Recruitment Privacy Notice

Effective Date: 17 July 2026 – version 1

In this notice, “Accesa”, “we”, “us” or “our” means Accesa (UK) LIMITED (Accesa UK) and Accesa IT Systems SRL (AITS), where they act as joint controllers for Accesa UK recruitment.

This privacy notice explains how we collect, use, share and protect your personal data when you apply for, or are considered for, a role with Accesa UK. It is prepared in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. This notice sets out how we handle your personal data responsibly throughout the recruitment process. We encourage you to read it carefully so you understand how your information is used and protected, and how you can exercise your rights.

If you have any questions about this notice or how we handle your personal data, please contact us using the details below.

1. Who We Are and Who Is Responsible for Your Data

Who we are

Contact us

Accesa UK is Accesa (UK) LIMITED, a company registered in England and Wales (company number 17314155), with registered office at Riverside East, 2 Millsands, Sheffield, South Yorkshire, United Kingdom, S3 8DT, part of the Accesa Group.

AITS is Accesa IT Systems SRL, a company incorporated under the laws of Romania (company number 32930567), with registered office at Constanta 12, Platinia Office, 400158 Cluj-Napoca, Romania.

For recruitment, Accesa UK and AITS act as joint controllers of your personal data. This means they jointly determine why and how your personal data is processed for Accesa UK recruitment. The main points of the joint-controller arrangement are explained in Section 2.

If you have any questions about this notice, or wish to exercise your data protection rights, please contact our UK Privacy Contact, who will coordinate a response with AITS where needed. You may exercise your data protection rights against either Accesa UK or AITS. Using UK Privacy Contact does not limit your right to contact either joint controller directly.

For UK candidates, your single point of contact for privacy queries and to exercise your rights is the

UK Privacy Contact: Email: privacy.contact@accesa.co.uk

Postal address: Riverside East, 2 Millsands, Sheffield, South Yorkshire, United Kingdom, S3 8DT

Joint controller - Accesa IT Systems SRL (AITS) - reachable through the UK Privacy Contact above as part of the joint-controller arrangement.

2. Joint Controllers — Essence of the Arrangement

Article 26(2) UK GDPR requires us to make available to you the essence of the joint-controller arrangement. In summary:

  • Accesa UK is the UK-facing party. It is responsible for the UK role, the relationship with you as a UK candidate, and the UK contracting position.

  • AITS provides and runs the recruitment systems, tools, sourcing methods, shortlisting and evaluation processes used for the UK role, and jointly sets the purposes and essential means of the processing.

  • Both parties are accountable for protecting your data. Regardless of this internal split, you may exercise your rights against, and contact, either controller. For practical handling, you may use the UK Privacy Contact in Section 1, who will coordinate with AITS where needed. Using UK Privacy Contact does not limit your right to contact either joint controller directly.

3. Who This Privacy Notice Covers

This Recruitment Privacy Notice applies to individuals whose personal data we process in connection with recruitment for Accesa UK roles. This includes job applicants and candidates who apply to us directly, and individuals we identify and approach as potential candidates through professional networking platforms such as LinkedIn or other professional sources (see Section 4).

We process your personal data for recruitment purposes — to identify suitable candidates, to evaluate and assess your suitability for a role, to communicate with you during the process, and to meet our legal and accountability obligations. The purposes and the lawful bases we rely on are set out in Section 5.

This notice covers recruitment for Accesa UK. Where a role is filled, the processing of your personal data as an employee or worker will be governed by a separate employee privacy notice provided to you at that stage.

If you have any questions or concerns about how we handle your personal data, or if you wish to exercise your rights, please contact our UK Privacy Contact using the details in Section 1.

4. What Personal Data Do We Collect

How We Collect Your Data

We collect your personal data through different channels and tools to support a transparent and effective recruitment process. This includes both direct and indirect collection methods.

Direct Collection

  • Data you provide: We collect information directly from you when you apply for a position, participate in recruitment discussions, interviews or assessments, or submit documents. This includes details such as your name, contact information, professional background and any other relevant information or documents you choose to share as part of the recruitment process.

Indirect Collection

  • Professional and publicly available sources: We may obtain publicly available information relevant to the recruitment process from professional networking platforms, such as LinkedIn, business websites, professional registers or other role-relevant professional sources. This helps us identify potential candidates and verify or complement role-relevant information. We do not carry out general searches of candidates’ personal social-media profiles. Any review of online information is limited to professional or role-relevant sources and is necessary and proportionate for the recruitment process.

  • Recruitment Supporting Tools: We use recruitment tools and integrations to identify, communicate, engage with and manage potential candidates. Our recruitment platform securely processes and manages your data throughout the recruitment stages.

  • Data from Other Third Parties: Where relevant to the role, we may obtain information from third parties such as former employers, referees, educational institutions, professional bodies or recruitment providers. We will let you know before we approach referees.

When we collect your personal data indirectly, we will tell you the source it came from, where possible, and whether it came from a publicly accessible source. We will provide this privacy notice within a reasonable period after obtaining your personal data and at the latest within one month; or, if we use your data to contact you, no later than our first communication with you; or, if we disclose your data to anyone else, no later than that disclosure — whichever is earliest. An exception may apply where permitted under UK data protection law.

If you provide personal information about another person, such as a referee or referral contact, please make sure you are authorised to do so and that the information you provide is accurate and relevant. We may use that information only for recruitment-related purposes, such as contacting the referee or assessing the referral.

Types of Personal Data We Process

During the recruitment process, we collect and process personal data necessary to evaluate your qualifications and suitability for a position. The specific data we collect may vary depending on the nature of the role, the recruitment stage and the requirements of the recruitment process.

We handle this data in accordance with the UK GDPR, the Data Protection Act 2018 and other applicable UK law. The main categories of personal data we may process include:

Identification information

Name, surname, date of birth, nationality, citizenship, home address, or other identification data included in your CV, application or recruitment-related forms, where relevant to the role or recruitment stage.

Contact details

Email address, phone number, correspondence address and other relevant contact information.

Signature and photo

Signatures and photos included in recruitment-related documents, where you choose to provide them or where they are necessary for a specific recruitment step.

Demographic data

Information such as age or gender, where voluntarily provided by you, included in documents you provide, or necessary for a specific lawful recruitment purpose. We do not request this information unless it is relevant and proportionate for the recruitment process or required by law.

Data on professional experience

Information related to your occupation, previous employment, job titles, responsibilities, projects, achievements and professional profile.

Education data and

professional certifications

Academic qualifications, attended institutions, diplomas, professional certifications, licences, accreditations and training details.

Professional skills and competences

Details about language proficiency, technical skills, and competencies relevant to the role.

Remuneration Data

Information on expected salary, bonuses, benefits and compensation expectations, where relevant to the role or offer process.

Communication Records

Records of email correspondence, messages, interview scheduling, meeting notes and other recruitment-related communications exchanged with you or with recruitment-related third parties, such as recruitment providers, referees or former employers.

Data resulting from video recordings

Voice and image data, only in limited cases where video recordings are made during online interviews and only where you have been informed and have agreed to the recording.

Interview transcripts and summaries

Transcripts or summaries of online interviews or recruitment meetings, including those generated by AI-assisted tools (for example, automated transcripts, meeting summaries or recap features), only where you have been informed.

Candidate evaluation data and assessment results

Interview notes, assessments, shortlisting records, evaluation comments, results and scores from skills, technical or coding assessments, where used for the role, selection decisions and results from role-relevant verification or pre-employment checks, prepared or collected by authorised recruitment personnel.

References

Professional information and employment-history confirmation obtained from referees or former employers, where relevant to the role and recruitment stage, and where you have been informed. We will normally contact referees only after you have provided their details or after we have told you that reference checks will be carried out.

Data on potential

conflicts of interest

Information about possible kinship, affinity or other relationships with our employees, management or business partners, only where this is relevant and necessary to assess a potential conflict of interest for the specific role.

Regulatory data

Data related to certifications, licenses, permits, accreditations, professional restrictions or industry-specific qualifications required for the position you applied for.

Complaints, requests and dispute records

Information related to complaints, data protection requests, queries, disputes or legal claims that may arise during or in connection with the recruitment process.

Audit and compliance data

Records needed to demonstrate that our recruitment process is fair, lawful and accountable, such as access logs, decision records, approval records and evidence of recruitment-process checks.

IT Usage and communication metadata

Information such as server logs, timestamps, email delivery logs, IP addresses and security metadata collected to secure our communication channels, recruitment systems, network and infrastructure, and to respond to security incidents or data breaches.

AI-assisted or tool-generated recruitment information

Where AI-assisted or automated features are enabled, we may process tool-generated outputs such as candidate search results, suggested matches, profile or CV summaries, workflow status, interview transcripts, meeting summaries or assessment-support information. These outputs support human review (see Section 7).

Other relevant data

Any additional personal data you voluntarily provide during interviews, assessments or correspondence, where relevant to your application or to address your requests or queries.

Special category data and Criminal-offence data

We process special category data and criminal-offence data only where strictly necessary, lawful and relevant for a specific role or recruitment stage (for example, health/disability, professional-restriction or criminal-offence information). We explain the categories and the conditions we rely on in Section 5.

We do not request special category data or criminal-offence data at the initial application stage unless it is necessary and justified for the specific role. Where pre-employment vetting or verification is required, we will explain what information is needed, why it is needed, who will have access to it, the process used, the relevant sources, and how long the information will be kept.

Why We Need Your Data

We request personal data from candidates to support recruitment, competence evaluation, communication, verification, compliance checks and, where relevant, steps needed before entering into an employment or worker relationship.

Some personal data is necessary to assess your application or to take steps before entering into a contract with you. Some information may be required by law or by role-specific regulatory requirements. Other information is optional.

If you do not provide information that is necessary for the recruitment process, we may not be able to assess your application, progress you to the next stage, make an offer, or complete required checks. Where information is optional, choosing not to provide it will not affect your application unless the information is necessary for the specific role or recruitment stage. We ask candidates to provide accurate and relevant information so that we can assess applications fairly and maintain reliable recruitment records.

5. Why and How We Use Your Information

We process your personal data in accordance with the UK GDPR, the Data Protection Act 2018, and other applicable UK law, observing the principles of transparency, fairness and data minimisation.

The table below sets out why we process your personal data and the lawful basis for each purpose under Article 6 UK GDPR.

Where we process special category data, we also rely on a condition under Article 9 UK GDPR and, where required, a condition under Schedule 1 of the Data Protection Act 2018. Where we process criminal-offence data, we rely on a condition under Article 10 UK GDPR and Schedule 1 of the Data Protection Act 2018.

For most recruitment activity before any offer is made, we rely on our legitimate interests in identifying, assessing and communicating with suitable candidates, balanced against your rights. We rely on taking steps prior to entering into an employment or worker contract where the processing is necessary because you apply or ask us to consider you for a role, and especially at the offer and onboarding stage. We rely on consent only for specific, optional activities, which you can withdraw at any time.

Purpose

Details on the Purpose

Legal Base

Identifying and assessing candidates

Evaluating candidates’ skills, qualifications, professional experience and suitability for Accesa UK roles.

Legitimate interests, where we assess sourced candidates or manage recruitment fairly and efficiently (Art. 6(1)(f)).

Steps prior to entering into an employment contract, where you apply or ask us to consider you for a role. (Art. 6(1)(b)).

Sourcing and candidate outreach

Identifying potential candidates through professional sources such as LinkedIn, LinkedIn Recruiter or other role-relevant professional sources, and contacting individuals who may be suitable for open Accesa UK roles. When we contact you directly through LinkedIn messaging, InMail or similar electronic communication channels, we also apply applicable UK electronic communications and direct-marketing rules.

Legitimate interests — identifying and approaching suitable candidates for Accesa UK roles and managing recruitment for the UK business - Art. 6(1)(f)

Candidate matching and recruitment-process support

Using recruitment tools, search functions, matching features, candidate-management functions or AI-assisted features to support human review of candidate suitability against role requirements. These tools may help with search, matching, profile or CV summarisation, workflow management or assessment support. See Sections 6 and 7.

Legitimate interests — improving recruitment efficiency, consistency and candidate management, while keeping recruitment decisions subject to human review. Art. 6(1)(f).

Maintaining data accuracy

Updating, checking or synchronising role-relevant candidate information, including by comparing information provided by you with professional profile information or our recruitment-system records.

Legitimate interests — maintaining accurate and relevant recruitment records. Art. 6(1)(f).

Conducting interviews and assessments

Arranging, conducting and documenting interviews, assessments and recruitment discussions.

Legitimate interests — assessing suitability and managing a fair recruitment process. Art. 6(1)(f)

Steps prior to entering into an employment or worker contract. Art. 6(1)(b)

Competence evaluation

Assessing hard skills, soft skills, qualifications, experience and role-specific competencies against the requirements of the role.

Legitimate interests — selecting suitable candidates and maintaining recruitment quality. Art. 6(1)(f)

Steps prior to entering into an employment or worker contract. Art. 6(1)(b)

Interview panels / multi-interviewer assessments

Coordinating and documenting multi-interviewer assessments and notes to support fair, consistent and role-relevant evaluation.

Legitimate interests — ensuring a fair, consistent and effective recruitment process. Art. 6(1)(f)

Steps prior to entering into an employment or worker contract may also apply where the assessment is part of the application process. Art. 6(1)(b)

Verification of role requirements

Verifying qualifications, certifications, permits, professional status, right-to-work information or other role-specific or eligibility requirements, where relevant and proportionate before employment or worker engagement.

Legitimate interests — verifying candidate suitability, recruitment integrity and risk management. Art. 6(1)(f).

Legal obligation applies only where a specific UK legal or regulatory obligation requires the check (for example, right-to-work checks under UK immigration law). Art. 6(1)(c)

Steps prior to entering into an employment or worker contract. Art. 6(1)(b) - after an accepted offer.

Obtaining and verifying References

Verifying professional history, employment dates, role-related experience or qualifications with referees or former employers, where relevant and proportionate for the role and recruitment stage.

Legitimate interests — verifying candidate suitability, recruitment integrity and risk management. Art. 6(1)(f)

Steps prior to entering into an employment or worker contract may also apply where reference checks are part of the pre-contract process. Art. 6(1)(b)

Legal obligation applies only where a specific UK legal or regulatory requirement requires the check for the relevant role. Art. 6(1)(c)

Communication and engagement during recruitment

Communicating with you about the recruitment process, including interview invitations, process updates, feedback, scheduling and messages sent by email, phone, LinkedIn messaging or InMail.

Legitimate interests — managing recruitment communications and candidate engagement. Art. 6(1)(f)

Responding to your inquiries

Addressing questions, inquiries or requests you raise about the recruitment process.

Legitimate interests — responding to candidate communications and managing recruitment fairly. Art. 6(1)(f)

Steps prior to entering into an employment or worker contract. Art. 6(1)(b) - after an accepted offer.

Talent Pool Expansion / Future opportunities

Keeping your details to consider you for future Accesa UK roles, where this is separate from your current application, and contacting you about relevant future opportunities where you have opted in.

Consent (opt-in) and you can withdraw at any time. Art. 6(1)(a)

Interview recordings

Recording online interviews, where recordings are used instead of written notes or for internal review.

Consent, where recording is optional and you are given a genuine choice. Art. 6(1)(a)

If you do not agree to recording, we will use another assessment method where possible.

Employment documentation after offer

Preparing and managing offer letters, employment or worker contract documentation and related pre-employment administration after you have accepted an offer

Steps prior to entering into an employment or worker contract. Art. 6(1)(b)

Legal obligation may apply where specific employment, immigration, tax or regulatory checks are legally required.Art. 6(1)(c)

Remuneration and offer discussion

Discussing salary expectations, benefits and compensation package information where relevant to the role or offer process.

Legitimate interests may apply to workforce planning and offer management. Art. 6(1)(f)

Steps prior to entering into an employment or worker contract. Art. 6(1)(b) – after an accepted offer.

Recruitment records and accountability

Keeping recruitment records to document the recruitment process, demonstrate fairness, support accountability and manage queries, complaints or disputes.

Legitimate interests — maintaining fair, accountable and defensible recruitment records. Art. 6(1)(f)

Legal obligation may apply where records are needed to comply with UK data protection, employment, tax, immigration or other legal obligations. Art. 6(1)(c)

Conflict-of-interest assessment

Assessing potential conflicts of interest between candidates and Accesa UK, AITS, employees, management, clients, suppliers or business partners, where relevant to the role.

Legitimate interests — protecting recruitment integrity, business ethics, client trust and risk management. Art. 6(1)(f)

Handling recruitment complaints

Handling complaints or concerns about the recruitment process, including documenting the complaint and the response.

Legitimate interests may apply to handling complaints, maintaining recruitment accountability, managing recruitment fairly and keeping appropriate accountability records. Art. 6(1)(f).

Legal obligation may apply where processing is required by UK law, a court, regulator or competent authority. Art. 6(1)(c)

Handling data protection requests or complaints

Responding to candidate data protection rights requests or complaints and keeping records of how requests were handled.

Legal obligation may apply where processing is required by UK data protection law. Art. 6(1)(c)

Legitimate interests may apply to keeping appropriate accountability records. Art. 6(1)(f).

Dispute resolution and legal claims

Handling disputes, investigations or legal proceedings connected with the recruitment process, including establishing, exercising or defending legal rights.

Legitimate interests in handling disputes and protecting our legal rights. Art. 6(1)(f)

Legal obligation where required by UK law, a court, regulator or authority. Art. 6(1)(c)

Candidate experience and process automation

Using our recruitment-system functions to track candidate status, manage workflows, automate scheduling or reminders, and improve recruitment experience for candidates and recruiters.

Legitimate interests — managing recruitment efficiently and consistently. Art. 6(1)(f)

Recruitment analytics and process improvement

Using aggregated or minimised recruitment data to analyse recruitment effectiveness, candidate recruitment pipeline trends, process duration and outcomes. We do not use this purpose to make decisions about individual candidates.

Legitimate interests — improving recruitment processes, planning recruitment resources and monitoring process effectiveness. Art. 6(1)(f)

Security monitoring, fraud prevention and incident investigation

Processing IT usage logs, access records, communication metadata and security records to protect recruitment systems, prevent fraud, investigate incidents and respond to data breaches.

Legitimate interests — protecting systems, data and business operations. Art. 6(1)(f)

Legal obligation may apply where processing is necessary to comply with UK data protection security or data breach response duties.Art. 6(1)(c) and Articles 32–34 UK GDPR.

Internal / external audit and compliance monitoring

Audits and compliance checks relating to recruitment processes, privacy compliance, information security and accountability.

Legitimate interests — monitoring compliance and accountability. Art. 6(1)(f)

Legal obligation applies where a specific UK legal, regulatory, court or authority requirement requires the audit or record. Art. 6(1)(c)

Risk management and control activities

Assessing and managing recruitment-related risks, including privacy, information security, legal, regulatory and operational risks.

Legitimate interests — managing risk and maintaining compliant recruitment operations. Art. 6(1)(f)

Legal obligation applies only where a specific UK legal or regulatory duty requires the processing. Art. 6(1)(c)

The specific purposes and lawful bases may vary depending on the role and the stage of the recruitment process.

  • Where we rely on legitimate interests, we balance our interests against your rights, freedoms and reasonable expectations and carry out a legitimate interest assessment.

  • Where we rely on consent, this applies only to processing that is genuinely optional and where you can withdraw your consent without affecting processing already carried out before withdrawal.

Special Category Data and Criminal-Offence Data (where applicable to the role)

We process special category data or criminal-offence data only where strictly necessary, lawful and relevant to the specific role or recruitment stage.

This may include:

  • health or disability information, for example to consider reasonable adjustments during recruitment or a role-specific fitness-to-work check.

  • criminal-record checks or related criminal-offence information, only where necessary and permitted for the specific role; and

  • professional restrictions, licence or accreditation status, regulatory status or disciplinary information, where this is necessary for the role and relevant to role suitability, legal eligibility, professional integrity or risk management.

We do not request this data at the initial application stage unless it is necessary and justified for the specific role. Where verification or vetting is required, we will carry it out at the appropriate stage of the recruitment process and only to the extent necessary.

For this processing, we rely on the applicable Article 6 UK GDPR lawful basis, depending on the specific case:

  • Article 6(1)(c) UK GDPR — legal obligation, where processing is necessary to comply with employment-law obligations or rights, or with a specific UK legal or regulatory requirement applicable to the role; or

  • Article 6(1)(f) UK GDPR — legitimate interests, where processing is necessary and proportionate for role suitability, recruitment integrity, security or risk management and is permitted by law.

For special category data, we rely on the relevant Article 9 UK GDPR condition and, where required, the relevant DPA 2018 Schedule 1 condition. This may include:

  • Article 9(2)(b) UK GDPR and DPA 2018 Schedule 1, Part 1, paragraph 1, where processing is necessary for employment-law obligations or rights; or

  • Article 9(2)(h) UK GDPR and DPA 2018 Schedule 1, Part 1, paragraph 2, where a role-specific fitness-to-work or occupational-health assessment is carried out by, or under the responsibility of, a professional subject to confidentiality.

For criminal-offence data, Article 10 UK GDPR applies. Where we are not processing under official authority, we rely on a relevant DPA 2018 Schedule 1 condition, such as the employment condition or preventing or detecting unlawful acts, depending on the specific case.

Before processing special category data or criminal-offence data, we identify and document the applicable Article 6 lawful basis and the relevant Article 9 or Article 10 / DPA 2018 Schedule 1 condition. Where required, we also put in place an appropriate policy document.

6. Using Third-Party Services and Tools

To manage our recruitment process effectively and securely, we use selected third-party services, platforms and tools. These tools help us organise applications, communicate with candidates, identify potential candidates, coordinate interviews, manage recruitment workflows and protect recruitment data.

The tools we use may include the following categories:

  • Recruitment management platforms and applicant tracking systems We use recruitment platforms and applicant tracking systems to organise and manage candidate information, applications, communications, interview scheduling, assessment feedback and recruitment-stage records. These platforms enable secure communication, scheduling, and feedback collection, helping us maintain an efficient and structured recruitment process.

  • Professional Networking and Outreach Tools We may use professional networking platforms and recruitment outreach tools, such as LinkedIn or similar professional platforms, to identify potential candidates, review role-relevant professional profile information, and contact candidates who may be suitable for Accesa UK roles.

  • Technical assessment and skills evaluation tools Where relevant to the role, we may use technical assessment, coding-test, skills-assessment or candidate-evaluation platforms to support role-relevant assessment. These tools support human review (see Section 7).

  • Cloud services We use secure cloud platforms to store, manage and access recruitment data while maintaining data integrity and security.

  • Productivity and Collaboration Tools Our teams use productivity tools, such as email platforms, document-sharing, project management and video conferencing applications to collaborate internally and communicate with you. These tools facilitate internal collaboration and effective communication with candidates, regardless of their location.

  • Communication Platforms We use secure messaging and video conferencing tools to maintain ongoing communication with candidates, including interview scheduling, feedback provision, and follow-up messages.

  • Tools with AI-assisted features We use these AI-assisted features only to support our recruiters; a member of our team is always involved in decisions that affect you. We explain our approach to automated processing and profiling in Section 7.

We Use These Tools to

  • run an efficient, secure recruitment process and communicate with you and within our team.

  • identify and engage suitable candidates beyond direct applicants.

  • manage assessments, scheduling, workflows and recruitment records, keeping decisions subject to human review; and

  • protect recruitment systems, data and communication channels.

In some cases, using these tools requires us to share limited personal data with third-party providers, such as your name, contact details, professional profile information, application details, interview scheduling information, assessment information, communication records or technical metadata, depending on the tool and recruitment stage.

Where third-party providers process personal data on our behalf, we use them under appropriate data protection contracts, including Article 28 UK GDPR processor terms where required. These contracts require providers to process personal data only on documented instructions, apply appropriate confidentiality and security measures, assist with data protection obligations, and use sub-processors only under appropriate controls.

Some third-party platforms may also process personal data as independent controllers for their own platform, account, security, analytics or service-improvement purposes. Where this applies, their own privacy notice may also apply to that separate processing.

We assess third-party tools and providers before use and apply appropriate controls, including access controls, security measures, contractual safeguards and, where relevant, data protection impact assessment or AI-risk review. We only share candidate data with third-party providers where this is necessary and proportionate for recruitment, security, compliance or related operational purposes.

As joint controllers, Accesa UK and AITS remain responsible for your personal data. Where any of these tools involves a transfer of personal data outside the UK, we apply a recognised UK transfer mechanism, as explained in Section 9 (International Data Transfers).

7. Automated Decision-Making and Profiling

Automated Decision-Making

In our recruitment process, we may use AI-assisted recruitment solutions and other automated features to support recruitment administration, organising applications, candidate matching suggestions, assessment support, workflow management and communication. These tools may help us streamline workflows and assess role-relevant information, but they support our recruiters; they do not make recruitment decisions.

We do not use AI tools or automated systems to make final recruitment decisions without human involvement. We also do not use AI-assisted tools to make solely automated decisions about candidates that produce legal or similarly significant effects, such as automatically rejecting a candidate or making a final hiring decision without meaningful human review.

Where we use AI-assisted tools to support assessment, they analyse role-relevant information, such as skills and experience, to produce suggestions, matches or scores that help our recruiters. These outputs support, but do not determine, decisions about you. We do not use profiling to infer special category data for recruitment decisions.

Profiling and automated analysis

We may use limited automated analysis or profiling features during recruitment where this is relevant and proportionate for the recruitment process. These activities may include:

Candidate matching and recruitment support

We may use recruitment tools to help identify role-relevant skills, experience, qualifications or professional background and to support matching against role requirements. These tools support human review.

Security monitoring

We may analyse technical data, such as access logs, IP addresses, device information or communication metadata, to identify and mitigate security threats and protect our IT systems, tools and data during the recruitment process.

Candidate preferences and communication support

Where relevant, we may use information you provide, such as communication preferences or survey feedback, to manage communications and improve your recruitment experience.

Soft skills and competency profiling

We may use assessment and feedback tools to support the evaluation of technical and professional competencies, soft skills and role-specific requirements. These insights are always combined with human review to assess a candidate's suitability for a role.

Role-specific risk profiling (only where applicable to the role)

For certain roles — for example, regulated, security-sensitive or trust-sensitive positions — we may profile candidate information to assess role-relevant risks, such as compliance, integrity or suitability requirements that apply specifically to that role. We carry out this profiling only where it is necessary and proportionate for the specific role, always with human review, and we will make clear where such checks apply. We do not carry out this profiling for general commercial roles.

We also analyse recruitment data at an aggregate level to measure the effectiveness and timeliness of our recruitment process and to improve it. This aggregated analysis does not influence decisions about individual candidates, and when preferences like communication options are considered, they are used solely to manage our interactions with you.

We use automated tools, profiling or automated analysis only where relevant to support recruitment administration, candidate assessment, recruitment quality, system security, communication and process efficiency.

Purpose and benefits of profiling

Our profiling activities are aimed at:

  • supporting a secure recruitment process by identifying and managing security threats.

  • supporting fair and consistent assessment by combining tool-assisted analysis with human review.

  • where a specific role requires it, supporting role-relevant risk and suitability assessment, with human review.

  • improving our recruitment process through aggregate analysis; and

  • managing our communications with you appropriately.

Your Rights Regarding Automated Decisions and Profiling

We carry out these activities in accordance with UK data protection law and apply appropriate safeguards.

You have the right to object to profiling based on our legitimate interests. We do not currently use solely automated decisions that produce legal or similarly significant effects in the recruitment process. If this changes for a specific role or process, we will inform you and apply the safeguards required by Articles 22A–22D UK GDPR.

8. Who Do We Share Your Data With

To manage our business and fulfil our legal and contractual obligations, we may need to share your personal data with others. We only share your information when necessary and take steps to ensure your data is handled securely and confidentially.

The following are examples of possible categories of recipients of your data:

Group Entities and Affiliates

For UK recruitment, Accesa UK and AITS act as joint controllers, as explained in this Privacy Notice. We share your data with AITS and, where necessary, with other Accesa entities involved in recruitment support, HR support, IT, information security, administration, management, governance or related internal support activities.

Third-Party Providers

These are companies that support our recruitment and business operations. They provide services like technical support, email hosting, cloud storage, productivity tools, communication platforms (such as video conferencing), AI-powered solutions, security and risk management tools, data analysis, and IT support. When these providers process personal data on our behalf, they act as processors under Article 28 UK GDPR. They process your personal data only on our documented instructions and are contractually required to apply appropriate confidentiality and security measures. Some third-party platforms may also process personal data as independent controllers for their own platform, account, security, analytics or service-improvement purposes, as explained in Section 6.

Clients and

Business Partners

We do not routinely share candidate data with clients or business partners. In limited cases, we may share relevant candidate information with a client or business partner where this is necessary for a specific role, for example where the role is client-facing, assignment-based, regulated, security-sensitive, or subject to role-specific client approval or eligibility requirements. We share only the information that is necessary for that purpose and apply data minimisation and confidentiality controls.

Professional Advisors

We work with lawyers, accountants, auditors, consultants and other professionals who may need access to your data to provide their services. They help us comply with legal requirements and offer expert advice, ensuring our business runs effectively and lawfully.

Public Authorities

We may be required to share your data with law enforcement, regulators, or government authorities to comply with legal obligations, conduct investigations, or fulfil reporting requirements.

Business Transfers

If our company undergoes a merger, acquisition, sale, or other significant organisational change, your personal data may be transferred to the new entity or owners as part of the transition.

Other Authorised Recipients

We may share your data with other recipients only where you have authorised the sharing, where the sharing is required by law, or where it is necessary and proportionate for the recruitment purposes described in this Privacy Notice.

9. International Data Transfers (outside UK)

In some cases, we transfer or make your personal data accessible outside the United Kingdom.

This may include access by AITS or other Accesa entities involved in recruitment support, and by third-party service providers used for recruitment, IT, cloud, communication, security, assessment or productivity services.

When we make a restricted transfer of personal data outside the UK, we apply a recognised UK transfer mechanism in accordance with the UK GDPR, so that your personal data continues to receive an appropriate level of protection. Depending on the destination country and the recipient, this may include:

  • UK adequacy regulations. Where the destination country, territory, sector or international organisation is covered by UK adequacy regulations, we may transfer personal data without putting in place additional transfer safeguards.

  • UK Extension to the EU-US Data Privacy Framework / UK-US Data Bridge. Where we transfer personal data to a US recipient that is certified under the UK Extension to the EU-US Data Privacy Framework and the certification covers the relevant type of personal data, we may rely on that UK adequacy mechanism. Our recruitment platform and professional networking provider are certified under this framework.

  • UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses. Where there is no applicable UK adequacy regulation or UK-US Data Bridge coverage, we may use the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner's Office under the Data Protection Act 2018, or another transfer safeguard recognised under the UK GDPR. Where required, we also carry out a transfer risk assessment and apply any additional safeguards needed.

In our recruitment process, your personal data is transferred outside the UK in two main ways.

First, because Accesa UK and AITS act as joint controllers, your personal data is transferred to AITS in Romania, which operates the recruitment systems and processes. Romania is in the European Economic Area, which benefits from UK adequacy regulations, so this transfer is made on the basis of UK adequacy.

Second, your personal data may be transferred to providers of our recruitment platform and professional networking and sourcing tools, including in the United States; these transfers are protected primarily by the UK Extension to the EU–US Data Privacy Framework, with the UK Addendum to the EU Standard Contractual Clauses applied as a contractual safeguard where relevant.

You can ask us for more information about how we protect your personal data when it is transferred outside the UK, including a copy of, or access to, the relevant safeguard. To do so, please contact the UK Privacy Contact (Section 1).

10. How Long Do We Keep Your Data

We keep your personal data only for as long as necessary for the purposes set out in this privacy notice, to comply with our legal obligations, and to support our legitimate business needs.

Where there is no fixed statutory retention period, we determine how long to keep your data based on the purpose of the processing, type of data, the recruitment stage, any applicable legal or limitation periods, and the principle of data minimisation. Throughout the retention period, we apply appropriate measures to keep your personal data secure and confidential.

The main retention periods we apply for recruitment activities:

  • For unsuccessful candidates, we typically keep your recruitment data for up to 6 months after the end of the recruitment process, to deal with any follow-up queries, feedback or complaints and to demonstrate a fair and accountable process. We keep it for longer only where one of the specific situations below applies.

  • If you are successful and accept an offer, the recruitment data that remains relevant to your employment or worker relationship is transferred to your employee record and retained in accordance with the separate employee privacy notice. Recruitment information that is no longer needed will be securely deleted or anonymised.

  • When any pre-employment or background-check is carried out, we keep only a record of whether the check was completed and its outcome, and we securely destroy the underlying check data as soon as possible and in any event within 6 months of the end of the recruitment process.

  • Talent pool / future opportunities. If you have opted in, we keep your details for up to 12 months to consider you for future roles, after which we delete them or ask whether you wish to remain in the talent pool. You can withdraw your consent at any time.

  • Security, fraud prevention and incident investigation. Routine security and IT-usage logs (such as access logs and communication metadata) are kept for up to 12 months. If a data breach or security incident occurs and action is taken, we keep the related incident records for up to 6 years to investigate, respond to and defend against claims, having regard to the Limitation Act 1980 and our obligations under Articles 32–34 UK GDPR.

  • Disputes and legal claims. In cases where there is an actual or anticipated dispute, complaint or legal claim involving your personal data, we keep the relevant data for as long as necessary to establish, exercise or defend legal rights, having regard to the applicable limitation periods under the Limitation Act 1980 (generally up to 6 years).

  • Where any other UK law, regulatory requirement, court, regulator or competent authority requires us to keep data for a longer or shorter period, we apply that requirement.

  • If you exercise your rights under the UK GDPR and the Data Protection Act 2018, we keep a record of your request and how we handled it, as part of demonstrating our compliance. Where you exercise your right to restrict processing, we securely retain the restricted data only for the duration of the restriction.

What Happens When the Retention Period Ends?

When the retention period ends, we securely delete or anonymise your personal data in accordance with UK data protection law, so that it is no longer accessible or attributable to you. Where we destroy records, we do so securely and in a manner appropriate to the sensitivity of the data.

11. How We Keep Your Data Safe

We use appropriate technical and organisational measures to protect your personal data. These measures are designed to protect your data against unauthorised access, disclosure, loss, alteration or destruction, taking into account the nature of the data, the recruitment process, the systems used and the risks involved.

Organisational Safeguards

We have policies and procedures that govern data protection across our organisation. These policies are regularly reviewed and updated to ensure their effectiveness and alignment with regulatory requirements. We also have strict guidelines for handling candidate data managed through our recruitment platforms and internal systems.

Data Encryption

Where appropriate, we use encryption and secure transmission methods to protect personal data, including when data is stored or transmitted through recruitment systems and related tools.

Access Controls

We maintain strict access controls to ensure that only authorised personnel can access your personal data based on their role and responsibilities. Access permissions are regularly reviewed and updated, and our systems are designed with role-based restrictions to prevent unauthorised access.

Data Minimisation

We only collect and use the personal data that is necessary for the specific purposes outlined in this privacy notice. This means we keep the amount of data we collect to a minimum, which helps protect your privacy.

Privacy from the Start

We consider data protection requirements when designing, selecting or changing recruitment processes, tools and AI-assisted features. This includes considering data minimisation, access controls, retention, transparency, security and the impact on candidates.

Employee Training

We provide regular training to our employees and internal users who handle recruitment data. We also require service providers that process personal data for us to apply appropriate confidentiality and security measures.

Incident Response

In the unlikely event of a data breach or security incident, we have procedures in place to promptly respond, investigate, and mitigate the impact.

Regular Assessments

We conduct regular assessments and audits of our data protection practices, security measures and third-party tools to identify and address any vulnerabilities or risks related to personal data. This helps us maintain the effectiveness of our security controls and ensure ongoing data protection.

Continuous Improvement

We review and update our security measures where needed to maintain the confidentiality, integrity and availability of your personal data.

If you have any concerns about the security of your personal data, or if you suspect any unauthorised access or disclosure, please contact the UK Privacy Contact using the details in Section 1.

12. Your Privacy Rights

You have the following rights over your personal data under the UK GDPR and the Data Protection Act 2018, and we will help you exercise them.

Right to withdraw your consent at any time

When we are processing your personal data based on your consent, you can withdraw that consent at any time.

Right to be informed

You have the right to know how your personal data is collected and used, including the purposes, who processes it, and how long it is kept.

Right of access

You can ask whether we process your data, obtain details about the processing, and receive a copy of your data.

Right to rectification

You can ask us to correct inaccurate or incomplete personal data we hold about you.

Right to erasure

(Right to be forgotten)

You can ask us to delete your personal data in certain circumstances, for example where it is no longer needed for the purposes for which it was collected.

Right to object

Where we process your data on the basis of legitimate interests, you have the right to object to that processing.

Right to restrict processing

In certain circumstances you can ask us to restrict the processing of your personal data. Where processing is restricted, we will only store your data and not otherwise use it, except where permitted under UK data protection law.

Right to data portability

You have the right to receive certain personal data in a structured, commonly used, machine-readable format, and to have it transferred to another controller where technically feasible. This applies where the processing is automated and based on your consent or on a contract.

Rights in relation to automated decision-making

You have rights and safeguards in relation to significant decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects. As explained in Section 7, we do not currently use solely automated decisions that produce legal or similarly significant effects in the recruitment process.

To exercise any of your rights, please contact our UK Privacy Contact using the details in Section 1.

We will respond without undue delay and, in any event, within one month of receiving your request. Where your request is complex or you have made a number of requests, we may extend this period by up to two further months, and we will let you know within one month of your request if this applies and why.

Limitations and Exceptions:

Some rights are subject to certain limits. There may be legal or legitimate reasons why we cannot fulfil some of your requests. For example, if your request conflicts with our legal obligations or affects the rights of others, we will explain why we are unable to comply with your request.

Where we rely on your consent, we will make clear when consent is needed and for what purpose.

You can withdraw your consent at any time, and withdrawal does not affect the lawfulness of any processing carried out before you withdrew it. In recruitment, we rely on consent only for the following, and withdrawing it has these effects:

  • Talent pool / future opportunities:

    if you withdraw consent, we will remove your details from our talent pool and will not contact you about future roles. This does not affect any current application, and you can ask to be considered for future roles again at any time.

  • Interview recordings:

    if you withdraw consent to recording, we will use another assessment method where possible.

Withdrawing consent for these optional activities does not exclude you from the recruitment process.

Complaints

If you raise a data protection complaint with us, we will acknowledge it as soon as reasonably possible and in any event within 30 days. We will investigate and respond to your complaint without undue delay. Where possible, we aim to provide a substantive response within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority, at https://ico.org.uk/for-the-public/.

13. Changes to This Privacy Notice

We may update this privacy notice from time to time to reflect changes in our privacy practices or legal obligations. When we make material changes to this privacy notice, or where we intend to use your personal data for a new purpose, we will update this privacy notice and, where required, bring the change to your attention before the new processing starts. The revised version will be published on our website and will show the date on which it was last updated. We encourage you to check this privacy notice periodically for the latest information on how we handle your personal data.