Privacy Policy

We have created he following policy in a user-friendly format and language to aid the understanding of our service and systems to our end users. It draws reference and is also binding to all of our policies and terms:

Introduction- GRB and Data Protection

The UK General Data Protection Regulation (UK GDPR), together with the Data Protection Act 2018, provides the main legal framework for protecting personal information in the UK. These laws give individuals rights over their personal data and place obligations on organisations that collect, use, store or share it.

Graduate Recruitment Bureau Ltd, also referred to as GRB, operates under the following trading names:

  • The GRB Group
  • Early Talent Academy
  • Graduate Mentor
  • Graduate Recruiters Network
  • Metrica Recruitment

Graduate Recruitment Bureau Ltd is registered with the Information Commissioner’s Office under registration number Z7502403.

We take data privacy seriously and process personal information in accordance with applicable UK data protection legislation. We use appropriate technical and organisational measures to protect personal information and do not sell work-seeker or client personal data.

Our Service – Why we store personal data

We process and store the personal data of the work-seekers and individual client contacts that opt-in or request the use of our services by agreeing to our Privacy Policy or Terms of Business. We hold and store this personal data on individuals so we can efficiently retrieve it at the appropriate time to provide the work-finding and employee-finding services you request. This storage and access requirement comes in the following but not exclusive forms of:

  • Website functionality
  • Internal administration
  • Candidate selecting and screening
  • Advertising and marketing relevant employer opportunities
  • Internal research to improve our services

Your Data - What Do We Collect and Why?

Our recruitment service for graduates, students and employers consists of, but not exclusively:

  • Screening CVs and contacting candidates to assess suitability
  • Matching candidates to employers that meet their requirements
  • Organising some or every stage of the recruitment process
  • Advertising and marketing relevant job and career or training related opportunities
  • Research projects

So that we can accurately carry out our recruitment service, we collect the following compulsory and optional information:

Compulsory:

  • First Name and Surname
    For identification 
  • Email Address
    For job contact purposes, confirmations and website functionality
  • Contact Phone Number
    For job contact purposes, confirmations and interviews 
  • University
    For employer requirements and location 
  • Course Subject
    For employer requirements and skill assessment 
  • CV and Cover Letter
    For employer requirements and skill assessment 
  • Course Type
    For employer requirements, skill assessment and graduating month 
  • Course Grade
    For skill assessment 
  • Nationality
    For security clearance and additional language skills
  • IP Address
    For abuse claims and location information

Non-Compulsory:

  • Personal Statement
    For employer requirements and skill assessment 
  • Industry Career Choices
    For insight into the industries you would consider working in  
  • Region Career Choices
    For insight into the geographical locations you would consider working in  
  • Driving Licence and Car Status
    For roles where this is a requirement 
  • Qualifications before university e.g. A-levels or equivalent
    For employer requirements and skill assessment 
  • Postgraduate course interests
    So we can provide you with recommended providers of postgraduate courses
  • Equal Opportunities information
    To help employers monitor fairness and promote equal opportunities in their hiring processes

While using our website we also collect and store other data while you use our website for the features to work and to better improve our services. We also store unobtrusive cookies in your browser that allows our website to function correctly. These cookies are typically set when you submit a form, login or interact with the site by doing something that goes beyond clicking on simple links. Please view our Website Usage and Cookie Privacy Policy for more information.

Information Obtained from Third Party Recruitment Sources

We may obtain candidate information from third party sources including job boards, CV databases, professional networking sites, and recruitment platforms. Where we identify a CV that appears to belong to you, for example by matching identifiers such as name, email address, or phone number, we may add that CV to your profile within our recruitment system in order to support job applications and candidate matching.

We process this information under our legitimate interests in providing recruitment services and connecting candidates with relevant opportunities. If you believe information has been added to your profile incorrectly, you may request that it is corrected or removed at any time.

By creating an account you agree that we may match your profile with CVs from job boards or CV databases that we subscribe to.

Call Recording
If you are in communication with any member of staff at GRB via telephone, we may store the call as a recording for training or reference.

Email / SMS / RCS and WhatsApp

We provide email and SMS updates to keep interested visitors to our website informed of developments and events related to job opportunities and workshops. In order to receive these updates you must provide us with your name, email address and mobile number. This information will be held in complete confidence, and will NOT be sold, traded or otherwise revealed to a third party. You will be given the option to remove your name from our email and SMS/RCS and WhatsApp lists at the bottom of each message.  Users are required to comply with the terms of use and notification services, hereby accepting the terms and agreeing to send and receive messaging via email, RCS, WhatsApp, phone calls or SMSes facilitated via GRB. Message and data rates may apply and message frequency varies.

Emails sent by GRB may contain technologies that allow us to understand how recipients interact with our communications. This may include information such as whether an email has been opened and whether links within the email have been clicked. We use this information to measure the effectiveness of our communications, understand engagement and improve the relevance of the information and opportunities we send. Where required by applicable law, we will provide appropriate information and obtain any necessary consent before using email tracking technologies.

Your Privacy Notice - What happens with your data

When you register with GRB you will be provided with our Privacy Notice explaining how we process your personal data.  This will outline the following important GDPR compliance factors as to what we do with your data:

  • We have a purpose and legal basis to process
  • We have legitimate interest to process
  • If we will or will not use a third-party to process
  • This is dependent on how you registered. If you registered on a paper form at an event, we use a GDPR compliant third party to process the paper registration forms
  • If your data will go outside the EU
  • How long we will retain your data
  • Your data protection rights

Please preview the full Privacy Notice you will receive when registering here – GDPR Privacy Notice

Data Storage - Where we safely store your data

Your personal data is stored within secure UK or EU based infrastructure. Where data is processed outside the UK or EU, appropriate safeguards such as Standard Contractual Clauses will be used. Your information may be stored in one or more of the following systems either temporarily or until your account is deleted:

  • Our website server
  • Our internal database
  • Our backup server
  • Our cloud storage account
  • A data entry service
  • A cloud based document processor
  • A cloud based call recording system

Details of the principal service providers we use are available in our GDPR Privacy Notice.

The Data Protection Principles – The care we take when handling your personal data

GRB lawfully process their data in a fair and transparent manner and we do not discriminate by gender, ethnicity or any other protected characteristic or social background. The data collected is exclusively for legitimate work-finding purposes and limited to only what is necessary in relation to it.

Every reasonable step is taken to keep data accurate and up to date, including by the use of email requests or in some cases telephone calls, to ensure that any personal data stored is valid and still relevant to the purposes of which it was collected. GRB do not intend to keep data for longer than is necessary to the services we offer in student, graduate and experienced recruitment. We retain personal information in accordance with our retention policy, taking account of the purposes for which it is used and any legal or regulatory requirements. Further details are provided in our GDPR Privacy Notice.

We ensure that appropriate security of personal data is in place to protect against unauthorised or unlawful access, accidental loss and destruction or damage. We do so by using, amongst others, the following technical, cyber security and organisational measures:

  • Secure Socket Layer (SSL) certificates installed on the GRB and sister websites
  • Separate non-public access servers to store candidate data
  • Enterprise level secure managed hosting
  • Enforced strong passwords and password change lockouts
  • Encrypted backups for all systems
  • Regular auditing of internal computers and laptops
  • Password or user permissions protected documents and folders
  • Industry leading anti-virus and firewall software
  • All staff trained in safely handling data
  • Third-party providers are subject to appropriate due diligence, contractual requirements and data-protection safeguards.
  • Appointed Data Protection representative

Legal Bases for Processing – We store personal information the correct and legal way

GRB only process your personal data where it has a legal basis for doing so that is with the requirements of the service we offer. Before transferring personal data to any third party (such as past, current or prospective employers, suppliers, customers and clients, intermediaries such as our sister companies, persons making an enquiry or complaint and any other third party (such as software solutions providers and back office support)), we will ensure that we have an appropriate lawful basis before processing or sharing personal information.

GRB take every possible step to implement measures and procedures that protect your privacy and we ensure that data protection is integral to all processing activities. This includes implementing measures such as:

  • Data minimisation
    Only completely necessary data is requested and stored
  • Anonymisation
    Personal information is anonymised if it is not required for the purpose of use. Individuals who request their personal data to be removed will have their records anonymised.

Anonymisation (of data) is a type of information sanitisation whose intent is privacy protection. It is the process of either encrypting or removing personally identifiable information from data sets, so that the people whom the data describe remain anonymous.

Privacy Notices – We’ll always tell you and make it clear

It is important that you know exactly what data is being collected and what it is used for. GRB ensure that whenever personal data is collected the individual is clearly notified as to what is going to happen with the data. You will be given at least one of the following notices and will be required to confirm with us that you accept before we process and store your information for our services:

  • For the GRB website registration form, an opt-in tick box that refers to our full Privacy Policy. The website form will not submit without checking it.
  • For third-party website registration forms, a clear non-compulsory opt-in tick box asking the user if they would like to register with GRB, along with a link to GRB’s full Data Privacy Policy, will be included in the third-party company’s registration form.
  • For paper forms from live events, a clear message will be provided on the form that refers to agreeing to a statement of consent for GRB, or our third-party GDPR approved supplier, to process the data.

All new user registrations will receive an email containing our terms of consent depending on how their data was acquired and guidelines on our data policy. This will normally arrive in the welcome email.

GRB does not intend to further process personal data for any purpose other than that for which the data was initially collected. If this should change in the future for a reason that would benefit the users of GRB’s service, then full consent will be requested from the affected individuals before they carry out any further processing.

Data Processors – Who handles your personal information

We process the majority of our data internally, but additionally GRB use third-party data processors who meet GDPR requirements when necessary. For physical registrations that are collected at events, GRB use a third-party data entry company. The companies and their GDPR statements with details of how they process data on behalf of GRB are available by request.

Use of Artificial Intelligence Tools

We use approved business artificial intelligence and automated processing tools to support the administration and delivery of our recruitment services and to make our registration and application processes quicker and easier to use.

These tools may process information contained in CVs, application documents, forms and correspondence to identify, organise, analyse and structure information relevant to our recruitment services. This may help us create and maintain candidate profiles, populate information within our systems, reduce the need for users to enter the same information manually and support candidate and vacancy matching.

We also use approved business AI tools to assist authorised members of staff with analysis, administration, software development and preparing communications.

The services we use are operated within controlled business environments. Information submitted through these services is not used to train or improve the providers’ underlying artificial intelligence models by default.

Artificial intelligence and automated tools assist with processing and administration but do not make final recruitment or employment decisions. Decisions about a candidate’s suitability for an opportunity involve appropriate human review. Candidates can ask us to correct any inaccurate information held about them.

Personal Data Request – Take a look at what we have

If we hold any of your personal data then you or a representative of your behalf can request a copy from GRB. A full copy of your data will be supplied in a Microsoft Excel file within one month. GRB would also be happy to assist if you would like to rectify any inaccurate or incomplete personal data. See Making Requests at the end of this document.

Data Changes and Deletion – Your right to be forgotten

GRB strongly believe in your right to be forgotten. This is both good for the autonomy and respect of our users, and business efficiency. This is at the core of GRB’s values as a company and GDPR.

If you would like your personal data removed then please email your request to GRB (See Making Requests at the end of this document) with confirmation that you would like to be removed entirely, or whether you are happy to remain as a user that does not get contacted in the future (for a specified period or otherwise). You can also achieve this yourself by editing your settings, deactivating for a period or fully deactivating.

If you ask us to remove your personal information, we will delete or irreversibly anonymise it where appropriate, subject to any legal, regulatory or legitimate retention requirements. If you have given prior consent for your information to be passed on to a recruiter or another third party then we will attempt to reach out and request they follow the same procedure however we can’t enforce or follow-up to prove action from them. This initial process will be completed within one month of the request made.

Please note that you will be able to re-submit your data again in the future should you wish to. It is also possible to be re-registered via another route that you may not be aware of such as opting-in while registering with one of our partners. As we will not keep a record of people we have removed, we can’t avoid this, so you may be contacted again.

Deletion and the Conduct Regulations

Employment businesses such as GRB must keep records that are sufficient to show that we have complied with the legal Acts and the Conduct Regulations of our industry. This includes a regulation that requires us to retain work-seeker and client records for at least one year following the date we last provided services. What this means is that if you request to be deleted, certain information will be stored in a separate location for a year before we can completely delete it.

Restriction of Processing – When and why data processing might be restricted

You have the right to ask us to stop using your data if you know it to be inaccurate, unlawful or against legitimate interest where the grounds of use override those of yours. In these cases GRB will revert to the anonymisation of your data once you agree. Please see Making Requests at the end of this document.

Data Portability – How you can move your data

You have the right to a copy of your data, and where feasible, GRB will send your personal data to a named third party on the individual’s request. We supply your data in Microsoft Excel format which is considered as a good choice for data portability. We can also supply it in other formats on request. Please see Making Requests at the end of this document.

Object to Processing – Your right to ask us to stop

You have the right to object to your personal data being used or profiled by GRB if you feel it’s of public or legitimate interest. You can also object to your personal data being used for direct marketing. Once we receive a request we shall cease using your data, unless we have legitimate grounds to continue which take precedence over your interests, rights and freedoms or for the establishment, exercise or defence of legal claims. To cease using your data we will revert to full anonymisation of your record in all our systems. Please see Making Requests at the end of this document.

Enforcement of Rights – Our responsibility to action your requests in a given timeframe

GRB will act upon any requests relating to your personal data within one month. This includes personal data requests, requests relating to rectification, erasure, restriction, data portability or objection or automated decision making processes or profiling. We may extend this period for two further months where necessary, when taking into account the complexity and the number of requests. These timeframes meet the GDPR standards.

Requests are normally free of charge. However, where requests are manifestly unfounded or excessive, particularly due to their repetitive nature, GRB may either refuse to act on the request or charge a reasonable administrative fee.

Reporting personal data breaches – How we are prepared

In the unlikely event of a data breach, GRB will take steps to contain and recover the breach. If a personal data breach is likely to result in a risk to the rights and freedoms of any individual, GRB will notify the ICO. If a personal data breach presents a high risk to the rights and freedoms of any individual then GRB will tell all affected individuals without undue delay. If a personal data breach happens outside of the UK, GRB shall alert the relevant supervisory authority for data breaches in the affected jurisdiction.

Making Requests

Please email your request to GRB providing the following information:

What action you would like to take:

  • Account Snoozed
    Your data will remain within the GRB systems and contact will not be made until your account is reactivated on a specified date that you set.
     
  • Account Unsubscribed
    Your data will remain within the GRB systems but no email contact will be made.
     
  • Account Deactivated
    Your data will remain within the GRB systems but contact will not be made without additional prior consent.
     
  • Account Data Request
    We will supply a copy of the personal data we hold on your account.
     
  • Account Deleted
    Your data will be fully deleted in the form of anonymisation.
     
  • Other Request
    Please specify and direct us to any part of this privacy policy that may assist us with your request
     

For identification:

  • Full Name
  • Email address/addresses that may be registered
  • Contact phone number
  • Your university and year of graduation

You must make your request from the registered email on your account. In the cases where we can’t identify you with certainty we may ask for further identification such as photographic ID.

Please send the above information from your registered email to [email protected]