Legal
Privacy Policy
Candidates, referees, client contacts and website visitors
Effective date: 9 September 2026 · Version 1.0
This policy explains how Staffixo Ltd collects and uses personal data in its recruitment activities and through its website. It is designed for candidates, prospective candidates, referees, client and supplier contacts, website visitors and other people who communicate with us. Staffixo processes personal data in accordance with the EU General Data Protection Regulation (EU GDPR) and other applicable data protection laws.
1 Who controls your data
Staffixo Ltd (“Staffixo”, “we”, “us” or “our”) is normally the controller of personal data used to source, assess and introduce candidates and to manage its business relationships. A hiring client will usually be a separate controller for its own recruitment decisions and subsequent employment or engagement. Where Staffixo processes data solely on documented instructions for a client, the relevant contract will allocate controller and processor responsibilities.
This policy is governed by the EU General Data Protection Regulation (EU GDPR) and other applicable data protection laws. It does not describe a client’s independent processing; candidates should read the client’s privacy notice as well.
2 Personal data we collect
| People | Typical data |
|---|---|
| Candidates and prospects | Identity and contact details; CV and work history; education, skills, languages and qualifications; compensation and availability; location and mobility; interview notes and communications; job preferences; right-to-work and identity evidence where required; references; application and placement history; publicly available professional information. |
| Referees and emergency or nominated contacts | Name, role, employer, contact details, relationship to the candidate, and the reference or confirmation provided. |
| Client and supplier contacts | Business contact details, job requirements, communications, contracts, billing and relationship records. |
| Website and communications users | IP address, device and browser data, cookie identifiers, pages and actions, referral data, approximate location, consent choices, enquiry content, email engagement where permitted, and security logs. |
| Compliance and dispute records | Identity checks, consent and objection records, complaints, rights requests, audit logs, suspected fraud or misconduct, and information needed for legal claims. |
We do not ask for information that is irrelevant to recruitment. Please do not include unnecessary sensitive data in a CV or free-text field.
3 Special category and criminal offence data
Some roles or voluntary monitoring may involve health or disability information, racial or ethnic origin, religion, sexual orientation, trade-union membership, biometric identifiers, or other special category data. We process this only where an Article 9 condition and an Article 6 lawful basis apply—for example, explicit consent for genuinely optional diversity monitoring, employment and social-protection obligations, substantial public interest supported by law, or legal claims. Criminal record information is processed only where authorised by law, necessary for the role, and supported by an appropriate policy document when required. Access is restricted and diversity data should be separated from selection decisions where practicable.
4 How we obtain data
- directly from you through applications, forms, calls, interviews, messages and events;
- from job boards, professional networks and other sources where you made information available for career or business purposes;
- from a person who referred you, a former employer, referee, education provider or screening provider;
- from hiring clients, service providers and public registers; and
- automatically through cookies, analytics, server logs and security technologies.
If we obtain candidate data indirectly, we will provide privacy information within the period required by law, ordinarily no later than one month, and sooner if we first contact you or disclose the data. Exceptions apply where the law permits.
5 Why we use data and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Respond to enquiries, register candidates, discuss roles and take steps requested before a contract | Steps before contract and, where applicable, performance of a contract. |
| Source and assess potential candidates; match and introduce them; maintain talent networks; communicate with referees and client contacts | Legitimate interests in operating a fair and effective recruitment business, subject to a documented necessity and balancing assessment. Contract may also apply. |
| Verify information, qualifications, references, identity and right to work | Legal obligation where required; contract steps; and legitimate interests in protecting candidates, clients and recruitment integrity. |
| Operate, secure, troubleshoot and improve the website and services | Legitimate interests in reliable and secure operations. Consent applies to non-essential cookies or tracking where required. |
| Send marketing and measure permitted communications | Consent where electronic-privacy law requires it; otherwise legitimate interests after balancing. Every marketing message will offer a simple opt-out. |
| Meet tax, accounting, regulatory, equality, safeguarding and legal requirements; prevent fraud; establish or defend claims | Legal obligation, legitimate interests, and legal-claims conditions where relevant. |
| Business sale, financing, restructuring or due diligence | Legitimate interests in managing the business, with confidentiality and data-minimisation safeguards. |
Where we rely on legitimate interests, you may request information about the balancing assessment. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing. We will identify any mandatory information and explain the consequences of not providing it; generally, we may be unable to assess or introduce you for a role.
6 Recruitment disclosures
We disclose only information reasonably needed for the relevant purpose. Recipients may include prospective and actual hiring clients; referees and organisations verifying qualifications or work history; screening, identity and right-to-work providers; applicant-tracking, CRM, email, cloud hosting, communications, analytics and security suppliers; professional advisers, insurers, auditors and finance providers; regulators, courts, law enforcement and public authorities; and potential buyers or investors under confidentiality obligations.
Before sending a candidate’s identifiable profile to a hiring client, we will ordinarily discuss the opportunity or otherwise ensure the disclosure is reasonably expected and lawful. Service providers must be bound by appropriate data-protection and confidentiality terms. Some recipients, including hiring clients, act as independent controllers.
7 Cookies analytics and similar technologies
Strictly necessary technologies may operate without consent where permitted. We will ask for consent before using non-essential analytics, advertising or similar technologies where consent is required. The consent control must allow users to reject non-essential technologies as easily as accepting them and to change choices later. We will not set non-essential cookies before valid consent.
8 Marketing
We may send relevant service updates, role alerts or business marketing in accordance with data protection and electronic marketing law. Consent will be obtained where required. In other cases, such as certain business-to-business communications, we may rely on legitimate interests after assessing reasonable expectations. You can opt out at any time by using an unsubscribe link or contacting us. We will retain a minimal suppression record so that we can respect the request.
9 International transfers
Some clients or service providers may process personal data outside the European Economic Area. Before a restricted transfer, we will use a lawful transfer mechanism, such as an adequacy decision or the EU Standard Contractual Clauses, as applicable. We will assess the destination and supplementary safeguards where required. You may request information about the relevant safeguards from our privacy contact.
10 Retention
We keep personal data only as long as reasonably necessary for the purpose collected, including recruitment opportunities, legal and regulatory duties, dispute limitation periods and suppression preferences. We then delete or irreversibly anonymise it. Backups are isolated and removed on their normal cycle.
| Record | Provisional retention rule |
|---|---|
| Unsuccessful candidate and talent-network records | Normally up to 24 months after the last meaningful contact, then review, delete or renew the relationship. Shorter periods may apply where local law or the circumstances require. |
| Placed candidate and client transaction records | Duration of the relationship plus up to 6 years where needed for contracts, tax, accounting or legal claims. |
| References and screening evidence | Only as long as required for the recruitment decision and legal obligations; minimise or delete source documents sooner where a verification record is sufficient. |
| Marketing preferences and suppression list | Active marketing data until opt-out or inactivity review; minimal suppression data retained as necessary to honour the objection. |
| Cookie and analytics data | As stated in the live cookie notice and vendor configuration; use the shortest practical period. |
| Rights requests and complaints | Normally up to 6 years after closure where needed to demonstrate compliance or manage claims. |
These are provisional periods and must be aligned with Staffixo’s documented retention schedule, the type of role, applicable limitation periods and regulatory requirements.
11 Your rights
Subject to conditions and exemptions, you may ask us to:
- confirm whether we process your data and provide access to it;
- correct inaccurate or incomplete data;
- erase data;
- restrict processing;
- provide data you supplied in a portable format where the right applies;
- object to processing based on legitimate interests;
- stop direct marketing at any time;
- withdraw consent; and
- review a qualifying decision made solely by automated means that has legal or similarly significant effects.
We normally respond within one month, although the law permits extensions for complex or numerous requests. We may request proportionate identity evidence. Rights are not absolute, and we will explain any lawful refusal.
12 Automated decisions and profiling
Staffixo may use search, filtering or ranking tools to support recruiters, but will not make a decision based solely on automated processing that produces legal or similarly significant effects unless a lawful exception applies and required safeguards are provided. Material recruitment decisions should involve meaningful human review. If this changes, we will explain the logic, significance, expected consequences and available challenge rights before the processing begins.
13 Security and data breaches
We use proportionate technical and organisational measures designed to protect data, including access controls, authentication, staff confidentiality, supplier review, backups, logging, patching and secure deletion appropriate to the risk. No system is completely secure. We maintain procedures to assess and respond to incidents and will notify regulators and affected people when legally required.
14 Children
Our general recruitment services are intended for adults. We do not knowingly use children’s data for recruitment unless a lawful, age-appropriate service or placement requires it and suitable notices, consent or other safeguards are in place. Contact us if you believe a child’s data was provided inappropriately.
15 Complaints
Please contact us first so we can investigate. You also have the right to complain to the competent EU data protection supervisory authority in the country of your habitual residence, workplace or the alleged infringement. Contacting a regulator does not affect other rights.
16 EU representative
If Staffixo offers services to, or monitors, people in the European Economic Area without an EEA establishment, it may need to appoint an EU representative under Article 27 of the EU GDPR. Representative details will be published here if the requirement applies.
17 Changes and contact
We may update this policy to reflect changes in law, technology, suppliers or services. We will publish the revised date and provide an appropriate notice of material changes.