BrandHire Privacy Policy
Last Updated: 10 May 2026
1. Definitions and Interpretation
1.1 In this Privacy Policy (the “Policy”), unless the context otherwise requires, “Applicable Data Protection Law” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, the Data (Use and Access) Act 2025, the Online Safety Act 2023, the Digital Economy Act 2017, and the Human Rights Act 1998, together with all binding and non-binding guidance issued by the Information Commissioner’s Office, each as amended or replaced from time to time.
1.2 “Candidate” means any identified or identifiable natural person whose Personal Data is Processed by the Company for the purposes of identifying, assessing, or placing that individual in connection with employment opportunities.
1.3 “Client” means any natural or legal person who engages the Company to provide recruitment or talent-related services.
1.4 “Company”, “we”, “us” or “our” means Brand Hire Ltd, a company incorporated in England and Wales.
1.5 “Controller”, “Processor”, “Processing” and “Personal Data” shall have the meanings given to them under Applicable Data Protection Law.
1.6 “Services” means the recruitment, sourcing, screening, assessment, shortlisting and placement services provided by the Company, together with any ancillary services reasonably connected to those activities.
1.7 References to statutes include any statutory modification, re-enactment or replacement thereof.
2. Identity of the Controller and Contact Details
2.1 The Company determines the purposes and means of Processing in respect of Personal Data where it acts as Controller and shall comply with the obligations imposed on Controllers under Applicable Data Protection Law.
2.2 The Company is registered in England and Wales under company number 17165137 and has its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, and is registered with the Information Commissioner’s Office under registration number ZC126596.
2.3 The Company may be contacted in relation to data protection matters at privacy@brandhire.co.uk and maintains internal governance arrangements to ensure that data protection responsibilities are clearly allocated and effectively discharged, notwithstanding that it is not required to appoint a statutory data protection officer.
2.4 The Company acts as a Controller in respect of Personal Data relating to Candidates and prospective Candidates which it sources, assesses, and introduces to Clients. The Company may act as a Processor where it Processes Personal Data solely on the documented instructions of a Client, including where the Company supports recruitment processes using data provided directly by the Client, and in such circumstances the respective roles and responsibilities of the parties shall be governed by a written agreement compliant with Article 28 UK GDPR.
3. Scope and Application
3.1 This Policy applies to all Processing of Personal Data carried out by or on behalf of the Company in connection with the provision of the Services, including Processing relating to Candidates, Clients, and users of the Company’s website.
3.2 This Policy is intended to provide a comprehensive and transparent account of the Company’s Processing activities and shall be interpreted in a manner consistent with Applicable Data Protection Law and regulatory expectations, including those of the Information Commissioner’s Office.
4. Data Protection Principles and Compliance Framework
4.1 The Company shall ensure that all Personal Data is Processed in accordance with the principles set out in Article 5 of the UK GDPR, and shall implement appropriate measures to demonstrate compliance with those principles in accordance with the accountability obligation.
4.2 In operational terms, the Company embeds those principles into its recruitment processes by ensuring that Personal Data is collected only where it is necessary to identify, assess, and place Candidates, that such data is not used for unrelated purposes without a lawful basis, that data is kept accurate through ongoing engagement with Candidates and Clients, and that retention is limited to what is necessary to maintain effective recruitment operations and comply with legal obligations.
4.3 The Company maintains a structured compliance framework which includes the maintenance of Records of Processing Activities, the completion of Data Protection Impact Assessments where Processing is likely to result in a high risk to individuals, and the documentation of Legitimate Interest Assessments and, where applicable, Recognised Legitimate Interest Assessments under the Data (Use and Access) Act 2025, and the Company keeps such documentation under review to ensure that it reflects its actual Processing activities.
5. Categories of Personal Data Processed
5.1 The Company Processes Personal Data relating to Candidates which typically includes identity information, contact details, professional and educational history, employment preferences, screening responses, right-to-work status, and records of communications, insofar as such data is necessary to assess suitability for roles and to facilitate recruitment processes.
5.2 The Company Processes Personal Data relating to Clients and their personnel, including identity and contact details, organisational information, and information relating to hiring requirements, where such Processing is necessary to deliver recruitment services and manage commercial relationships.
5.3 The Company Processes Personal Data relating to users of its website, including technical and usage information generated through interaction with the website, where such Processing is necessary to ensure functionality, security, and improvement of the website.
5.4 In each case, the Company ensures that the Personal Data Processed is limited to that which is necessary in light of the purposes for which it is collected and processed.
6. Sources of Personal Data
6.1 The Company obtains Personal Data directly from data subjects through applications, registration forms, communications, and interactions in the course of providing the Services.
6.2 The Company also obtains Personal Data from third-party sources, including publicly available information and professional networking platforms such as LinkedIn, where such data has been made available by the individual or is otherwise lawfully disclosed.
6.3 Where Personal Data is obtained indirectly, the Company ensures that appropriate transparency information is provided to the data subject within the timeframes required under Applicable Data Protection Law.
7. Why We Use Your Personal Data and Our Lawful Basis
7.1 The Company Processes Personal Data only where such Processing is supported by a lawful basis under Article 6 of the UK GDPR and, where relevant, Article 9, and shall not rely on consent as the primary lawful basis except where required by law.
7.2 In relation to Candidates, the Company Processes Personal Data for the purposes of identifying suitable individuals for employment opportunities, assessing their suitability, presenting them to Clients, and facilitating recruitment processes, and such Processing is necessary for the legitimate interests of the Company in operating a recruitment business and for the legitimate interests of Candidates in being considered for relevant roles, and the Company has determined, following a documented balancing assessment, that such interests are not overridden by the rights and freedoms of the data subject. The Company processes Candidate Personal Data through structured recruitment workflows, including sourcing, screening, role-specific assessment, and targeted disclosure to Clients in respect of specific vacancies, and does not disclose Candidate information on a speculative or bulk basis without a lawful basis and appropriate safeguards. Where Personal Data is obtained from publicly available or professional sources, the Company considers that Candidates reasonably expect to be contacted in relation to relevant employment opportunities within their professional field, and ensures that such contact is proportionate, targeted, and limited to roles which are objectively aligned with the Candidate’s experience and profile.
7.3 The Company further relies on recognised legitimate interests under the Data (Use and Access) Act 2025, including the Processing of Personal Data for talent matching, fraud prevention, and business continuity, and ensures that such Processing is proportionate and subject to appropriate safeguards.
7.4 Where a Candidate engages with the Company with a view to securing employment opportunities, the Processing of their Personal Data is also necessary for taking steps at the request of the data subject prior to entering into a contract.
7.5 The Company also Processes Personal Data where necessary to comply with legal obligations, including obligations relating to right-to-work verification and regulatory compliance.
7.6 In relation to Clients, the Company Processes Personal Data for the purposes of delivering recruitment services, managing commercial relationships, and administering contracts, and such Processing is necessary for the performance of contracts and for the legitimate interests of the Company in operating and developing its business.
7.7 In relation to website users, the Company Processes Personal Data for the purposes of ensuring the functionality, security, and improvement of its website, and such Processing is carried out on the basis of legitimate interests, except where consent is required under the Privacy and Electronic Communications Regulations 2003 for the use of non-essential cookies or similar technologies.
8. Special Category Data
8.1 The Company Processes Special Category Data only where such Processing is strictly necessary and permitted under Article 9 of the UK GDPR, and typically only where the data subject has manifestly made such data public or where Processing is required for equality monitoring and subject to appropriate safeguards.
8.2 The Company implements enhanced protections in respect of such data, including restricted access and strict data minimisation.
9. Automated Decision-Making, Profiling and AI
9.1 The Company does not make decisions based solely on automated Processing which produce legal or similarly significant effects on individuals.
9.2 The Company may utilise technology-assisted tools to support recruitment activities, including the organisation and filtering of Candidate information based on role-relevant criteria, but such tools operate under meaningful human oversight and do not replace human decision-making.
9.3 The Company ensures that any use of such technologies is consistent with guidance issued by the Information Commissioner’s Office relating to artificial intelligence and data protection.
9.4 The Company recognises that the use of technology-assisted tools in recruitment may give rise to risks of bias, unfairness, or disproportionate outcomes and, accordingly, implements appropriate governance measures to mitigate such risks. In particular, the Company ensures that any tools used to support the organisation, filtering, or ranking of Candidate information are designed and configured to operate on objective, role-relevant criteria and are subject to meaningful human oversight at all material decision points. The Company takes reasonable steps to ensure that such tools do not systematically disadvantage individuals on the basis of protected characteristics or otherwise produce outcomes which are inconsistent with the principles of fairness and non-discrimination. The Company periodically reviews the outputs of such tools, having regard to the nature and scale of its Processing activities, in order to identify any patterns of bias or unintended outcomes and to implement appropriate corrective measures where necessary. The Company also ensures that personnel involved in recruitment decision-making are aware of the limitations of automated or technology-assisted tools and are trained to exercise independent judgment, and that final decisions relating to Candidate progression or selection are not made solely on the basis of automated Processing.
10. Data Sharing and Disclosure
10.1 The Company discloses Personal Data only where such disclosure is necessary for the provision of the Services or is otherwise required or permitted by law, and ensures that such disclosures are proportionate and subject to appropriate safeguards.
10.2 Where Personal Data relating to Candidates is disclosed to Clients, those Clients act as independent Controllers, and the Company ensures that only relevant and necessary information is shared and that such sharing is consistent with the reasonable expectations of the Candidate.
10.3 The Company engages third-party service providers to Process Personal Data on its behalf and ensures that such providers act only on the documented instructions of the Company and are subject to written agreements compliant with Article 28 of the UK GDPR, including obligations relating to confidentiality, security, assistance with data subject rights, and audit.
10.4 The Company may disclose Personal Data to regulators, courts, or law enforcement agencies where required by law or where necessary for the establishment, exercise, or defence of legal claims.
10.5 The Company undertakes appropriate due diligence prior to engaging any Processor and ensures that all Processing carried out on its behalf is governed by a written agreement which satisfies the requirements of Article 28 of the UK GDPR, including obligations relating to confidentiality, security, sub-processing, and audit rights. The Company maintains oversight of its Processors on an ongoing basis and requires that any sub-processing arrangements are subject to equivalent contractual protections and appropriate approval mechanisms.
10.6 The categories of Processors engaged by the Company include providers of recruitment and candidate management systems, email and communication platforms, website hosting and form processing services, and business operations tools, each of which Processes Personal Data only to the extent necessary to provide their respective services to the Company.
11. International Data Transfers
11.1 Where Personal Data is transferred outside the United Kingdom, the Company ensures that such transfers are conducted in accordance with Applicable Data Protection Law and are subject to appropriate safeguards, including the use of International Data Transfer Agreements approved by the Information Commissioner’s Office and the completion of Transfer Risk Assessments.
11.2 The Company assesses the legal and practical risks associated with such transfers and ensures that the level of protection afforded to Personal Data is essentially equivalent to that provided within the United Kingdom.
11.3 In assessing whether a transfer of Personal Data outside the United Kingdom may lawfully take place, the Company evaluates the legal and regulatory framework of the destination jurisdiction, including any laws permitting access to data by public authorities, the effectiveness of the safeguards implemented, and the practical enforceability of data subject rights, and documents such assessment through a Transfer Risk Assessment in accordance with Applicable Data Protection Law.
12. Data Retention
12.1 The Company retains Personal Data only for so long as is necessary to fulfil the purposes for which it was collected, including the provision of recruitment services, the maintenance of business records, and compliance with legal obligations.
12.2 In determining retention periods, the Company takes into account the nature of the data, the purposes of Processing, the expectations of the data subject, and the need to retain data for the establishment, exercise, or defence of legal claims.
12.3 Personal Data is securely deleted or anonymised once it is no longer required.
12.4 Personal Data relating to Candidates may be retained beyond initial engagement where necessary to enable the Company to identify and present future employment opportunities, provided that such retention remains proportionate, is subject to periodic review, and is consistent with the reasonable expectations of the data subject.
13. Data Security
13.1 The Company implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including measures designed to prevent unauthorised or unlawful Processing and accidental loss, destruction, or damage.
13.2 The Company adopts a risk-based approach to security and regularly reviews its measures to ensure their continued effectiveness.
13.3 The Company ensures that access to Personal Data is limited to personnel who require such access for the performance of their duties and that such personnel are subject to appropriate confidentiality obligations.
14. Personal Data Breach Procedures
14.1 The Company maintains procedures for the detection, investigation, and reporting of Personal Data breaches and ensures that such breaches are managed in accordance with Applicable Data Protection Law.
14.2 Where required, the Company notifies the Information Commissioner’s Office and affected individuals within the timeframes prescribed by law.
15. Data Subject Rights
15.1 The Company recognises and facilitates the exercise of data subject rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, and objection.
15.2 The Company maintains procedures to ensure that such rights are handled promptly and in accordance with statutory requirements.
16. Children’s Data and Online Safety
16.1 The Company does not target children and processes Personal Data in a manner consistent with the ICO Age Appropriate Design Code and the Online Safety Act 2023.
16.2 Where the Company becomes aware that it has inadvertently collected Personal Data relating to a child, it shall take steps to delete such data without undue delay.
17. Marketing and PECR Compliance
17.1 The Company conducts marketing activities in accordance with the Privacy and Electronic Communications Regulations 2003 and ensures that communications are sent only where permitted by law, including reliance on the “soft opt-in” where applicable and legitimate interests in respect of business-to-business communications.
17.2 Individuals are provided with clear and effective mechanisms to opt out of marketing communications at any time, and the Company maintains suppression records to ensure that such preferences are respected.
18. Cookies and Tracking
18.1 The Company uses cookies and similar technologies in accordance with Applicable Data Protection Law and ensures that non-essential cookies are deployed only where valid consent has been obtained.
18.2 Further details are provided in the Company’s Cookie Policy.
19. Accountability, Governance and Documentation
19.1 The Company maintains comprehensive documentation to demonstrate compliance with Applicable Data Protection Law, including Records of Processing Activities, Data Protection Impact Assessments, and Legitimate Interest Assessments.
19.2 The Company ensures that personnel are trained and that Processing activities are subject to appropriate oversight and audit.
19.3 The Company maintains internal audit and review processes designed to monitor compliance with Applicable Data Protection Law, including the maintenance of incident and breach logs, periodic reviews of Processing activities, and the assignment of responsibility for data protection compliance to designated personnel within the organisation, and ensures that such governance measures are proportionate to the nature, scope, and risk profile of its Processing activities.
20. Changes to this Policy
20.1 The Company shall keep this Policy under review and shall update it where necessary to reflect changes in law, regulation, or Processing activities, and shall ensure that any such changes are assessed, documented, and implemented in accordance with its accountability obligations.
20.2 Where changes materially affect the rights or expectations of data subjects, the Company shall undertake an assessment of compatibility in accordance with Article 6(4) UK GDPR and, where required, conduct a Data Protection Impact Assessment prior to implementing such changes, and shall provide appropriate notice in advance of such changes taking effect.
21. Contact and Complaints
21.1 Any queries in relation to this Policy may be directed to privacy@brandhire.co.uk.
21.2 Data subjects have the right to lodge a complaint with the Information Commissioner’s Office.