Candidate Privacy Notice

1. What is the purpose of this document?

iwoca Ltd (“We”, “Us”) are committed to protecting and respecting your privacy. This Privacy Notice (together with any other documents referred to herein) sets out the basis on which the personal data collected from you, or that you provide to Us, will be processed by Us in connection with Our recruitment processes. Please read the following carefully to understand Our views and practices regarding your personal data and how We will treat it.

For the purpose of the EU Regulation 2016/679 General Data Protection Regulation (“GDPR”) which includes when it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018 (the ‘UK GDPR’) the Data Controller is iwoca Ltd.

We use Ashby, an online application provided by Ashby Inc, to assist with our recruitment process. We use Ashby to process personal information as a data processor on Our behalf. Ashby is only entitled to process your personal data in accordance with Our instructions.

Where you apply for a job opening posted by Us, these Privacy Notice provisions will apply to Our processing of your personal information in addition to Our other Privacy Notice which has been provided to you separately or is available on Our Website.

Where you apply for a job opening via the application function on a job site or similar online service provider (“Partner”), you should note that the relevant Partner may retain your personal data and may also collect data from Us in respect of the progress of your application. Any use by the Partner of your data will be in accordance with the Partner’s Privacy Notice.

2. Contact details

If you have any questions about this privacy notice, you can reach out to us by emailing our Data Protection Officer (DPO) at dpo@iwoca.co.uk

3. Information we collect from you

We collect and process some or all of the following types of information from you:

  • Information that you provide when you apply for a role. This includes information provided through an online job site, via email, in person at interviews and/or by any other method.
  • In particular, We process personal details such as name, email address, address, date of birth qualifications, experience, information relating to your employment history, skills and experience that you provide to Us.
  • If you contact Us, We may keep a record of that correspondence.
  • A record of your progress through any hiring process that we may conduct.
  • Details of your visits to Ashby’s Website including, but not limited to, traffic data, location data, weblogs and other communication data, the site that referred you to Ashby’s Website and the resources that you access.

4. The data we collect about you (from third parties)

  • Ashby provides Us with the facility to link the data you provide to Us, with other publicly available information about you that you have published on the Internet – this may include sources such as LinkedIn and other social media profiles.
  • Ashby’s technology allows Us to search various databases – some publicly available and others not, which may include your personal data (include your CV or Resumé), to find possible candidates to fill Our job openings. Where We find you in this way We will obtain your personal data from these sources.
  • We may receive your personal data from a third party, such as a recruitment agency, who recommends you as a candidate for a specific job opening or for Our business more generally.
  • Previous employers, we request certain information to validate your credentials, positions held and dates of employment.
  • Background check providers, for us to assess your suitability as an employee, identity verification and a criminal record check.

5. Purposes of processing your personal data

We use information held about you in the following ways:

  • To consider your application in respect of a role for which you have applied.
  • To consider your application in respect of other roles.
  • To communicate with you in respect of the recruitment process.
  • To enhance any information that We receive from you with information obtained from third party data providers.
  • To find appropriate candidates to fill Our job openings.
  • To help Our service providers (such as Ashby and its processors and data providers) and Partners (such as the job sites through which you may have applied) improve their services.

6. Automated Decision-Making / Profiling

We may use Ashby’s technology to select appropriate candidates for us to consider based on criteria expressly identified by us, or typical in relation to the role for which you have applied. The process of finding suitable candidates is automatic, however, any decision as to who we will engage to fill the job opening will be made by Our staff.

7. Lawful basis for processing your personal data

Processing activity Lawful basis
Assessing the suitability of candidates for the open roles As a prerequisite of entering into a contract with you
Arranging and conducting interviews and tests (including recording the outcome of these assessments and discussing it internally) As a prerequisite of entering into a contract with you
Proactively researching potential candidates using their social media profiles For our legitimate interests in sourcing suitable candidates
Liaising with recruitment agencies to discuss the suitability of candidates they have referred to us For our legitimate interests in sourcing suitable candidates
Digital ID Checks - this is for UK and Irish passport holders. Digital right to work checks - this is for overseas passport holders. Digital criminal record checks - all new starters Though this is a prerequisite of entering into a contract with you, we always gain your explicit consent due to the nature of the checks
For unsuccessful candidates, retaining your personal data listed below for a period of 24 months in relation to future job opportunities: CV, Email correspondence, Interview notes, Application test scores We will obtain your Consent as part of the application process

Please note: Where you apply for a job opening through one of our recruitment partners ( Google Jobs, LinkedIn, Otta, Glassdoor etc.) via their Apply functionality, We rely on your consent, which is freely given by you during the application process, to disclose your personal data to our partners on the basis described below.

8. Disclosure of your personal data

Where you have applied for a job opening through one of our Partner’s Apply functionality, and where you have consented to this disclosure, We will disclose to Indeed certain personal data that We hold, including but not limited to a unique identifier used by Indeed to identify you, and information about your progress through Our hiring process for the applicable job opening, as well as tangible, intangible, visual, electronic, present, or future information that We hold about you, such as your name, contact details and other information involving analysis of data relating to you as an applicant for employment (collectively “Disposition Data”). Each Partner will make available to you their Privacy Notice in respect of their use of the Disposition Data on their website.

Where you have applied to a job opening through another service provider, We may disclose data similar to the Disposition Data defined above to such service provider. The service provider shall be the data controller of this data and shall therefore be responsible for complying with all applicable law in respect of the use of that data following its transfer by Us.

The personal information we have collected from you will be shared with Cifas (fraud prevention membership organisation) who will use it to prevent fraud, other unlawful or dishonest conduct, malpractice and other seriously improper conduct. If any of these are detected you could be refused certain services or employment. Your personal information will also be used to verify your identity. Further details of how your information will be used by Us and Cifas can be found here.

If we are required to do so by applicable law and regulation or by any governmental, tax, regulatory body or law enforcement agency.

9. How we store your personal data

Data Security

We take appropriate measures to ensure that all personal data is kept secure including security measures to prevent personal data from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal data to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where We are legally required to do so.

Unfortunately, the transmission of information via the internet is not completely secure. Although We will do Our best to protect your personal data, We cannot guarantee the security of your data transmitted through any online means, therefore any transmission remains at your own risk.

10. Data transfer outside of the EU

Where We store your personal data in Our own systems, it is stored on servers within the EU.

Some of the data processors we use are outside the EU, or may host your personal data outside the EU.

Whenever we transfer your personal data out of the EU, we ensure a similar degree of protection is afforded to it by ensuring that at least one of the following safeguards is implemented:

Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EU.

11. How long do we keep your personal data

We will hold all the data for 6 months unless you have given Us your express consent to hold your personal data for longer. If you have given Us your consent to hold your personal data for longer than 6 months, we will hold your data for a maximum period of 24 months after consent has been granted. Please note that once consent has been given to Us you can withdraw your consent for Us to hold your data for longer than 6 months at any time by emailing dpo@iwoca.co.uk.

Your personal information will be deleted on one of the following occurrences:

  • Once the prescribed retention period of 6 months has expired; or
  • receipt of a written request by you (or another person engaged by you) to us to withdraw your consent to retain your data for longer than 6 months.

12. Your right in connection with personal information

In certain circumstances, you have rights under data protection laws in relation to your personal data. Please click on the links below to find out more about these rights:

For more information or to exercise your data protection rights, please use the contact details above. You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to address your concerns before you approach the ICO so please contact us in the first instance.

Last updated - December 2024