Legal
Privacy notice
Last updated:
This notice explains how RISKTAE LIMITED (“RiskTAE”, “we”, “us”) collects and uses personal data about people who visit this website, contact us, work with us as clients or suppliers, or talk to us about their career. We are the controller of that data under the UK General Data Protection Regulation and the Data Protection Act 2018.
Who we are
RISKTAE LIMITED is registered in England and Wales under company number 14317003. Our registered office is 4 Bullfinch Lane, Sevenoaks, Kent, England, TN13 2DY. We are registered with the Information Commissioner’s Office under number ZC256357.
Benn Pople, Co-founder and Managing Director, is responsible for data protection at RiskTAE. We are not required to appoint a data protection officer. To contact us about your data, email info@risktae.com with “Privacy” in the subject line, or write to us at our registered office.
Whose data this notice covers
It covers visitors to this website; people who email, call or book a call with us, or send us a form on this website; candidates, meaning people we talk to about roles, including people we approach after finding their professional details in public sources; clients and prospective clients and their staff; and trainers, associates and suppliers who work with us.
What we collect
For everyone we deal with, we hold your name, job title, employer and contact details, and a record of our contact with you: emails, messages, notes, and the recordings and summaries of calls and meetings described below.
If you are a candidate, we also hold the information you or public sources give us about your career: your CV, employment history, qualifications and skills, your current package and what you are looking for, your notice period, your right to work in the UK where a role requires it, interview notes and references. If you do not give us information a client needs to consider you, we may not be able to put you forward for that role.
If you are a client or supplier, we also hold the business and billing details we need to work with you.
When you book a call, TidyCal passes us the details you enter. When you visit this website, our host keeps standard server logs (IP address, browser type, the pages requested and the time), which are used to keep the site secure and working. This website does not use analytics or advertising cookies; our cookie statement explains what it does use.
If you use a form on this website, what you type goes to our team by email, or into ATSPro if you are a candidate. The website keeps a copy until it has been delivered and deletes it seven days later, and anything that could not be delivered after 30 days.
We do not ask for health information, ethnicity or other special category data. If you choose to tell us about a health condition so that we can arrange adjustments for an interview, we use it only for that purpose. We do not carry out criminal record checks; where a regulated role requires one, the hiring firm carries it out under its own privacy notice.
Where the data comes from
Most of it comes from you. We also collect professional details from public sources such as LinkedIn, company websites, the Financial Services Register and published articles; from people who recommend you to us; and from clients about their vacancies and the staff we deal with. If we collect your details from a public source, we tell you when we first contact you, and in any case within one month.
What we use it for, and our lawful basis
We answer enquiries and hold the calls you book, relying on our legitimate interest in running our business and responding to you, or on taking steps at your request before a contract.
We provide recruitment services to candidates and clients. For candidates, we rely on our legitimate interest in matching experienced risk professionals with suitable roles; for clients, on our contract with them. We only send a candidate’s details to a hiring firm after the candidate has agreed to be put forward for that specific role.
We deliver advisory work, training and RisKIT licences under our contracts with clients, and use the contact details of client staff under our legitimate interest in delivering that work.
We record and summarise calls to and from our main number, and some video meetings, relying on our legitimate interest in keeping an accurate record of what was discussed and agreed. You can ask us not to record a call.
We send occasional updates about roles, services and RisKIT to people who have dealt with us or who work in risk, relying on our legitimate interest and, where the law requires it, on your consent. Every message tells you how to opt out, and if you object we stop.
We keep records the law requires, including accounting and tax records and the records the Conduct of Employment Agencies and Employment Businesses Regulations 2003 require of recruitment firms, relying on legal obligation. We may also use data to establish or defend legal claims, relying on our legitimate interests.
How we use AI tools
We use AI features in our phone system and recruitment database, and the AI assistants Claude and ChatGPT, to transcribe and summarise calls and meetings, to prepare and summarise documents, and to help us search our own records for people who may suit a role. A person reviews the results and makes every decision. We do not make decisions about anyone that have legal or similarly significant effects by automated means alone.
Who we share it with
We share candidate details with a client only with the candidate’s agreement, as above. We use service providers who process data on our behalf under contract: Microsoft for email, documents and Teams meetings, Zoom for video meetings, Ringover for our phone system and call recording, WhatsApp for messages with people who prefer it, ATSPro for our recruitment and client database, TidyCal for call bookings, Anthropic and OpenAI for the AI assistants Claude and ChatGPT, and Krystal Hosting for this website, which is hosted in London. Our accountants and professional advisers see data where their work needs it.
Associates who work on a client engagement see the data that work needs, under a confidentiality agreement. We disclose data to regulators, courts or law enforcement when the law requires it, and to a buyer of our business if it is ever sold, under the same protections. We never sell personal data.
Transfers outside the UK
Some of our providers store or access data outside the UK, including in the European Economic Area and the United States. Where they do, we rely on UK adequacy regulations, which cover the EEA and US companies certified under the UK Extension to the EU-US Data Privacy Framework, or on the Information Commissioner’s International Data Transfer Agreement or Addendum.
How long we keep it
We keep candidate records for two years after our last meaningful contact with you, and in every case for at least the period the Conduct of Employment Agencies and Employment Businesses Regulations 2003 require. After that we delete or anonymise them, unless you ask us to keep your details on file.
We keep client and supplier records for six years after the end of the relationship, for tax purposes and in case of legal claims. Once a call or meeting has been summarised, the summary is saved to the record of the person it concerns and the recording is deleted; we never keep a recording for more than 12 months. If a caller is not on our database, the recording is deleted and no summary is kept. Enquiries that do not lead to any work are deleted after 12 months. Our host keeps website server logs only for as long as it needs them to keep the site secure and working.
Your rights
You can ask us for a copy of your data, and ask us to correct it, delete it, restrict how we use it, or transfer it to you or someone else where that right applies. You can object to any use based on legitimate interests, and you can always object to marketing, in which case we stop. Where we rely on your consent, you can withdraw it at any time.
We answer requests within one month and do not normally charge. To make a request, email info@risktae.com with “Privacy” in the subject line.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113.
Cookies
See our cookie statement.
Changes to this notice
We update this notice when the way we use personal data changes. The date at the top shows when it was last updated.