Candidate privacy policy

INTRODUCTION

PPRO (“we”, “us”) are committed to protecting and respecting your privacy. This Privacy Notice sets out the basis on which the personal data collected from you, or that you provide to us, will be processed by us in connection with our recruitment processes.

For the purpose of the General Data Protection Regulation (“GDPR”) the Data Controller is PPRO.

We use Ashby, an online software product, to assist with our recruitment process. We use Ashby to process personal information as a data processor on our behalf. Ashby will not separately use our data for its own purposes.

For more information on Ashby’s own Privacy Policy see here: https://www.ashbyhq.com/resources/privacy.

WHAT PERSONAL DATA WE COLLECT?

At PPRO we collect and use the following information about you, to the extent provided by you and permitted under applicable law:

  • Contact information (such as name, address, email address, and phone number);
  • Experience information (such as education, skills, CVs, photographs, references, employee records);
  • Demographic information (such as age, date of birth, gender). We use this data to ensure we’re giving job applicants equal opportunity and treatment regardless of their demographic. Providing this data won’t affect your application in any way, and you are free to omit any information that you don’t want to share.  In addition, we may use this data in an aggregated and anonymised format in order to track our Diversity and Inclusion progress.
  • Interview records;
  • Data from public profiles;

HOW IS YOUR INFORMATION COLLECTED?

We collect personal information from the following sources:

  • Yourself the candidate, when you apply for a role with us directly. This includes all the information in your CV,  provided through an online application, via email, in person at interviews and/or by any other method;
  • Zinc, our background check provider only after the candidate accepts the job offer. We collect the following categories of data: name, your addresses from the last three years, references, criminal record, work permit data, national identification numbers, and proof of address document. For more information on Zinc’s privacy policy see here: https://zincwork.com/privacy;
  • Public sources, including social media platforms i.e. LinkedIn;
  • Third party recruitment platforms i.e. Cord and agencies;

WHY ARE WE COLLECTING YOUR DATA?

We process your personal data only for the following purposes related to recruitment:

  • Assess your skills, qualifications, and suitability for the role;
  • Carry out background and reference checks, where applicable;
  • Communicate with you about the recruitment process;
  • Keep records related to our hiring processes;

WHAT IS OUR LAWFUL BASIS FOR PROCESSING YOUR DATA?

Consent – when, after we have informed you of the purpose of the processing, you freely, specifically, unambiguously allow us, we will use a recording and/or automatic transcription of your interviews to assist us in creating your internal candidate record; the transcription will be reviewed by our staff for accuracy;

Contract – to take steps to assess your suitability for the vacancy prior to entering into an employment contract (necessity for hiring decisions);

Legal obligation – Ensure we are complying with our legal and regulatory obligations i.e. background checks to prevent illegal working.;

Legitimate interest – to actively reach out to potential new or previously screened candidates and to use your data to improve our application or recruitment process, we do so on the basis that it is in our legitimate interests to ensure we recruit the best possible candidates.

PPRO may use automated systems and artificial intelligence tools as part of our recruitment process, for example to help screen applications, identify relevant skills, or support scheduling and communication. These tools are used to assist our recruiters and hiring managers, not to replace their judgment. No decision about whether to progress, reject, or hire a candidate is made solely by an automated system – a human decision-maker always reviews the relevant information and makes the final call.

HOW LONG WILL WE USE YOUR INFORMATION FOR?

Successful applicants

If your application for employment is successful, personal data gathered during the recruitment process will be transferred to our HR management system and retained during your employment.

Unsuccessful applicants

If your application for employment is unsuccessful, we will hold your data on file for up to 2 years after the end of the relevant recruitment process for our legitimate interest. This will ensure that we are able to contact you about relevant future opportunities. At the end of that period we will securely destroy your personal data in accordance with applicable laws and regulations.

For the establishment, exercise or defence of legal claims, personal data will be deleted after termination of the court action or legal proceeding as appropriate.

HOW DO WE PROTECT YOUR DATA?

We take appropriate measures to ensure that all personal data is kept securely, including security measures to prevent personal data from being accidentally lost, or used or accessed in any unauthorised way. We limit access to your personal data to those employees who have a business need-to-know.  They will only process your personal data on our instructions and they are bound in writing to confidentiality or are under an appropriate statutory obligation of confidentiality. 
 

WHAT ARE YOUR RIGHTS?

Data subjects enjoy a defined suite of rights in respect of the processing of their personal data. Under Chapter III of Regulation (EU) 2016/679 (“GDPR”), these comprise:

  • the right of access (Article 15),
  • the right to rectification (Article 16),
  • the right to erasure, or “right to be forgotten” (Article 17),
  • the right to restriction of processing (Article 18),
  • the right to data portability (Article 20),
  • the right to object to processing (Article 21), and rights in relation to automated individual decision-making, including profiling (Article 22).

The equivalent rights subsist under the UK GDPR and the Data Protection Act 2018 (“DPA 2018”).

In addition, and without prejudice to any other administrative or judicial remedy, every data subject has the right to lodge a complaint with a supervisory authority:

  • in the European Economic Area, the competent supervisory authority of the Member State of the data subject’s habitual residence, place of work, or place of the alleged infringement (Article 77(1) GDPR);
  • in the United Kingdom, the Information Commission (section 165(2) DPA 2018). This right is exercisable independently of, and does not require prior recourse to, any complaints procedure operated by the controller. Under section 164A DPA 2018 (inserted by section 103 of the Data (Use and Access) Act 2025), you can also complain to the controller PPRO Financial Ltd. directly; however, use of that procedure remains optional  for you and is not a precondition to lodging a complaint with the Information Commissioner under section 165.

To do any of the things above, please contact our Data Protection Officer (DPO) at data@ppro.com. We will acknowledge your request within 2 working days. UK & EU data protection laws give us one month to see your request to completion.

WHO SHOULD I CONTACT WITH QUESTIONS?

For any further information regarding your rights or have questions about the use of your Personal Data, please contact data@ppro.com we will endeavour to help you as quickly as possible.

If you are still not happy, you may lodge a complaint with your relevant supervisory authority or other public body with responsibility for enforcing data protection or privacy laws.

Last Updated: 16 September 2026