Privacy Policy

HireFlow Direct is a trading name of YourRecruit Ltd

1. Introduction

YourRecruit Ltd (“we”, “us”, “our”) trading as HireFlow Direct is committed to protecting and respecting your privacy.

This Privacy Policy explains how we collect, use, store and protect personal data when you use our website and services. Please read it carefully.

2. Who We Are

YourRecruit Ltd (trading as HireFlow Direct) is a UK-based business providing job advertising and distribution services to employers.

For the purposes of data protection law, we act as:

  • Data Controller – for our own business operations and website
  • Data Processor – where we process personal data on behalf of clients

We are registered with the Information Commissioner’s Office (ICO). Our ICO registration number is: ZA445499

3. What Data We Collect

We may collect and process the following categories of personal data:

Client Data

  • Name, job title and company name
  • Email address and telephone number
  • Billing and payment information
  • Job vacancy details

Candidate Data

Where applicable (for example, via enquiries or contact forms submitted directly to us):

  • Name and contact details
  • CV or employment history (if submitted directly to HireFlow Direct)

Important: In most cases, candidates apply directly to the Client via the job advertisement. HireFlow Direct does not receive or process those applications. See Section 6 for more detail.

Website Visitor Data

  • IP address and browser/device information (via cookies – see our Cookie Policy)
  • Pages visited and time spent on site

4. How We Use Your Data

We use personal data to:

  • Provide and manage our services
  • Process payments and orders
  • Communicate with clients and users
  • Improve our website and services
  • Send marketing communications where you have given consent
  • Comply with legal and regulatory obligations

5. Legal Basis for Processing

We process personal data under the following lawful bases under UK GDPR:

  • Contractual necessity – to deliver services you have purchased or enquired about
  • Legitimate interests – to operate, protect and improve our business, where your interests do not override ours
  • Legal obligation – where we are required to process data by law
  • Consent – for example, for marketing communications. You have the right to withdraw consent at any time without affecting the lawfulness of prior processing.

6. How Candidate Data Works

HireFlow Direct is primarily a job advertising and distribution service.

  • Candidates typically apply directly to the Client via the advertised job posting
  • In these cases, the Client becomes the Data Controller for that candidate’s data
  • HireFlow Direct does not receive, store or process those applications unless explicitly agreed in writing

Where a candidate submits their details directly to HireFlow Direct (for example, via a contact form or email enquiry), we will:

  • Only use that data for the purpose for which it was provided
  • Not share it with third parties without a lawful basis for doing so
  • Retain it only for as long as necessary (see Section 8)

7. Data Sharing

We may share personal data with:

  • Payment providers (e.g. Stripe) – for secure payment processing
  • IT and website service providers – who support the operation of our platform
  • Job boards and advertising platforms – to distribute job adverts on your behalf
  • Professional advisers – including legal and accounting services, under confidentiality obligations

We do not sell personal data to third parties. Any third parties we share data with are required to handle it in accordance with UK GDPR and our data processing agreements.

8. Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy. Our typical retention periods are:

  • Client data: up to 6 years from the end of the contractual relationship (for financial and legal records)
  • Candidate data submitted directly to us: up to 6 months, unless there is an ongoing legitimate purpose
  • Enquiry and contact form data: reviewed every 12 months and deleted if no longer required
  • Website analytics data: up to 26 months (via Google Analytics)

At the end of the applicable retention period, data is securely deleted or anonymised.

9. Data Security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or disclosure. These measures include:

  • Encrypted data transmission (SSL/TLS)
  • Secure access controls and password policies
  • Use of reputable, GDPR-compliant third-party providers
  • Internal data handling policies and staff awareness

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours as required by UK GDPR, and affected individuals where required.

10. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • Right of access – to request a copy of the data we hold about you
  • Right to rectification – to correct inaccurate or incomplete data
  • Right to erasure – to request deletion of your data in certain circumstances
  • Right to restriction – to limit how we process your data
  • Right to object – to processing based on legitimate interests or for direct marketing
  • Right to data portability – to receive your data in a structured, machine-readable format
  • Right to withdraw consent – at any time where processing is based on consent, without affecting prior lawful processing

To exercise any of these rights, please contact us using the details in Section 13.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe we have not handled your data lawfully:

ICO website: www.ico.org.uk

ICO helpline: 0303 123 1113

11. Cookies

Our website uses cookies to improve your experience and help us understand how the site is used. For full details of the cookies, we set, their purpose and how to manage your preferences, please refer to our Cookie Policy, available at www.hireflow.co.uk/cookie-policy.

12. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites and recommend you review their privacy policies before providing any personal data.

13. Contact Us

We have not appointed a formal Data Protection Officer (DPO) as we are not required to do so under UK GDPR. All data protection queries and rights requests should be directed to:

YourRecruit Ltd (trading as HireFlow Direct)

Email: hello@hireflowdirect.co.uk
Website: hireflowdirect.co.uk
Registered address: Quadrant House, 65B Croydon Road, Caterham, Surrey, CR3 6PB

We will respond to all legitimate requests within one calendar month.

14. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal obligations. The latest version will always be available on our website, with the ‘Last updated’ date revised accordingly. Where changes are significant, we will take reasonable steps to notify you.