Privacy Policy
Last updated: 12 April 2026
PerfectIT Group Ltd ("we", "us", "our") is the data controller for personal data collected through 16capabilities.com. We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Contact: privacy@perfectit.group
1. What data we collect
- Account data: email address and name (collected at sign-up via magic link authentication)
- Assessment data: your responses to the 16 Capabilities assessment questionnaire
- AI-generated outputs: career archetype results and personalised development advice produced by our AI systems
- Resume data: documents you upload for analysis (optional)
- Payment data: billing information processed by Stripe (we do not store card numbers)
- Technical data: browser type, device, IP address, and cookies (see Section 7)
2. How and why we use your data
We process your data on the following lawful bases under UK GDPR Article 6:
- Contract (Art. 6(1)(b)): account creation, assessment delivery, AI-generated advice, resume analysis, and payment processing. These are necessary to provide the service you signed up for.
- Consent (Art. 6(1)(a)): analytics cookies and marketing communications. You can withdraw consent at any time.
- Legitimate interest (Art. 6(1)(f)): security logging, fraud prevention, and service improvement.
3. AI-generated advice and automated decisions
Your assessment responses are processed by AI models (OpenAI) to generate your capability archetype and personalised career development suggestions. This constitutes automated processing under UK GDPR Article 22.
- The AI analyses your assessment answers against our 16 Capabilities framework to identify your archetype, strengths, and development areas.
- AI outputs are informational and do not constitute professional career counselling. You should not make significant career or financial decisions based solely on these outputs.
- You have the right to request human review of any AI-generated output by contacting us at privacy@perfectit.group.
4. Who we share your data with
We share data with the following third-party processors, each under a Data Processing Agreement:
- Google Cloud Platform (hosting and infrastructure) -- data stored in europe-west2 (London, UK)
- OpenAI (AI processing of assessments and career advice) -- API usage only; your data is not used to train their models
- Stripe (payment processing)
- Resend (transactional email delivery)
We do not sell your data to third parties.
5. International data transfers
Your primary data is stored in the UK (Google Cloud europe-west2, London). Some processing involves transfers to the United States (OpenAI, Stripe). These transfers are protected by:
- The UK Extension to the EU-US Data Privacy Framework (for DPF-certified processors)
- UK International Data Transfer Agreements (IDTA) or Standard Contractual Clauses where applicable
6. How long we keep your data
- Active account data: retained while your account is active
- Deleted accounts: personal data erased within 30 days of deletion request
- Billing records: retained for 6 years after transaction (HMRC requirement)
- Security logs: retained for 12 months
- Cookie consent records: retained for 2 years
7. Cookies
We use the following categories of cookies:
- Strictly necessary: authentication session, CSRF protection, locale preference. These do not require consent.
- Analytics (optional): Google Analytics and Microsoft Clarity for understanding how the site is used. Only activated with your consent.
You can manage your cookie preferences using the cookie banner or by contacting us.
8. Your rights
Under UK GDPR, you have the right to:
- Access a copy of all personal data we hold about you
- Rectification of inaccurate data
- Erasure ("right to be forgotten") of your personal data
- Data portability in a machine-readable format (JSON or CSV)
- Restrict processing in certain circumstances
- Object to processing based on legitimate interest
- Withdraw consent for consent-based processing at any time
- Human review of automated decisions (including AI-generated advice)
To exercise any of these rights, contact privacy@perfectit.group. We will respond within one calendar month.
9. Children
This service is intended for users aged 16 and over. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, please contact us immediately.
10. Complaints
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
11. Changes to this policy
We may update this policy from time to time. We will notify you of significant changes by email or by posting a notice on the site.