YOUR DATA & YOU
TrueSearch Headhunters Limited (“we”, “us”, “our”) is committed to protecting the privacy and personal data of candidates, clients, suppliers, and users of our website. We process personal data lawfully, fairly, and transparently, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This Privacy Policy explains how we collect, use, store, and protect personal data provided via our website, email, telephone, meetings, CV submissions, and other business communications.
This policy is effective from 01 January 2021 and may be updated from time to time. Where material changes are made, appropriate notice will be provided.
For questions regarding this policy or our data practices, please contact:
DATA CONTROLLER
TrueSearch Headhunters Limited is the Data Controller for the personal data described in this policy.
PERSONAL DATA WE COLLECT
We may collect and process the following categories of personal data:
We do not intentionally collect special category data unless it is voluntarily provided and relevant to a recruitment process.
HOW WE USE PERSONAL DATA
We use personal data for the following purposes:
We will only submit your details to a client or apply for roles on your behalf with your explicit consent.
LAWFUL BASES FOR PROCESSING (UK GDPR)
We rely on the following lawful bases:
Contractual Necessity
Where processing is required to perform or enter into a contract or to take steps at your request prior to entering into a contract.
Legal Obligation
Where processing is necessary to comply with legal or regulatory requirements.
Legitimate Interests
Where processing is necessary for our legitimate business interests and does not override your rights and freedoms. These interests include responding to enquiries, managing recruitment processes, improving services, and business development. Legitimate interest assessments are conducted where required.
Consent
Where you have provided clear and specific consent, particularly in relation to role submissions and direct marketing. Consent may be withdrawn at any time.
DIRECT MARKETING
We may contact you with information about opportunities, services, or industry insights where permitted under UK GDPR and PECR. You may opt out of marketing communications at any time using unsubscribe links or by contacting us directly.
DATA SHARING
We do not sell personal data. We may share personal data with:
All third parties are required to maintain appropriate security and confidentiality standards.
WEBSITE HOSTING & THIRD-PARTY PROCESSORS
Our website is hosted and operated using Squarespace, which provides website hosting, form submission handling, analytics, and related infrastructure services.
Squarespace acts as a Data Processor on our behalf and processes personal data only in accordance with our instructions and appropriate contractual safeguards.
Squarespace may store or process personal data outside the UK. Where international transfers occur, appropriate safeguards are in place, including UK-approved Standard Contractual Clauses and other lawful transfer mechanisms to ensure an adequate level of protection.
Squarespace is not permitted to use personal data for its own marketing purposes.
DATA RETENTION
We retain personal data only for as long as necessary for the purposes for which it was collected, including legal, regulatory, and contractual obligations. Data is securely deleted or anonymised when no longer required.
DATA SECURITY
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure.
COOKIES AND WEBSITE DATA
Our website uses cookies to enable core functionality, analyse traffic, and improve user experience. Some cookies are placed by GoDaddy as part of its website functionality, analytics, and performance services. These cookies help us understand how visitors use our website and allow us to improve its operation.
We may collect:
You can manage cookie preferences through your browser settings. Disabling cookies may affect website functionality.
INTERNATIONAL DATA TRANSFERS
Where personal data is transferred outside the UK, including to the United States, we ensure appropriate safeguards are in place in accordance with UK GDPR. These include adequacy regulations where applicable, Standard Contractual Clauses, and additional technical and organisational measures where required.
LINKS TO THIRD-PARTY WEBSITES
Our website may contain links to external websites. We are not responsible for the privacy practices or content of those sites. You should review the relevant privacy policies before providing personal data.
YOUR RIGHTS UNDER UK GDPR
You have the right to:
Requests should be submitted to admin@truesearch.co.uk. Identity verification may be required. We will respond within statutory timeframes and explain any lawful refusal.