Rubicon Consulting (UK) Ltd - Data Protection Policy
As a recruitment company Rubicon Consulting (UK) Ltd (Rubicon) processes personal data in relation to its own staff, work-seekers and individual client contacts. It is vitally important that we abide by the principles of the Data Protection Act 1998 set out below.
Throughout this Privacy and Data Protection Policy, “we” and “us” refer to Rubicon Consulting (UK) Ltd
The purpose of this Privacy Notice is to tell you what information we collect from you, how and when it may be collected and what happens to it.
1. What information might we collect about you?
Personal Information is any information which can be used to directly or indirectly identify an individual, such as your name, home or work address, telephone number, email address, bank details or tax codes
When you interact with us in the ways described below, we may ask you for the following information:
- personal and contact details (for example your name, email address, date of birth, gender and your choice of language with which you wish to interact with us);
- personal and contact details you give us when subscribing to receive emails, newsletters or marketing information from us;
- during pre-assignment vetting we will request details from you including, your name, your work history, qualifications, contact details (such as email, telephone number and home address), your right to work documents, details required for equality and discrimination legislation checks and your personal preferences, choices and requirements specific to particular requests or services;
- details of your education, employment history, bank details and national insurance number, references, right to work and other information you tell us about yourself (e.g. the information contained within your CV) when you engage with us for the provision of services;
- information we collect via cookies or similar technology stored on your device, your IP address;
- information from social media activity (such as likes, shares and tweets) when you interact with us on social media;
- information you provide if you report a problem with our website or service;
- additional information which you provide voluntarily and/or which we may ask from you to better understand you and your interests.
We may also collect sensitive Personal Information about you (including details of your physical or mental health, racial or ethnic origin, criminal allegations or offences, trade union membership and/or other sensitive Personal Information that you may choose to provide to us voluntarily from time to time.
2. How, when and why do we collect your Personal Information?
How and when do we collect your Personal Information?
We may collect your Personal Information when you apply for a role through us (or otherwise contact us from time to time) by:
- responding to an advert on a job board or other website;
- by directly contacting our business;
- by filling in an application form in a branch;
- when you speak to one of our consultants by telephone; or
- another organisation passes your details to us.
Why do we collect your Personal Information?
We collect and use your Personal Information because it is necessary to obtain certain details including Personal Information from you in the work-searching process and it is in our legitimate interests in the course of operating our business, including:
- responding to your queries;
- providing work-finding services and/or information to you;
- transmitting Personal Information between our offices or functions for internal administrative purposes;
- setting you up on a work assignment with a client;
- hosting and maintaining our websites;
- ensuring network and information security; and/or
- carrying out direct marketing.
We will only collect, use and handle your Personal Information when:
- it is necessary for our legitimate interests in connection with carrying out our business, provided in each case, these interests are in line with applicable law and your legal rights;
- and/or where you have agreed;
- and/or where this is necessary for legal obligations which apply to us.
3. How we use the Personal Information that you provide to us
We undertake the following processing of your Personal Information on the legal basis that it is necessary to perform the contract with you and to provide the services we have agreed to provide to you. Where we have not entered into a contract with you, we may also carry out this processing where we consider it is necessary in our legitimate business interests to deal with requests, enquiries or comments you have made to us.
Submission of details to clients – if you register to apply for a particular role, request to be put forward for a role or if you have asked us to put you forward for suitable roles, we will share some of your personal details including your name, work history and qualifications with our clients offering potential roles which might be suitable for you.
On-boarding for a work-assignment – If you are offered and accept a work assignment through us, we will need further Personal Information from you such as NI number, bank details, emergency contact details and some medical information to fulfil our statutory and contractual obligations to both you and our client.
Reporting to clients and managing timesheets, payroll and work performance – We sometimes have to prepare reports for clients relating to the services provided by us for example reports on financial or administrative matters or compliance with legal requirements. Such reports may contain your Personal Information such as your name, hours worked and pay rate. In addition, we may need to manage submission of timesheets, payroll services and other Human Resourcing services such as managing your statutory rights and work appraisals for our clients, all of which would require use of your Personal Information.
Other lawfully permitted processing – We may also use any Personal Information that you provide to us for example to employers or any other company who you ask us to approach on your behalf for work-searching purposes If you choose not to provide Personal Information requested by us, we may not be able to provide you with the services and/or information you have requested or otherwise fulfil the purpose(s) for which we have asked for the Personal Information, including placing you in a work-assignment. We will where possible anonymise or aggregate such data for reporting purposes.
We undertake Pre-Assignment vetting
Pre-Assignment vetting – we collect your Personal Information which you provide to us when applying for a role or registering for our job-finding services to comply with our (and clients’) legal obligations regarding your right to work and any necessary qualifications for roles. We may also process your Personal Information for this purpose where we consider it necessary for performance of the contract with you, or otherwise with your consent.
4. How and when do we share information with third parties?
Some services that we provide require the involvement of third parties. We have carefully selected these third parties and taken steps to ensure that your Personal Information is adequately protected. The third parties may include our clients, suppliers of IT services, pay-rolling services or vetting services.
Where we employ third party companies or individuals to process Personal Information provided by us on our behalf for business functions, including (without limitation) IT support, hosting our data on cloud platforms, legal, accounting, audit, consulting and other professional service providers, and providers of other services related to our business.
Portions of our services may be provided by organisations with which we have a contractual relationship, including subcontractors, and, accordingly, your Personal Information may be disclosed to them. We only provide these organisations with the information that they need to be able to perform their services.
We will have in place an agreement with our service providers which will restrict how they are able to process your Personal Information.
International Transfers of your Personal Information
- where the transfer is to a place that is regarded by the European Commission as providing adequate protection for your Personal Information; or
- where we have put in place appropriate safeguards, for example by using a contract for the transfer which contains specific data protection provisions that have been adopted by the European Commission or a relevant data protection authority; or
- where you have consented to it, or there is another legal basis to allow us to make the transfer.
Sharing with other third parties
We may also provide your information to other third parties such as regulators and law enforcement agencies, where we are required by law to do so, where necessary for the purposes of preventing and detecting fraud, other criminal offences and/or to ensure network and information security.
5. How long do we store Personal Information for?
6. Security and Confidentiality
We employ appropriate security measures to help protect your Personal Information and guard against access by unauthorised persons. Information storage is on secure computers in a secure environment, or in secure, locked storage in the case of hard copy information. The information is encrypted wherever possible and we undergo periodic reviews of our security policies and procedures to ensure that our systems are secure and protected. The transmission of information via the Internet, however, is not completely secure so we cannot guarantee the security of your information when it is transmitted to our website or from third party websites such as job boards.
7. Your rights
It is important to us that you are in control of your own information. As a result, we offer the following controls:
- You may request access to or copies of the Personal Information that we hold about you. If you would like to exercise this right, please contact us at firstname.lastname@example.org;
- If you believe that any information we have about you is incorrect or incomplete, please contact us email@example.com as soon as possible. We will take steps to seek to correct or update any information if we are satisfied that the information we hold is inaccurate. You may request that we restrict our processing;
- You may request that your Personal Information be deleted, where it is no longer necessary for the purposes for which it is being processed and provided there is no other lawful basis for which we may continue to process such information;
- To the extent we are processing your Personal Information to meet our legitimate interests (as set out above), you may object to the processing of your Personal Information by us. If we are unable to demonstrate our legitimate grounds for that processing, we will no longer process your Personal Information for those purposes;
- You may object to our processing as set out above;
- You may withdraw any consent given to processing; or
- Where we are processing your Personal Information automatically for the purposes of performing our contract with you, you may have the right to request that the Personal Information we hold about you be transferred to a third party data controller;
- Where we may undertake automated decision-making we will request your explicit consent if the decision-making is not authorised by law or necessity for the performance of a contract.
You may also request that we restrict the processing of your data to that to which you have consented or for the establishment, exercise or defence of legal claims or the protection of the rights of another person, whilst we verify your data as set out in point 2 above; pending verification of our legitimate grounds as set out in point 4 above; or if the processing is unlawful or no longer necessary, but you wish us to retain your data for the purposes of establishing, exercising or defending legal claims.
Please contact firstname.lastname@example.org and we will assist you and provide you with all rights to which you are entitled in relation to your Personal Information under applicable data protection law.
If you are unhappy with the way that we have handled your Personal Information, you can make a complaint to the Information Commissioners Office (ICO) which is the UK authority responsible for data protection. Contact details are available online, or alternatively please ask us on email@example.com for assistance.
All queries about Rubicon's Data Protection Act policy on behalf of the data subjects or employees should be addressed in writing to the Directors at Rubicon Consulting (UK) Ltd, Blythe Valley Innovation Centre, Central Boulevard, Blythe Valley Park, Solihull, B90 8AJ.