Privacy Policy

Last updated: 27 February 2026

1. Introduction

GrimmGear (Pty) Ltd ("we", "us", "our") is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your personal information in compliance with the Protection of Personal Information Act (POPIA) and the General Data Protection Regulation (GDPR) where applicable.

2. Information We Collect

Account information: Name, email address, phone number (optional), town/location.

CV data: Personal details, work experience, education, skills, and references you provide when building a CV.

Payment information: Transaction records, payment method, subscription status. We do not store credit card numbers — payments are processed by PayFast.

Usage data: Pages viewed, job searches, features used, device and browser type.

3. How We Use Your Information

We use your information to: provide the job search and CV builder service; process payments and manage subscriptions; send job alerts and service notifications; improve our platform; and comply with legal obligations.

4. AI Processing

When you use our AI CV enhancement features, your CV data is processed by AI systems to generate summaries, enhance job duties, and create cover letters. This data is processed in real-time and not stored by the AI provider beyond the request.

5. Data Sharing

We do not sell your personal information. We share data only with: PayFast (payment processing); hosting providers (infrastructure); and law enforcement when legally required. Job applications you submit may share your details with the relevant employer.

6. Data Security

We protect your data with: encrypted connections (HTTPS/TLS); hashed passwords (PBKDF2-SHA512, 600,000 iterations); secure database access; and regular security audits. No system is 100% secure, and we cannot guarantee absolute protection.

7. Data Retention

Account data is retained while your account is active. After account deletion, personal data is removed within 30 days. Payment records are retained for 5 years for tax and legal compliance. Anonymised analytics data may be retained indefinitely.

8. Your Rights

Under POPIA and GDPR, you have the right to: access your personal data; correct inaccurate data; request deletion of your data; object to processing; request data portability; and withdraw consent. Contact us to exercise these rights.

9. Cookies

We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising pixels.

10. Contact

For privacy-related enquiries: privacy@grimmgear.com

Information Officer: Richard Beukes