Skip to content
Call us on0131 629 4041
Legal

Supplier and Partner Notice

How Recruitta Limited uses information about suppliers, partners and their people.

At a glance

We use business-contact and due-diligence information to assess, appoint and manage suppliers and partners, operate our supply chain, make payments, protect our services and meet legal and contractual obligations. We do not sell this information.

1. Who we are and when this notice applies

Recruitta Limited is the data controller for the personal information described in this notice. We are registered in Scotland under company number SC667162. Our registered office is 294 Duke Street, Glasgow, Scotland, G31 1RZ. Our Information Commissioner’s Office registration number is ZB159936.

This notice applies to sole traders, consultants and individual contacts, directors, owners, employees and subcontractors of current or prospective suppliers, recruitment partners, payroll or umbrella providers, framework partners and other organisations that work with us. It should be read with our main Privacy Policy.

Privacy questions and rights requests: privacy@recruitta.com.

2. Information we may collect

Depending on the relationship and services involved, we may collect:

  • name, title, role, employer, business contact details, signature and communication preferences;
  • professional history, qualifications, licences, memberships, references and authorised-signatory status;
  • tenders, proposals, questionnaires, contracts, orders, invoices, payment records and correspondence;
  • bank, tax, VAT and other payment-administration information where it relates to an identifiable person or sole trader;
  • ownership, directorship, key-person and conflict-of-interest information;
  • insurance, accreditation, policy, audit, quality, security, safeguarding and regulatory information;
  • financial-standing, sanctions, fraud-prevention, credit and other proportionate due-diligence results;
  • performance, service levels, complaints, incidents, investigations and business-continuity information;
  • building, system or platform access records and information needed to protect our people, clients and systems;
  • accessibility, health-and-safety or adjustment information where relevant; and
  • technical information submitted through our website, partner form or business systems.

Information about a company is not normally personal information, but information about an identifiable person — including a named business contact or sole trader — is personal information and is covered by this notice.

3. Where information comes from

We may obtain information:

  • directly from you through enquiries, onboarding, tenders, contracts, meetings and service delivery;
  • from your organisation, colleagues, group companies, advisers or authorised representatives;
  • from clients, framework or procurement bodies, referees and other supply-chain participants;
  • from Companies House, professional registers, sanctions lists and other lawful public sources;
  • from credit-reference, fraud-prevention, identity, due-diligence or compliance providers; and
  • from regulators, public authorities, courts or law-enforcement bodies where permitted.

If we obtain your information indirectly, we provide this notice within the period required by law — normally within one month, at our first communication with you, or before our first disclosure to another recipient, whichever applies.

4. Why we use information and our lawful bases

We use information only where we have a lawful basis. Depending on the activity, we use it to:

Assess and appoint

To respond to enquiries, evaluate capability, complete prequalification and due diligence, negotiate terms and decide whether to work together. We rely mainly on legitimate interests, steps requested before a contract with an individual, and legal obligations.

Manage the relationship

To administer contracts, orders, services, contacts, performance, renewals, audits and communications. For a corporate supplier we normally rely on legitimate interests; where the contract is with you personally, contract may apply.

Administer payments

To validate invoices, make and reconcile payments, maintain accounts and meet tax duties. We rely on contract, legal obligations and legitimate interests.

Meet compliance duties

To manage supply-chain, safeguarding, anti-fraud, sanctions, insurance, health-and-safety, security and regulatory requirements. We rely on legal obligations and legitimate interests.

Protect and improve services

To secure premises and systems, investigate incidents, manage continuity, assess performance and improve our operations. We rely on legitimate interests and, where relevant, legal obligations.

Handle disputes and change

To respond to complaints, establish or defend claims, obtain advice, support audits, and manage a reorganisation or business transfer. We rely on legal obligations and legitimate interests.

Relevant business communications

To send service, procurement, framework or relationship updates and proportionate business-to-business communications. We rely on legitimate interests and consent where electronic-marketing law requires it.

Where we rely on legitimate interests, we consider the purpose, necessity and impact on the individual and document the balance where appropriate. You may object as explained in section 11.

5. Sensitive and criminal-offence information

We do not routinely need special-category or criminal-offence information about supplier and partner contacts. We may process limited information about accessibility, health and safety, equality, safeguarding, suspected fraud, sanctions or offences where it is necessary and lawful.

Where such information is used, we identify both an Article 6 lawful basis and the additional condition required by Article 9, Article 10 and Schedule 1 to the Data Protection Act 2018. Depending on the circumstances, this may relate to employment and social-protection law, equality, safeguarding, preventing unlawful acts, legal claims or explicit consent. We maintain an Appropriate Policy Document where required.

6. Information supplied about other people

If you give us personal information about your employees, subcontractors, candidates, referees or other contacts, you must ensure that you are permitted to do so, that the information is accurate and proportionate, and that the person has received appropriate privacy information. Candidate and worker information is also covered by our Candidate Data Notice and any applicable data-sharing or processing agreement.

7. Who we share information with

Where necessary and lawful, recipients may include:

  • our clients, prospective clients, framework bodies and contracting authorities where supply-chain transparency, due diligence or service delivery requires it;
  • other suppliers, subcontractors and delivery partners involved in the relevant service;
  • banks, payment providers, accountants, auditors, insurers and professional advisers;
  • credit-reference, identity, fraud-prevention, sanctions, security and due-diligence providers;
  • providers of procurement, recruitment, communications, forms, document storage, cloud hosting and IT services;
  • HM Revenue & Customs, regulators, public authorities, law-enforcement bodies and courts where required or permitted; and
  • a buyer, investor or successor where our business or assets are reorganised or transferred.

Some recipients act as separate controllers and provide their own privacy information. Others process information only on our documented instructions. We require appropriate confidentiality, security and contractual safeguards.

8. International transfers

A service provider or partner may process information outside the United Kingdom. Where the destination is not covered by UK adequacy regulations, we use an approved safeguard such as the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses and apply supplementary measures where needed. Contact privacy@recruitta.com for information about the safeguard relevant to your data.

9. How long we keep information

We keep information only as long as needed. Our usual starting points are:

  • unsuccessful supplier or partner enquiries and onboarding records: normally two years after the process ends;
  • contract, due-diligence, performance and relationship records: normally six years after the relationship ends;
  • invoice, payment, tax and accounting records: for the applicable statutory period, normally at least six years;
  • security, access, complaint and incident records: for the period justified by the risk, investigation or legal claim; and
  • marketing opt-outs: a minimal suppression record for as long as needed to respect the opt-out.

A period may be shortened or extended where the circumstances, a legal hold, a regulator, a framework or a client requirement lawfully justifies it. Information is securely deleted or anonymised when no longer required.

10. When information is required

You may choose whether to provide most information, but we may be unable to assess an application, appoint a supplier or partner, provide access, make payment or continue the relationship without information needed for due diligence, a contract, security or legal compliance. We will explain when information is mandatory and the likely consequence of not providing it.

11. Your data protection rights

Depending on the circumstances, you may have the right to:

  • ask for access to your personal information and a copy of it;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase information or restrict its use;
  • receive information you provided in a portable format where the right applies;
  • withdraw consent where a particular activity relies on consent; and
  • object to direct marketing and object to processing based on legitimate interests.

Your right to object. You can object at any time to direct marketing. You can also object to processing based on our legitimate interests; we will stop unless we demonstrate compelling legitimate grounds or need the information for legal claims.

Send requests to privacy@recruitta.com. We may need to verify your identity. Rights are not absolute, and we will explain any lawful limitation. There is normally no fee, although the law permits a reasonable fee or refusal in limited cases.

12. Automated decisions

We may use systems to help organise due-diligence, risk, compliance or supplier information. These tools support human judgement. We do not currently make decisions about individuals based solely on automated processing where the decision produces legal or similarly significant effects. If that changes, we will provide the required information and safeguards.

13. Questions and complaints

Contact privacy@recruitta.com if you have a question, wish to exercise a right or want to make a data protection complaint. We will acknowledge a data protection complaint within 30 days, investigate and respond without undue delay, and keep you informed where appropriate.

You may also complain to the Information Commissioner’s Office (ICO), the UK supervisory authority. We would welcome the opportunity to address your concern first, but you do not have to contact us before approaching the ICO. Current contact details are available at ico.org.uk.

14. Changes to this notice

We may update this notice when our supply-chain practices, technology or legal obligations change. The current version will be published on our website with its last-updated date. We will draw material changes to your attention where appropriate.

Questions about this notice?

Email privacy@recruitta.com or send us a message and we will route your query to the right team.

Contact Recruitta

Discuss a requirement

Have an operational requirement to plan, resource or mobilise?

Talk to our team about staffing, facilities, project and operational delivery, procurement or training — we scope, resource and deliver with clear governance from day one.