Theo Solutions Ltd acts as both a data controller (when collecting candidate data) and a data processor (when handling client information). We are committed to full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. GDPR Principles
We adhere to the seven key principles of GDPR, ensuring that personal data is:
- Processed lawfully, fairly, and transparently.
- Collected only for specified, explicit, and legitimate purposes.
- Adequate, relevant, and limited to what is necessary.
- Accurate and kept up to date.
- Stored no longer than necessary.
- Processed securely to ensure confidentiality and integrity.
- Managed responsibly with accountability measures in place.
2. Data Processing Activities
We process personal data for the following purposes:
- Candidates: CVs, job applications, references, right-to-work documents, and compliance checks.
- Clients: Vacancy details, contracts, and invoicing data.
- Employees: Payroll, HR, and performance records.
3. Rights of Data Subjects
Under the UK GDPR, individuals have the right to:
- Request access to their personal data.
- Request correction or deletion of inaccurate or outdated data.
- Withdraw consent for processing where applicable.
- Request restriction or object to certain types of processing.
- Request data portability where legally applicable.
We are committed to responding to all data subject requests within the statutory timeframe.
4. International Data Transfers
Where personal data is transferred outside the UK, we ensure that appropriate safeguards are in place to protect the data in line with GDPR requirements. This may include recognised legal mechanisms and agreements that uphold equivalent standards of protection.
5. Data Breach Policy
In the event of a personal data breach:
- We will assess the risk to individuals and, where legally required, notify the Information Commissioner’s Office (ICO) within 72 hours.
- Where there is a high risk to individuals’ rights and freedoms, we will notify affected individuals without undue delay.
6. Contact & Complaints
If you have any queries regarding how your data is processed or wish to exercise your GDPR rights, please contact us:
- Email: info@theosolutions.co.uk
- Phone: +44 74 2423 8485
- Address: Marlborough House, 32-36 Hazelwood Road, Northampton, NN1 1LN