Last Updated: October 2025
This Privacy Policy explains how we collect, use, store, and protect your personal data. We are committed to complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).
Who We Are
We are a UK-based Independent Financial Adviser (IFA) recruitment agency. References to "we," "us," "our," or "the company" mean our organisation. For data protection queries, contact our Data Protection Officer at [insert email].
What Personal Data We Collect
We collect personal data from candidates, employers, and website visitors:
From Candidates:
- Contact information (name, email, phone, address)
- Professional details (CV, qualifications, work history, FCA registration status)
- References and referee contact details
- Interview notes and assessment records
- Salary expectations and availability
- Equal opportunities monitoring data (optional)
- Right to work verification documents
From Employers:
- Contact information (name, email, phone, company details)
- Job requirements and vacancy specifications
- Feedback on candidates
- Interview and hiring decisions
From Website Visitors:
- IP address and device information
- Pages visited and time spent on site
- Form submissions (name, email, enquiry details)
- Cookies and similar tracking technologies
Legal Basis for Processing
We process your personal data on the following legal bases under UK GDPR:
- Contract Performance: Processing necessary to fulfil recruitment services and employment contracts
- Legal Obligation: Compliance with FCA regulations, employment law, and right to work checks
- Legitimate Interest: Business operations, fraud prevention, candidate and employer safety, marketing (where you have not objected)
- Consent: Marketing communications, optional equal opportunities monitoring, optional cookies beyond essential ones
How We Use Your Data
For Candidates:
- Matching you with suitable job opportunities
- Conducting interviews and assessments
- Verifying qualifications and FCA registration
- Obtaining references
- Processing payments (if applicable)
- Complying with employment law and right to work requirements
- Sending job alerts and career updates (with your consent)
- Improving our recruitment services
For Employers:
- Presenting suitable candidates for vacancies
- Conducting interviews and assessments
- Processing placements and fees
- Obtaining feedback on candidates
- Complying with employment law
- Improving our services
For Website Visitors:
- Analysing website usage and improving user experience
- Responding to enquiries
- Marketing (where you have opted in)
Who We Share Your Data With
We may share your personal data with:
- Employers: Candidate CVs and information (only with your consent or as part of the recruitment process)
- Candidates: Job descriptions and employer information
- Referees: Contact details provided by you for reference checks
- FCA and Regulatory Bodies: Where legally required
- Right to Work Verification Services: For employment eligibility checks
- IT Service Providers: Cloud storage, email, and website hosting (under data processing agreements)
- Legal and Compliance Advisers: Where necessary for regulatory compliance
- Third-Party Recruiters: Only with your explicit consent
We do not sell your personal data to third parties. All data sharing is subject to strict confidentiality agreements and UK GDPR requirements.
International Data Transfers
We primarily process data within the UK and EU. If we transfer data outside the UK/EU, we ensure appropriate safeguards are in place, including Standard Contractual Clauses or adequacy decisions recognised by the UK government.
Data Retention
We retain personal data for as long as necessary to fulfil the purposes outlined in this policy:
- Candidate Data: 3 years after last contact (unless you request deletion sooner or we have a legal obligation to retain)
- Employer Data: Duration of business relationship plus 3 years
- Website Visitor Data: Up to 2 years (or as per cookie consent)
- Right to Work Records: 2 years after employment ends (legal requirement)
- Equal Opportunities Data: Retained separately and anonymised after 1 year
You can request deletion at any time, subject to legal retention obligations.
Your Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data we hold
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data (subject to legal obligations)
- Restrict Processing: Limit how we use your data
- Data Portability: Receive your data in a portable format
- Object: Opt out of marketing, profiling, or processing based on legitimate interest
- Withdraw Consent: Withdraw consent for any processing at any time
- Lodge a Complaint: File a complaint with the Information Commissioner's Office (ICO)
To exercise any of these rights, contact us at [insert email]. We will respond within 30 days.
Marketing Communications
We may send you marketing emails, job alerts, and updates about our services. You can opt out at any time by:
- Clicking the "unsubscribe" link in any email
- Contacting us directly at [insert email]
- Updating your preferences in your account (if applicable)
For phone and SMS marketing, we will only contact you with your prior consent (PECR compliance).
Cookies and Tracking
Our website uses cookies to improve user experience. We use:
- Essential Cookies: Required for website functionality (no consent needed)
- Analytics Cookies: Google Analytics to understand user behaviour (consent required)
- Marketing Cookies: Retargeting and advertising purposes (consent required)
You can manage cookie preferences via our cookie banner or browser settings. For more information, see our Cookie Policy.
Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction, including:
- Encryption of data in transit and at rest
- Secure password protection and multi-factor authentication
- Regular security audits and vulnerability assessments
- Staff training on data protection and confidentiality
- Restricted access to personal data on a need-to-know basis
However, no system is completely secure. We cannot guarantee absolute security of your data.
Data Breaches
If we discover a data breach that poses a risk to your rights and freedoms, we will notify you and the ICO without undue delay (within 72 hours) as required by UK GDPR, unless the risk is low.
Children's Data
We do not knowingly collect personal data from children under 13. Our services are intended for adults seeking recruitment or employment. If we become aware that we have collected data from a child, we will delete it immediately.
Third-Party Links
Our website may contain links to third-party websites. We are not responsible for their privacy practices. Please review their privacy policies before providing personal data.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or by posting a notice on our website. Your continued use of our services constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or how we handle your personal data, please contact:
Data Protection Officer / Privacy Team
Email: [insert email]
Address: [insert address]
Phone: [insert phone]
Information Commissioner's Office (ICO)
If you wish to lodge a complaint about our data handling practices, you can contact the ICO at:
Website: www.ico.org.uk
Phone: 0303 123 1113