Privacy Notice

BRIGHTSMITH GROUP LTD (”We”) are committed to protecting and respecting your privacy.

Any mention of “Our Group” means our subsidiaries, our ultimate holding company and its subsidiaries, our associated companies as defined in section 1159 of the UK Companies Act 2006 (our Group).

This notice sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us.

The UK General Data Protection Regulation (UK GDPR) (Regulation (EU) 2016/679) is a regulation which replaces the Data Protection Regulation (Directive 95/46/EC). The Regulation aims to harmonise data protection legislation across EU member states, enhancing privacy rights for individuals and providing a strict framework within which commercial organisations can legally operate.

The Brexit transition period ended on 31 December 2020 and the UK has now officially left the EU. The UK GDPR has been directly incorporated into UK law sitting alongside the Data Protection Act 2018.

Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.

 

For the purposes of data protection legislation in force from time to time the data controller is Brightsmith Group Ltd of 128 City Road, London, EC1V 2NX

Our nominated representative is Lauren Miller.

 

Who we are and what we do

We are a recruitment agency and recruitment business as defined in the Employment Agencies and Employment Businesses Regulations 2003 (our business). We collect the personal data of the following types of people to allow us to undertake our business;

Prospective and placed candidates for permanent or temporary roles; Prospective and live client contacts; Supplier contacts to support our services; Employees, consultants, temporary workers;

We collect information about you to carry out our core business and ancillary activities.

 

Information you give to us or we collect about you.

We use Bullhorn, an online application provided by Bullhorn Inc., to assist with our recruitment process. We use Bullhorn to process personal information as a data processor on our behalf. Bullhorn is only entitled to process your personal data in accordance with our instructions.

The information you give us or we collect about you may include your name, address, private and corporate e-mail address and phone number, identification, financial information, compliance documentation and references verifying your qualifications and experience, curriculum vitae and photograph, links to your professional profiles available in the public domain e.g. LinkedIn, Twitter, business Facebook or corporate website.

 

Information we collect from you.

We collect and process some or all of the following types of information from you:

  • Information that you provide when you apply for a role. This includes information provided through an online job site, via email, in person at interviews and/or by any other method.

  • In particular, we process personal details such as name, email address, address, date of birth qualifications, experience, information relating to your employment history, skills and experience that you provide to us.

  • If you contact us, we may keep a record of that correspondence.

  • A record of your progress through any hiring process that we may conduct.

  • Details of your visits to Bullhorn’s Website including, but not limited to, traffic data, location data, weblogs and other communication data, the site that referred you to Bullhorn's Website and the resources that you access.


Information we obtain from other sources.

This is information we obtain about you from other sources such as LinkedIn, corporate websites, job board websites, online CV libraries, or your business card.

We may receive information about you from third parties for the purposes of our recruitment services and ancillary support services.

 

Purposes of the processing and the legal basis for the processing

We use information held about you in the following ways:

To consider your application in respect of a role for which you have applied. To consider your application in respect of other roles. To communicate with you in respect of the recruitment process. To enhance any information that we receive from you with information obtained from third party data providers. To find appropriate candidates to fill our job openings. To help our service providers (such as Bullhorn and its processors and data providers) and Partners (such as the job sites through which you may have applied) improve their services.

Our legal basis for the processing of personal data is our legitimate interests, described in more detail below. We will rely on contractual obligations if we are negotiating or have entered into a placement agreement with you or your organisation or any other contract to provide services to you or receive services from you or your organisation.

 

Our Legitimate Interests

Our legitimate interests in collecting and retaining your personal data is described below:

As a recruitment business and recruitment agency we introduce candidates to clients for permanent employment, temporary worker placements or independent professional contracts.  The exchange of personal data of our candidates and our client contact details is a fundamental part of this process.

In order to support our candidates’ career aspirations and our clients’ resourcing needs, we require a database of candidate and client personal data. The database will contain historical information as well as current resourcing requirements.

To maintain, expand and develop our business we need to record the personal data of prospective candidates and client contacts.

 

Consent

Should we want or need to rely on consent to lawfully process your data we will request your consent orally, by email or by an online process for the specific activity we require consent for and record your response on our system.  Where consent is the lawful basis for our processing you have the right to withdraw your consent to this particular processing at any time.

 

Other Uses we will make of your data:

We will also use your data:

To administer our site and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes; To improve our site to ensure that content is presented in the most effective manner for you when you are using your computer or other devices; To notify you about changes to our service; To allow you to participate in interactive features of our service, when you choose to do so; As part of our efforts to keep our site safe and secure; To measure or understand the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you; To make suggestions and recommendations to you and other users of our site about goods or services that may interest you or them.

We may use Bullhorn's technology to select appropriate candidates for us to consider based on criteria expressly identified by us, or typical in relation to the role for which you have applied. The process of finding suitable candidates is automatic, however, any decision as to who we will engage to fill the job opening will be made by a member of our staff.

Do you have to provide us with personal data?

You may refuse to give us your personal and sensitive personal data. Furthermore, you have the right to ask us to delete, change or stop processing your data that we have already received or collected. If you do not provide us with personal or sensitive personal data, or if you request a restriction of processing however, we may not be able to provide you with the services that you have requested and that are stated in this policy.

 

Cookies  

Our website uses cookies. If you do not want those cookies to run then please use the disable button below. We use only session cookies on this website. We may send to you the following cookies:

(1) JSESSION_ID cookie We may use the information we obtain from your use of our cookies for the following purposes:

(1) to recognise your computer when you visit our website; (2) to improve the website's usability; (3) to analyse the use of our website; (4) to connect to 3rd party services of benefit;


Third party cookies:

When you use our website, you may also be sent third party cookies.


Google Analytics:

We use Google Analytics to track visitors experience so we can continually improve our site and provide you with the most relevant information. Google Inc's registration is a http://safeharbor.export.gov/companyinfo.aspx?id=10543. For more information on the cookies set by Google Analytics please go to: http://code.google.com/apis/analytics/docs/concepts/gaConceptsCookies.html. Google has also created their own opt-out plugin that you can get from: http://tools.google.com/dlpage/gaoptout.

 

Disclosure of your information inside and outside of the UK and the EEA

We will not share your personal information with any third parties without your express consent, including:

Any member of our group both in the UK, the EEA and outside of the EEA, clients for the purpose of introducing candidates to them; Candidates for the purpose of arranging interviews and engagements; Clients, business partners, suppliers and sub-contractors for the performance and compliance obligations of any contract we enter into with them or you; Subcontractors including email marketing specialists, event organisers, payment and other financial service providers. Analytics and search engine providers that assist us in the improvement and optimisation of our site; Credit reference agencies, our insurance broker, compliance partners and other sub-contractors for the purpose of assessing your suitability for a role where this is a condition of us entering into a contract with you.

We will only disclose your personal information to third parties:

In the event that we sell or buy any business or assets, in which case we will disclose your personal data to the prospective seller or buyer of such business or assets. If Brightsmith or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.

The lawful basis for the third party processing will include:

Their own legitimate interests in processing your personal data, in most cases to fulfil their internal resourcing needs; Satisfaction of their contractual obligations to us as our data processor; For the purpose of a contract in place or in contemplation; To fulfil their legal obligations.

 

Where we store and process your personal data

We store your personal data on the Bullhorn CRM system, and email systems within the UK and EEA.

The data that we collect from you and process using Bullhorn's Services, may/will be transferred to, and stored at, a destination outside the UK or European Economic Area (”EEA”). It may be transferred to third parties outside of the UK or the EEA for the purpose of our recruitment services. It may/will also be processed by staff operating outside the UK or the EEA who work for us or for one of our suppliers. This includes staff engaged in, among other things, our recruitment services and the provision of support services. By submitting your personal data, you agree to this processing. Brightsmith will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy notice.

In particular, your data may be accessible to i) Bullhorn's staff in the USA or ii) may be stored by Bullhorn's hosting service provider on servers in the USA as well as in the EU. The USA does not have the same data protection laws as the United Kingdom and EEA. Bullhorn, Inc. and its other US entities that process personal data participate in and have certified their compliance with the EU-U.S. Data Privacy Framework (DPF), the Swiss-U.S. DPF, and the UK Extension to the EU-U.S. DPF (UK Extension) as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal data transferred from the European Economic Area (EEA), United Kingdom (UK), and Switzerland to the United States, respectively, for the purposes of showing our customers that we adhere to a stringent privacy framework. (I pulled this from Bullhorn’s own privacy policy)

Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.

 

Retention of your data

We understand our legal duty to retain accurate data and only retain personal data for as long as we need it for our legitimate interests and that you are happy for us to do so.  Accordingly, we have a data retention notice and run data routines to remove data that we no longer have a legitimate interest in maintaining.

We do the following to try to ensure that the data we hold on you is accurate:

Prior to making an introduction we check that we have accurate information about you. We keep in touch with you so you can let us know of changes to your personal data.

We may store and handle your data in the following ways:

We may archive part or all of your personal data, and retain it on our Customer Relationship Manager (CRM) system.

Our current retention notice is available upon request.  

 

Your rights

Mobile information will not be shared with third parties/affiliates for marketing/promotional purposes. All the previously mentioned categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

By providing your phone number and opting into our SMS notifications, you confirm that you are the owner or an authorized user of the number provided. You consent to receive automated text messages (SMS, MMS) regarding interview schedules, service updates, job opportunities, and other relevant notifications. We will not use your phone number or SMS for marketing purposes. Message frequency may vary based on your interaction with us.


Opt Out Instructions

Participation in automated texts is entirely voluntary. You may opt out at any time:

  • To stop receiving messages, reply “STOP,” “END,” “CANCEL,” “UNSUBSCRIBE,” or “QUIT” to any SMS from us.

  • You may also email info@brightsmithgroup.com with your opt-out request.

  • After opting out, you will receive a confirmation message, and no further texts will be sent unless you re-subscribe.

Our site may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliate. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.

 

The UK GDPR provides you with the right to:

Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected. Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below). Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes. Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it. Request the transfer of your personal information to another party in certain formats, if practicable. Make a complaint to a supervisory body which in the United Kingdom is the Information Commissioner’s Office. The ICO can be contacted through this link: https://ico.org.uk/concerns/.

 

Access to information  

The Data Protection Act 2018 and the UK GDPR give you the right to access information held about you.  We also encourage you to contact us to ensure your data is accurate and complete. Your right of access can be exercised in accordance with the Act and the UK GDPR.

A subject access request should be submitted to info@brightsmithgroup.com. No fee will apply unless the requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character. In such circumstances, we may charge a fee or refuse to act on the request.

 

Changes to our privacy notice  

Any changes we make to our privacy notice in the future will be posted on this page and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes to our privacy notice.

 

Contact  

Questions, comments and requests regarding this privacy notice are welcomed and should be addressed to:
email: info@brightsmithgroup.com
phone: +44 020 4578 3657