Privacy Policy
Effective date: March 2026
Climblly Ltd ("Climblly", "we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights you have under UK data protection law.
Climblly Ltd is registered in England and Wales. We are the data controller for the personal data described in this policy.
If you have any questions about this policy, contact us at: hello@climblly.com
1. WHO THIS POLICY APPLIES TO
This policy applies to:
- Visitors to climblly.com
- Users of CareerKit, our AI-powered career platform
- Clients of Climblly Managed, our done-for-you application service
- Anyone who joins our waitlist or contacts us by email
2. WHAT DATA WE COLLECT
2.1 Website visitors
- IP address and browser type (via analytics)
- Pages visited, time on site, and referral source
- Cookie data (see our Cookie Policy for full details)
2.2 Waitlist signups
- Email address
- First name (where provided)
2.3 CareerKit users
- Name and email address
- CV and career history documents you upload or generate
- Voice recordings made during Architect sessions (processed and not stored in raw form)
- Career stories, achievements, and professional details stored in your Story Bank
- Application documents generated on your behalf
- Usage data — features used, kits generated, session activity
2.4 Climblly Managed clients
- Full name, email address, and phone number
- Current location and right-to-work status
- Employment history and CV
- Target roles, salary expectations, and job search preferences
- Job board account credentials shared for submission purposes
- Application records and submission history
- Discovery call notes and onboarding information
2.5 Payment data
We use Stripe to process payments. We do not store your card details. Stripe processes and stores payment information in accordance with their own privacy policy and PCI DSS compliance standards.
2.6 Booking data
When you book a discovery call via Cal.com, we collect your name, email address, and the details you provide in the booking form. This data is processed by Cal.com and shared with us to manage the appointment.
3. HOW WE USE YOUR DATA
- To provide and improve CareerKit and Climblly Managed services
- To generate tailored career documents using AI processing
- To communicate with you about your account, applications, and service updates
- To process payments and manage billing
- To send you waitlist updates and product announcements (with your consent)
- To analyse website usage and improve our platform
- To comply with our legal obligations
4. LEGAL BASIS FOR PROCESSING
We process your personal data on the following legal bases under UK GDPR:
- Contract — to deliver the services you have subscribed to
- Legitimate interests — to improve our services, prevent fraud, and manage our business
- Consent — for marketing emails and non-essential cookies (which you can withdraw at any time)
- Legal obligation — where required by law
5. AI PROCESSING
CareerKit uses OpenAI's API to process career information, generate documents, and power voice transcription. Data sent to OpenAI for processing is subject to OpenAI's data processing terms. We do not permit OpenAI to use your data to train their models under our API agreement.
Voice recordings made during Architect sessions are transcribed and then discarded. The transcribed text is stored in your Story Bank as structured career data.
6. THIRD-PARTY SERVICES
We share data with the following third parties only to the extent necessary to provide our services:
- Google Analytics — website usage analytics
- Stripe — payment processing
- OpenAI — AI document generation and voice transcription
- Cal.com — discovery call booking
- Email marketing platform (e.g. Mailchimp) — waitlist and product communications
Each third party is required to handle your data in accordance with applicable data protection law. We do not sell your personal data to any third party.
7. DATA RETENTION
- Website analytics data — 26 months
- Waitlist email addresses — until you unsubscribe or request deletion
- CareerKit account data — retained while your account is active and for 12 months after closure
- Climblly Managed client data — retained for the duration of the service and 24 months after the engagement ends, or as required by law
- Payment records — 7 years (legal requirement)
8. YOUR RIGHTS UNDER UK GDPR
You have the following rights regarding your personal data:
- Right to access — request a copy of the data we hold about you
- Right to rectification — ask us to correct inaccurate data
- Right to erasure — request deletion of your data where no legal basis for retention exists
- Right to restriction — ask us to limit how we use your data
- Right to portability — receive your data in a structured, machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — for any processing based on consent, including marketing emails
To exercise any of these rights, contact us at hello@climblly.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been handled unlawfully.
9. DATA SECURITY
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include encrypted data storage, secure access controls, and regular security reviews.
Despite these measures, no system is completely secure. If you believe your data has been compromised, contact us immediately at hello@climblly.com.
10. INTERNATIONAL TRANSFERS
Some of our third-party service providers (including OpenAI and Stripe) are based outside the UK. Where data is transferred internationally, we ensure appropriate safeguards are in place in accordance with UK GDPR requirements.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. When we make material changes, we will notify users by email or via a notice on our website. The effective date at the top of this page will always reflect the most recent version.
12. CONTACT
Data Controller: Climblly Ltd
Address: 128 City Road, London, EC1V 2NX, United Kingdom
Registered in England and Wales
Email: hello@climblly.com
Website: climblly.com