Red Flag Recruitment Limited (referred to as Red Flag or we or our or us) is committed to protecting and respecting your privacy.
The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a new regulation which replaces the Data Protection Regulation (Directive 95/46/EC). The GDPR aims to harmonise data protection legislation across the European Union, enhancing privacy rights for individuals and providing a strict framework within which commercial organisations can legally operate.
Candidates: applicants for roles advertised or promoted by us with Clients of Red Flag as well as people who have supplied a speculative CV to Red Flag not in relation to a specific job.
Clients: our customers, clients and prospective customers and clients to whom we provide or market our recruitment services in the course of our business.
Website Users: any individual who accesses our website.
It does not apply to Red Flag staff and employees who will be issued with separate fair processing information.
For the purposes of the data protection legislation from time to time in force, Red Flag is the data controller and is responsible for your personal data.
You can contact Red Flag Recruitment Ltd’s nominated Data Protection Officer at email@example.com.
What kind of information do we collect?
Depending on the circumstances, we may collect some or all of the information listed below to enable us to offer you employment opportunities tailored to your circumstances and interests. This may include: your name, contact numbers, email addresses, curriculum vitae, photograph, education details, employment history, links to your professional profiles available in the public domain e.g. LinkedIn, Twitter, business Facebook or corporate website) immigration status, financial information (where we need it to carry out financial background checks or pay you), social security number and tax-related information, referee details, details about your current remuneration, pensions and benefits arrangements and emergency contact details, In addition, you may choose to share other information with us that you think is relevant.
Where appropriate or necessary (and in accordance with legal requirements) we may also collect information related to your health or details of any criminal convictions (where this is required for a role that you are applying for). We may ask you to provide diversity information (on a voluntary basis) for the reasons and in the circumstances set out below.
We collect your personal data (such as name and contact details) when we receive it directly from you such as where you contact us proactively (by phone, email, in person) or where you connect with our consultants on business networking sites or through our consultant’s business development activities more generally.
We may seek more information about you from analysing online and offline media and we may be supplied with information about you by Candidates (for example when you are named as a referee).
We need a small amount of personal data to ensure our relationship with you runs smoothly such as contact details of relevant individuals at your organisation so that we can communicate with you and we may need bank details so that we can pay you for the services you provide.
How do we collect personal data?
We collect information about Candidates when you register as a Candidate with Red Flag by completing the registration form on our website (www.redflagrecruitment.com) or by sending us your CV or by corresponding with our consultants by phone, e-mail or in person.
You may also provide us with your personal data when you use our website, subscribe to our services, participate in salary and other market surveys, attend our events, participate in discussion boards or other social media functions on our site or when you apply for jobs with us via other job boards (such as Natives, Gumtree, Indeed, The Lady).
We may also receive personal data about you from other sources such as referees, our Clients and from third-party sources, such as LinkedIn and other job board websites, your business card, personal recommendations or if you contact us through social media channels. For example, if you ‘like’ our page on Facebook or ‘follow’ us on Twitter we will receive your personal information from those sites.
We also work closely with third parties including, business partners, sub-contractors in technical, professional, payment and other services, advertising networks, analytics providers, search information providers, credit reference agencies and professional advisors. We may receive information about you from them for the purposes of our recruitment services and ancillary support services.
What information do we collect about website users?
When you visit our website there is certain information that we may automatically collect, whether or not you decide to use our services. This includes your IP address, the date and the times and frequency with which you access the website and the way you browse its content.
We will also collect data from you automatically via cookies in line with the cookie settings in your browser. If you would like to know more about cookies including how we use them and the choices available to you please ask the DPO.
How do we use your personal data and what is the legal basis for the processing?
We use Candidate data as follows:
• Storing your details (and updating them when necessary) on our database, so that we can contact you in relation to recruitment services.
• Providing you with our recruitment services and to facilitate the recruitment process.
• Assessing data about you against vacancies which we think may be suitable for you.
• Sending your information to Clients (with your prior consent) in order to apply for jobs or to assess your eligibility for jobs.
• Enabling you to submit your CV, apply online for jobs or to subscribe to alerts about jobs we think may be of interest to you.
• Carrying out our obligations arising from any contracts entered into between us.
• Carrying out our obligations arising from any contracts entered into between Red Flag and third parties in relation to your recruitment.
• Carrying out market surveys and market reports.
• Verifying details you have provided, using third-party resources (such as credit, DBS and regulatory checks).
• To request information (such as references, qualifications and potentially any criminal convictions, to the extent that this is appropriate and necessary with respect to roles you are applying for).
• Complying with our legal obligations in connection with the detection of crime or the collection of taxes or duties.
• Processing your data to enable us to send you targeted, relevant marketing materials or other communications which we think are likely to be of interest to you.
We use Client data as follows:
• To provide our Clients with the best recruitment services possible.
• We store your personal data and/or the personal data of individual contacts at your organisation as well as keeping records of our conversations, meetings, registered jobs and placements on our database.
• From time to time, we may also ask you to undertake a customer satisfaction survey.
• Processing your data to enable us to send you targeted, relevant marketing materials or other communications which we think are likely to be of interest to you.
• To provide professional references on any previously employed candidate
We use Supplier data as follows:
• To facilitate receipt of services from you and we hold your financial data so that we can pay you for your services.
• To enable us to send you targeted, relevant marketing materials or other communications which we think are likely to be of interest to you.
Our legal basis for the processing of personal data is our legitimate business interests, described in more detail below, although we will also rely on contract, legal obligation and consent for specific uses of data.
We will rely on the contract if we are negotiating or have entered into a placement agreement with you or your organisation or any other contract to provide services to you or receive services from you or your organisation.
We will rely on legal obligation if we are legally required to hold information on to you to fulfil our legal obligations – including where you are applying for roles or are placed in a role where you will be working with vulnerable persons such as children.
We will in some circumstances rely on consent for particular uses of your data and you will be asked for your express consent if legally required. Examples of when consent may be the lawful basis for processing include permission to introduce a Candidate to a Client and in relation to sending third-party marketing communications to you via email
With respect to marketing, if you have previously engaged with us (for example submitting a job application or CV or registering for a vacancy to be filled) and we are marketing other recruitment related services we will take your consent as given unless or until you opt out (this is called soft opt-in consent). For other types of e-marketing, we are required to obtain your explicit consent. You have the right to withdraw consent to marketing at any time by contacting us on firstname.lastname@example.org.
Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you. In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.
Our Legitimate Business Interests:
Our legitimate interests in collecting and retaining your personal data are described below:
• In order to support our Candidates’ career aspirations and our Clients’ resourcing needs, we require a database of Candidate and Client personal data containing historical information as well as current resourcing requirements.
• As a recruitment agency, we introduce Candidates to Clients for employment opportunities. The exchange of personal data of our Candidates and our Client contacts is a fundamental, essential part of this process.
• We think that it is reasonable to expect that if you are looking for employment or have posted your professional background and information on a job board or professional networking site which allows the public (including recruiters) to view your information that you are happy for us to collect and otherwise use your personal data to offer or provide our recruitment services to you, assess your skills against our bank of vacancies and, with your consent, share that information with prospective employers.
• Once an offer of a role is made to a Candidate, your prospective employer may also want to double check any information you’ve given us (such as the results from credit and criminal records/DBS checks or confirm your references and qualifications) to the extent that this is appropriate and necessary for the role.
Should we want or need to rely on consent to lawfully process your data we will request your consent orally, by email or by an online process for the specific activity we require consent for and record your response on our system. Where consent is the lawful basis for our processing you have the right to withdraw your consent to this particular processing at any time (as set out below under Your legal rights).
Establishing or defending legal claims:
Sometimes it may be necessary for us to process personal data and, where appropriate and in accordance with local laws and requirements, special category personal data in connection with exercising or defending legal claims.
This may arise for example where we need to take legal advice in relation to legal proceedings or are required by law to preserve or disclose certain information as part of the legal process.
Change of purpose:
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us on email@example.com. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Automated Decision Making or Profiling:
We do not undertake automated decision making or profiling. We do use our computer systems to search and identify personal data in accordance with parameters set by a person. A person will always be involved in the decision-making process.
Disclosure of your information inside and outside of the EEA
We may share your personal information within our organisation both in the EEA and outside of the EEA and with selected third parties including:
- Clients for the purpose of introducing Candidates to them.
- Candidates for the purpose of arranging interviews and engagements with Clients.
- Clients, business partners, suppliers and sub-contractors for the performance and compliance obligations of any contract we enter into with them or you.
- Cloud-based storage providers.
- Subcontractors including email marketing specialists, event organisers, payment and other financial service providers.
- Analytics and search engine providers that assist us in the improvement and optimisation of our website.
- Credit reference agencies, our insurance broker, compliance partners and other sub-contractors for the purpose of assessing your suitability for a role where this is a condition of us entering into a contract with you.
We will disclose your personal information to third parties:
- If we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms and conditions of service and other agreements; or to protect the rights, property, or safety of Red Flag our Candidates, Clients or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.
Where a third party processes your personal data – the lawful basis for the third-party processing will include:
- Their own legitimate business interests in processing your personal data, in most cases to fulfil their internal resourcing needs.
- Satisfaction of their contractual obligations to us as our data processor.
- For the purpose of a contract in place or in contemplation.
- To fulfil their legal obligations.
We require all third parties to respect the security of personal data and to treat it in accordance with the law. We do not allow third-party service providers with whom we may work to use your personal data for their own purposes and we only permit them to process your personal data for specified purposes and in accordance with our instructions.
Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
- We may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe.
Please contact us at firstname.lastname@example.org if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
It is important to be aware that unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our website; any transmission is at your own risk.
Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access. All information you provide to us is stored on our secure servers in the UK. We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Retention of your data:
We understand our legal duty to retain accurate data and only retain personal data for as long as we need it for our legitimate business interests and where you are happy for us to do so. We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
We may archive part or all of your personal data or retain it on our financial systems only, deleting all or part of it from our main Customer Relationship Manager (CRM) system. We may pseudonymise parts of your data, particularly following a request for suppression or deletion of your data, to ensure that we do not re-enter your personal data on to our database unless requested to do so. For your information, Pseudonymised Data is created by taking identifying fields within a database and replacing them with artificial identifiers, or pseudonyms.
Details of retention periods for different aspects of your personal data are available in our retention policy which you can request from us at email@example.com.
Your legal rights:
Under the GDPR you have the right to:
• Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
• Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
• Object to the processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes. To stop receiving marketing communications from us or change your preferences please contact us on firstname.lastname@example.org.
• Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example, if you want us to establish its accuracy or the reason for processing it.
• Request the transfer of your personal information to another party in certain formats, if practicable.
• Withdraw consent to processing at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
• Make a complaint to a supervisory body which in the United Kingdom is the Information Commissioner’s Office. The ICO can be contacted through this link: https://ico.org.uk/concerns/
• If you wish to exercise any of the rights set out above, please contact the DPR at email@example.com.
• You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
• We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
• We try to respond to all legitimate requests within one month. Occasionally it may take us l longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
Red Flag Recruitment LTD
44 North Road,
Company Number 6362242. Registered in the UK.
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so we encourage you to contact us in the first instance.