Privacy Policy
A legal disclaimer
1. What Data We Collect and Why
​
We only collect information required to deliver our services.
​
Candidate Data
-
Name and contact details
-
CV, qualifications, certificates, work history
-
Right-to-work documents (where required)
-
Interview notes and observations
-
Technical, aptitude, logic and scenario-based test results
-
Video interview recordings
-
Behavioural indicators relevant to engineering roles
-
Final vetting summary, scores, and recommendations
​
Employer & Recruiter Data
-
Contact details
-
Job descriptions, shift requirements
-
Communication logs
-
Account information
-
Payment details processed through Stripe
​
Training Data
-
Attendee names and company details
-
Training progress and feedback
​
Website & System Data
-
Form submissions
-
Cookies and analytics (IP anonymised)
-
Device information for performance and security
​
Why We Use This Data
-
To run engineer-led vetting and assessments
-
To produce vetting reports for clients
-
To deliver training and workshops
-
To manage accounts, payments and communication
-
To improve service quality and security
We do not sell personal data or use automated decision-making for hiring.
​
​
2. Legal Basis for Using Data
​
​
We use the following lawful bases:
-
Legitimate interests: delivering vetting, assessments, training, improving services
-
Contract: processing necessary to provide a service
-
Consent: video interviews, marketing communications
-
Legal obligation: financial and tax compliance
​
3. How We Share Data
We only share personal data when necessary and always securely.
​
We May Share With:
-
The employer or recruiter who requested the vetting
-
Technology providers who support our service (secure storage, email, analytics, Stripe)
-
Authorities where disclosure is legally required
We do not share video interviews unless required by contract or with your explicit consent.
​
4. Data Retention
We retain data for only as long as necessary:
-
Vetting notes, assessments, reports: 12 months
-
Video recordings: 6 months
-
Raw test answers: 6 months
-
Training records: 3 years
-
Financial records: 6 years
You may request deletion at any time unless legal obligations require retention.
​
5. Your Rights
Under GDPR, you have the right to:
-
Access your personal data
-
Correct inaccurate information
-
Request deletion
-
Restrict or object to processing
-
Request a copy of your data
-
Withdraw consent
-
Make a complaint to the ICO
To exercise your rights, email service@shiftt.co.uk with the subject line GDPR Request.
​
6. Security
We protect your personal data using:
-
Encrypted storage
-
Strict access controls
-
Multi-factor authentication
-
Regular security reviews
-
Confidentiality agreements
-
Secure deletion procedures
​
7. Contact Us
Shiftt
Email: service@shiftt.co.uk