Welcome to Goodfit ("Goodfit", "we", "us", or "our"). Protecting your privacy is central to our mission of connecting talent with opportunity. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit https://www.goodfit.so (the "Site") or use any of our web, mobile, or integrated recruitment services (together, the "Services"). We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and all other applicable privacy laws. Please read this Policy carefully to understand our practices.
This Policy applies to anyone who accesses or uses the Services, including:
This Policy does not apply to third‑party websites or services that may be linked from our platform.
In certain scenarios (for example, when Goodfit processes candidate data solely on behalf of an employer), we act as a Processor and the employer is the Controller. Such processing is governed by a Data Processing Agreement (DPA).
a. Information You Provide Directly
b. Information Collected Automatically
c. Information from Third Parties
We do not intentionally collect any special‑category data (for example, health or religion) unless you voluntarily provide it and we have a lawful basis to process it.
We rely on the following lawful bases under Article-6 of the GDPR:
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Provide and maintain the Services, including account creation and candidate–employer communication.Improve, personalise, and develop features through usage analytics and user feedback.Send transactional communications such as account alerts, interview reminders, and password resets.Send marketing communications if you have opted in.Prevent fraud and ensure platform security by monitoring suspicious activity and verifying identities.Comply with legal obligations such as tax filings and lawful data‑access requests.We do not engage in automated decision‑making that produces legal or similarly significant effects without human involvement.
We disclose personal data only as described below:
We never sell personal data to third parties.
We operate globally and may transfer personal data to countries outside the EEA or UK. When we do so, we rely on appropriate safeguards such as EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision by the European Commission or UK Government.
We use cookies, web beacons, SDKs, and local storage to:
You can control or disable cookies via your browser settings. Some features may not function properly without cookies.
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including to:
When retention is no longer required, we will delete or irreversibly anonymise the data.
We employ technical and organisational measures to protect personal data, including:
No internet transmission is completely secure; you use the Services at your own risk.
Subject to conditions and exceptions in applicable law, you have the right to:
To exercise any right, email support@goodfit.so. We will respond within 30-days.
The Services are not directed to anyone under 18-years of age. We do not knowingly collect personal data from children. If we learn that we have done so, we will delete it promptly.
Our Site may contain links to external websites or integrations whose privacy practices we do not control. We encourage you to review their privacy policies before providing personal data.
We may update this Policy from time to time. When we do, we will post the revised version on this page, update the "Last updated" date, and notify registered users by email or in‑app notice if changes are material. Your continued use of the Services after such changes constitutes acceptance of the updated Policy.
If you have questions, concerns, or wish to exercise your rights, please contact: support@goodfit.so