Privacy Notice & Data Protection Policy
Version 1.0 | Last Updated: July 2026
This Privacy Notice & Data Protection Policy explains how Stafty Technologies Ltd collects, uses, stores, shares and protects personal information when providing the Stafty Platform and related services.
Stafty is a software platform designed to help recruitment agencies, employers and workforce providers manage recruitment, compliance, onboarding, workforce administration and related business activities through a secure cloud-based platform.
We are committed to processing personal information fairly, lawfully and transparently in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations and other applicable UK legislation.
This document should be read together with our Terms of Platform Use, Cookie Policy, Data Processing Agreement, Agency Platform Agreement, Identity Verification Policy and any other written agreement that applies to the relevant service.
The Platform is operated by Stafty Technologies Ltd, company number 17257359, registered office Radclyffe House, 66-68 Hagley Road, Birmingham, England, B16 8PF. References to Stafty, we, our or us mean Stafty Technologies Ltd unless otherwise stated.
Stafty is a software platform and technology provider. We develop, maintain and operate software that enables organisations to manage recruitment and workforce-related activities digitally.
The Platform may include job advertising, candidate management, employer management, compliance monitoring, secure document storage, identity verification, timesheets, messaging, notifications, reporting, AI-assisted productivity features and integrations with approved third-party services.
Stafty does not act as the employer of candidates or workers unless this is expressly agreed in a separate written agreement. We do not make recruitment decisions on behalf of customers. The Platform provides technology that enables customers to manage their own recruitment and workforce processes.
This Privacy Notice applies whenever personal information is collected or processed through the Stafty website, Platform, mobile applications where available, customer support services, onboarding activities, account registration, identity verification, communications, integrations, demonstrations, webinars or other services operated by Stafty.
It applies to recruitment agencies, employers, candidates, workers, contractors, business contacts, website visitors and any person whose personal information is processed through the Platform.
Platform means the Stafty software platform, website, mobile applications, APIs and any related online services provided by Stafty Technologies Ltd.
Customer means any recruitment agency, employer, organisation or business using the Platform.
Agency means a recruitment business using the Platform.
Employer means an organisation using the Platform to recruit, engage or manage workers or candidates.
Candidate means an individual whose information is uploaded, stored or processed through the Platform for recruitment or workforce purposes.
Worker includes employees, contractors, temporary workers, agency workers, consultants and individuals engaged through a Customer.
Customer Data means information uploaded, created or stored by or on behalf of a Customer while using the Platform.
Personal Data has the meaning given under UK GDPR.
Processing includes collecting, storing, organising, updating, accessing, sharing, transferring, deleting or otherwise handling personal information.
Stafty processes personal information lawfully, fairly and transparently. We collect only what is necessary, restrict access to authorised persons, retain information only for as long as needed, and apply appropriate technical and organisational measures to protect information processed through the Platform.
This chapter explains when Stafty Technologies Ltd acts as a Data Controller, when it acts as a Data Processor and how responsibilities are allocated between Stafty, agencies, employers and other customers. This distinction is important because it determines who is responsible for deciding why and how personal data is processed.
Stafty acts as a Data Controller when we determine the purposes and means of processing personal information for our own business, legal, security or platform administration purposes. In these cases, we are responsible for ensuring that processing is fair, lawful and transparent.
Examples include website enquiries, direct platform registration, customer support, billing, account administration, security monitoring, fraud prevention, platform analytics, service improvement, identity verification carried out by Stafty, direct marketing by Stafty and legal compliance.
Where an agency, employer or other customer uses the Platform to manage its own candidates, workers, staff, clients, vacancies or recruitment records, the customer will normally be the Data Controller. In those circumstances, Stafty acts as a Data Processor and processes personal data only on documented instructions from the customer and in accordance with the applicable Data Processing Agreement.
Customers are responsible for ensuring they have a lawful basis to collect, upload, store, share and otherwise process personal information through the Platform. Customers are also responsible for providing privacy notices to their candidates, workers, employees, clients and other relevant individuals where they act as Data Controller.
Where Stafty acts as a Data Controller, individuals may contact Stafty directly to exercise their rights. Where Stafty acts as a Data Processor, requests should normally be directed to the relevant customer. Stafty will provide reasonable assistance to the customer in accordance with the applicable agreement and law.
When an agency or employer migrates data into Stafty, the originating organisation remains responsible for ensuring that the data has been collected lawfully and can be transferred to the Platform. Stafty processes migrated data for platform onboarding, migration, hosting, support and related services only.
Customer Data remains owned or controlled by the customer or relevant user who uploaded it, subject to applicable law and contract. Stafty does not claim ownership of customer recruitment records, candidate files, compliance documents or employer data. Stafty owns the Platform, software, databases, workflows, templates, documentation, analytics structures and intellectual property used to provide the services.
This chapter explains the main categories of personal information processed through the Platform and the lawful bases that may apply. Not every category will apply to every user. The information processed depends on the services used, the customer configuration and the role of the person using or appearing on the Platform.
We may process IP address, device information, browser type, approximate location derived from technical data, pages visited, referral source, cookie preferences, enquiry form details and communication preferences. This helps us operate the website, maintain security, respond to enquiries and understand how the site is used.
We may process names, work email addresses, phone numbers, organisation names, job titles, login credentials, role permissions, authentication records, support tickets, usage logs and security records. This information is required to provide access to the Platform and keep accounts secure.
Customer use of the Platform may involve candidate names, contact details, CVs, employment history, qualifications, training records, availability, interview notes, job applications, messages, right to work information, visa information, proof of address, compliance documents, professional registrations, references, timesheets, work records and other recruitment-related data.
We may process business contact details, authorised user information, billing information, vacancy details, placement records, communications, account configuration, service usage and contractual records.
The Platform may allow customers to upload or process information that is sensitive, including health information, disability adjustment information, equal opportunity monitoring information, background check information, criminal record check information, DBS status, right to work evidence and professional compliance information. Customers are responsible for ensuring that any such information is processed lawfully and only where necessary.
Stafty relies on different lawful bases depending on the processing activity. These may include performance of a contract, legitimate interests, legal obligation, consent and, where required, explicit consent or another applicable condition for special category information. Where a customer is the Data Controller, the customer is responsible for identifying and documenting its own lawful basis.
|
Processing activity |
Likely lawful basis |
Purpose / notes |
|
Account creation and access |
Contract / legitimate interests |
To create and manage secure user accounts and provide platform access. |
|
Customer support |
Contract / legitimate interests |
To respond to support requests, investigate issues and maintain service quality. |
|
Platform security and audit logs |
Legitimate interests / legal obligation |
To detect misuse, prevent fraud, protect systems and investigate incidents. |
|
Billing and commercial administration |
Contract / legal obligation |
To manage subscriptions, invoices, payment records and accounting obligations. |
|
Identity verification |
Contract / legitimate interests / legal obligation where applicable |
To reduce fraud, confirm account integrity and enable selected features. |
|
Marketing to business contacts |
Consent or legitimate interests, subject to PECR |
To send relevant service information where permitted and allow opt-out. |
|
Customer recruitment processing |
Customer-determined basis |
The customer normally acts as Controller and determines the lawful basis. |
|
Legal claims and regulatory compliance |
Legal obligation / legitimate interests |
To comply with law and protect legal rights. |
The table is intended to describe common Stafty processing activities. Where a customer acts as Controller, the customer must maintain its own lawful basis assessment and privacy information.
Stafty may provide identity verification features to help protect the Platform, reduce fraud, protect users and enable selected premium features. Identity verification may be required for certain account types, higher-risk activities, access to sensitive platform areas or features that require a higher level of trust.
Verification may include reviewing a government-issued identification document, proof of address where appropriate, visa or right to work evidence where relevant, and a recent selfie or photograph provided by the user. The selfie is used to support a standard visual comparison with the identity document.
Stafty does not use biometric identification, facial recognition technology, automated facial matching, biometric templates or biometric profiling as part of its standard identity verification process. The process is based on document review and ordinary visual comparison where required. Stafty does not create biometric templates for the purpose of uniquely identifying users.
Identity verification helps reduce risk but does not guarantee that every person, document or account is genuine. Verification decisions may involve manual review, quality checks, fraud indicators and reasonable platform controls. Stafty may refuse, suspend or restrict access where verification fails, appears suspicious or cannot be completed.
Identity verification information will be retained only for as long as reasonably necessary for fraud prevention, security, legal, contractual, audit or dispute purposes. Where a shorter retention period is suitable, Stafty may delete or restrict access to verification material while retaining a verification status record.
The Platform may include AI-assisted tools to support productivity, drafting, searching, summarising, matching, profile preparation, CV support, workflow recommendations or administrative assistance. These tools are intended to assist users and should not be treated as final decisions or professional advice.
Users and customers remain responsible for reviewing AI-assisted outputs before using them. Stafty does not guarantee that AI-assisted outputs will be complete, accurate, suitable, lawful or free from bias. Recruitment, employment, compliance and commercial decisions must be made by authorised humans using appropriate judgement.
Stafty may use automated tools to organise, prioritise, flag or suggest information. Unless clearly stated otherwise in a separate notice or agreement, Stafty does not make solely automated decisions that produce legal or similarly significant effects for individuals. Where customers configure or rely on automated tools, they are responsible for ensuring appropriate human review and lawful use.
Stafty may use technical checks, audit logs, account signals, document status records and user behaviour indicators to detect possible fraud, account abuse, unauthorised access, spam, platform scraping, fake profiles, false documents or misuse of the Platform.
Stafty may share personal information where necessary to provide the Platform, comply with law, protect legal rights, maintain security, investigate misuse or fulfil contractual obligations. We do not sell personal information.
Where a user applies for a role, communicates with an employer or agency, is invited to a platform workflow, uploads information for a customer or is managed through the Platform by a customer, relevant information may be shared with that customer according to the Platform configuration and the customer relationship.
Stafty may use trusted service providers for hosting, infrastructure, email delivery, SMS delivery, support tools, analytics, security monitoring, payment processing, file storage, backups and other operational services. Where these providers process personal information for Stafty, appropriate contractual protections will be used.
We may disclose information to regulators, law enforcement, courts, professional advisers, insurers, auditors or other parties where required by law, necessary to protect legal rights, necessary to prevent fraud, or required to investigate misuse of the Platform.
Where personal information is transferred outside the United Kingdom, Stafty will take steps designed to ensure the transfer is lawful. This may include use of adequacy regulations, International Data Transfer Agreements, approved addenda, contractual safeguards or other mechanisms permitted under UK data protection law.
Stafty applies appropriate technical and organisational measures having regard to the nature, scope, context and purpose of processing and the risks to individuals. Measures may include access controls, authentication, role-based permissions, encryption where appropriate, secure hosting, logging, monitoring, backups, least privilege access, vulnerability management and staff confidentiality obligations.
Although Stafty takes security seriously, no internet-connected platform or electronic storage system can be guaranteed to be completely secure. Users and customers remain responsible for maintaining secure devices, strong passwords, safe account access and appropriate internal controls.
Customers are responsible for managing their authorised users, removing access for leavers, assigning appropriate roles, preventing credential sharing, training staff and ensuring that information is uploaded, accessed and shared only by authorised persons.
If Stafty becomes aware of a personal data breach affecting personal information for which it is responsible, it will assess the incident and take appropriate steps in accordance with applicable law and contractual obligations. Where Stafty acts as a Processor, it will notify the relevant Controller without undue delay after becoming aware of a relevant breach.
Stafty keeps personal information only for as long as reasonably necessary for the purposes for which it was collected, including providing the Platform, fulfilling contractual obligations, complying with legal requirements, resolving disputes, preventing fraud, maintaining security and enforcing rights.
Where Stafty acts as a Processor, the customer is normally responsible for deciding how long Customer Data should be retained. Customers should configure, delete, export or request deletion of Customer Data in accordance with their own retention policies and legal obligations.
The retention periods below are general guidance and may vary depending on contract terms, legal obligations, disputes, security needs or customer instructions. Stafty may retain limited records for longer where necessary to establish, exercise or defend legal claims.
|
Data category |
Indicative retention approach |
|
Website enquiries |
Up to 24 months from last contact unless needed longer |
|
Customer account records |
For the account term plus up to 7 years for contractual and legal records |
|
Support tickets |
Up to 36 months unless needed for security, service quality or disputes |
|
Billing and accounting records |
Normally 6 to 7 years to meet tax and accounting obligations |
|
Security logs and audit records |
Normally 12 to 36 months, or longer for investigations |
|
Identity verification status |
For the account term and a reasonable period afterwards |
|
Identity documents and selfies |
Only as long as necessary for verification, fraud prevention, audit, legal or dispute purposes |
|
Customer Data |
As instructed by the customer or configured in the Platform |
|
Marketing preferences |
Until changed or withdrawn, with suppression records retained as necessary |
Retention should be reviewed periodically and adjusted where required by law, contract, security requirements or customer instructions.
Individuals may have rights under UK data protection law including the right to be informed, access personal information, request correction, request deletion, restrict processing, object to processing, request portability and withdraw consent where consent is relied upon. These rights are subject to legal limits and exemptions.
Where Stafty acts as Controller, individuals may contact Stafty using the details in this notice. We may need to verify identity before responding. We will respond within the period required by law unless an extension is permitted.
Where Stafty acts as Processor for a customer, requests should normally be directed to that customer. Stafty will not usually respond directly to a data subject request about Customer Data without instructions from the relevant customer unless required by law.
Individuals may raise privacy concerns with Stafty using the contact details in this notice. Individuals also have the right to complain to the Information Commissioner’s Office if they are unhappy with how their personal information has been handled.
Recruitment agencies, employers and workforce providers may use Stafty to manage candidate records, recruitment workflows, compliance documents, communications, timesheets, job bookings, invoices or related workforce activities. In most cases, those organisations decide why personal information is processed and are the Data Controller for their own recruitment and workforce data.
Customers must ensure they have a lawful basis and appropriate transparency arrangements before uploading, importing, storing or sharing personal information through the Platform. Stafty is not responsible for checking whether a customer had permission to upload particular information unless this is expressly agreed in writing.
Customer Data remains owned or controlled by the relevant customer, user or organisation that uploaded it, subject to applicable law and contract. Stafty does not claim ownership of candidate CVs, employer records, agency files, compliance documents, right to work documents or customer recruitment databases.
Stafty owns or licenses the Platform, software, source code, workflows, features, templates, design, database structures, documentation, service names, trade marks, know-how, analytics methods and other intellectual property used to provide the Platform. Customer access to the Platform does not transfer ownership of Stafty technology.
During onboarding or migration, customers may transfer candidate, employer, worker, client, compliance, operational or other business records from existing systems into Stafty. The customer remains responsible for ensuring that all migrated data is accurate, complete, lawful, up to date where required, and has been collected and transferred with an appropriate legal basis. Stafty may provide technical assistance with data migration, formatting, import, mapping or system setup. However, Stafty does not become responsible for any data collection, processing decisions, notices, consents, lawful bases, record keeping, errors, omissions or compliance issues that occurred before the data was transferred to the Platform. Unless otherwise agreed in writing, the originating organisation remains responsible for informing relevant individuals where required, maintaining appropriate records of processing, responding to requests relating to pre-migration processing, and ensuring that any transfer of data into Stafty complies with applicable data protection laws.
Customers using the Platform for business, agency, recruitment or workforce purposes may be required to enter into a separate Agency Platform Agreement, Employer Agreement, Data Processing Agreement or other written contract. Those agreements govern commercial terms, processing roles, security responsibilities, support, data export, deletion and liability.
Where a customer submits candidate or worker information to employers, agencies, clients or other third parties through the Platform, the customer is responsible for ensuring that disclosure is lawful, relevant, fair and consistent with its own privacy notice and agreements.
Customers and users are responsible for keeping information accurate and up to date where required. Stafty may provide tools to edit, correct, flag or remove information, but the legal responsibility for the accuracy of Customer Data normally remains with the customer acting as Controller.
Stafty may use cookies and similar technologies to operate the website and Platform, keep users signed in, remember preferences, improve performance, analyse use, secure accounts and support marketing where permitted. Non-essential cookies or similar technologies will be used only where permitted by law and, where required, with user consent.
Cookies may include strictly necessary cookies, functionality cookies, analytics cookies, performance cookies and marketing cookies. Strictly necessary cookies are required for the Platform to work. Optional cookies should be controlled through a cookie banner or preference tool where required.
Users should be given clear information about cookies and a practical way to accept, reject or change non-essential cookie preferences where required. Cookie choices may need to be stored so the Platform can respect the user’s decision.
Stafty may send service messages, account notices, security alerts, operational updates and legally required communications. These are not marketing messages and may be necessary to provide the Platform. Marketing communications will be sent only where permitted by law, and users will be given a way to opt out where required.
Where Stafty contacts business users about relevant services, product updates or commercial opportunities, it will do so in accordance with applicable data protection and electronic marketing rules. Even where consent is not required for certain business communications, Stafty will respect reasonable opt-out requests.
The Platform is not intended for use by children. Users should not create an account or submit personal information if they are below the minimum age stated in the relevant terms or if they lack authority to use the Platform. Customers must ensure that any processing involving minors is lawful and subject to appropriate safeguards.
Stafty may update this Privacy Notice & Data Protection Policy from time to time to reflect changes in law, technology, Platform features, business operations or regulatory guidance. The latest version will be made available on the website or Platform. Material changes may be notified where appropriate.
Privacy enquiries may be sent to Stafty Technologies Ltd, Radclyffe House, 66-68 Hagley Road, Birmingham, England, B16 8PF. Customers with a separate agreement should use the contact details or support channels set out in that agreement.
This Privacy Notice is intended to provide transparent information about how personal information is handled. It does not replace any written Data Processing Agreement, Agency Platform Agreement, Employer Terms, Candidate Terms or other contractual document that applies to specific services. Where there is a conflict, the applicable signed or accepted agreement will apply to the extent permitted by law.