Wesend Candidate Privacy Notice
Last Updated: July 2026
Contents
- Who this notice applies to
- Who controls candidate data
- Data we collect
- Sensitive data and background checks
- How we use candidate data
- Lawful bases
- AI-assisted review and automated tools
- Sharing and service providers
- International transfers
- Retention
- Security
- Your rights
- Complaints and contact
- Appendix A - Retention Guide
1. Who this notice applies to
This notice applies to people who apply for a role with Wesend, express interest in future roles, are introduced by a recruiter or referral source, participate in interviews, assessments or trial tasks, or are considered for contractor, advisor, internship or freelance opportunities.
This notice covers candidate information collected through our website, application forms, email, scheduling tools, interview notes, recruiter submissions, referrals, public professional profiles and other hiring-related channels. It does not replace the customer-facing privacy policy that applies to users of the Service.
2. Who controls candidate data
Unless stated otherwise, WESEND LTD is the controller of candidate personal data for the recruitment activities described in this notice. If another group company or local hiring entity is involved, that entity may also act as a controller for the relevant role or jurisdiction.
Questions about this notice can be sent to [email protected].
3. Data we collect
Depending on the role and how you interact with us, we may collect the following categories of data:
- Identity and contact data: name, email address, telephone number, location, right-to-work information and preferred contact details.
- Application and profile data: CVs, cover letters, portfolios, websites, LinkedIn profiles, work history, education, qualifications, certifications and salary or rate expectations.
- Recruitment process data: interview notes, assessment results, technical exercises, hiring manager feedback, scheduling records and communications.
- Reference and verification data: referee details, reference comments and, where legally permitted, verification or screening results.
- Publicly available professional information: content on professional networking sites, personal websites, publications, conference talks or open-source contributions.
- Sensitive or special-category data: only where necessary and lawful, such as health or accommodation information relevant to interview adjustments, diversity data you choose to provide, or background-check information where required by law.
4. Sensitive data and background checks
We do not ask for sensitive or special-category data unless it is reasonably necessary, lawful and proportionate for the recruitment process. If a role requires identity, sanctions, criminal-record, regulatory or employment-history checks, those checks will normally be carried out only at a later stage and only where lawful for the relevant jurisdiction.
5. How we use candidate data
We may use candidate data to:
- Review applications, shortlist candidates and assess suitability for current or future roles.
- Communicate with candidates, arrange interviews and send practical recruitment updates.
- Run skills assessments, interview exercises and reference or verification processes.
- Provide reasonable adjustments or accommodations during the hiring process.
- Maintain internal records of recruitment decisions, pipeline activity and diversity or hiring metrics in aggregated form.
- Defend or establish legal claims, comply with employment, tax, or immigration obligations, and improve our recruitment process and documentation.
6. Lawful bases
Where UK GDPR, EU GDPR or similar privacy laws apply, our lawful bases include taking steps at your request before entering into a contract, legitimate interests in recruiting and evaluating talent, compliance with legal obligations, consent where specifically requested, and substantial public interest or employment-law grounds where special-category data is involved. We will not rely on legitimate interests where your rights override those interests.
7. AI-assisted review and automated tools
Wesend may use software tools that help organise applications, transcribe interviews, detect duplicate records, summarise notes, support scheduling, or assist reviewers. We do not intend this notice to authorise solely automated decisions with legal or similarly significant effects about candidates where prohibited by law. Material hiring decisions always involve human review.
Candidates should not include unnecessary sensitive information in free-text answers, uploads or portfolio links. Furthermore, we do not use candidate personal data (such as CVs, portfolios, interview recordings or assessment materials) to train or fine-tune our own AI models or those of third-party AI providers.
8. Sharing and service providers
We may share candidate data with recruiters, interviewers, internal decision-makers, IT and collaboration providers, applicant tracking or scheduling vendors, legal or HR advisers, background-check providers, and other service providers acting on our behalf under suitable contractual safeguards.
If a role sits with a group company, partner entity or local employer-of-record, we may share relevant candidate information with that entity for the same recruitment purpose. We do not sell candidate personal data.
9. International transfers
Candidate data may be processed in countries outside your home jurisdiction, including the UK, the EEA, and the United States. Where required by law, we use approved transfer mechanisms such as adequacy regulations, the UK International Data Transfer Addendum, or EU Standard Contractual Clauses.
10. Retention
We keep candidate data only for as long as reasonably necessary for the recruitment purpose, to comply with legal obligations, to resolve disputes and to maintain appropriate records of hiring decisions. Typical retention periods are summarised in Appendix A. If you are hired, relevant information will become part of your personnel file and will thereafter be governed by our applicable employee or contractor privacy documentation.
11. Security
We use administrative, technical and organisational measures designed to protect candidate data against unauthorised access, loss, misuse or disclosure. These measures include, where appropriate, access controls, encryption, logging, monitoring and staff confidentiality obligations. Access is limited to people who need the data for recruitment, legal, compliance or security purposes.
12. Your rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, withdrawal of consent, objection to certain processing and review of certain automated decisions. To exercise a privacy right, contact [email protected].
13. Complaints and contact
If you have questions about this notice or how candidate data is handled, contact [email protected]. If you are in the UK, you may also complain to the Information Commissioner's Office (ICO). If you are in the EEA, you may complain to your local supervisory authority.
Appendix A - Retention Guide
| Record type | Retention approach |
|---|---|
| Unsuccessful candidate records | 12 months after role closure or final candidate communication, to address any legal queries or disputes. |
| Talent pool / future opportunities | Up to 24 months, or until consent is withdrawn by the candidate. |
| Interview notes and assessments | Kept in line with the main candidate record for the relevant role (12 months). |
| Reasonable-adjustment information | Kept only as long as needed for the specific recruitment process. |
| Background-check results | Retained only as long as necessary for the specific check outcome and legal audit requirements. |
| Hired candidate records | Transferred to employee/contractor files and retained under workforce privacy policies. |