control Sharing: Manage privacy settings and visibility.

Data Retention

We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.

Customer Data (Controller Role)

Account Information: Retained for the duration of your account plus 7 years after account closure for legal and tax compliance purposes.
Billing and Payment Data: Retained for 7 years after the last transaction for accounting, tax, and legal compliance purposes.
Usage and Analytics Data: Retained for up to 3 years for service improvement and analytics purposes.
Marketing Communications: Retained until you withdraw consent or unsubscribe, plus a reasonable period to process your request.

Candidate Data (Processor Role)

Processing Duration: We retain Candidate Personal Data only for as long as instructed by You (the Customer) or as necessary to provide the Service.
Customer Instructions: You control the retention period for Candidate data through your account settings and data management tools.
Service Termination: Upon termination of our agreement, we will delete or return Candidate Personal Data as instructed by You, typically within 30 days.
Legal Requirements: We may retain data longer if required by applicable law or to defend legal claims.

Factors Affecting Retention Periods

  • — Legal and regulatory requirements
  • — Ongoing legal proceedings or investigations
  • — Legitimate business needs
  • — Data subject requests and preferences
  • — Technical limitations and backup systems
  • — Industry best practices and standards

Secure Deletion: When Personal Data is no longer needed, we securely delete or anonymize it using industry-standard methods to ensure it cannot be recovered or reconstructed.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience, analyze usage patterns, and improve our Service. This section explains what cookies we use and how you can control them.

Essential Cookies

These cookies are necessary for the Service to function properly and cannot be disabled.

  • — Authentication and session management
  • — Security and fraud prevention
  • — Load balancing and performance optimization

Analytics Cookies

These cookies help us understand how you use our Service so we can improve it.

  • — Usage statistics and user behavior analysis
  • — Performance monitoring and optimization
  • — Feature usage and effectiveness measurement

Functional Cookies

These cookies enable enhanced functionality and personalization.

  • — User preferences and settings
  • — Language and region preferences
  • — Customized user interface elements

Marketing Cookies

These cookies are used to deliver relevant advertisements and marketing communications.

  • — Targeted advertising and remarketing
  • — Social media integration and sharing
  • — Campaign effectiveness measurement

Managing Your Cookie Preferences

You can control and manage cookies in several ways:

  • — Browser Settings: Most browsers allow you to refuse or accept cookies.
  • — Cookie Banner: Use our cookie consent banner when you first visit.
  • — Account Settings: Manage preferences in your account dashboard.
  • — Third-party Opt-outs: Use industry opt-out tools for advertising cookies.

Children's Privacy

Age Restriction: Our Service is not intended for individuals under the age of 18 ("Children"), unless a different age threshold applies under the applicable laws of the Data Subject's jurisdiction. We do not knowingly collect Personal Data from Children.

Our Commitment

  • — We do not knowingly collect, use, or disclose Personal Data from Children
  • — We do not knowingly allow Children to create accounts
  • — We do not direct our marketing or advertising to Children

If We Discover Child Data

If we become aware that we have collected Personal Data from a child under 16, we will:

  • — Delete the information as quickly as possible
  • — Terminate the associated account
  • — Take steps to prevent future collection

Parents and Guardians: If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without verification of parental consent, we take steps to remove that information from our servers.

Changes to This Privacy Policy

We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top.

We will notify You via email and/or a prominent notice on Our Service, prior to the change becoming effective, for material changes.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page. Your continued use of X-Unframed after any changes indicates your acceptance of the updated policy.

Data Breach Notification

Our Commitment: In the event of a personal data breach, we will notify the relevant Supervisory Authority without undue delay, and where feasible, within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.

Authority Notification

We will notify the appropriate Supervisory Authority (such as the UK Information Commissioner's Office or the competent European Union supervisory authority) within the required timeframe.

  • — Nature of the breach and categories of data affected
  • — Approximate number of data subjects affected
  • — Likely consequences and measures taken

Data Subject Notification

Where applicable, we will also notify affected Data Subjects in accordance with the requirements of UK GDPR, EU GDPR and, for customers contracting with X Unframed Establishment, Saudi PDPL.

  • — Clear description of the breach in plain language
  • — Contact details for further information
  • — Recommended measures to mitigate adverse effects

Prevention and Response: We maintain comprehensive incident response procedures and continuously monitor our systems to prevent data breaches and respond effectively if they occur.

Assignment and Transfer

The Company may assign, transfer, novate, or otherwise transfer its rights and obligations under these Terms, in whole or in part, to any affiliated entity, successor entity, or entity resulting from a corporate restructuring, merger, reorganisation, or change of jurisdiction, without prior notice to or consent from you.

Such assignment or transfer shall not affect the rights and obligations you have under these Terms, which shall continue to be enforceable against the assignee or successor entity in the same manner as against the Company.

In the event of any such assignment, transfer, or change of jurisdiction, any Personal Data held by the Company shall be handled in accordance with applicable data protection laws and the provisions of this Privacy Policy.

Your Rights: You may not assign, transfer, or delegate any of your rights or obligations under these Terms without our prior written consent. Any attempted assignment in violation of this provision shall be void.

Billing Entity and Payment Processing

The Company reserves the right to change the billing entity, invoicing entity, and/or payment processor used to provide the Services at any time, without prior notice or consent, provided that such change does not materially affect the terms of your subscription or payment obligations.

Such changes may include, but are not limited to, the use of a different legal entity within the Company's group of companies to issue invoices and collect payments, or the engagement of a different third-party payment processor.

Any change in billing entity shall not alter the amount, currency, or frequency of your payments, unless otherwise agreed upon or required by applicable law.

Notice: Where practicable, we will provide you with reasonable notice of any material changes to our billing arrangements. Your continued use of the Service following any such change constitutes your acceptance of the new billing entity or payment processor.

Contact Us

Have questions about our privacy practices? We're here to help.

Email: privacy@x-unframed.com
Address: X-Unframed Privacy Team, UNFRAMED LTD, 66 Paul Street, London, England, EC2A 4NA, United Kingdom; for Gulf workspaces: X Unframed Establishment, 4925 Bakr Kamal Street, 8444 Al Narjis District, Riyadh 13333, Kingdom of Saudi Arabia

We'll respond to privacy-related inquiries within 48 hours.