Cookies & Privacy Policy
Updated: 20 February 2026
Introduction
This Privacy Policy describes how we collect, use and process your personal data, and how, in doing so, we comply with our legal obligations to you. Your privacy is important to us, and we are committed to protecting and safeguarding your data privacy rights.
Opus Recruiter together with its subsidiaries forms the Opus Recruiter group ("Opus Recruiter", "we" or "us") and is responsible for your personal data.
The Opus Recruiter group processes the personal data of the following categories of people: Candidates, Temporary Workers, Clients, Suppliers and Third Parties, People Whose Data We Receive, Website Users, Staff Alumni, and Visitors.
The processing carried out by Opus Recruiter for the purposes of this Privacy Policy is likely to be limited to the personal data of only a few of these categories of people, namely Suppliers and Third Parties (in particular, parties with whom we have a business or other type of relationship such as investors, shareholders and charitable organisations), Visitors (for example, if you visit one of our AGMs as a shareholder) and Website Users. However, we may also process the personal data of the other categories of people on a limited basis, for instance Candidates and Clients that visit the Opus Recruiter website (and who are therefore also Website Users).
We are subject to applicable data protection legislation including but not limited to the General Data Protection Regulation (Regulation (EU) 2016/679) (the "GDPR"), and the UK GDPR. When we refer to the GDPR throughout this Privacy Policy, we mean the EU GDPR and, where applicable, national implementations (including French law where specified).
We may amend this Privacy Policy from time to time. We will post any changes on this page.
If you are dissatisfied with any aspect of our Privacy Policy, you may have legal rights and, where relevant, we have described these in this document.
How to Use This Privacy Policy
This Privacy Policy explains context-specific privacy information for: Candidates, Temporary Workers, Clients, Suppliers & Third Parties, People Whose Data We Receive, Website Users, Staff Alumni, and Visitors.
It also contains general privacy information that applies across categories: who we share data with, safeguards, retention, rights, controller info, international transfers, cookies, and use of third-party services. Defined terms are capitalised and explained in the Glossary.
1. Candidates
Scope
"Candidates" includes individuals we consider may be interested in or benefit from our services: applicants, speculative CV submitters, contractors/freelancers put forward for client roles, and those seeking temporary roles.
What kind of personal information do we collect?
Depending on circumstances and local law, we may collect some or all of the categories below.
Key identification and contact information
- Name
- Age / Date of birth
- Birth number / national identifier
- Sex / Gender
- Photograph
- Marital status
- Nationality / citizenship / place of birth
- Contact details (postal, email, phone)
- Emergency contacts / next of kin / dependants
- Copy of driving licence and/or passport / identity card
Education and employment information
- Education details
- Employment history
- Current job title / specialism / industry sector
- Skills and languages
- Referee details
- Immigration / work permit status
- Availability / start date
- Previous and current remuneration, pensions and benefits
- Hours worked (where placed)
- Interests and preferences (directly provided or inferred)
Financial information
- Bank details (for payroll/payments)
- Financial background check information
- Social security / tax numbers (where required)
Special category information (sensitive)
- Racial / ethnic origin, sexual orientation, religious beliefs, health/disability where relevant (e.g., diversity monitoring, reasonable adjustments)
- Vaccination / COVID-19 related health info where relevant
- Video recordings of interviews/training (where consented)
- Religious beliefs (where required for e.g., leave entitlement)
Criminal conviction data
Conviction details where required for role eligibility (processed in line with local law and typically with explicit consent).
Automatically collected information
- IP address
- Usage data (dates/times/frequency of access)
- Marketing preferences and user choices
- Device, log and troubleshooting info
- Website browsing data (pages viewed)
- Email engagement history
- Inferred location data
- Account access/verification info (e.g., PIN)
Information others provide about you
- Referee reports
- Client feedback
- Publicly available profile data (LinkedIn, job platforms)
- Data from MSP/RPO suppliers or partners
How do we collect your personal data?
We collect Candidate data:
- Directly from you: website forms, registration, CVs, interviews, events.
- From third parties: referees, clients, job boards, LinkedIn, MSP/RPO suppliers, social media interactions.
- Automatically: via cookies, pixels and other tracking technologies when you use our digital services.
How do we use your personal data?
We generally use Candidate data for:
- Pre-recruitment activities
- Recruitment activities
- Marketing activities
- Equal opportunities monitoring
- Legal purposes (establishing/defending claims)
- Profiling (where appropriate)
Pre-recruitment Activities
We use data to determine whether our services may be relevant and to contact you about opportunities. Activities include collecting and storing Candidate details, reviewing and assessing suitability against vacancies, and contacting you to discuss services.
Legal basis: Legitimate interests (to assess fit for services and help you find relevant roles) — Article 6(1)(f). You have the right to object to processing based on legitimate interests.
Recruitment Activities
We use Candidate personal data to deliver recruitment services: matching Candidates to vacancies, submitting applications to clients, arranging interviews and assessments, and supporting placement logistics. Processing often relies on legitimate interests and/or contract performance; consent is used where required.
Payroll and invoicing
We process key identification and contact information, education and employment information, and financial information (bank details, payment records).
Legal basis: Legitimate interests (to operate business and pay Candidates); Contract performance where applicable.
Marketing Activities
We send recruitment-related marketing (job alerts, industry reports, event invites). Some messaging relies on soft opt-in (where you previously engaged with us); other communications require explicit opt-in. You may opt out or withdraw consent at any time.
Soft opt-in: Where you engaged with us (e.g., applied for a job), we may send recruitment-related e-marketing unless you opt out. Each e-marketing message provides an unsubscribe option.
Explicit consent: For marketing not covered by soft opt-in, we will request your explicit consent before sending communications.
Digital advertising & cookies: We may use cookies/pixels and advertising identifiers to show targeted adverts on third-party sites (e.g., Facebook, Google). We obtain consent via the Cookie Preferences tool where required.
Special category data
We process sensitive personal data only where necessary and lawful (e.g., employment/social security obligations, occupational health, reasonable adjustments, public health). Article 9 GDPR exceptions and local law guide processing.
- Equal opportunities monitoring (anonymised where possible)
- Health information to make reasonable adjustments or provide occupational health services
- Criminal conviction data for role-specific checks (explicit consent where required)
- Religious beliefs for leave entitlement calculations
Profiling, Algorithms and Automated Decision Making
We build profiles to personalise experiences, recommend jobs and content, and assist shortlisting and ranking. Tools used include personalisation cookies/pixels, filtering tools and automated shortlisting algorithms, and machine learning models (where used, monitored for fairness/accuracy).
We assign engagement/approachability scores based on web behaviour to help consultants prioritise outreach and to populate talent pools. Assignment to talent pools may be fully automated and can involve bots.
If automated decision-making produces legal or similarly significant effects (Article 22 GDPR), we will ensure necessary lawful basis, provide information about the logic used and rights to human review, and offer mechanisms to challenge or request human intervention where applicable.
Compliance with a legal obligation
We will disclose data where required to comply with legal obligations or valid legal requests (court orders, requests from law enforcement or regulators).
Data Sharing and International Transfers
We may share personal data with:
- Opus Recruiter group companies
- Internal colleagues (including overseas offices)
- Potential employers and recruitment agencies
- Service providers (background checks, cloud storage, analytics, ATS providers)
- Job boards and aggregators
- Auditors, legal advisers, regulators
- Potential acquirers in corporate transactions
Transfers outside EEA/UK: We transfer data internationally under safeguards including adequacy decisions by the European Commission, Standard Contractual Clauses (SCCs), Binding Corporate Rules or other approved mechanisms, and consent where required.
2. Temporary Workers
Temporary Workers are those engaged or employed by Opus Recruiter to undertake temporary work for a Client or Opus Recruiter group company. We continue to process Temporary Workers as Candidates for recruitment-related processing.
Data collected (in addition to Candidate data)
- Staff number / social security number / other identifiers
- Workplace location (Client site)
- Complaints, grievances, disciplinary records (where relevant)
- Leave records, travel, resident/work permit details
- Assignment start/end dates, hours worked, bonuses/promotions
- Performance assessments, interactions with colleagues
- Sickness absence and related health data (where necessary)
Why we collect it
To administer the Temp Relationship: payroll, invoicing, assignment management, performance reviews, absence management, benefits and statutory compliance.
Legal bases
- Contract performance (managing Temp Relationship)
- Legitimate interests (business operation)
- Special category processing (health) only where necessary and lawful; consent where required.
Sharing Temporary Worker data
We may share Temporary Worker data with Clients where assignments occur, payroll and benefits providers, occupational health professionals (limited cases), and relevant Opus Recruiter colleagues (including overseas offices).
3. Clients
Clients are organisations and contacts to whom Opus Recruiter provides recruitment, RPO, MSP, consultancy or other services.
Data collected
- Contact names and job titles
- Phone numbers and corporate email addresses
- Engagement metrics (site usage, candidate searches)
- Any additional information provided by the Client contact
How we use Client data
- Provide and tailor recruitment and advisory services
- Communicate about candidate submissions and service delivery
- Conduct market research and client satisfaction surveys
- Undertake contractual obligations (RPO/MSP delivery)
Legal bases
- Legitimate interests (relationship management, service provision)
- Contract performance (where services are under contract)
4. Suppliers and Other Third Parties
Suppliers include partnerships, companies, sole traders, contractors or freelancers supplying goods or services to Opus Recruiter.
Data collected
- Contact details (names, job titles, emails, phone)
- Business account bank details (for payments)
- Company identification numbers
- Any additional information provided during contracting or due diligence
How we use Supplier data
- Manage supplier relationships and contracts
- Process payments
- Conduct due diligence and compliance checks
- Communicate about service delivery
Legal bases
- Contract performance (where contracted)
- Legitimate interests (relationship management)
- Compliance with legal obligations where required
5. People Whose Data We Receive
This includes referees, emergency contacts, and dependants of Candidates and Staff.
Data collected
- Referees: name, contact details, professional reference information
- Emergency contacts/dependants: name, contact details, date of birth, limited health/dependent info where necessary for benefits
How we use it
- Contact referees to obtain references
- Contact emergency contacts in the event of an accident or incident
- Administer benefits for dependants where required
Legal bases
- Legitimate interests (emergency contact, reference checks)
- Contract performance where related to benefits administration
- Consent where sensitive data is processed
6. Website Users
Website Users are individuals visiting Opus Recruiter websites or using our mobile apps.
Data collected
- Provided data: name, contact details (when registering or contacting us)
- Automatically collected: IP address, device/browser details, pages visited, referral data, cookies/pixel data, form submissions, email engagement
How we use it
- Provide services (newsletters, surveys)
- Protect systems (fraud prevention)
- Improve and personalise user experience and content
Legal bases
- Legitimate interests for site operation and improvement
- Contract performance for registered services
- Consent for non-essential cookies and marketing where required
7. Staff Alumni
Former employees who opt into the alumni network or portal.
Data collected
Name, contact details, limited employment history, optional additional info.
How we use it
- Communications (newsletters, events, job postings)
- Maintain alumni relationship
Legal bases
Legitimate interests and consent for marketing communications where required.
8. Visitors
Visitors to Opus Recruiter premises (non-staff).
Data collected
- Name, contact details, ID (if required), vehicle registration, purpose of visit, job title
- Health-related info (temperature checks, vaccination status) where necessary
- CCTV footage while on site
- Device identifiers and MAC addresses when accessing guest Wi-Fi
How we use it
- Visitor management and site access
- Health & safety and public health compliance
- Security and CCTV monitoring
Legal bases
- Legitimate interests for site security and visitor management
- Vital / public interest or public health where processing health data
General Privacy Information
1. Who do we share your personal data with?
We share personal data where appropriate and lawful. When sharing with processors we require written contracts and appropriate safeguards.
2. How do we safeguard your personal data?
We employ technical and organisational measures to protect personal data, including:
- Access controls and role-based permissions
- Encryption where appropriate (at rest and in transit)
- Secure cloud storage and vetted processors with contractual safeguards
- Regular security testing and monitoring
- Staff training and incident response procedures
Report suspected data misuse or breaches to privacy@opusrecruiter.com immediately.
3. How long do we keep your personal data?
Retention is based on purpose, legal requirements, and business needs. Typical retention periods:
| Category | Typical Retention |
|---|---|
| Candidates | Up to 2 years from collection or last meaningful contact |
| Temporary Workers | Duration of Temp Relationship + statutory/tax/audit needs |
| Clients & Suppliers | Duration of business relationship + legal/tax retention |
| Website Users (logs) | 365 days |
| Referees, emergency contacts | As necessary to fulfil the purpose |
| Other categories | As necessary; otherwise deleted/anonymised |
"Meaningful contact" refers to active interactions (e.g., CV submission, replies, clickthroughs to job content) — passive opens of emails do not count.
4. How can you access, amend or take back your personal data?
You have rights under GDPR and local law. To exercise rights contact privacy@opusrecruiter.com.
Rights include:
- Right to access (DSAR)
- Right to rectification
- Right to erasure (subject to exceptions)
- Right to restrict processing
- Right to object (including to profiling and legitimate-interest processing)
- Right to withdraw consent
- Right to data portability
- Right to lodge a complaint with your supervisory authority
We will respond to DSARs within one month (extensions where lawfully permitted). We may request identity verification. Fees apply only for manifestly unfounded/excessive requests where permitted.
5. Who is responsible for processing your personal data?
Controller details depend on the country and service. For specific controller details, contact privacy@opusrecruiter.com.
6. How do we store and transfer data internationally?
We may transfer personal data within Opus Recruiter and to third parties outside the EEA. Transfers are permitted only with adequate safeguards:
- Transfers to countries with EU adequacy decisions
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules or other approved transfer mechanisms
- Explicit consent where required
How to Contact Us
| Purpose | Contact |
|---|---|
| Data subject rights, DSARs, deletion, rectification | privacy@opusrecruiter.com |
| Data breach reporting | privacy@opusrecruiter.com |
| General enquiries & policy feedback | privacy@opusrecruiter.com |
Supervisory Authorities
South Africa (POPIA)
For South Africa operations, Opus Recruiter (Pty) Ltd acts as the Controller for processing carried out in South Africa. Registered office: Wilderness, South Africa.
The Information Regulator (South Africa)
Website: inforegulator.org.za
United Kingdom
For UK operations, Opus Recruiter UK acts as the Controller for processing carried out in the United Kingdom.
Information Commissioner's Office (ICO)
Website: ico.org.uk | Phone: 0303 123 1113 | Email: casework@ico.org.uk
Postal: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
France
For France operations, the Opus Recruiter French legal entity acts as Controller for processing carried out in France.
Commission Nationale de l'Informatique et des Libertés (CNIL)
Website: cnil.fr
Postal: CNIL — 3 place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07
Portugal
For Portugal operations, Opus Recruiter Portugal acts as the Controller for processing carried out in Portugal.
Comissão Nacional de Proteção de Dados (CNPD)
Website: cnpd.pt
For specific controller details for a particular processing activity, contact privacy@opusrecruiter.com.
Glossary
| Term | Definition |
|---|---|
| Candidates | Individuals seeking or submitted for roles via Opus Recruiter |
| Clients | Organisations that use Opus Recruiter's services |
| Suppliers | Businesses or sole traders providing services to Opus Recruiter |
| Temporary Workers | Individuals engaged by Opus Recruiter for client assignments |
| Staff | Current and former Opus Recruiter employees |
| Staff Alumni | Former employees who opt into the alumni network |
| Website Users | Anyone accessing Opus Recruiter websites or apps |
| Special category data | Sensitive data: health, racial/ethnic origin, religion, sexual orientation |
| Delete | Putting data beyond use in operational systems and eventual hard-delete |
| GDPR | EU General Data Protection Regulation and national implementations |
