Privacy Policy

Last updated: 11 August 2026

This policy explains how WorkinVirtual processes personal information when people search for jobs, create candidate or employer accounts, apply, recruit, purchase services, contact support, receive notifications, or use our editorial and AI-assisted features.

Who operates WorkinVirtual

The current website operator and data controller is WorkinVirtual (Private) Limited, Pakistan (company registration H219002). Contact: support@workinvirtual.com. WorkinVirtual CIC (UK company 16560537) was dissolved on 10 March 2026 and is not the current operator or controller.

Information we process

  • Account, role, identity and contact details.
  • Candidate profiles, resumes, skills, location and work-eligibility preferences.
  • Job listings, employer and company-verification information.
  • Applications, screening responses, application snapshots, messages, interview scheduling and outcome stages.
  • Orders, package entitlements and limited payment records. Card details are handled by the payment provider, not stored by WorkinVirtual.
  • Support conversations and tickets, including AI-assistant routing and human escalation.
  • Email and browser-notification preferences, device push endpoints, delivery and suppression records.
  • Security, fraud-prevention, consent, cookie, advertising and aggregated analytics signals.

Why we use it and our legal grounds

PurposeGround
Accounts, applications, hiring tools, purchases and requested supportPerformance of a contract or steps requested before a contract
Platform security, fraud prevention, quality, service measurement and enforcing rulesLegitimate interests, balanced against user rights
Tax, accounting, legal requests and dispute recordsLegal obligation or legal claims
Optional marketing email, non-essential cookies and browser pushConsent where required; consent can be withdrawn

Applications, employers and AI

When a candidate applies, relevant application information is shared with the employer responsible for that vacancy. External applications continue on the employer’s website; email applications are delivered to the stated employer address. Employers act independently for information they receive and must use it lawfully.

AI may assist with support triage, drafting, matching explanations or structured interview preparation. It must not make the final hiring, rejection, credit or legal decision. Users may request human support or an alternative process. Do not submit passwords, complete payment-card data, government identity documents or unnecessary sensitive information to the assistant.

Email and browser notifications

Account, application, security, billing and support messages are transactional. Optional job alerts and marketing are controlled separately. Browser notifications require an explicit device permission and a WorkinVirtual subscription; they can be disabled in Manage Subscriptions or browser settings. WorkinVirtual does not import unconfirmed or bounced legacy newsletter contacts into marketing.

Advertising, cookies and measurement

WorkinVirtual uses limited advertising and measurement technologies. Non-essential advertising or measurement storage is subject to the consent choices shown for the visitor where required. Employers and administrators do not receive WorkinVirtual job-application ads. Advertising does not buy editorial conclusions or employer verification.

Service providers and international transfers

We use service providers for hosting and security, email delivery, payment processing, analytics/advertising, trust reviews and AI features. Examples may include Hostinger, the configured SMTP provider, Stripe, Google, Trustpilot and OpenAI. They receive only the information needed for their service and are subject to contractual and access controls.

WorkinVirtual operates from Pakistan and serves users internationally. Where UK data-protection law applies to a restricted transfer, WorkinVirtual must assess the transfer and use an appropriate UK mechanism and safeguards before enabling it. A feature must remain restricted if required safeguards have not been verified.

Retention and security

Notification and email-delivery records are normally retained for up to 120 days. Revoked or expired browser-device endpoints are removed after a shorter operational period. Account, application, support, payment and security records are kept while the workflow is active and afterwards only as necessary for legal, accounting, safety, dispute or fraud-prevention purposes. Backups expire under controlled backup schedules. Access controls, encryption in transit, logging, rate limits and least-privilege administration are used; no system can be guaranteed completely secure.

Your choices and rights

You can correct account information, withdraw optional consent, disable browser push, unsubscribe from optional marketing, request access or deletion, and object or restrict processing where applicable. Some records may be retained where legally required or needed for security and claims. Use Delete Account, Manage Subscriptions, or contact support. Where UK law applies, a person may also complain to the UK Information Commissioner’s Office.

Children and changes

WorkinVirtual is intended for adults aged 18 or older. We may update this policy when services, providers or law change; material changes will be dated and, where appropriate, notified.

Official references: ICO privacy information guidance, ICO direct-marketing checklist, Pakistan MOITT data-protection bill materials.

Scroll to Top