Skip to content

Privacy policy

Version v2.0 · Effective date: 17 May 2026

This policy explains how Tenure handles personal data across both products: the consumer careers platform at tenurecareers.io and the B2B compensation intelligence product (Tenure Comp Intelligence) at business.tenurecareers.io.

If you are a candidate using the consumer side, sections 1, 3, 4, 5, 7, 9, 10, 11 apply to you. If you are an organisation buying Tenure Comp Intelligence, sections 1, 2, 4, 6, 7, 8, 9, 10, 11 apply to you. Section 12 is the privacy-specific commitment we make to candidates about how their data flows into the B2B product.

1. Who we are

Tenure ("Tenure", "we", "us", "our") operates two products under a single brand.

The data controller for both products is Tenure Careers FZE LLC, a UAE Free Zone Establishment based in Dubai.

Contact for privacy questions, data subject rights requests, and security reports: privacy@tenuredata.com.

Contact for legal correspondence: legal@tenuredata.com.

2. Definitions

In this policy:

  • "Personal data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on personal data, including collection, storage, use, disclosure, and erasure.
  • "Aggregate data" means data summarised across many sources such that no individual is identifiable.
  • "Consumer user" means an individual using the careers platform at tenurecareers.io.
  • "B2B user" means an authorised user of an organisation that has purchased Tenure Comp Intelligence.
  • "Org" means an organisation that holds a Tenure Comp Intelligence subscription.

3. What we collect from consumer users

When you use tenurecareers.io, we collect:

Category Examples Source
Account data Email address, full name You, at signup
Profile data Preferred sectors, seniority level, country, current salary (if you choose to share) You, in your dashboard
CV data CV file you upload for review You
Salary submissions Compensation data you submit to the Pay Index (sector, role, level, country, base, allowances, total cash, optional payslip for verification) You, through the salary submission form
Usage data Pages viewed, searches run, jobs viewed Your interaction with the site
Communications Emails you send us; support chat messages You
Cookies and analytics Session cookies, GA4 measurement events Your browser

4. What we collect from B2B users

When you use business.tenurecareers.io as part of an org subscription, we collect:

Category Examples Source
Account data Email address, full name, role at organisation You or the org owner who invites you
Org data Company name, country, size band, industry The org owner at signup
Billing data Card details (held by Stripe, not Tenure), billing address, billing contact Org at checkout
Benchmark uploads CSV of comp bands the org uploads to compare against the market. May include named employees if the org chooses to include that field. Org user upload
Usage data Filters applied, roles viewed, exports run, saved views created Your interaction with the dashboard
Activation data Email open and click events, in-product tour completion Resend (email) and our own event log

5. Why we process personal data (lawful basis)

We process personal data under the following lawful bases:

Processing activity Lawful basis (UAE PDPL Art. 5-6; Saudi PDPL Art. 5-6)
Provide consumer account access Performance of contract
Provide B2B account access and subscription services Performance of contract
Process billing and payments Performance of contract
Send transactional emails (account notifications, billing receipts) Performance of contract
Provide AI CV review Performance of contract
Provide salary data to B2B customers Legitimate interest, balanced against the public availability of the underlying sources and the anonymisation guarantees in section 12
Aggregate candidate salary submissions into the Pay Index Consent (granted at submission)
Send marketing emails Consent (opt-in)
Cold outbound B2B sales emails to corporate contacts Legitimate interest, with clear opt-out in every message
Detect and prevent fraud, abuse, and scraping Legitimate interest
Improve the product through analytics Legitimate interest, with the right to object
Comply with legal obligations Legal obligation

You can object to any processing based on legitimate interest by emailing privacy@tenuredata.com. We will assess and respond within 30 days.

6. Org-uploaded benchmark data

When a B2B user uploads a CSV of the org's comp bands to the Benchmarking tab:

  • The data is stored encrypted in the org's private space, isolated by row-level security
  • The data is never combined into the aggregate Pay Index
  • The data is never visible to any other org or to any consumer user
  • The data is retained until the org deletes it or the org's subscription ends and a 30-day grace period elapses
  • If the upload includes named employees (e.g. an "employee_name" column), we treat that field as personal data of the org's employees and the org is the data controller; we are the data processor

Orgs are responsible for ensuring they have a lawful basis to share their employees' compensation data with us as a processor. We recommend orgs anonymise their uploads before submission.

7. Who we share personal data with

We do not sell personal data. We share personal data only as listed below.

Recipient Purpose Personal data shared Region
Supabase Database, authentication, storage All personal data we hold EU (Frankfurt)
Stripe Payment processing Billing data (cards held by Stripe, not us) US (with EU representative)
Resend Transactional and marketing email Email address, name, send context US
Anthropic AI CV review, salary matching, benchmarking match CV text content (consumer); role title text (B2B benchmarking); never combined with directly identifying fields US
Vercel Application hosting All personal data passes through Vercel infrastructure Global edge (primary US)
Apollo Org enrichment at B2B signup (company size lookup) Org domain, founder email US
exchangerate.host Currency conversion rates No personal data EU

Each recipient acts as a data processor under our instructions, governed by a data processing agreement.

We do not share personal data with employers as part of the consumer product. Employers receive only aggregate, anonymised compensation data through Tenure Comp Intelligence.

8. Cross-border data transfers

Tenure's infrastructure routes personal data through the EU (Supabase Frankfurt primary), the US (Stripe, Resend, Anthropic, Apollo, Vercel global edge), and globally via CDN.

UAE PDPL (Article 22-23) and Saudi PDPL (Article 29) permit cross-border transfers where the destination jurisdiction provides adequate protection or where specific safeguards are in place. We rely on:

  • EU jurisdictions: GDPR equivalence is generally recognised
  • US: data processing agreements with each recipient, plus contractual safeguards equivalent to Standard Contractual Clauses

If you object to your data being transferred to any of these jurisdictions, contact privacy@tenuredata.com and we will work through alternatives.

9. How long we keep personal data

Category Retention period
Consumer account data Until account deletion + 30-day grace period
Consumer CV data Until you delete the CV or 24 months from upload, whichever is sooner
Salary submissions (your individual submission record) Until you request deletion. The anonymised value, once aggregated into a cell with 5+ contributors, becomes unrecoverable from the aggregate and cannot be individually deleted
B2B account data Until org subscription ends + 90-day grace period for billing reconciliation
B2B benchmark uploads Until org deletes or 12 months after last access, whichever is sooner
Billing records 7 years (UAE accounting requirement)
Email communications and support chat 24 months from last contact
Activation and usage logs 24 months rolling window
Audit and security logs 24 months rolling window

After the retention period, personal data is deleted or fully anonymised.

10. Your rights

Under UAE PDPL and Saudi PDPL you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate personal data
  • Request deletion of personal data
  • Object to processing based on legitimate interest
  • Withdraw consent where processing is based on consent
  • Receive a copy of your data in a structured, machine-readable format
  • Lodge a complaint with your local data protection authority (UAE Data Office for UAE residents, Saudi Data and Artificial Intelligence Authority for Saudi residents)

To exercise any of these rights, email privacy@tenuredata.com. We respond within 30 days. We may ask for identity verification before acting on a request.

11. Security

We protect personal data using:

  • Encrypted database (Supabase Postgres with encryption at rest)
  • Encrypted transit (TLS 1.2+ everywhere)
  • Row-level security policies preventing cross-org and cross-user access
  • Magic-link authentication (no passwords stored)
  • Vendor data processing agreements
  • Access logging and anomaly detection
  • Org-private benchmark data isolation

We do not yet hold SOC 2, ISO 27001, or similar certifications. We will pursue these as customer demand justifies and document any progress on the Security page at business.tenurecareers.io/security.

If you believe your data has been compromised, email privacy@tenuredata.com immediately. We will investigate, notify affected users where required, and notify the UAE Data Office and SDAIA where required by law (typically within 72 hours of becoming aware).

12. Promise to candidates about B2B data flows

This is the commitment that matters most. When you submit personal data on the consumer side, you can verify that:

  • Your individual submission never appears in any B2B output
  • Aggregate compensation data shown to B2B buyers contains a minimum of 5 contributors per cell
  • B2B buyers never see your name, your employer, or any combination of fields that could identify you
  • We never sell your personal data
  • We never share your personal data with employers
  • The Pay Index sees compensation data; it never sees who submitted it

If you believe this commitment has been broken, email privacy@tenuredata.com. We treat any breach of this commitment as a P0 incident.

13. Cookies

We use cookies for:

  • Session management (necessary)
  • Authentication state (necessary)
  • Active org selection on B2B (necessary)
  • GA4 analytics (consent required)
  • Marketing attribution (consent required)

You can manage non-essential cookies in your browser or via the cookie settings link in our footer.

14. Changes to this policy

We may update this policy. Material changes are communicated by email to all account holders at least 30 days before they take effect. We maintain a public version history; the current version and effective date appear at the top of this document.

15. Children

Tenure is not directed to anyone under 18. We do not knowingly collect personal data from anyone under 18. If you believe we have, email privacy@tenuredata.com and we will delete it.

16. Contact

Privacy questions, rights requests, security reports: privacy@tenuredata.com. Legal correspondence: legal@tenuredata.com.

Manage your cookie preferences

Change which categories of cookies you accept on this device at any time.