The Trust Centre.

GDPR, security, infrastructure, data lifecycle, auditability, client isolation. Everything an enterprise or agency buyer needs to green-light Talent Hub Intelligence. Transparent. Auditable. Yours.

GDPR Principles

Six principles.Engineered in, not bolted on.


We comply with the UK GDPR, the EU GDPR (where applicable), and the Isle of Man Data Protection Act 2018. Each statute sets out the same six principles — and each one shapes how the platform is designed, not just what the policy says.

Lawful, fair and transparent

Every candidate sees clear, plain-language consent screens. Every recruiter action is logged. Nothing happens silently.

Purpose limitation

Data collected for one purpose isn't reused for another. Candidate data is for matching candidates to roles — full stop.

Data minimisation

We only store what the platform actually needs to work. Optional fields stay optional. Nothing is harvested in the background.

Accuracy

Candidates can update their own profile any time. Recruiters can correct records on request. Inaccurate data is never load-bearing.

Storage limitation

You set the retention rules per data category. Old records are flagged for review or auto-purged on schedule.

Integrity & confidentiality

Encryption in transit (TLS 1.3) and at rest (AES-256). Isolated instances. Role-based access control. Daily backups, geographically redundant.

Your Rights

Six rights.All built into the platform.


Under UK GDPR, every data subject has six rights. We don't make you fill in a form to exercise them — they're surfaced inside the candidate portal.

Right 01 · Access

The right to access

See exactly what's held about you, how it's being used, and who has access — at any time, from the candidate portal.

01In-platform view

All fields, all communications, all applications — visible in the portal in plain English.

02Subject Access Request

One-click export of the full record. Delivered within statutory timeframes.

Right 02 · Rectification

The right to rectification

Correct anything inaccurate or incomplete — directly, or with a single recruiter touch.

01Self-edit

Candidates update their own profile fields directly in the portal.

02Audit-tracked changes

Every edit timestamped. The before/after is preserved for audit.

Right 03 · Erasure

The right to be forgotten

Request deletion of personal data and have it purged across every system — primary, backups, audit logs (where legally permitted).

01One-click request

Candidates initiate erasure from inside the portal — no email chains required.

02Backup propagation

Deletion cascades into backup rotations on the documented schedule.

03Legal-hold awareness

The platform flags any record under legal hold so you can act compliantly.

Right 04 · Restriction

The right to restrict processing

Pause processing while a dispute is resolved — the record stays, but no matching, no comms, no exports.

01Processing freeze

Toggle a candidate out of all automated workflows with a single setting.

02Visible status

Frozen records are clearly flagged for every recruiter who views them.

Right 05 · Portability

The right to data portability

Take your data with you — in a structured, commonly-used, machine-readable format.

01JSON + PDF export

Complete profile data delivered in both human-readable and machine-readable formats.

02No lock-in

Your data isn't held hostage — export anytime, regardless of subscription status.

Right 06 · Objection

The right to object

Object to specific types of processing — marketing emails, automated matching, profiling — with granular control per candidate.

01Granular preferences

Per-channel and per-category opt-outs — not all-or-nothing.

02Honoured immediately

Objections take effect in real-time. No queued sends, no exceptions.

Where Your Data Lives

Hosted on certifiedEuropean infrastructure.


Talent Hub Intelligence runs on OVHcloud — Europe's largest sovereign cloud provider. Your data stays in UK or EU data centres, governed by UK and EU law.

Hosting Partner · OVHcloud

OVHcloud — sovereign European cloud

Dedicated bare-metal servers and dedicated VMs in OVH's UK and EU regions. No US-data-flow dependencies for primary processing. ISO-certified across the full stack.

Region UK / EU

Certifications & Audits

ISO 27001

Information security management.

ISO 27017

Cloud-specific security controls.

ISO 27018

Personal-data protection in the cloud.

ISO 27701

Privacy information management.

SOC 1 & SOC 2

Audited service organisation controls.

HDS

Healthcare-grade data hosting.

PCI DSS

Payment-card industry security.

UK & EU GDPR

Full statutory compliance, audited annually.

Security

Defence in depth —at every layer.


Encryption, isolation, audit, backup, access control — engineered in from day one. Not a bullet point added when the contract demanded it.

Encryption

In transit & at rest

TLS 1.3 for all traffic. AES-256 encryption at rest. Keys rotated on the documented schedule, never reused across instances.

Isolation

Single-tenant by design

Each client runs on its own dedicated instance. No shared database. No cross-client query paths. No accidental data bleed.

Audit

Every change recorded

Every recruiter action, every candidate edit, every system event — timestamped and stored in an immutable audit trail.

Backup

Daily, geographically redundant

Automated daily backups to a separate OVH region. Restore-tested on a defined cadence. Documented RTO and RPO.

Access

Role-based, MFA-enforced

Granular roles and permissions. Multi-factor authentication for all recruiter accounts. SSO integration available.

Incident

48-hour breach notification

Documented incident-response process. We commit to notifying you within 48 hours of becoming aware of a personal data breach — ahead of the statutory 72-hour window — so you can meet your own ICO obligations with time to spare.

Data Lifecycle

From collectedto erased.


Every piece of candidate data follows a defined journey — and a defined end. You configure the retention rules; the platform honours them automatically.

01

Collected — with explicit consent

Candidates choose what to share. Optional fields stay optional. Consent records are timestamped and version-tracked.

02

Processed — for matching only

Data is used to score the candidate against open roles. No silent secondary use. No external sharing without explicit additional consent.

03

Retained — on your schedule

You define retention periods per data category. Candidates can also set their own opt-out date.

04

Reviewed — when retention hits

The platform surfaces records approaching their retention limit. Recruiters can extend (with renewed consent) or let the auto-purge proceed.

05

Erased — across all systems

Deletion cascades to primary storage, backup rotations, and indexes. Audit logs retain the fact of deletion, not the deleted data itself.

06

Retrievable — for 30 days after exit

If your subscription ends, your Client Platform is preserved offline for a 30-day Retention Period. During that window we can return your data in a commonly used, machine-readable format. After 30 days, the instance is permanently and securely destroyed.

Have compliance questions? Talk to our DPO.

We're happy to walk through our security posture, share our DPA template, or answer specific questions about how your team's data would be handled. No salesperson — just a direct conversation.