Privacy Policy
Last updated: 14 April 2026
1. Who we are
Jobs in Psychedelics ("we", "us", "our") is a trading name of a United Kingdom–based business. We operate the website jobsinpsychedelics.com (the "Platform"), a specialist careers platform for the psychedelic medicine and mental health innovation sector.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller. If you have any questions about this policy or how we handle your data, please contact us at our contact page.
2. What data we collect
We collect the following categories of personal data depending on how you use the Platform:
Account information
- Name, email address, and username (when you register)
- Password (stored securely using one-way hashing)
- Profile information you choose to provide (professional headline, summary, LinkedIn URL)
Candidate data
- CV/resume files you upload (PDF, DOC, DOCX)
- Job applications, including cover letters and screening question responses
- Saved job listings
Employer data
- Company name, description, logo, website, and location
- Job listing content
- Subscription and billing information (processed by our payment provider — we do not store full card details)
Automatically collected data
- IP address, browser type, device type, and operating system
- Pages visited, time on page, and referring URL
- Cookies and similar technologies (see Section 7)
3. How we use your data
We process your personal data for the following purposes:
- To provide and operate the Platform — creating accounts, processing applications, displaying job listings, and enabling employer-candidate communication (legal basis: contract performance)
- To process payments — managing employer subscriptions through our payment provider (legal basis: contract performance)
- To communicate with you — responding to enquiries, sending service-related emails such as application confirmations (legal basis: contract performance and legitimate interests)
- To improve the Platform — analysing usage patterns, fixing bugs, and developing new features (legal basis: legitimate interests)
- To ensure security — detecting fraud, abuse, and unauthorised access (legal basis: legitimate interests)
- To comply with legal obligations — responding to lawful requests from authorities (legal basis: legal obligation)
We do not sell your personal data to third parties. We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
4. Who we share your data with
We share your personal data only where necessary to operate the Platform:
- Employers — when you apply for a job, the employer receives your application details, including your name, email, cover letter, CV (if attached), screening answers, and profile information you have provided
- Payment provider — we use Stripe to process employer subscription payments. Stripe acts as an independent data controller for payment data. See Stripe's privacy policy
- Hosting provider — the Platform is hosted on infrastructure within secure data centres
- Email provider — we use a transactional email service to send system emails (e.g. application confirmations)
We do not share your data with advertisers or data brokers.
5. International transfers
Some of our service providers may process data outside the United Kingdom. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner's Office (ICO), or transfers to countries with an adequacy decision.
6. How long we keep your data
- Account data — retained for as long as your account is active. If you delete your account, we will permanently remove your data within 30 days, subject to any legal retention requirements
- Job applications — retained for 12 months after the position is filled or closed, unless the employer or candidate requests earlier deletion
- Job listings — retained for as long as the employer's account is active
- Server logs — retained for up to 90 days
- Payment records — retained for 7 years to comply with HMRC requirements
7. Cookies
We use cookies that are essential to the operation of the Platform:
- Session cookies — to keep you logged in and maintain your preferences during a browsing session
- Security cookies — to protect against cross-site request forgery (CSRF)
We do not currently use third-party advertising or analytics cookies. If this changes, we will update this policy and provide you with appropriate choices.
8. Your rights
Under UK GDPR, you have the following rights:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — request that we limit processing of your data
- Portability — request your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — where processing is based on consent, withdraw it at any time
To exercise any of these rights, please contact us via our contact page. We will respond within one month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not handled your data correctly.
9. Children
The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. Security
We take reasonable technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (HTTPS/TLS)
- Secure password hashing
- Regular software updates and security patches
- Access controls limiting who can view personal data
No system is completely secure. If we become aware of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the ICO in accordance with UK GDPR.
11. Changes to this policy
We may update this privacy policy from time to time. We will post any changes on this page and update the "last updated" date. For significant changes, we will notify registered users by email.
12. Contact
If you have any questions about this privacy policy or our data practices, please contact us via our contact page.