Privacy policy
Version v2.3 · Effective date: 9 September 2026
This policy explains how Tenure handles personal data across both products: the consumer careers platform at tenurecareers.io and the B2B compensation intelligence product (Tenure Comp Intelligence) at tenuredata.com.
If you are a candidate using the consumer side, sections 1, 3, 4, 5, 7, 9, 10, 11 apply to you. If you are an organisation buying Tenure Comp Intelligence, sections 1, 2, 4, 6, 7, 8, 9, 10, 11 apply to you. Section 12 is the privacy-specific commitment we make to candidates about how their data flows into the B2B product.
1. Who we are
Tenure ("Tenure", "we", "us", "our") operates two products under a single brand.
The data controller for both products is Tenure Careers FZE LLC, a UAE Free Zone Establishment based in Dubai.
Contact for privacy questions, data subject rights requests, security reports and legal correspondence: liam@tenurecareers.io. Tenure is founder-run; that address reaches the person who holds the data.
2. Definitions
In this policy:
- "Personal data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on personal data, including collection, storage, use, disclosure, and erasure.
- "Aggregate data" means data summarised across many sources such that no individual is identifiable.
- "Consumer user" means an individual using the careers platform at
tenurecareers.io. - "B2B user" means an authorised user of an organisation that has purchased Tenure Comp Intelligence.
- "Org" means an organisation that holds a Tenure Comp Intelligence subscription.
3. What we collect from consumer users
When you use tenurecareers.io, we collect:
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, full name | You, at signup |
| Profile data | Preferred sectors, seniority level, country, current salary (if you choose to share) | You, in your dashboard |
| CV data | CV file you upload for review | You |
| Salary submissions | Compensation data you submit to the Pay Index (sector, role, level, country, base, allowances, total cash, optional payslip for verification) | You, through the salary submission form |
| Usage data | Pages viewed, searches run, jobs viewed | Your interaction with the site |
| Communications | Emails you send us; support chat messages | You |
| Cookies and analytics | Session cookies, your cookie choice, GA4 measurement events, cookieless page-view counts, error reports if something breaks | Your browser |
4. What we collect from B2B users
When you use tenuredata.com as part of an org subscription, we collect:
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, full name, role at organisation | You or the org owner who invites you |
| Org data | Company name, country, size band, industry | The org owner at signup |
| Billing data | Card details (held by Stripe, not Tenure), billing address, billing contact | Org at checkout |
| Benchmark uploads | CSV of comp bands the org uploads to compare against the market. May include named employees if the org chooses to include that field. | Org user upload |
| Usage data | Filters applied, roles viewed, exports run, saved views created | Your interaction with the dashboard |
| Activation data | Email open and click events, in-product tour completion | Resend (email) and our own event log |
5. Why we process personal data (lawful basis)
We process personal data under the bases available in the laws that apply. The two regimes differ: the UAE PDPL (Federal Decree-Law No. 45 of 2021) is consent-first, with an exhaustive set of statutory exceptions that includes contract performance, legal obligation, protection of your interests, and processing for research and statistical purposes; it does not contain a general "legitimate interest" basis. The Saudi PDPL recognises a legitimate-interest basis for non-sensitive personal data. Where this table names legitimate interest, that basis applies under Saudi law and, for people covered by UK or EU law, under the GDPR; for processing in scope of the UAE PDPL we rely on the statutory basis shown alongside it.
| Processing activity | Lawful basis |
|---|---|
| Provide consumer account access | Performance of contract |
| Provide B2B account access and subscription services | Performance of contract |
| Process billing and payments | Performance of contract |
| Send transactional emails (account notifications, billing receipts) | Performance of contract |
| Provide AI CV review | Performance of contract |
| Provide aggregate salary intelligence to B2B customers | The published product is aggregate data (section 2) from which no individual is identifiable, produced under the anonymisation guarantees in section 12. The underlying statistical processing rests on the UAE PDPL's research and statistical purposes exception; under Saudi law and the GDPR, on legitimate interest |
| Aggregate candidate salary submissions into the Pay Index | Consent (granted at submission), plus the same statistical-purposes basis for the aggregation itself |
| Send marketing emails | Consent (opt-in) |
| Cold outbound B2B sales emails to corporate contacts | Legitimate interest (Saudi PDPL, GDPR) with clear opt-out in every message; limited to professional contact details used in a business capacity |
| Detect and prevent fraud, abuse, and scraping | Protection of our and our users' interests; legitimate interest where recognised |
| Improve the product through analytics | Legitimate interest where recognised, with the right to object |
| Comply with legal obligations | Legal obligation |
You can object to any processing that rests on legitimate interest, or withdraw any consent, by emailing liam@tenurecareers.io. We will assess and respond within 30 days.
6. Org-uploaded benchmark data
When a B2B user uploads a CSV of the org's comp bands to the Benchmarking tab:
- The data is stored encrypted in the org's private space, isolated by row-level security
- The data is never combined into the aggregate Pay Index
- The data is never visible to any other org or to any consumer user
- The data is retained until the org deletes it or the org's subscription ends and a 30-day grace period elapses
- If the upload includes named employees (e.g. an "employee_name" column), we treat that field as personal data of the org's employees and the org is the data controller; we are the data processor
Orgs are responsible for ensuring they have a lawful basis to share their employees' compensation data with us as a processor. We recommend orgs anonymise their uploads before submission.
7. Who we share personal data with
We do not sell personal data. We share personal data only as listed below.
| Recipient | Purpose | Personal data shared | Region |
|---|---|---|---|
| Supabase | Database, authentication, storage | All personal data we hold | India (Mumbai, AWS ap-south-1) |
| Stripe | Payment processing | Billing data (cards held by Stripe, not us) | US (with EU representative) |
| Resend | Transactional and marketing email | Email address, name, send context | US |
| Anthropic | AI CV review, salary matching, benchmarking match | CV text content (consumer); role title text (B2B benchmarking); never combined with directly identifying fields | US |
| Vercel | Application hosting | All personal data passes through Vercel infrastructure | Global edge (primary US) |
| Apollo | Org enrichment at B2B signup (company size lookup) | Org domain, founder email | US |
| exchangerate.host | Currency conversion rates | No personal data | EU |
| Sentry | Error and performance monitoring, so we find out when something breaks | Error reports: the page, browser and device, the request path, and the account id of a signed-in user so we can tell whether one person or many are affected. Emails and other fields are redacted before sending. With your analytics consent only: a masked session replay (all text hidden, all media blocked) of the moments around an error | US |
| Google Analytics | Usage analytics to improve the product (consent required for anything identifying) | Page views and product events. Without consent: cookieless pings with no identifier stored on your device. With consent: an analytics cookie and, for signed-in members, a pseudonymous account id | US |
| Google Ads | Conversion measurement on the consumer platform: whether a Google search ad led to a Tenure Pro subscription (consent required) | One cookieless conversion report when you subscribe: the subscription value, currency and a timestamp reference (not your invoice or account id). No advertising cookie is written or read; we do not use this for retargeting | US |
| Microsoft Advertising | Conversion measurement on the consumer platform: whether a Bing search ad led to a Tenure Pro subscription (consent required) | The same single cookieless conversion report as Google Ads, plus page-load events while consent is on. No advertising cookie is written; we do not use this for retargeting | US |
| Ahrefs | Cookieless page-view counting (Ahrefs Web Analytics) | Page URL, referrer, browser type and country. No cookie is set and no identifier is stored; your IP address is used to derive the country and is not retained by us | Singapore |
| Telegram | Founder alerts on new sign-ups and enquiries. Built in 2026 and, on our records, switched off on 17 July 2026; listed because the code path still exists | When active: the email address on a sign-up or enquiry, and the event type | Telegram's own infrastructure (multiple jurisdictions) |
| Instantly | B2B outbound email tooling. On our records the subscription was cancelled on 17 July 2026; listed because the code path still exists | When active: professional contact details of corporate prospects (name, work email, employer, role). Never consumer users | US |
| Voyage AI | Optional semantic search behind the B2B advisor; only used when a key is configured, which on our records it is not | When active: the question a B2B user types into the advisor | US |
Each recipient acts as a data processor under our instructions, governed by a data processing agreement or the recipient's published data processing terms.
We do not share personal data with employers as part of the consumer product. Employers receive only aggregate, anonymised compensation data through Tenure Comp Intelligence.
8. Cross-border data transfers
Tenure's infrastructure routes personal data through India (Supabase primary database, Mumbai), the US (Stripe, Resend, Anthropic, Apollo, Sentry, Google, Microsoft, Vercel global edge), Singapore (Ahrefs, cookieless page counts only), and globally via CDN.
UAE PDPL and Saudi PDPL permit cross-border transfers where the destination jurisdiction provides adequate protection or where specific safeguards are in place. We rely on:
- India: our database provider processes data under a data processing agreement with contractual safeguards equivalent to Standard Contractual Clauses; India's Digital Personal Data Protection Act 2023 provides a national data protection framework
- US: data processing agreements with each recipient, plus contractual safeguards equivalent to Standard Contractual Clauses
If you object to your data being transferred to any of these jurisdictions, contact liam@tenurecareers.io and we will work through alternatives.
9. How long we keep personal data
| Category | Retention period |
|---|---|
| Consumer account data | Until you delete the account. Deletion runs immediately, in the request that asks for it: there is no grace period and no restore. A single record of the deletion is kept (see section 10) |
| Consumer CV data | Until you delete the CV or 24 months from upload, whichever is sooner |
| Salary submissions (your individual submission record) | Until you request deletion. Your submission is held as a record and is not entered into any published figure (section 12), so deleting it removes it entirely |
| B2B account data | Until org subscription ends + 90-day grace period for billing reconciliation |
| B2B benchmark uploads | Until org deletes or 12 months after last access, whichever is sooner |
| Billing records | 7 years (UAE accounting requirement) |
| Email communications and support chat | 24 months from last contact |
| Activation and usage logs | 24 months rolling window |
| Audit and security logs | 24 months rolling window |
After the retention period, personal data is deleted or fully anonymised.
10. Your rights
Under UAE PDPL and Saudi PDPL you have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Request deletion of personal data
- Object to processing based on legitimate interest
- Withdraw consent where processing is based on consent
- Receive a copy of your data in a structured, machine-readable format
- Lodge a complaint with your local data protection authority (UAE Data Office for UAE residents, Saudi Data and Artificial Intelligence Authority for Saudi residents)
To exercise any of these rights, email liam@tenurecareers.io. We respond within 30 days. We may ask for identity verification before acting on a request.
11. Security
We protect personal data using:
- Encrypted database (Supabase Postgres with encryption at rest)
- Encrypted transit (TLS 1.2+ everywhere)
- Row-level security policies preventing cross-org and cross-user access
- Magic-link authentication (no passwords stored)
- Vendor data processing agreements
- Access logging and anomaly detection
- Org-private benchmark data isolation
We do not yet hold SOC 2, ISO 27001, or similar certifications. We will pursue these as customer demand justifies and record any progress in this policy.
If you believe your data has been compromised, email liam@tenurecareers.io immediately. We will investigate, notify affected users where required, and notify the UAE Data Office and SDAIA where required by law (typically within 72 hours of becoming aware).
12. Promise to candidates about B2B data flows
This is the commitment that matters most. When you submit personal data on the consumer side, you can verify that:
- Your individual submission never appears in any B2B output, and it is not entered into any published pay band. Published bands are built from verified primary sources such as employer listings and disclosures, not from what individuals submit
- No published figure rests on fewer than three independent verified sources. That floor is enforced in the data itself, not by a reviewer: a figure that falls below it is withdrawn from every page automatically and returns only when a fresh source clears it. It is a data-quality rule rather than a privacy control, but it is the reason no published figure can be traced back to one person's disclosure
- B2B buyers never see your name, your employer, or any combination of fields that could identify you
- We never sell your personal data
- We never share your personal data with employers
- The Pay Index sees compensation data; it never sees who submitted it
If you believe this commitment has been broken, email liam@tenurecareers.io. We treat any breach of this commitment as a P0 incident.
13. Cookies
We use cookies for:
- Session management (necessary)
- Authentication state (necessary)
- Recording your cookie choice, so we do not ask again (necessary;
tenure_consent) - Active org selection on B2B (necessary)
- Google Analytics 4 (consent required; without consent GA4 receives cookieless pings and stores nothing on your device)
We set no advertising or retargeting cookies. On the consumer platform, if you accept analytics and later subscribe to Tenure Pro, we send one cookieless conversion report to Google Ads or Microsoft Advertising so we know whether a search ad brought you here; both platforms run with advertising storage denied, so no advertising cookie is written and nothing is used to show you ads elsewhere. Without your consent no conversion report is sent at all. Ahrefs page counting and Sentry error reporting use no cookies.
You can change your choice at any time via the cookie settings link in our footer; the single Analytics toggle covers both Google Analytics and the conversion reports above.
14. Changes to this policy
We may update this policy. Where a change expands what we collect or who we share it with, we email account holders before it takes effect. Changes that add protections, complete or correct the description of processing we already do, or fix errors take effect on publication. The current version and effective date appear at the top of this page; earlier versions are available on request at liam@tenurecareers.io.
15. Children
Tenure is not directed to anyone under 18. We do not knowingly collect personal data from anyone under 18. If you believe we have, email liam@tenurecareers.io and we will delete it.
16. Contact
Privacy questions, rights requests, security reports, legal correspondence: liam@tenurecareers.io.
Manage your cookie preferences
Change which categories of cookies you accept on this device at any time.