Legal
Privacy Policy
How ApplyForge Recruiter handles personal data under the UK GDPR and the Data Protection Act 2018.
Last updated: 10 August 2026
This Privacy Policy explains how ApplyForge Ltd (“ApplyForge”, “we”, “us”) collects and uses personal data when we provide the ApplyForge Recruiter platform (the “Service”) to recruitment agencies operating in the United Kingdom. It is written to align with the retained EU General Data Protection Regulation as it forms part of UK law (the “UK GDPR”), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (“PECR”).
We are supervised by the UK Information Commissioner's Office (ICO). You can contact the ICO at ico.org.uk or by writing to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
1. Our role: controller and processor
For the agencies that subscribe to the Service and their recruiter seats, we are a data controller. We decide what personal data we need to run the Service, why we collect it, and how long we keep it.
For candidate personal data that agencies upload into their private workspace (CVs, contact details, notes, application history), the agency is the controller and we act as a data processor on their behalf. We handle candidate data only on the agency's documented instructions, under a written processing agreement (available on request or via our Data Processing Addendum).
For clients of an agency whose contact details are entered by the agency, we are a processor on the agency's behalf; the agency remains the controller.
2. Who we are
ApplyForge Ltd, registered in England and Wales. Registered office and company number are available on request until published here. Contact:
- Data protection: privacy@applyforge.co.uk
- Legal / contract: legal@applyforge.co.uk
- Security incidents: security@applyforge.co.uk
3. Personal data we process
As a controller (agencies & recruiter seats):
- Account data — agency name, recruiter name, work email, hashed password, seat role.
- Session data — access and refresh tokens, IP address, user-agent, timestamps.
- Billing data — Stripe customer identifier, subscription status, invoices. Payment card details are handled by Stripe and are never stored by us.
- Usage data — feature counts (CVs ingested, shortlists generated) for billing metering and product analytics.
- Support correspondence — messages you send us and our replies.
As a processor (candidates & client contacts):
- Candidate profile fields — name, contact details, headline, location, years of experience, expected pay expectations, notes.
- CV file content and its extracted skills, work history, qualifications.
- Application and pipeline data — stage, activity notes, SWOT payloads, screening questions.
- Client contact data — primary contact name, work email, phone, address.
- Client feedback submitted via a share link — sentiment and comments.
We do not knowingly process special-category data (Article 9 UK GDPR) unless a candidate volunteers it in their CV. Agencies should train their recruiters to avoid inputting special-category data unnecessarily.
4. Purposes and lawful bases
Our lawful bases under Article 6 UK GDPR are:
- Contract (Art. 6(1)(b)) — providing the Service to the subscribing agency, managing seats, billing, and support.
- Legitimate interests (Art. 6(1)(f)) — securing the Service against fraud and abuse, product analytics (feature counts, not user-identifying), and pursuing our own commercial marketing to business contacts subject to the right to object at any time.
- Legal obligation (Art. 6(1)(c)) — tax and accounting records, responding to lawful requests from authorities, cooperating with the ICO.
- Consent (Art. 6(1)(a)) — optional cookies (see section 12) and, where required by PECR, marketing emails to prospective new customers.
When we process candidate personal data on behalf of an agency, the agency is responsible for identifying the lawful basis under Article 6, providing candidates with the required privacy information (Articles 13–14), and responding to candidate rights requests. We assist under our processor obligations (Article 28).
5. Automated decision-making and AI
The Service uses artificial intelligence to help recruiters investigate: it ranks candidates against roles, drafts screening questions, and answers grounded questions about a candidate. These outputs are not automated decisions with legal or similarly significant effects under Article 22 UK GDPR — the recruiter remains the human decision-maker at every step of shortlisting, submission, and placement.
Recommendations are traceable to the input evidence. We do not use candidate personal data or agency-uploaded content to train shared or third-party models. Model calls to our AI provider (OpenAI or an equivalent) are sent per request and are not retained by us beyond what is required to deliver the response and satisfy operational logging.
6. Who we share personal data with
We share personal data with the following categories of recipient, all under written contracts:
- Hosting & infrastructure — the cloud provider that hosts the Service.
- Payments — Stripe (payment card processing and subscription billing).
- AI providers — the LLM provider used for CV parsing, SWOT polish, JD auto-fill, screening questions, and grounded Q&A.
- Email & transactional messaging — for account emails and invites (added when configured).
- Analytics & product telemetry — kept minimal and aggregated where feasible.
- Professional advisors — accountants, lawyers, insurers.
- Public authorities — where legally required.
A current sub-processor list is available on request. Agencies subscribed to a paid plan will be notified of material changes to our sub-processor list with a reasonable objection window as described in our Data Processing Addendum.
7. International transfers
Some of our sub-processors operate outside the UK. Where personal data is transferred outside the UK, we rely on one of the following safeguards under Chapter V UK GDPR:
- UK adequacy regulations, where the destination country has been recognised as providing an adequate level of protection;
- the UK International Data Transfer Agreement (IDTA); or
- the EU Standard Contractual Clauses with the UK Addendum.
We carry out a transfer risk assessment before enabling a new international transfer. Copies of the relevant safeguards can be requested at privacy@applyforge.co.uk.
8. Retention
We retain personal data only for as long as we need it, then delete or anonymise it. Default retention windows:
- Agency account & recruiter identities — for the life of the subscription, plus 90 days after termination for wind-down and dispute handling, then deleted or anonymised.
- Billing records & invoices — 6 years from the end of the tax year (HMRC requirement).
- Session, security and access logs — 12 months.
- Support tickets — 24 months from resolution.
- Candidate personal data uploaded by agencies — controlled by the agency. Agencies can delete individual candidates at any time; on termination we return or delete the workspace within 30 days as instructed.
Agencies should configure their own candidate-retention policy in line with their lawful basis for holding candidate data (often up to 12 months from last activity for legitimate-interest sourcing, subject to their own DPIA).
9. Security
We implement technical and organisational measures appropriate to the risks (Article 32 UK GDPR), including:
- Tenant isolation: every record is agency-scoped through the API and the database layer.
- Encryption in transit (TLS) on all endpoints.
- Encryption at rest for databases and backups.
- Access controls, least-privilege service roles, and audit logging of privileged actions.
- Password hashing (bcrypt) and short-lived access tokens with refresh rotation.
- Secure software development practices, dependency scanning, and staged deployments.
- Regular backup and restore testing.
If we become aware of a personal-data breach affecting an agency's data, we will notify the agency without undue delay in line with our Data Processing Addendum, providing the information the agency needs to comply with Article 33 UK GDPR.
10. Your rights
Where we are the controller, you have the following rights under the UK GDPR:
- Right of access (Art. 15) — a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — correction of inaccurate data.
- Right to erasure (Art. 17) — deletion in certain circumstances.
- Right to restriction (Art. 18) — pause processing pending review.
- Right to data portability (Art. 20) — receive data in a structured, commonly used format.
- Right to object (Art. 21) — object to processing based on legitimate interests or for direct marketing.
- Rights in relation to automated decision-making (Art. 22) — as noted, the Service does not make automated decisions with legal or similarly significant effects.
- Right to withdraw consent — where processing is based on consent, with effect for the future.
To exercise these rights, contact privacy@applyforge.co.uk. We will respond within one month; complex requests may be extended by up to two further months under Article 12 UK GDPR.
Candidates: if you are a candidate and want to exercise your rights over data held about you inside an agency's workspace, please contact that agency (the controller). We will assist the agency in responding but cannot act on candidate data without the agency's instructions.
11. Complaints
If you are unhappy with how we handle your personal data, please tell us first at privacy@applyforge.co.uk so we can try to resolve it. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.
13. Changes to this Policy
We may update this Policy from time to time. When we do, we will change the “Last updated” date at the top. Where changes are material, we will notify subscribed agencies by email or in-product notice in advance.
Questions about this document?
Contact us at privacy@applyforge.co.uk (data protection) or legal@applyforge.co.uk (contract).