UK GDPR

Privacy notice

Version 2.4  ·  last updated 11 September 2026

Open as PDF Save the PDF


Version history

We keep the history so that if you relied on an earlier version, you can see exactly what changed and when. Ask at hello@hiringuk.co.uk for a copy of any earlier version.

VersionDateWhat changed
2.411 September 2026Added section 8e, what the legal words actually mean. Three phrases do most of the work in a notice like this and they are usually left undefined. The one worth the space is legitimate interests, because 'we process your data on the basis of our legitimate interests' is a sentence somebody can read and learn nothing from: it sounds like permission another person granted, when it is a decision WE made. So the section says what the weighing is, links the assessment in full rather than offering it on request, and says plainly that you can object to the conclusion.
2.310 September 2026Added section 8d, for the person whose name is on a company contact page. We hold that kind of information in order to decide who to write to about advertising, and while the letters themselves already said who we are and where we got the address, this notice did not mention it at all and neither did the record of processing. The letter was right and the paperwork behind it was missing. Both now say the same thing: published sources only, never bought and never scraped, an address we cannot tell is a business address is not approached at all, and the whole thing stops the same day you say so.
2.29 September 2026Added section 8c, what happens to your data if this business is sold or stops trading. Most notices deal with it in one sentence that promises nothing. This one says a buyer must take the promises with the data, that a candidate list will never be sold separately from the business in a sale or an insolvency, that if the business simply stops the data is erased rather than left on a server, and that you are told before any of it takes effect rather than after.
2.19 September 2026Published the record of processing activities that Article 30 asks for, on the compliance page: every purpose, whose data, what data, the lawful basis with its article, who else sees it, how long it is kept and what protects it. It reads its retention figures from the same constants the deletion sweep uses, so it cannot describe a system that no longer exists.
2.07 September 2026Section 3a rewritten around the do not email list. Pressing stop now switches off every alert on that address rather than the one it was pressed from, and adds the address to a list checked at the moment of sending, so a later sign up or a future mailing cannot reach somebody who has said stop. Says plainly that a reply saying stop counts the same as the link, that a person may stop marketing only or everything, and that the do not email entry is the one record kept after an erasure, because deleting it would make an erased person contactable again.
1.96 September 2026Added section 2b, the anonymous card on the available now list. It is a separate purpose with its own consent, so it is described separately: what a card may show, the complete list of what it may never show, that special category data is refused outright, that an enquiry from an employer does not identify anybody and that no detail is passed on without a fresh yes to that employer and that role, and that a card dies with the CV it belongs to.
1.81 September 2026Added a ten line summary at the top, because a notice nobody reads to the end protects nobody. Published dpo@hiringuk.co.uk as the data protection address and explained why the role is named Data Protection Lead rather than Officer: a voluntary DPO carries the full statutory duties, and under Article 38(6) the person who decides how data is processed cannot hold the role. Added what we do not do in recruitment terms (no online sourcing, no AI sifting, no vetting), which is what the Information Commissioner's recruitment guidance asks a board to be clear about, and stated the six month rule for inactive accounts in the retention table's first row.
1.728 August 2026The consent wording for keeping a CV on file is now quoted in full, rendered from the same place in our software as the live tick box, so the notice and the form cannot say different things.
1.628 August 2026The special category wording is now written once in the code and rendered identically into this notice, the candidate data policy and the employer terms of business, so the three documents cannot say different things. The categories are named in the sentence itself.
1.528 August 2026Added a plain summary of the security position, named the principle of least privilege for both software and people, described the access and deletion logs and the backup arrangements precisely, and set out what every processor contract requires, with a named list available on request.
1.428 August 2026Strengthened the special category data section: what it is, why it turns up on a job board, that we actively discourage it and do not need it, that it is processed only on explicit consent under Article 9(2)(a) and only for that application, and that asking for a reasonable adjustment is a separate thing a candidate should feel able to do.
1.328 August 2026Named the processors by role, set out the technical and organisational measures in full, confirmed data stays in the UK or EEA and named the transfer mechanism, sharpened the breach procedure, added a plain statement that there is no automated decision making, explained each right, and named the director as the responsible person.
1.228 August 2026Added the talent pool: what we keep with express consent, for how long, and how to withdraw. Added first party measurement without cookies.
1.126 August 2026Added the statutory right to complain to us under section 164A, job alert consent, minimum age, breach notification and processors.
1.025 August 2026First published.