Recruitment Privacy Policy

‍ ‍

Recruitment Privacy Policy - The Little HR Department (Trading name of Astraea HR Limited)

‍ ‍

Last updated: March 2026

‍ ‍

The Little HR Department (“we”, “our”, “us”) is the trading name of Astraea HR Limited. We take your privacy seriously and are committed to handling all personal information lawfully, fairly, and transparently.

‍ ‍‍ ‍

This Privacy Policy explains what information we collect when you use our website or interact with us, how we use it, who we share it with, and your rights under UK data protection law.

‍ ‍

We process personal data in two different recruitment scenarios:

1. When we recruit for roles within our own team, and

2. When we recruit on behalf of our clients as their outsourced HR partner.

 

This policy covers both.

1. Who We Are

Astraea HR Limited (trading as The Little HR Department)

Company number: 12073106

Registered office: Unit 11, Riverside Park, Farnham, Surrey GU9 7UG

‍ ‍Email: hello@thelittlehrdepartment.com

·   When we recruit on behalf of a client, we act as a data processor, and the client is the data controller.

·   When we recruit for our own vacancies, we are the data controller.

‍ ‍

2. The Information We Collect

‍During the recruitment (and onboarding where appropraite) processes, we may collect and process the following types of information:

 

Information you provide directly:

·         CV

·         Application form

·         Cover letters or supporting statements

·         Employment history and qualifications

·         Interview notes

·         References (only when requested and with your consent)

·         Evidence of your right to work in the UK

·         Assessment or test results (if applicable)

·         Sensitive data such as gender/race/disability/religion for the purpose of diversity tracking

·         Data relating to disabilities and reasonable adjustments required as part of the recruitment process

·         Data related to disability or other health matters that may be relevant as part of pre employment checks (this will be requested only once an offer has been confirmed)

Information we generate:

·         Shortlisting notes

·         Interview scoring

·         Internal communications relating to your application

Information from third parties:

·         Referees

·         Background or screening checks (only where appropriate and lawful)

Or other such data reasonably required either to make a recruitment decision or to support onboarding to a new role.

3. How We Use Personal Data

‍ We only use your personal data to:

·         Assess your suitability for a role

·         Communicate with you throughout the recruitment process

·         Arrange interviews or assessments

·         Check your legal right to work (if you are offered a role)

·         Take up references (with your consent)

·         Meet our legal and regulatory obligations

·         Provide recruitment services to our clients (where applicable)

 

We do not use your data for any unrelated purpose, and we do not sell your information.

‍ ‍‍ ‍

4. Lawful Bases for Processing

‍ ‍We process your data on one or more of the following lawful bases:

·         Legitimate interests – to manage a fair and effective recruitment process

·         Contract – to take steps at your request before entering into a contract

·         Legal obligation – such as checking your right to work

·         Consent – for specific actions like contacting referees

 

Where we recruit on behalf of a client, the client determines the legal basis and we process your data under their instructions.

‍ ‍

5. How We Collect Your Data

We usually collect your data:

·         When you apply directly via our website, email, or job advert

·         Through our Applicant Tracking System, Hireful, which securely stores your application

·         When a recruitment agency submits your details

·         When a client provides us information about you to us (e.g. for internal applicants, or where you have applied directly to the client initially)

·         During interviews, assessments, or discussions with us

‍ ‍

6. Who We Share Personal Data With

‍ ‍We may share your data with:

·         Our clients (only when we are recruiting on their behalf)

·         Hireful, our Applicant Tracking System provider

·         IT service providers who support our systems

·         Referees (only with your permission)

·         Government regulators where legally required

 

We do not share your data outside the UK unless adequate protection measures are in place.

‍ ‍‍ ‍

7. International Data Transfers

‍ Some providers process data outside the UK/EU.

We ensure lawful safeguards including:

·         Standard Contractual Clauses (SCCs) which ensure that data is processed and managed at GDPR standards

· Adequacy decisions (e.g., UK-US Data Bridge), which meet UK Government requirements to confirm they have adequate data protection standards in place and that data can therefore be shared.

·         Transfer Impact Assessments where required.

‍ ‍‍ ‍

8. How Long We Keep Data

‍We keep your data only for as long as necessary.

Typical retention periods:

·         Unsuccessful candidates: normally 12 months after the end of the recruitment process

·         Successful candidates: your data becomes part of your employee record (with its own retention rules)

·         Client recruitment: we follow the client’s required retention period unless otherwise stated

 

You may ask us to delete your data sooner (unless we must keep it for legal reasons).

9. How We Protect Your Data

‍ ‍Safeguards include:

·         Secure hosting

·         Access controls

·         Encryption (where applicable)

·         Confidentiality and training for employees

·         Data processing agreements

10. How We Protect Your Data

‍Some limited automated decision-making may be used during the recruitment process. This happens only where specific essential criteria have been set either by us or by our client (for example, required qualifications, legal right-to-work confirmations, or other mandatory requirements). If an application does not meet these essential criteria, the system may automatically screen it out and we may be unable to proceed further.

However:

·         Automated tools are only used for clearly defined, essential criteria, and

·         All final hiring decisions involve a human.

You have the right to request human review of an automated decision, express your point of view, or contest that decision.

‍ ‍‍

11. Your Rights

‍ You have the right to:

·         Access your data

·         Correct inaccuracies

·         Request deletion

·         Object to processing

·         Withdraw consent (where applicable)

·         Request portability of data

‍ ‍

Contact: hello@thelittlehrdepartment.com

You may also complain to the ICO at www.ico.org.uk

‍ ‍

12. Updates to This Policy

‍ We may update this Recruitment Privacy Policy from time to time. The latest version will always be published on our website.

‍ ‍