Who we are
Keldon Search Ltd ("Keldon Search", "we") is a recruitment business registered in England and Wales under company number 17488669, with its registered office at 29 West Hatch Manor, Ruislip, England, HA4 8QU. We are the data controller for the personal data described here. You can reach us about anything in this notice at hello@keldonsearch.com.
What we collect
If you are a candidate, or you contact us about a role, we may hold:
- your name, email address, phone number and location;
- your CV and anything in it: work history, education, skills and qualifications;
- notes from our conversations with you, including what you are looking for and your salary expectations;
- the record of which roles we have discussed with you and which clients you have agreed we may approach;
- if a placement goes ahead, the documents needed to confirm your identity and right to work in the UK, and references we take with your agreement.
If you are a client, or work for one, we hold your name, job title, employer, work contact details and the record of roles we have discussed with you.
This website does not use analytics or advertising cookies and does not track you. The contact form sends us only what you type and attach.
Where it comes from
Most of it comes from you: the contact form, email, phone calls and meetings. We also look at information you have made public professionally, such as a LinkedIn profile, GitHub account or personal website, and we may receive your details from a referral or from a client who asks us to speak with you.
How we use it and on what basis
| Purpose | Lawful basis |
|---|---|
| Assessing your suitability for roles and introducing you to clients you have agreed to | Legitimate interests, and your consent for each introduction |
| Keeping in touch about roles that match what you have told us you want | Legitimate interests; you can ask us to stop at any time |
| Arranging interviews, references and offers | Taking steps towards a contract at your request |
| Checking identity and right to work, and keeping the records recruitment businesses must keep by law | Legal obligation |
| Working with clients: understanding roles, agreeing terms, invoicing | Contract and legitimate interests |
We never send your CV to a client without first telling you who the client is and getting your agreement.
Who we share it with
- clients you have agreed we may introduce you to;
- referees, once you have given us their details;
- the suppliers that run our systems: website hosting and form handling, email, document storage and any recruitment database we use. Each acts on our instructions under a contract that protects your data;
- professional advisers, insurers and regulators where the law requires.
We do not sell personal data. Where a supplier stores data outside the UK, we rely on UK adequacy decisions or the UK International Data Transfer Agreement.
How long we keep it
If we have placed you or introduced you to a client, we keep the records of that process for six years after it ends, which is how long we may need them for contractual and legal reasons. Otherwise we keep candidate details for two years from our last contact with you, after which we delete them unless you ask us to keep them. Recruitment businesses must keep certain records for at least one year under the Conduct of Employment Agencies and Employment Businesses Regulations 2003, and we do.
Your rights
Under UK data protection law you can ask us to: tell you what we hold about you and give you a copy; correct anything that is wrong; delete your data; stop or limit how we use it; give you your data in a portable form; and withdraw any consent you have given. You can object to us relying on legitimate interests at any time. Email hello@keldonsearch.com and we will respond within one month.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put things right first.
Security
Your data is stored in password-protected, access-controlled systems with multi-factor authentication. Only the people who need it to work with you can see it.
Changes
We will update this notice when our practices change and post the new version here with a new date.