Introduction
Lavender HR Ltd (“the Company”, “we”, “us”, “our”) is committed to protecting individuals’ privacy and takes its responsibilities regarding the security of personal data very seriously. This Privacy Policy explains:
- what personal data we collect,
- how and why we use it,
- who we disclose it to,
- how we protect your privacy.
Lavender HR Ltd is a company registered in England & Wales with its registered office at: 52 Lavender Way, Louth, Lincs, LN11 8FN
Lavender HR Ltd is the Data Controller for the purposes of the UK Data Protection Act 2018, the UK GDPR, and all applicable data protection legislation (“Data Protection Legislation”). The Data Controller contact is: Lavender HR Ltd
Address: as above
The following sections set out the Company’s statements on dealing with personal data.
- Section 1: Applicants (Recruitment)
- Section 2: Customers, Clients, Service Subjects, Suppliers
- Section 3: Marketing
Please refer to the section relevant to your relationship with us.
Section 1: Privacy Notice – Recruitment
This notice explains how we collect, retain, and process personal data relating to individuals applying for employment with Lavender HR Ltd. We are committed to transparency and compliance with our data protection obligations.
1.1 Purposes & Legal Basis of Processing
We collect and process personal data:
- To enter into a contract of employment or take steps before entering such a contract
- To meet our legal responsibilities as an employer (e.g., right-to-work checks, Equality Act 2010 compliance)
- To pursue legitimate interests (e.g., managing recruitment, assessing candidates, making job offers)
- We may process special category data when necessary for legal obligations such as equality monitoring.
- If unsuccessful, we may retain your details for up to 6 months in case a suitable vacancy arises.
1.2 Access to Personal Data
Personal data may be accessed by authorised individuals within Lavender HR Ltd involved in recruitment, including HR personnel, hiring managers, those involved in interviewing, and IT support where relevant.
Data may also be shared with third parties:
- Recruitment agencies
- IT service providers or cloud storage systems
- Providers managing background checks or Disclosure and Barring Service (DBS) checks
- Professional advisors if needed
- All third parties operate under confidentiality and contractual obligations.
- Data may be transferred outside the UK/EEA where cloud services are used. Appropriate safeguards (e.g., Standard Contractual Clauses) will apply.
1.3 Retention Period
If unsuccessful, your data will be retained for up to 6 months.
If successful, it will form part of your employment file and be handled under our employee privacy notice.
1.4 Your Rights
You have the right to:
- Request access to your data
- Request correction or deletion
- Restrict processing
- Object to processing
- Data portability (where applicable)
- To exercise these rights, contact the Data Controller.
- You may also complain to the Information Commissioner’s Office (ICO).
- Provision of certain data is necessary for recruitment. Failure to provide it may impact
- our ability to process your application.
No automated decision-making is used.
1.5 Categories of Personal Data
We may collect:
- Contact details, identity documents
- Right-to-work information
- Qualifications, CVs, employment history
- Salary expectations and benefits information
- Interview notes, assessments
- Criminal record information (where lawful)
- Health or disability data relating to reasonable adjustments
- References and information from recruitment agencies or job boards
- Information from professional networking sites (e.g., LinkedIn)
1.6 Sources
Data comes from:
- You (directly)
- Recruitment agencies
- Job boards
- Previous employers
- Background-check services
- Online professional profiles
- Data is stored securely on electronic systems, cloud systems, emails, HR systems, and recruitment files.
Section 2: Privacy Notice – Customers, Clients, Service Subjects & Suppliers
This notice explains how Lavender HR Ltd processes data relating to commercial relationships.
2.1 Purpose of Processing
We collect and process personal data:
- To enter into commercial contracts
- To meet obligations under those contracts
- To comply with legal obligations (e.g., tax requirements)
- To pursue legitimate interests (e.g., delivering services, maintaining relationships, providing service updates)
2.2 Legal Basis
Processing is based on:
- Consent (where provided)
- Contract performance or steps prior to entering a contract
- Legal obligations
- Legitimate interests (e.g., service provision, communication)
2.3 Access to Personal Data
Data may be accessed by:
- Authorised employees of Lavender HR Ltd
- Third-party providers, including:
- Accountants
- IT providers
- Legal advisors
- Cloud storage systems
- Web-based platforms supporting our services
- HMRC or regulatory bodies where legally required
- All third parties operate under confidentiality agreements.
- Transfers outside the UK/EEA may occur where cloud services are used. Adequate safeguards will be in place.
2.4 Retention Period
Data relating to clients/suppliers is kept for 6.5 years from the end of the tax year following service delivery, in line with legal and tax requirements.
2.5 Your Rights
You have the rights to:
- Access your data
- Request correction or deletion
- Restrict or object to processing
- Data portability (where applicable)
- Contact the Data Controller to exercise these rights.
- Some personal data is contractually or legally required. Failure to provide it may result in service limitations or contract termination.
- No automated decision-making is used.
2.6 Categories of Data
May include:
- Name, email address, contact details, phone number
- Business and personal address (if applicable)
- Bank details (if required for contract)
- Contractual details relating to services provided to you
2.7 Sources
Data comes from:
- You or your organisation
- Contractual documentation
- Communications with us
- Secure storage is maintained via electronic systems, cloud solutions, email, and filing systems.
2.8 Where We Act as Processor
Sometimes we act only as a data processor on behalf of our clients.
In such cases, we:
- Process data only on written instructions of the Data Controller
- May handle special category data
- Apply all required safeguards under the Data Protection Legislation
Section 3: Privacy Notice – Marketing
3.1 Purpose of Processing
We may process personal data for marketing purposes, including:
- Staying in contact
- Providing updates on services
- Offering relevant information to clients and business contacts
3.2 Legal Basis
Processing is based on:
- Consent (where given)
- Legitimate interests (e.g., informing clients of services)
3.3 Access to Personal Data
Data may be disclosed to:
- Authorised Lavender HR Ltd personnel
- Third-party email or marketing platforms
- IT and cloud service providers
- Third parties operate under confidentiality obligations.
- International transfers may occur through cloud technology, with safeguards applied.
3.4 Retention Period
Marketing-related data is retained until you unsubscribe or request removal.
3.5 Your Rights
You may:
- Withdraw consent any time
- Request access, correction, deletion, restriction
- Object to processing
- Request data portability (where applicable)
- Unsubscribe using any provided link, or contact the Data Controller.
3.6 Categories of Personal Data
Includes:
- Name
- Email address
- Contact details
- Business address
- Phone number
3.7 Sources
Data comes from:
- You or your organisation
- Your interactions with our services
- Networking and professional communications
- Data is stored securely via electronic and cloud systems.
