Logo
  • People
  • Jobs
  • Resources
    • Help Centre
    • Career Advice
    • Blogs
  • Company
    • About us
    • Contact
    • Privacy Policy
    • Terms of Use
  • Directories
    • Members
    • Companies

Jobs

  • Browse jobs
  • Browse jobs by companies
  • Browse locations
  • Browse sectors
  • Job for Everyone
  • Popular searches

Directories

  • Members
  • Jobs
  • Companies
  • People Search

Company

  • About us
  • Contact
  • Privacy Policy
  • Terms of Use

Other Links

  • Career advice
  • Blog
  • Help

© Copyright 2026 | Stafty | All Rights Reserved.

Privacy Policy

  1. Home
  2. Privacy Policy

Privacy Notice & Data Protection Policy

Version 1.0 | Last Updated: July 2026


Chapter 1 - Introduction, Definitions & Platform Scope

1. Introduction

This Privacy Notice & Data Protection Policy explains how Stafty Technologies Ltd collects, uses, stores, shares and protects personal information when providing the Stafty Platform and related services.

Stafty is a software platform designed to help recruitment agencies, employers and workforce providers manage recruitment, compliance, onboarding, workforce administration and related business activities through a secure cloud-based platform.

We are committed to processing personal information fairly, lawfully and transparently in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations and other applicable UK legislation.

This document should be read together with our Terms of Platform Use, Cookie Policy, Data Processing Agreement, Agency Platform Agreement, Identity Verification Policy and any other written agreement that applies to the relevant service.

2. Company Information

The Platform is operated by Stafty Technologies Ltd, company number 17257359, registered office Radclyffe House, 66-68 Hagley Road, Birmingham, England, B16 8PF. References to Stafty, we, our or us mean Stafty Technologies Ltd unless otherwise stated.

3. About the Platform

Stafty is a software platform and technology provider. We develop, maintain and operate software that enables organisations to manage recruitment and workforce-related activities digitally.

The Platform may include job advertising, candidate management, employer management, compliance monitoring, secure document storage, identity verification, timesheets, messaging, notifications, reporting, AI-assisted productivity features and integrations with approved third-party services.

Stafty does not act as the employer of candidates or workers unless this is expressly agreed in a separate written agreement. We do not make recruitment decisions on behalf of customers. The Platform provides technology that enables customers to manage their own recruitment and workforce processes.

4. Scope of this Notice

This Privacy Notice applies whenever personal information is collected or processed through the Stafty website, Platform, mobile applications where available, customer support services, onboarding activities, account registration, identity verification, communications, integrations, demonstrations, webinars or other services operated by Stafty.

It applies to recruitment agencies, employers, candidates, workers, contractors, business contacts, website visitors and any person whose personal information is processed through the Platform.

5. Definitions

Platform means the Stafty software platform, website, mobile applications, APIs and any related online services provided by Stafty Technologies Ltd.

Customer means any recruitment agency, employer, organisation or business using the Platform.

Agency means a recruitment business using the Platform.

Employer means an organisation using the Platform to recruit, engage or manage workers or candidates.

Candidate means an individual whose information is uploaded, stored or processed through the Platform for recruitment or workforce purposes.

Worker includes employees, contractors, temporary workers, agency workers, consultants and individuals engaged through a Customer.

Customer Data means information uploaded, created or stored by or on behalf of a Customer while using the Platform.

Personal Data has the meaning given under UK GDPR.

Processing includes collecting, storing, organising, updating, accessing, sharing, transferring, deleting or otherwise handling personal information.

6. Privacy Principles

Stafty processes personal information lawfully, fairly and transparently. We collect only what is necessary, restrict access to authorised persons, retain information only for as long as needed, and apply appropriate technical and organisational measures to protect information processed through the Platform.


Chapter 2 - Data Controller & Data Processor Responsibilities

1. Purpose of this Chapter

This chapter explains when Stafty Technologies Ltd acts as a Data Controller, when it acts as a Data Processor and how responsibilities are allocated between Stafty, agencies, employers and other customers. This distinction is important because it determines who is responsible for deciding why and how personal data is processed.

2. When Stafty Acts as a Data Controller

Stafty acts as a Data Controller when we determine the purposes and means of processing personal information for our own business, legal, security or platform administration purposes. In these cases, we are responsible for ensuring that processing is fair, lawful and transparent.

3. Controller Examples

Examples include website enquiries, direct platform registration, customer support, billing, account administration, security monitoring, fraud prevention, platform analytics, service improvement, identity verification carried out by Stafty, direct marketing by Stafty and legal compliance.

4. When Stafty Acts as a Data Processor

Where an agency, employer or other customer uses the Platform to manage its own candidates, workers, staff, clients, vacancies or recruitment records, the customer will normally be the Data Controller. In those circumstances, Stafty acts as a Data Processor and processes personal data only on documented instructions from the customer and in accordance with the applicable Data Processing Agreement.

5. Customer Controller Responsibilities

Customers are responsible for ensuring they have a lawful basis to collect, upload, store, share and otherwise process personal information through the Platform. Customers are also responsible for providing privacy notices to their candidates, workers, employees, clients and other relevant individuals where they act as Data Controller.

6. Data Subject Requests

Where Stafty acts as a Data Controller, individuals may contact Stafty directly to exercise their rights. Where Stafty acts as a Data Processor, requests should normally be directed to the relevant customer. Stafty will provide reasonable assistance to the customer in accordance with the applicable agreement and law.

7. Platform Migration

When an agency or employer migrates data into Stafty, the originating organisation remains responsible for ensuring that the data has been collected lawfully and can be transferred to the Platform. Stafty processes migrated data for platform onboarding, migration, hosting, support and related services only.

8. Data Ownership

Customer Data remains owned or controlled by the customer or relevant user who uploaded it, subject to applicable law and contract. Stafty does not claim ownership of customer recruitment records, candidate files, compliance documents or employer data. Stafty owns the Platform, software, databases, workflows, templates, documentation, analytics structures and intellectual property used to provide the services.


Chapter 3 - Categories of Personal Data & Lawful Basis

1. Overview

This chapter explains the main categories of personal information processed through the Platform and the lawful bases that may apply. Not every category will apply to every user. The information processed depends on the services used, the customer configuration and the role of the person using or appearing on the Platform.

2. Website Visitor Data

We may process IP address, device information, browser type, approximate location derived from technical data, pages visited, referral source, cookie preferences, enquiry form details and communication preferences. This helps us operate the website, maintain security, respond to enquiries and understand how the site is used.

3. Account and User Data

We may process names, work email addresses, phone numbers, organisation names, job titles, login credentials, role permissions, authentication records, support tickets, usage logs and security records. This information is required to provide access to the Platform and keep accounts secure.

4. Candidate and Worker Data

Customer use of the Platform may involve candidate names, contact details, CVs, employment history, qualifications, training records, availability, interview notes, job applications, messages, right to work information, visa information, proof of address, compliance documents, professional registrations, references, timesheets, work records and other recruitment-related data.

5. Employer and Agency Data

We may process business contact details, authorised user information, billing information, vacancy details, placement records, communications, account configuration, service usage and contractual records.

6. Special Category and Sensitive Data

The Platform may allow customers to upload or process information that is sensitive, including health information, disability adjustment information, equal opportunity monitoring information, background check information, criminal record check information, DBS status, right to work evidence and professional compliance information. Customers are responsible for ensuring that any such information is processed lawfully and only where necessary.

7. Lawful Basis

Stafty relies on different lawful bases depending on the processing activity. These may include performance of a contract, legitimate interests, legal obligation, consent and, where required, explicit consent or another applicable condition for special category information. Where a customer is the Data Controller, the customer is responsible for identifying and documenting its own lawful basis.

Processing activity

Likely lawful basis

Purpose / notes

Account creation and access

Contract / legitimate interests

To create and manage secure user accounts and provide platform access.

Customer support

Contract / legitimate interests

To respond to support requests, investigate issues and maintain service quality.

Platform security and audit logs

Legitimate interests / legal obligation

To detect misuse, prevent fraud, protect systems and investigate incidents.

Billing and commercial administration

Contract / legal obligation

To manage subscriptions, invoices, payment records and accounting obligations.

Identity verification

Contract / legitimate interests / legal obligation where applicable

To reduce fraud, confirm account integrity and enable selected features.

Marketing to business contacts

Consent or legitimate interests, subject to PECR

To send relevant service information where permitted and allow opt-out.

Customer recruitment processing

Customer-determined basis

The customer normally acts as Controller and determines the lawful basis.

Legal claims and regulatory compliance

Legal obligation / legitimate interests

To comply with law and protect legal rights.

 

The table is intended to describe common Stafty processing activities. Where a customer acts as Controller, the customer must maintain its own lawful basis assessment and privacy information.


Chapter 4 - Identity Verification, AI Features & Automated Assistance

1. Identity Verification Overview

Stafty may provide identity verification features to help protect the Platform, reduce fraud, protect users and enable selected premium features. Identity verification may be required for certain account types, higher-risk activities, access to sensitive platform areas or features that require a higher level of trust.

2. Documents and Information Used

Verification may include reviewing a government-issued identification document, proof of address where appropriate, visa or right to work evidence where relevant, and a recent selfie or photograph provided by the user. The selfie is used to support a standard visual comparison with the identity document.

3. No Biometric Identification

Stafty does not use biometric identification, facial recognition technology, automated facial matching, biometric templates or biometric profiling as part of its standard identity verification process. The process is based on document review and ordinary visual comparison where required. Stafty does not create biometric templates for the purpose of uniquely identifying users.

4. Manual Review and Limitations

Identity verification helps reduce risk but does not guarantee that every person, document or account is genuine. Verification decisions may involve manual review, quality checks, fraud indicators and reasonable platform controls. Stafty may refuse, suspend or restrict access where verification fails, appears suspicious or cannot be completed.

5. Retention of Verification Data

Identity verification information will be retained only for as long as reasonably necessary for fraud prevention, security, legal, contractual, audit or dispute purposes. Where a shorter retention period is suitable, Stafty may delete or restrict access to verification material while retaining a verification status record.

6. AI Assisted Features

The Platform may include AI-assisted tools to support productivity, drafting, searching, summarising, matching, profile preparation, CV support, workflow recommendations or administrative assistance. These tools are intended to assist users and should not be treated as final decisions or professional advice.

7. Human Responsibility

Users and customers remain responsible for reviewing AI-assisted outputs before using them. Stafty does not guarantee that AI-assisted outputs will be complete, accurate, suitable, lawful or free from bias. Recruitment, employment, compliance and commercial decisions must be made by authorised humans using appropriate judgement.

8. Automated Decision Support

Stafty may use automated tools to organise, prioritise, flag or suggest information. Unless clearly stated otherwise in a separate notice or agreement, Stafty does not make solely automated decisions that produce legal or similarly significant effects for individuals. Where customers configure or rely on automated tools, they are responsible for ensuring appropriate human review and lawful use.

9. Fraud Prevention and Platform Integrity

Stafty may use technical checks, audit logs, account signals, document status records and user behaviour indicators to detect possible fraud, account abuse, unauthorised access, spam, platform scraping, fake profiles, false documents or misuse of the Platform.


Chapter 5 - Data Sharing, International Transfers, Security & Incidents

1. Sharing Personal Information

Stafty may share personal information where necessary to provide the Platform, comply with law, protect legal rights, maintain security, investigate misuse or fulfil contractual obligations. We do not sell personal information.

2. Sharing with Customers

Where a user applies for a role, communicates with an employer or agency, is invited to a platform workflow, uploads information for a customer or is managed through the Platform by a customer, relevant information may be shared with that customer according to the Platform configuration and the customer relationship.

3. Service Providers and Sub-processors

Stafty may use trusted service providers for hosting, infrastructure, email delivery, SMS delivery, support tools, analytics, security monitoring, payment processing, file storage, backups and other operational services. Where these providers process personal information for Stafty, appropriate contractual protections will be used.

4. Legal and Regulatory Sharing

We may disclose information to regulators, law enforcement, courts, professional advisers, insurers, auditors or other parties where required by law, necessary to protect legal rights, necessary to prevent fraud, or required to investigate misuse of the Platform.

5. International Transfers

Where personal information is transferred outside the United Kingdom, Stafty will take steps designed to ensure the transfer is lawful. This may include use of adequacy regulations, International Data Transfer Agreements, approved addenda, contractual safeguards or other mechanisms permitted under UK data protection law.

6. Security Measures

Stafty applies appropriate technical and organisational measures having regard to the nature, scope, context and purpose of processing and the risks to individuals. Measures may include access controls, authentication, role-based permissions, encryption where appropriate, secure hosting, logging, monitoring, backups, least privilege access, vulnerability management and staff confidentiality obligations.

7. No Absolute Security Guarantee

Although Stafty takes security seriously, no internet-connected platform or electronic storage system can be guaranteed to be completely secure. Users and customers remain responsible for maintaining secure devices, strong passwords, safe account access and appropriate internal controls.

8. Customer Security Responsibilities

Customers are responsible for managing their authorised users, removing access for leavers, assigning appropriate roles, preventing credential sharing, training staff and ensuring that information is uploaded, accessed and shared only by authorised persons.

9. Incident Handling

If Stafty becomes aware of a personal data breach affecting personal information for which it is responsible, it will assess the incident and take appropriate steps in accordance with applicable law and contractual obligations. Where Stafty acts as a Processor, it will notify the relevant Controller without undue delay after becoming aware of a relevant breach.


Chapter 6 - Data Retention, Individual Rights & Complaints

1. Retention Principles

Stafty keeps personal information only for as long as reasonably necessary for the purposes for which it was collected, including providing the Platform, fulfilling contractual obligations, complying with legal requirements, resolving disputes, preventing fraud, maintaining security and enforcing rights.

2. Customer Controlled Retention

Where Stafty acts as a Processor, the customer is normally responsible for deciding how long Customer Data should be retained. Customers should configure, delete, export or request deletion of Customer Data in accordance with their own retention policies and legal obligations.

3. Indicative Retention Periods

The retention periods below are general guidance and may vary depending on contract terms, legal obligations, disputes, security needs or customer instructions. Stafty may retain limited records for longer where necessary to establish, exercise or defend legal claims.

Data category

Indicative retention approach

Website enquiries

Up to 24 months from last contact unless needed longer

Customer account records

For the account term plus up to 7 years for contractual and legal records

Support tickets

Up to 36 months unless needed for security, service quality or disputes

Billing and accounting records

Normally 6 to 7 years to meet tax and accounting obligations

Security logs and audit records

Normally 12 to 36 months, or longer for investigations

Identity verification status

For the account term and a reasonable period afterwards

Identity documents and selfies

Only as long as necessary for verification, fraud prevention, audit, legal or dispute purposes

Customer Data

As instructed by the customer or configured in the Platform

Marketing preferences

Until changed or withdrawn, with suppression records retained as necessary

 

Retention should be reviewed periodically and adjusted where required by law, contract, security requirements or customer instructions.

4. Individual Rights

Individuals may have rights under UK data protection law including the right to be informed, access personal information, request correction, request deletion, restrict processing, object to processing, request portability and withdraw consent where consent is relied upon. These rights are subject to legal limits and exemptions.

5. Requests Where Stafty is Controller

Where Stafty acts as Controller, individuals may contact Stafty using the details in this notice. We may need to verify identity before responding. We will respond within the period required by law unless an extension is permitted.

6. Requests Where Stafty is Processor

Where Stafty acts as Processor for a customer, requests should normally be directed to that customer. Stafty will not usually respond directly to a data subject request about Customer Data without instructions from the relevant customer unless required by law.

7. Complaints

Individuals may raise privacy concerns with Stafty using the contact details in this notice. Individuals also have the right to complain to the Information Commissioner’s Office if they are unhappy with how their personal information has been handled.


Chapter 7 - Agency Customers, Data Ownership & Migration

1. Agency and Employer Use of the Platform

Recruitment agencies, employers and workforce providers may use Stafty to manage candidate records, recruitment workflows, compliance documents, communications, timesheets, job bookings, invoices or related workforce activities. In most cases, those organisations decide why personal information is processed and are the Data Controller for their own recruitment and workforce data.

2. Customer Responsibility for Lawful Uploads

Customers must ensure they have a lawful basis and appropriate transparency arrangements before uploading, importing, storing or sharing personal information through the Platform. Stafty is not responsible for checking whether a customer had permission to upload particular information unless this is expressly agreed in writing.

3. Data Ownership and Control

Customer Data remains owned or controlled by the relevant customer, user or organisation that uploaded it, subject to applicable law and contract. Stafty does not claim ownership of candidate CVs, employer records, agency files, compliance documents, right to work documents or customer recruitment databases.

4. Platform Ownership

Stafty owns or licenses the Platform, software, source code, workflows, features, templates, design, database structures, documentation, service names, trade marks, know-how, analytics methods and other intellectual property used to provide the Platform. Customer access to the Platform does not transfer ownership of Stafty technology.

5. Migration from Existing Systems

During onboarding or migration, customers may transfer candidate, employer, worker, client, compliance, operational or other business records from existing systems into Stafty. The customer remains responsible for ensuring that all migrated data is accurate, complete, lawful, up to date where required, and has been collected and transferred with an appropriate legal basis.

Stafty may provide technical assistance with data migration, formatting, import, mapping or system setup. However, Stafty does not become responsible for any data collection, processing decisions, notices, consents, lawful bases, record keeping, errors, omissions or compliance issues that occurred before the data was transferred to the Platform.

Unless otherwise agreed in writing, the originating organisation remains responsible for informing relevant individuals where required, maintaining appropriate records of processing, responding to requests relating to pre-migration processing, and ensuring that any transfer of data into Stafty complies with applicable data protection laws.

6. Customer Agreements

Customers using the Platform for business, agency, recruitment or workforce purposes may be required to enter into a separate Agency Platform Agreement, Employer Agreement, Data Processing Agreement or other written contract. Those agreements govern commercial terms, processing roles, security responsibilities, support, data export, deletion and liability.

7. Submitting Candidate or Worker Information

Where a customer submits candidate or worker information to employers, agencies, clients or other third parties through the Platform, the customer is responsible for ensuring that disclosure is lawful, relevant, fair and consistent with its own privacy notice and agreements.

8. Accuracy of Customer Data

Customers and users are responsible for keeping information accurate and up to date where required. Stafty may provide tools to edit, correct, flag or remove information, but the legal responsibility for the accuracy of Customer Data normally remains with the customer acting as Controller.


Chapter 8 - Cookies, Marketing & Final Provisions

1. Cookies and Similar Technologies

Stafty may use cookies and similar technologies to operate the website and Platform, keep users signed in, remember preferences, improve performance, analyse use, secure accounts and support marketing where permitted. Non-essential cookies or similar technologies will be used only where permitted by law and, where required, with user consent.

2. Cookie Categories

Cookies may include strictly necessary cookies, functionality cookies, analytics cookies, performance cookies and marketing cookies. Strictly necessary cookies are required for the Platform to work. Optional cookies should be controlled through a cookie banner or preference tool where required.

3. Cookie Preferences

Users should be given clear information about cookies and a practical way to accept, reject or change non-essential cookie preferences where required. Cookie choices may need to be stored so the Platform can respect the user’s decision.

4. Marketing Communications

Stafty may send service messages, account notices, security alerts, operational updates and legally required communications. These are not marketing messages and may be necessary to provide the Platform. Marketing communications will be sent only where permitted by law, and users will be given a way to opt out where required.

5. Business-to-Business Communications

Where Stafty contacts business users about relevant services, product updates or commercial opportunities, it will do so in accordance with applicable data protection and electronic marketing rules. Even where consent is not required for certain business communications, Stafty will respect reasonable opt-out requests.

6. Children and Age Restrictions

The Platform is not intended for use by children. Users should not create an account or submit personal information if they are below the minimum age stated in the relevant terms or if they lack authority to use the Platform. Customers must ensure that any processing involving minors is lawful and subject to appropriate safeguards.

7. Changes to this Notice

Stafty may update this Privacy Notice & Data Protection Policy from time to time to reflect changes in law, technology, Platform features, business operations or regulatory guidance. The latest version will be made available on the website or Platform. Material changes may be notified where appropriate.

8. Contact Details

Privacy enquiries may be sent to Stafty Technologies Ltd, Radclyffe House, 66-68 Hagley Road, Birmingham, England, B16 8PF. Customers with a separate agreement should use the contact details or support channels set out in that agreement.

9. Legal Status of this Notice

This Privacy Notice is intended to provide transparent information about how personal information is handled. It does not replace any written Data Processing Agreement, Agency Platform Agreement, Employer Terms, Candidate Terms or other contractual document that applies to specific services. Where there is a conflict, the applicable signed or accepted agreement will apply to the extent permitted by law.