Privacy Policy and Data Protection Notice
Vanta Workspace (vantaworkspace.com)
Last updated: 21 August 2026 Version: 1.1
1. What this notice covers
This notice covers the vantaworkspace.com website and the Vanta Workspace app.
It is written for two groups of people:
- Clients. People who sign up, pay for the service and use it. Sections 2 to 16 are for you.
- Recruiters and other people our clients write about. If you never signed up but your name, email address or LinkedIn profile has been logged in the app by one of our clients, section 11 is your notice and it explains your rights.
We are the data controller for the personal data described here. Who we are, and how to reach us about anything in this notice, is set out in section 14.
2. The short version
- Everything in your profile is there because you typed it in. We do not buy data about you, we do not scrape it, and we do not sell it to anyone.
- Your career profile and the job advert you paste in are sent to Anthropic PBC, the company behind the Claude AI models, so the app can score your fit for a job and draft a tailored CV. See section 8.
- Two things are never sent to the AI and never printed on a CV: your right to work or visa status, and your reason for leaving any job. Those are stripped out in code before the request is made.
- Your Vanta coach, who is the founder and the only administrator, can see your data in order to coach you. Technically the coach can read every record you create, including fields the admin screens do not currently display.
- There is no advertising, no analytics, no tracking pixels and no third party cookies anywhere in the app. The only cookies are the ones that keep you logged in.
- We have no automatic deletion schedule. We keep your data until you delete your account. Section 12 explains exactly what deletion does and does not remove today.
- You can ask us for a copy of your data, to correct it, or to delete it, and you can complain to the Irish Data Protection Commission. See sections 13 and 15.
3. The data we collect from you, and why
All of the following comes from you, either at sign up or as you fill in the app. Nothing is collected from outside sources.
3.1 Account and sign in
Your email address, an encrypted version of your password, the promo code you signed up with, the date your account was created, the date you last signed in and your session records. This is handled by Supabase Auth, our authentication provider. We never see your password in readable form.
Used to: create your account, check your invite code, let you sign in, and let you reset your password.
3.2 Your profile and contact details
Your full name, a contact email address (which starts as your login email but you can change it), your phone number, the city you are in and your LinkedIn URL.
Used to: build the header and contact line on any CV the app generates, let your coach contact you, and point job board searches at the right location.
3.3 What you are looking for
Your target market, industry, desired job title, target roles and industries, a summary of the role you want, your years of experience, your strongest expertise and what you are known for. This is all free text you write yourself.
Used to: tailor CVs and match analysis, and to let your coach filter and prioritise clients.
3.4 Your right to work or visa status
This has its own section. See section 6.
3.5 Your career history
For each role: job title, employer, a one line description of the employer, location, working arrangement, start and end dates, whether it is current, your responsibilities, the achievement bullets you write and the metrics attached to them, and the tools you used.
Used to: provide the source facts for the CV and the match analysis. The app is built so that it can only use facts you have entered.
3.6 Your reason for leaving each role
This field is marked in our database as internal only. It exists so your coach has context for interview preparation. It is never included in the data sent to the AI, and it is never printed on a CV. Your coach can read it.
Please do not write anything about your health, a pregnancy, a disability, a harassment complaint or a legal claim in this box. See section 7.
3.7 Education, skills, certifications and languages
Institutions, qualifications, fields of study, dates, grades and any relevant details. Your technical and hard skills. Certification names, issuing bodies, issue and expiry dates and any credential link. The languages you speak and how well.
Used to: fill the education, skills, certifications and languages sections of a generated CV, and to match you against job requirements.
Two things worth knowing. Education dates are a strong indicator of your age, and describing a language as "native" is a well recognised indicator of your national or ethnic origin. Both end up on a CV that you control and send out, so think about whether you want them there.
3.8 Publications, volunteering, projects and awards
The kind of item, a title, a description, a date and a link.
Used to: fill the projects and additional information sections of a generated CV.
This is the single most likely place for genuinely sensitive information to enter the system. A volunteering entry that names a political party, a church or religious body, or a trade union role reveals your political opinions, religious beliefs or trade union membership. Unlike your reason for leaving, entries here are sent to the AI and are printed on the CV. Nothing in the app filters them. Please read section 6 before you fill this in.
3.9 The jobs you track
Job title, company, the text of the job advert you paste in, your own private notes, and the stage you are at.
Used to: run your pipeline, and to feed the match analysis and CV generation.
Your notes field is free text and nothing constrains it. In practice people use it for interview impressions, salary conversations and views about named individuals. Those notes are never sent to the AI, but your coach can read them.
3.10 Recruiter details you log against a job
A recruiter's name, email address and LinkedIn profile. This is information about somebody else. Section 11 explains what happens to it and what rights that person has. Please read it before you enter anyone's details.
3.11 Follow up tasks
Reminders, either created automatically seven days after you add an opportunity or created by you, with a title, a due date and whether they are done.
3.12 Daily LinkedIn activity
One record for each day you tick off each item on the daily LinkedIn checklist.
Used to: show you your own streak, and to show your coach whether you are keeping the activity up. Your coach sees, for each client, what was ticked today, how many days you were active in the last seven, your total ticks in the last seven days, and the dates you were active over the last twenty eight days.
We want to be plain about this: it is a day by day record of your effort, and your coach looks at it.
3.13 CV engine results
For every generation: a frozen copy of the job advert, a summary of the advert, an overall summary, a percentage match score, a score band, a confidence rating, a list of your strengths, a list of "risks", meaning what might hold you back for that job, the full generated CV content, a requirement by requirement breakdown with verbatim quotes taken from your own profile, and technical information about the run including the model used, token counts and the estimated cost.
Used to: give you and your coach the analysis and the draft CV you asked for, and to let you look back at previous generations.
This is an assessment of you as a person against a job. Section 8 explains how we treat it.
3.14 Generated CV documents
The finished PDF, containing your name, contact email, phone number, city, LinkedIn URL and tailored career history. Files are held in a private storage area. Downloads are served through a link that expires after 120 seconds, and only after we check that the file belongs to you.
3.15 Your joining record
The promo code you signed up with, the date you used it, and any note we wrote against that code when we issued it. That note is usually a person's name, so that we could remember who the code was for.
3.16 Cookies and similar technology
The only cookies we set are the Supabase session cookies that keep you signed in and refresh your session. They are strictly necessary for the service to work, so we do not ask for consent to set them, and we do not show a cookie banner.
There is no analytics, no advertising, no tracking and no session recording anywhere in the app. We have confirmed this by searching the codebase.
One page on our public website, the page we link to from our career diagnostic, embeds an explainer video hosted on YouTube. We use YouTube's no cookie player, which does not set cookies when the page loads. If you press play, Google sets its own cookies at that point and Google's privacy policy applies to what it does with them. Nothing on that page identifies you to us, and no video is embedded anywhere inside your signed in account.
3.17 Things we do not collect
- We do not collect card or bank details. Card payments go directly to Whop, our payment provider, and never reach us. See section 16.
- We do not collect your date of birth, your PPS number, or any government identifier.
- We do not ask for or store your LinkedIn password or connect to your LinkedIn account. The daily checklist is self reported.
4. Our lawful bases for using your data
Under Article 6 of the GDPR we need a lawful basis for each thing we do. Here they are.
| What we do | Lawful basis |
|---|---|
| Create and run your account, store your profile, track your opportunities, generate match analysis and CVs, provide coaching | Performance of our contract with you, Article 6(1)(b) |
| Check and consume your invite code at sign up, and keep a record of which code you joined with | Performance of our contract, and our legitimate interest in keeping an invite only service honest, Article 6(1)(f) |
| Meter and manage CV credits, and bill you | Performance of our contract, Article 6(1)(b) |
| Keep the daily LinkedIn activity record and show it to your coach | Performance of our contract, because coaching accountability is part of what you are paying for, Article 6(1)(b) |
| Send you service emails such as sign up confirmation and password reset | Performance of our contract, Article 6(1)(b) |
| Keep the service secure, prevent abuse, and investigate problems | Our legitimate interests, Article 6(1)(f) |
| Keep accounting records for the payments you make to us | Legal obligation under Irish tax law, Article 6(1)(c) |
| Handle your data protection requests and keep a record that we handled them | Legal obligation, Article 6(1)(c) |
| Store and use recruiter contact details entered by clients | Our legitimate interests and those of our clients, Article 6(1)(f). See section 11 |
| Defend or bring legal claims if we ever have to | Our legitimate interests, Article 6(1)(f) |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights. You can ask us for our reasoning, and you can object at any time. See section 14.
We do not rely on consent for anything at the moment, so there is no consent for you to withdraw. If we add anything that needs consent, such as marketing emails or analytics, we will ask you separately and clearly first.
5. Right to work and visa status
There is one field in your profile called right to work status. The dropdown offers options such as Irish, EU, EEA or Swiss citizen, UK citizen, permanent resident or settled status, Stamp 4, a valid work permit or visa with no sponsorship needed, requires visa sponsorship, working holiday authorisation, and a free text "Other".
Why we ask. It is coaching context. It helps your coach give you realistic advice about which roles are worth your time in the Irish and UK markets.
What happens to it in the app.
- It is never sent to Anthropic or any AI system. It is removed from the data payload in code before any request is made.
- It is never printed on a generated CV. On top of the field being stripped on the way in, the app also blocks any generated CV that mentions a visa, sponsorship, a work permit, right to work, or an immigration stamp. If the AI produces text like that, the app tries twice to fix it and then fails the generation and refunds your credit rather than give you the draft.
- Your coach can read it in the database, even though the current admin screens do not display it.
Why we treat it carefully. Citizenship and immigration status are not on the list of special category data in Article 9 of the GDPR, but they are a recognised proxy for national and ethnic origin, and nationality and national origin are protected grounds under the Irish Employment Equality Acts 1998 to 2015 and the UK Equality Act 2010. We therefore treat this field as high risk.
Two things to note. The field is optional and you can leave it blank. And please do not use the free text "Other" box to describe an asylum or international protection application, a medical condition or anything similar, because that would put genuinely special category data into a field that has no extra protection.
6. Please do not enter special category data
Some kinds of personal data get extra protection under Article 9 of the GDPR: information that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation.
We do not want this data and we do not ask for it. There is no field in Vanta Workspace designed to capture it.
However, several fields are free text, and you could put it there without meaning to. The realistic routes are:
- A volunteering or additional item that names a political party, a church or religious organisation, or a trade union role.
- A reason for leaving that mentions illness, disability, pregnancy, harassment or a discrimination claim.
- Notes on an opportunity.
- The free text "Other" option on the right to work field.
The app does not currently detect, warn about or filter any of this. We are being straight with you rather than implying a control that does not exist. Please keep this information out of the app. If you have already entered something like this and want it removed, email us at dylan@vanta-coach.com and we will delete it, or you can edit or delete the entry yourself.
Be aware that volunteering and additional items are sent to the AI and are printed on your CV, so a religious, political or trade union affiliation entered there will travel with the document.
7. How we use AI, and exactly what is sent
The CV engine is the part of Vanta Workspace that scores your fit for a job and drafts a tailored CV.
Who processes it. Anthropic PBC, through the Claude API at api.anthropic.com. The model in use is claude-sonnet-5. Calls are made from our server only, never from your browser, using a private API key.
When it happens. Only when the CV engine is switched on for your account, and only when you click generate on an opportunity that has a job description saved. The engine is off by default. Each run costs one credit. Nothing is sent to Anthropic in the background, on a schedule, or when you are simply editing your profile.
What is sent. For each generation there are two calls, plus up to two repair calls if the draft breaks a formatting rule. Between them they send:
- the text of the job advert you pasted in;
- your name, contact email, phone number, city and LinkedIn URL;
- your target market, target roles, target industries, desired role summary, years of experience, strongest expertise and what you are known for;
- for each role: job title, employer, employer one liner, location, working arrangement, dates, whether it is current, your responsibilities, every achievement bullet and its metric tags, and every tool listed;
- education: institution, qualification, field of study, grade and formatted dates;
- your skills;
- certifications: name, issuing body and issue date;
- languages and proficiency;
- publications, volunteering, projects and awards: kind, title, description and date;
- a brief derived from the first call, listing the job requirements, how well you fit each one, and the gaps.
What is never sent. These are deliberate decisions written into the code, not promises about how we behave:
- your right to work or visa status;
- your reason for leaving any job;
- your private notes on an opportunity;
- any recruiter's name, email address or LinkedIn profile;
- the database identifiers for your records, which are replaced with throwaway labels;
- certification expiry dates and credential links, links on additional items, raw education dates, your account flags, your CV plan and your credit balance.
What comes back and where it is stored. The analysis, the score, the strengths and risks, the requirement by requirement breakdown and the CV content are stored in our Supabase database, and the finished PDF is stored in our private document area. Your name and contact line on the finished CV are rebuilt by our own code from your profile rather than taken from the AI, so the AI cannot get your contact details wrong.
Anthropic's own handling. Anthropic acts as our processor for this. We do not currently set a zero retention option on our API calls. Under Anthropic's commercial terms for API use, what we send and what comes back is not used to train their models. They retain it only for as long as needed to return a result and to meet their own legal and safety obligations. Checked 17 August 2026.
Where Anthropic processes it. Anthropic PBC is established in the United States, so this involves a transfer outside the EEA. See section 11.
8. Scoring and profiling
The CV engine produces an assessment of you: a percentage match score, a score band of strong, moderate, limited or weak, a confidence rating, a list of strengths and a list of "risks", meaning what might hold you back for a particular job. It also quotes lines from your own profile as evidence for each requirement.
That is profiling as defined in Article 4(4) of the GDPR, because it is automated processing used to evaluate aspects of you, in this case your suitability for work. We are telling you about it because you are entitled to know.
It is not a decision made solely by automated means with legal or similarly significant effects, of the kind covered by Article 22. Nothing is decided about you by the engine. It does not accept or reject you, it does not gate access to anything, and it does not change your account. It produces advice that you and your coach read, argue with and act on however you choose. You are always free to ignore it, to regenerate, or to write your own CV.
If you think a score or a "risk" is wrong or unfair, tell us and we will look at it with you. You also have the right to have any inaccurate personal data corrected.
9. Who can see your data inside Vanta Workspace
There is one administrator account, held by the founder, who is also your coach.
What the admin screens show today. For every client: login email, full name, industry, desired job title, onboarding status, which features are enabled, sign up date, how many opportunities they have, and their LinkedIn activity statistics. On an individual client page: the promo code they joined with, login email, name, industry, desired job title, target market, target roles, years of experience, account flags, CV plan and credit balance, a list of every opportunity with job title, company and stage, and the dates they logged LinkedIn activity over the last twenty eight days. There is also a page listing recruiters logged across all clients, and a page listing promo codes.
What the founder can access in principle. We would rather tell you the real ceiling than the current screen layout. The founder holds the administrative key to the database and access to the hosting dashboards. That means the founder can read every row of every table for every client, including your reason for leaving each job, your right to work status, your phone number, your private notes on opportunities, the job adverts you pasted, the generated CV content and the PDF files. Assume that anything you put into Vanta Workspace can be read by your coach.
What the founder cannot do through the app. Clients cannot make themselves administrators, and the founder cannot edit your career content through the admin screens.
Other clients. No client can see any other client's data. This is enforced at the database level by row level security, not just in the interface.
An honest gap. We do not currently keep a log of when the founder viewed a particular client's records. That means if you ask us "who looked at my data and when", we cannot give you a complete technical answer. We can tell you that the only person with access is the founder.
10. The companies that process data for us, and transfers outside the EEA
We use a small number of providers. Each acts as our processor, meaning they handle data on our instructions and not for their own purposes.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Hosts our database, our authentication system and the private storage area holding generated CV PDFs. Effectively all of your data lives here | Ireland (eu-west-1) |
| Vercel | Hosts and runs the application. Every server side operation that touches your profile runs here, and Vercel's platform logs include IP addresses | Frankfurt, Germany (fra1) |
| Anthropic PBC | Runs the Claude models that produce the match analysis and the draft CV. See section 7 | United States |
| Supabase's email provider | Sends sign up confirmation and password reset emails | Resend, in the EU (Ireland) |
| Whop | Runs the card checkout and holds your payment details. We receive confirmation of payment and subscription identifiers, never card data. See section 16 | United States |
| Google (YouTube) | Serves the explainer video embedded on one page of our public website. Engaged only if you press play. Not used anywhere inside your account | United States |
We have a data processing agreement in place with each of Supabase, Vercel, Anthropic and Whop, as required by Article 28 of the GDPR. Each is bound to process your data only on our instructions.
Transfers outside the European Economic Area. Anthropic is in the United States, and depending on the regions confirmed above, some hosting or processing may also take place outside the EEA. Where data goes outside the EEA we rely on the European Commission's Standard Contractual Clauses, and where the provider is certified under it, the EU to US Data Privacy Framework. You can ask us for details of the mechanism that applies to a particular provider.
Links to job boards. Your dashboard has links that take you to LinkedIn, Indeed, IrishJobs, Reed and Google Jobs with your target role and city already filled into the search. If you click one, those search terms travel to that site in the web address, and that site's own privacy policy then applies. We do not send anything to those sites unless you click.
We do not sell your data. We do not share it with advertisers, data brokers, employers or agencies. We do not share it with other clients.
Legal disclosure. We would disclose data if we were legally required to, for example under a court order. If that happens we will tell you unless we are legally prevented from doing so.
11. If you are a recruiter, or someone a client has written about
This section is your notice under Article 14 of the GDPR, because we hold data about you that we did not get from you.
What we hold and where it came from. When one of our clients tracks a job opportunity, they can record the name, email address and LinkedIn profile of the recruiter or contact for that role. That information comes from our client, not from you. Clients may also mention hiring managers, interviewers, colleagues or former managers in free text notes, in their descriptions of past roles, or in the text of a job advert they paste in. Job adverts sometimes name a contact person.
What we do with recruiter contact details. Two things.
- We show them back to the client who entered them, as part of tracking their own application.
- The founder can view a single list of recruiters logged by all clients, alongside the name of the client who logged each one, with clickable email and LinkedIn links. The purpose of that list is for the founder to make contact about candidates and to build professional connections.
Our lawful basis. We rely on legitimate interests under Article 6(1)(f): our clients' interest in tracking their own job applications, and our interest in placing our clients with recruiters who hire in their field. We have taken the view that recruiter contact details are professional contact details, published or given out precisely so that candidates and their representatives can get in touch, and that using them to contact you about a candidate is within what you would reasonably expect. The second use, the cross client list used for the founder's own outreach, goes further than the reason the data was originally given, and we recognise that it needs to stand on its own footing.
Your rights. You have the full set of rights in section 14. In particular:
- You can object to us holding or using your details, under Article 21. If you object to the use of your details for our own outreach, we will stop, and we will not ask you to justify it.
- You can ask for a copy of what we hold about you.
- You can ask us to delete your details.
Email dylan@vanta-coach.com and we will deal with it. Please give us the name, email address or LinkedIn profile you want us to search for, so that we can find the right records.
Being honest about the limits. There is currently no automatic way for us to notify you that a client has logged your details, and no self service way for you to see or remove them. Publishing this notice, and acting quickly when someone contacts us, is how we address that today. Recruiter records are otherwise only deleted when the client deletes that opportunity or their whole account.
Job advert text. We store the text of the job advert a client pastes in, and a frozen copy of it against each generation. That text is usually the copyright of the employer or agency, and sometimes names a person. We keep it only so that a client can see what a CV was tailored against. If you are the owner of an advert and want it removed from our records, contact us.
Clients: please read this too. When you type someone else's name, email address or LinkedIn profile into Vanta Workspace, you are giving us personal data about a third party. Please only enter professional contact details, only where it is genuinely relevant to a job you are pursuing, and please do not write anything about a named person in your notes that you would not be willing to have them read.
12. How long we keep your data, and what deletion actually does
We do not currently have a retention schedule. There is no automatic expiry, no purge job and no inactivity rule anywhere in the system. We keep everything, including your full career history, your reasons for leaving jobs, recruiter details, saved job adverts, AI assessments and your daily activity record, until you delete your account. If you stop using Vanta Workspace and do nothing else, your data stays as it is. We would rather say that plainly than invent a retention period we do not enforce.
You can delete your account yourself at any time, from Settings. You have to type DELETE to confirm. There is no grace period and no undo.
What deletion removes. Deleting your account immediately and permanently removes: your login record, your identities and sessions, your profile, all work experiences with their achievements and tools, your education, skills, certifications, languages, additional items, all opportunities including notes, job advert text and recruiter details, all follow up tasks, all CV generations and their requirement breakdowns, and your entire LinkedIn activity history. This is enforced by the database structure, so it happens as one operation.
Files held outside the database. The CV you upload, the PDFs the engine generates and any files your coach uploads are kept in private storage rather than in the database. Deleting your account removes all of them, and deleting a single opportunity removes the PDFs generated for it. Your files do not outlive the record they belong to.
What deletion does not remove today. One exception, and we would rather you knew about it.
- Your joining record. The promo code you signed up with, the date you used it and the note we wrote when we issued that code are kept after your account is deleted, so that we have a record of which invite codes have been used. That note often contains a person's name. If you want the note cleared, ask us and we will clear it.
Backups. Our database provider takes automatic backups. Data you delete will remain in those backups for a period after deletion, and will then be overwritten. We do not restore backups in order to bring deleted accounts back. Those backups are kept for 7 days and are then overwritten.
Accounting records. Where we have invoiced you, we keep the invoice and payment record for as long as Irish tax law requires, currently six years, even if you delete your account. Those records contain your name and the amount, not your career data.
13. Your rights
Under the GDPR you have the following rights. They apply to clients and to anyone else whose data we hold, including recruiters.
- Access. You can ask for a copy of the personal data we hold about you, and for an explanation of what we do with it.
- Rectification. You can ask us to correct anything that is wrong or incomplete. Most of your own data you can simply edit in the app.
- Erasure. You can ask us to delete your data. Clients can do most of this themselves from Settings. See section 12 for what that does and does not cover.
- Portability. You can ask for the data you gave us in a structured, commonly used, machine readable format, and you can ask us to send it to another provider where that is technically feasible.
- Restriction. You can ask us to stop using your data while we sort out a dispute about its accuracy or about our basis for holding it.
- Objection. You can object to any processing we do on the basis of legitimate interests, including everything in section 12.
- Not to be subject to solely automated decisions. As explained in section 8, the CV engine does not make decisions about you, but you always have a human, your coach, to talk to.
How to exercise them. Email dylan@vanta-coach.com. Please send the request from the email address on your account where you can, because that is how we check it is really you. If we cannot match you to an account we may ask you for something else to confirm your identity, and we will only ask for the minimum needed.
What to expect. We will answer within one month. If your request is complicated we may take up to two further months, and we will tell you within the first month if that happens. There is no charge unless a request is clearly excessive or repetitive.
Being honest about how we do it. There is no download your data button in the app today. If you ask for a copy of your data, or for it in a portable format, we put it together manually by querying the database, and we send it to you as files. It works, but it is a manual process run by one person, which is why we ask you to allow us the full month if we need it.
14. Who we are and how to contact us
Vanta Workspace is a paid, invite only, coach backed job search service for people looking for work in Ireland and the UK. It is operated by Dylan Corrigan, based in Dublin, Ireland, trading as Vanta Coaching ("Vanta Workspace", "we", "us").
We are the data controller for the personal data described in this notice. That means we decide what data is collected and what happens to it, and we are responsible to you for it.
- Email for anything to do with your data or this notice: dylan@vanta-coach.com
- Postal address: Swiftbanks, Saggart, Dublin 24, Ireland
- Business registration number, if any: registered with the Companies Registration Office as a business name
We have not appointed a Data Protection Officer. We are a one person business and we do not believe we meet the tests in Article 37 of the GDPR that make one mandatory. You can raise any data protection question with us directly at the email above.
15. Complaints
If you are unhappy with how we have handled your data, please tell us first at dylan@vanta-coach.com and we will try to put it right.
You also have the right to complain to the Irish supervisory authority at any time, without going through us first:
Data Protection Commission 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland Website: www.dataprotection.ie
If you live or work in another EU or EEA country, you can complain to your local data protection authority instead.
16. Payments
Vanta Workspace is a paid service. Card payments are taken through a checkout hosted by our payment provider, Whop.
We never see, collect or store your card number, bank details or any other payment credential. Those go directly to Whop and stay with Whop. What comes back to us is confirmation that a payment succeeded, which plan it was for, and identifiers for your subscription so we know which account to activate and when it renews or lapses.
CV generations are metered as credits on your account. Whop's own privacy notice governs what they do with your payment details.
17. Security
- Passwords are hashed by our authentication provider. We never see them.
- The database enforces row level security, so one client's session cannot read another client's rows.
- Generated CV PDFs are held in a private storage area. They are not publicly addressable. Downloads are served through a link that expires after 120 seconds and only after we confirm the file belongs to the person asking.
- Clients cannot raise their own privileges. The columns that control administrator status, feature access, plan and credits cannot be written by a client account.
- The right to work field and reasons for leaving are stripped from AI requests in code, and generated CVs are scanned for prohibited content before you ever see them.
- All traffic is over HTTPS.
As set out in section 9, we do not currently log administrator access to individual client records.
If something goes wrong. If there is a personal data breach that is likely to be a risk to you, we will report it to the Data Protection Commission within 72 hours of becoming aware of it, and if the risk to you is high we will contact you directly and tell you what happened and what to do.
18. Children
Vanta Workspace is for working adults and is invite only. It is not intended for anyone under 18 and we do not knowingly hold data about children. We do not currently verify age at sign up. If you believe a person under 18 has an account, tell us and we will delete it.
19. Changes to this notice
If we change how we use your data in any way that matters, we will update this notice, change the version and date at the top, and tell you by email before the change takes effect. Minor wording fixes will just be updated here.
20. Questions
Email dylan@vanta-coach.com. A real person, the founder, reads it.