Trinnovo Group
Group Privacy Notice
United Kingdom · Ireland · Germany · Switzerland · United States
Trinnovo Group ("We", "Us", "Our") are committed to protecting and respecting your privacy.
References to "Our Group" mean Trinnovo Group Limited together with its subsidiaries and associated companies as defined in section 1159 of the UK Companies Act 2006 (Our "Group").
This notice sets out the basis on which any personal data We collect from you, or that you provide to Us, will be processed by Us. Please read the following carefully to understand Our views and practices regarding your personal data.
Document Control
How to Use This Notice
Our Group operates across the United Kingdom, Ireland, Germany, Switzerland and the United States. Data protection law differs in each of those places, and the law that applies to you depends on which Trinnovo Group entity is engaging with you and where you are located.
This notice is written to cover all five. Most of it applies to everyone. Where a section applies only in certain places, or applies differently, it is marked at the start of that section or paragraph with a shaded band naming the jurisdictions concerned. Where no marker appears, the section applies wherever you are.
The markers used in this notice are:
- United Kingdom — where the entity engaging with you is established in the United Kingdom, or you are located in the United Kingdom.
- Ireland — where the entity engaging with you is established in Ireland, or you are located in Ireland.
- Germany — where the entity engaging with you is established in Germany, or you are located in Germany.
- European Economic Area — where you are located in an EEA member state. This includes Ireland and Germany.
- Switzerland — where the entity engaging with you is established in Switzerland, or you are located in Switzerland.
- United States — where the entity engaging with you is established in the United States, or you are located in the United States. If you are unsure which applies to you, contact Us at gdpr@trinnovo.com and We will tell you.
Who We Are
We are a specialist staffing and recruitment group operating through the brands Trust in SODA, Broadgate Search, DeepRec.ai and Ex-Military Careers. We collect the personal data of:
- Prospective and placed candidates for permanent or temporary roles.
- Prospective and active client contacts.
- Suppliers and supplier contacts.
- Employees, consultants, and temporary workers. Our regulatory status differs by jurisdiction.
Applies to: United Kingdom
We are an Employment Agency and an Employment Business as defined in the Employment Agencies Act 1973 and the Conduct of Employment Agencies and Employment Businesses Regulations 2003.
Applies to: Ireland
We are an employment agency licensed under the Employment Agency Act 1971, and We supply agency workers within the meaning of the Protection of Employees (Temporary Agency Work) Act 2012.
Applies to: Germany
We provide recruitment and placement services (Arbeitsvermittlung) and We supply temporary agency workers (Arbeitnehmerüberlassung). Trinnovo Group Europe GmbH holds a permission to supply temporary agency workers (Erlaubnis zur Arbeitnehmerüberlassung) granted by the Bundesagentur für Arbeit under section 1 of the German Temporary Employment Act (Arbeitnehmerüberlassungsgesetz, AÜG).
Applies to: Switzerland
We provide recruitment and placement services (Arbeitsvermittlung) and We hire out personnel (Personalverleih) within the meaning of the Federal Act on Employment Services and the Hiring of Services (Arbeitsvermittlungsgesetz, AVG) and its implementing Ordinance (AVV). Our activities are conducted under the licences required by the AVG.
Applies to: United States
We are a staffing and recruiting company. We place candidates in permanent positions and supply temporary and contract workers to Our clients.
Data Controllers
The Data Controller of your personal data — in the United States, the entity responsible for your personal information — depends on the entity engaging with you.
Trust in SODA Limited
Broadgate Search Limited
DeepRec.ai Limited
Ex-Military Careers Limited
Broadgate Search Limited (registered in Ireland)
The law under which each controller processes your personal data is:
- United Kingdom — the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, each as amended by the Data (Use and Access) Act 2025.
- Ireland — Regulation (EU) 2016/679 (the General Data Protection Regulation, or GDPR) and the Data Protection Act 2018.
- Germany — the GDPR and the Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG).
- Switzerland — the Federal Act on Data Protection (Datenschutzgesetz, FADP) and the Data Protection Ordinance. Where Our processing relates to the offering of services to persons located in the European Economic Area, the GDPR may apply in addition.
- United States — applicable federal law and the privacy laws of the state in which you reside. There is no general federal privacy statute; state law varies. All Trinnovo Group personnel are based in the United Kingdom. Certain business activities and processing operations are therefore carried out on behalf of each non-UK controller by personnel of Our United Kingdom entities, under an intra-group arrangement. This is explained in "International Transfers of Personal Data" below.
Separate jurisdiction-specific versions of this notice are available on request from gdpr@trinnovo.com.
Data Protection Officer
Our Data Protection Officer is Matthew Goddard. You can contact the DPO at gdpr@trinnovo.com or by writing to the Data Protection Officer, Trinnovo Group Limited, 20 Westland Place, London, N1 7JR, United Kingdom.
Applies to: Germany
The DPO is appointed in accordance with Article 37 of the GDPR and section 38 of the BDSG.
Applies to: Switzerland
Matthew Goddard also acts as Our Data Protection Advisor (Datenschutzberater) within the meaning of Article 10 FADP.
Representative in the European Union
Trinnovo Group Europe GmbH, Am Zirkus 2, 10117 Berlin, Germany, has been designated as the representative in the Union, pursuant to Article 27 of the GDPR, for those Group controllers which are established outside the European Union. The representative may be contacted at that address or at gdpr@trinnovo.com.
This designation is relevant where a Group entity established outside the European Union processes the personal data of individuals located in the European Economic Area. Where the entity engaging with you is itself established in Ireland or Germany, no representative is required and this section does not apply to you.
The Personal Data We Collect
The categories of personal data We collect vary according to your relationship with Us and where you are located. In every jurisdiction they may include:
- Identifying information — full name, date and place of birth, gender, nationality.
- Contact information — postal address, email addresses (personal and corporate), telephone numbers.
- Professional information — curriculum vitae or resume, work history, qualifications, certifications, professional memberships, references and links to public professional profiles (e.g. LinkedIn).
- Communications — emails, telephone calls (which may be recorded for training and compliance purposes), instant messages, meeting notes.
- Event and community information (Ex-Military Careers) — attendance records, accessibility requirements, dietary requirements, marketing preferences.
- Inferences drawn from the above, for the purpose of matching candidates to suitable roles.
Identity and financial information
The identity documentation and financial information We collect depends on where you will be working.
Applies to: United Kingdom
Passport copies, driving licence copies, biometric residence permits, share codes, visa records and other immigration documents; bank account details, National Insurance number, tax status information, payroll information.
Applies to: Ireland
Passport copies, driving licence copies, employment permit records, immigration permission stamps and other immigration documents; bank account details, PPS number, tax status information, payroll information.
Applies to: Germany
Identity card or passport copies, residence titles (Aufenthaltstitel), work permission records and other immigration documents; bank account details, tax identification number (Steuer-Identifikationsnummer), social security number (Sozialversicherungsnummer), tax class information, payroll information.
Applies to: Switzerland
Identity card or passport copies, residence and work permits (including permit categories B, C, G and L), notification records under the notification procedure for short-term work, and other immigration documents; bank account details, AHV number, withholding tax (Quellensteuer) status, pension fund information, payroll information. We may also collect your place of origin (Heimatort) where applicable.
Applies to: United States
Social Security number, driver's license or state identification card number, passport number; bank account details for payment, tax withholding information, benefits elections, and compensation history where lawfully collected. We may also collect education information, commercial information relating to services provided, and internet and electronic network activity information arising from your interactions with Our websites, job portals and marketing communications.
Assignment information
Where you are placed on a temporary or contract assignment, We also collect assignment information.
Applies to: Ireland
Information relating to basic working and employment conditions, for the purpose of complying with the equal treatment requirements of the Protection of Employees (Temporary Agency Work) Act 2012.
Applies to: Germany
Information relating to essential working conditions, for the purpose of complying with the equal treatment and equal pay requirements of sections 8 and 9 AÜG, and information required for the assignment records We are obliged to maintain under section 7 AÜG. Where a collective bargaining agreement (Tarifvertrag) applies to your engagement, We also process working time and working time account data as necessary to apply the terms of that agreement.
Applies to: Switzerland
Information relating to working conditions and hours, for the purpose of complying with Our obligations under the AVG, the Employment Act (Arbeitsgesetz) and any applicable collective employment agreement (Gesamtarbeitsvertrag).
Applies to: United States
Assignment and placement records, and timesheets.
We do not knowingly collect personal data from individuals under sixteen years of age.
Special Category, Sensitive and Criminal Records Data
Some of the data described above receives additional protection under the law of your jurisdiction. Where We process it, We apply enhanced safeguards including restricted access and additional retention controls.
Applies to: United Kingdom, Ireland, Germany
In limited cases We process special category personal data, such as health information for accessibility and reasonable adjustment purposes. Where We do so, We rely on a condition under Article 9 of the applicable GDPR.
Applies to: United Kingdom
Where required, We also rely on a condition in Schedule 1 to the Data Protection Act 2018.
Applies to: Germany
We rely on Article 9(2) GDPR together with the safeguards required by section 22 BDSG. This may include data relating to severe disability status where necessary to comply with obligations under Book IX of the Social Code (SGB IX).
Applies to: Switzerland
In limited cases We process sensitive personal data within the meaning of Article 5(c) FADP. In Our business this may include health information collected for accessibility and workplace adjustment purposes, and information concerning administrative or criminal proceedings and sanctions. Where We do so, We rely on a justification under Article 31 FADP, in particular your express consent or an overriding private interest.
Applies to: United States
Some of the information We collect is treated as sensitive personal information under state privacy laws, including Social Security numbers and other government identifiers, financial account information, racial or ethnic origin, and health or disability information. We use and disclose sensitive personal information only for the purposes described in this notice and as permitted by applicable law. We do not use or disclose sensitive personal information for purposes of inferring characteristics about you. Where We collect characteristics of protected classifications under federal or state law, including date of birth, gender, race and ethnicity, veteran status and disability status, it is for equal employment opportunity, affirmative action, accommodation or benefits administration purposes, and it is provided on a voluntary basis unless a specific legal obligation applies.
Criminal records information
Our processing of criminal records information differs significantly between jurisdictions.
Applies to: United Kingdom
Where a client engagement or applicable law requires it, We process personal data relating to criminal convictions and offences under Article 10 of the UK GDPR and a condition in Schedule 1 to the Data Protection Act 2018, supported by an Appropriate Policy Document as required by that Act. Checks are carried out through the Disclosure and Barring Service or its equivalents in Scotland and Northern Ireland, via Our screening provider.
Applies to: Ireland
Where an engagement involves work with children or vulnerable persons, We may facilitate vetting through the National Vetting Bureau under the National Vetting Bureau (Children and Vulnerable Persons) Acts 2012 to 2016. Outside those circumstances, We do not require or process criminal records information in respect of engagements in Ireland.
Applies to: Germany
We do not require a certificate of good conduct (Führungszeugnis) as a matter of routine. Where a specific role or a legal requirement makes such a check necessary and proportionate, We will explain the basis for the request before it is made.
Applies to: Switzerland
Where a specific role or a legal requirement makes such a check necessary and proportionate, We may process information concerning administrative or criminal proceedings and sanctions, as described above.
Applies to: United States
See "Background Checks and Consumer Reports" below.
How We Obtain Personal Data
We obtain personal data through the following channels:
- Directly from you (when you register with Us, submit a CV or resume, contact Us, attend an event or subscribe to a Trinnovo service).
- From publicly available sources, including LinkedIn, corporate websites, professional directories and online CV libraries.
- From third parties, including referrals from existing candidates or clients, recruitment platforms, job boards, references you provide, and (for screening purposes) background-check providers.
- Third-party B2B contact data and sales intelligence providers (such as Sourcewhale, Lusha, ZoomInfo and Cognism), which compile business contact information from publicly available sources, professional networking platforms, and their own licensed datasets.
- From Our clients, in relation to assignments and placements.
Applies to: United Kingdom, European Economic Area
Where We obtain your personal data from a source other than you, We will provide you with this notice within a reasonable period, and in any event within one month, in accordance with Article 14 of the applicable GDPR.
Applies to: Switzerland
Where We obtain your personal data from a source other than you, We will inform you in accordance with Article 19 FADP.
How We Use Your Personal Data
We use personal data for the following purposes:
- Providing recruitment and staffing services: identifying suitable candidates, introducing or submitting them to clients, and supporting the engagement and placement process.
- Supporting candidates throughout their careers and supporting clients with their resourcing needs over time.
- Performance of contracts We have entered into with candidates, clients and contractors, including employment agreements with temporary and contract workers.
- Operating payroll, self-billing, benefits administration and invoicing arrangements.
- Compliance with legal and regulatory obligations, including recruitment-sector legislation, employment law, tax law and data protection law.
- Verifying your right to work in the relevant jurisdiction.
- Conducting pre-engagement screening where required by Our clients or by applicable law.
- Maintaining business relationships and communicating with you about services that may be of interest to you.
- Running events, podcasts and community activities.
- Operating Our information security, fraud-prevention and risk-management arrangements.
- Defending and resolving legal disputes, complaints and claims. The specific legal and regulatory obligations We are meeting, and the basis on which We verify your right to work, differ by jurisdiction.
Applies to: United Kingdom
The Conduct of Employment Agencies and Employment Businesses Regulations 2003; the off-payroll working rules in Chapter 10 of Part 2 of ITEPA 2003; right-to-work verification under the Immigration, Asylum and Nationality Act 2006 and Home Office guidance.
Applies to: Ireland
The Employment Agency Act 1971 and the Protection of Employees (Temporary Agency Work) Act 2012; right-to-work verification including under the Employment Permits Act 2024 where you are not a national of the European Economic Area or Switzerland.
Applies to: Germany
The AÜG and Book III of the Social Code (SGB III); wage tax and social security contribution obligations; verification of entitlement to work under the Residence Act (Aufenthaltsgesetz) and the Employment Ordinance (Beschäftigungsverordnung); defending claims under the General Equal Treatment Act (Allgemeines Gleichbehandlungsgesetz, AGG).
Applies to: Switzerland
The AVG and AVV; social insurance obligations including AHV/IV/EO, unemployment insurance, occupational pension and accident insurance; verification of entitlement to work under the Foreign Nationals and Integration Act (Ausländer- und Integrationsgesetz) and, where applicable, the Agreement on the Free Movement of Persons.
Applies to: United States
Federal, state and local obligations including employment eligibility verification through completion of Form I-9 as required by the Immigration Reform and Control Act, tax withholding and reporting, equal employment opportunity reporting, workers' compensation and unemployment insurance administration, and recordkeeping requirements.
We do not use your personal data for purposes that are unrelated to, or incompatible with, the purposes described above without providing you notice.
Our Lawful Basis
Applies to: United Kingdom, European Economic Area
The legal basis on which We rely depends on the activity.
- Performance of a contract, or steps taken at your request prior to entering into a contract (Article 6(1)(b)) — where We are negotiating or have entered into a placement, employment or services agreement with you or with the entity engaging you.
- Legitimate interests (Article 6(1)(f)) — for the operation and development of Our recruitment business, including matching candidates to clients, maintaining Our database of candidate and client information, business-to-business marketing, and managing Our business operations. We balance Our interests against your rights and freedoms in each case, and you may request a copy of the relevant balancing assessment.
- Legal obligation (Article 6(1)(c)) — where We are required to process your personal data to comply with applicable law, for example right-to-work checks, tax obligations and regulatory record-keeping requirements.
- Consent (Article 6(1)(a)) — for specific activities for which We seek your consent, for example certain electronic marketing communications, or retention of your application in Our talent pool beyond the periods described below. Where We rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Applies to: Germany
Where consent is given in the context of an employment relationship, We assess it in accordance with section 26(2) BDSG. Section 26 BDSG contains supplementary provisions on the processing of employee data. Following the judgment of the Court of Justice of the European Union of 30 March 2023 (Case C-34/21), We do not rely on section 26(1) sentence 1 BDSG as a free-standing legal basis, and each processing activity is assessed against the requirements of the GDPR itself.
Applies to: Switzerland
Under Swiss law, a private controller does not require a legal basis before processing personal data. We process personal data in accordance with the principles set out in Articles 6 and 8 FADP: lawfulness, good faith, proportionality, purpose limitation, transparency, accuracy and data security. Where Our processing would otherwise breach your personality rights within the meaning of Article 30 FADP, We rely on a justification under Article 31 FADP, being your consent, an overriding private or public interest, or a provision of law. Where you are employed by Us, We process your personal data in accordance with Article 328b of the Code of Obligations, which permits Us to process data concerning you only in so far as that data concerns your suitability for the employment relationship or is necessary for the performance of the employment contract.
Applies to: United States
United States law does not require Us to identify a legal basis before processing personal information. We process personal information for the business and commercial purposes described above, and only in ways consistent with the notice We have given you and with applicable federal and state law.
Background Checks and Consumer Reports
Applies to: United States
Where a client engagement or applicable law requires it, We may obtain a consumer report or investigative consumer report about you from a consumer reporting agency. This may include verification of employment and education history, criminal history where permitted by law, motor vehicle records, and in limited circumstances credit history where the role and applicable state law permit it. We will not obtain such a report without first providing you with a clear and conspicuous written disclosure in a document consisting solely of that disclosure, and obtaining your written authorization, as required by the federal Fair Credit Reporting Act and applicable state fair credit reporting laws. If We intend to take adverse action based in whole or in part on the contents of such a report, We will provide you with a copy of the report, a summary of your rights, and an opportunity to respond before taking final action. We comply with applicable state and local laws restricting inquiries into criminal history, salary history and credit history, including laws which restrict when such inquiries may be made in the hiring process.
Sale and Sharing of Personal Information
Applies to: United States
We do not sell your personal information, and We do not share your personal information for cross-context behavioral advertising, as those terms are defined under state privacy laws. We have not sold or shared personal information in the twelve months preceding the date of this notice. Certain state privacy laws require Us to treat the transmission of information to advertising and analytics providers through Our websites as a sale or sharing in some circumstances. Where that is the
case, Our Cookie Notice explains the controls available to you, and We honor opt-out preference signals, including the Global Privacy Control, transmitted by your browser.
Sharing Your Personal Data
We share personal data only as necessary for the purposes set out above, with the following categories of recipient:
- Other companies in Our Group, where necessary for operational reasons. This includes Our United Kingdom entities, which carry out business activities on behalf of each non-UK controller.
- Clients (for candidates) and candidates (for clients), as part of the recruitment, submission and assignment process.
- Suppliers and service providers acting as processors on Our behalf (see the processor table below).
- Professional advisers, including external lawyers, tax advisers, accountants and auditors.
- Payroll providers, benefits carriers, insurers, pension and retirement plan administrators, and social insurance institutions.
- Regulators, public bodies and law enforcement agencies, where required by law.
- Acquirers (in the event of a sale or restructuring of any part of the Group's business). The public bodies and regulators to whom We may disclose personal data include the following.
Applies to: United Kingdom
HM Revenue & Customs, the Employment Agency Standards Inspectorate and the Home Office.
Applies to: Ireland
The Revenue Commissioners, the Workplace Relations Commission and the Department of Enterprise, Tourism and Employment.
Applies to: Germany
The tax authorities (Finanzämter), social security institutions, health insurance funds (Krankenkassen), the Bundesagentur für Arbeit and, in relation to the AÜG permission, the competent supervisory authorities.
Applies to: Switzerland
Social insurance institutions, pension funds, accident insurers, tax authorities and, in relation to Our AVG licences, the competent cantonal authority and the State Secretariat for Economic Affairs (SECO). We are bound by a duty of confidentiality in respect of the personal data of jobseekers and hired-out personnel under Articles 7 and 18 AVG. Our employees are subject to corresponding confidentiality obligations.
Applies to: United States
The Internal Revenue Service, state tax and labor agencies, the Social Security Administration, the Department of Homeland Security and the Equal Employment Opportunity Commission, and consumer reporting agencies and background screening providers.
Processors
The following processors act on Our behalf under written contracts which restrict their use of personal data to the purposes for which it was disclosed. Those listed under a jurisdiction heading are engaged only in relation to that jurisdiction.
Group-wide
Jurisdiction-specific
Premises providers are recognised in Our supplier register as providers of operating premises but do not process personal data on Our behalf in the conventional sense.
Automated Processing
We use technology to help organise and search candidate information, including keyword matching and ranking within Our applicant tracking system, and We use generative artificial intelligence tools to assist Our consultants in drafting communications and reviewing documents.
We do not make decisions about your suitability, shortlisting, submission to a client, or placement by automated means alone. Those decisions are made by Our consultants, who review the underlying information themselves. Where a client uses its own automated tools in its hiring process, that use is governed by the client's own practices and disclosures.
Applies to: United States
Where state or local law requires notice, consent, or an independent bias audit before an automated employment decision tool is used, We will provide the required notice and comply with the applicable requirements before any such tool is used in connection with your application.
International Transfers of Personal Data
Personal data is principally hosted in the United Kingdom. All Trinnovo Group personnel are based in the United Kingdom and carry out business activities and processing operations on behalf of each Group controller. Personal data collected anywhere in Our Group is therefore routinely transferred to, and accessed from, the United Kingdom.
Transfers between Trinnovo Group companies are governed by an intra-group data transfer arrangement incorporating an appropriate transfer mechanism.
Applies to: Ireland, Germany, European Economic Area
On 19 December 2025 the European Commission renewed its adequacy decision in respect of the United Kingdom under Article 45 of the GDPR. That decision is currently in force. Transfers of personal data from the EEA to Our United Kingdom entities are made on the basis of that adequacy decision, and are additionally supported by the Standard Contractual Clauses adopted by the European Commission within Our intra-group arrangement, which would apply should the adequacy decision cease to have effect. Where personal data is transferred to a country outside the European Economic Area that is not the subject of an adequacy decision, We apply an appropriate transfer mechanism under Chapter V of the GDPR, including the Standard Contractual Clauses supported by a transfer impact assessment, or the EU-US Data Privacy Framework where the US recipient is appropriately certified.
Applies to: United Kingdom
Where personal data is transferred outside the United Kingdom, We apply an appropriate transfer mechanism under Chapter V of the UK GDPR, including UK adequacy regulations, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses supported by a transfer risk assessment, or the UK Extension to the EU-US Data Privacy Framework where the US recipient is appropriately certified.
Applies to: Switzerland
Personal data collected in Switzerland is transferred to the United Kingdom, and is also accessed remotely from the United Kingdom, which under Swiss law constitutes a disclosure abroad. The United Kingdom is listed in Annex 1 to the Data Protection Ordinance as a State which guarantees an adequate level of data protection. Disclosures from Switzerland to Our United Kingdom entities are accordingly made on the basis of Article 16 paragraph 1 FADP, without the need for additional safeguards. Where personal data is disclosed to a State which is not listed in Annex 1, We ensure adequate protection by other means in accordance with Article 16 paragraph 2 FADP, including standard data protection clauses approved, issued or recognised in advance by the Federal Data Protection and Information Commissioner (in particular the Standard Contractual Clauses adopted by the European Commission with the amendments required under Swiss law), or the Swiss-US Data Privacy Framework where the recipient is appropriately certified. You may request further information about the safeguards applied, and a copy of the relevant documentation, by contacting gdpr@trinnovo.com.
Applies to: United States
By providing personal information to Us, you understand that it will be transferred to, stored in, and processed in countries outside the United States, which may have data protection rules that differ from those of your state. We apply the same protections to your personal information wherever it is processed, and Our intra-group data transfer arrangement requires each receiving entity to maintain appropriate safeguards.
Retention of Personal Data
We do not retain personal data for longer than is necessary in light of the purposes for which it was collected and the obligations to which We are subject. In determining the retention period for a category of data, We consider the volume and sensitivity of the information, the purpose for which it was collected, the applicable limitation period, and any statutory recordkeeping requirement.
Applying those criteria across Our Group:
- Candidate and client data — held for the duration of the active relationship and for an extended period thereafter to support potential further engagement. Where no contact has occurred for 3 to 5 years (depending on the history of the relationship), data is reviewed for deletion as part of Our routine data-cleansing process.
- Pre-employment screening data — retained only for so long as necessary for the purpose for which it was obtained, and for the period required by the screening provider's contract and applicable law.
- Event and community records — retained for the period necessary to support the community relationship and to demonstrate compliance with marketing and consent obligations. The remaining retention periods are set by local law.
Applies to: United Kingdom
Records required by the Conduct of Employment Agencies and Employment Businesses Regulations 2003 are retained for at least one year. Employee data is retained for the duration of employment and for six years thereafter, in line with UK tax and employment law and the limitation period under the Limitation Act 1980. Right-to-work documentation is retained for the duration of the engagement and for two years after it ends, in line with Home Office guidance. Financial and tax records are retained for six years from the end of the relevant accounting period. Criminal records information is not retained beyond the recruitment decision unless a specific legal or contractual requirement applies.
Applies to: Ireland
Records required to be kept by a licensed employment agency are retained under the Employment Agency Act 1971. Employee and agency worker data is retained for the duration of the engagement and for six years thereafter, in line with the limitation period under the Statute of Limitations 1957. Working time records are retained for at least three years under the Organisation of Working Time Act 1997. Right-to-work and employment permit documentation is retained for the period required under the Employment Permits Act 2024. Financial and tax records are retained for six years under the Taxes Consolidation Act 1997 and the Companies Act 2014.
Applies to: Germany
Where an application is unsuccessful, applicant data is retained for six months following the conclusion of the application procedure, to enable Us to respond to any claim under the AGG; longer retention in Our talent pool takes place only with your consent. Assignment records are retained under section 7 AÜG. Payroll tax records are retained under section 41 of the Income Tax Act (Einkommensteuergesetz). Social security records are retained under section 28f SGB IV until the end of the calendar year following the last completed audit. Financial, accounting and tax records are retained for the periods required by section 257 of the Commercial Code (Handelsgesetzbuch) and section 147 of the Fiscal Code (Abgabenordnung), being up to ten years. Minimum wage records are retained for at least two years under section 17 of the Minimum Wage Act (Mindestlohngesetz).
Applies to: Switzerland
Placement and hiring records are retained under the AVG and AVV. Employee and hired-out personnel data is retained for the duration of the engagement and for ten years thereafter, in line with the general limitation period under Article 127 of the Code of Obligations. Working time and rest period records are retained for at least five years under the Employment Act and Ordinance 1 to the Employment Act. Social insurance and pension records are retained for the periods required under the Federal Act on Old Age and Survivors Insurance and related legislation. Accounting, financial and tax records are retained for ten years under Article 958f of the Code of Obligations.
Applies to: United States
Application and hiring records are retained for the period required under Title VII of the Civil Rights Act, the Age Discrimination in Employment Act, the Americans with Disabilities Act and the regulations of the Equal Employment Opportunity Commission, and for longer where a charge or claim is pending. Employment eligibility verification records (Form I-9) are retained for the duration of employment and thereafter for the period required by federal immigration law. Payroll and wage records are retained under the Fair Labor Standards Act, the Internal Revenue Code and applicable state wage and hour laws. Benefits and retirement plan records are retained under the Employee Retirement Income Security Act. Consumer report information is disposed of securely in accordance with the disposal rule under the Fair and Accurate Credit Transactions Act.
On expiry of the relevant retention period, personal data is securely deleted, archived, pseudonymised or de-identified in accordance with Our retention procedure.
Security
We have implemented appropriate technical and organisational measures to protect your personal data against accidental or unlawful loss, alteration, unauthorised disclosure or access. These include access controls, encryption, multi-factor authentication, endpoint protection, email security, supplier security management, and an Information Security Management System aligned with ISO/IEC 27001:2022.
Applies to: United Kingdom, European Economic Area
These measures are implemented as required by Article 32 of the applicable GDPR.
Applies to: Switzerland
These measures are implemented as required by Article 8 FADP and Articles 1 to 4 of the Data Protection Ordinance. Where a breach of data security is likely to result in a high risk to your personality or fundamental rights, We will notify the Federal Data Protection and Information Commissioner as soon as possible, and will inform you where necessary for your protection or where the Commissioner so requires.
Applies to: United States
We maintain a written information security program with administrative, technical and physical safeguards appropriate to the nature of the personal information We hold, including as required by the Massachusetts Standards for the Protection of Personal Information of Residents of the Commonwealth (201 CMR 17.00) and other applicable state data security laws. Where a breach of the security of personal information occurs, We will notify affected individuals and, where required, state regulators, in accordance with applicable state breach notification laws.
Cookies
Our websites use cookies. Details of the cookies We use, the purposes for which they are used and the options you have to manage them are set out in Our separate Cookie Notice, available on Our websites.
Applies to: United Kingdom
Non-essential cookies are set only with your consent, in accordance with the Privacy and Electronic Communications (EC Directive) Regulations 2003.
Applies to: Ireland
Non-essential cookies are set only with your consent, in accordance with S.I. No. 336 of 2011.
Applies to: Germany
Cookies and similar technologies which are not strictly necessary are used only with your consent, in accordance with section 25 of the Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG).
Applies to: Switzerland
Our use of cookies is described in accordance with Article 45c of the Telecommunications Act.
Applies to: United States
We honor opt-out preference signals, including the Global Privacy Control, transmitted by your browser.
Your Rights
The rights available to you depend on the law that applies to your personal data.
Applies to: United Kingdom, European Economic Area
You have the following rights.
- Right to be informed — about how We use your personal data (this notice forms part of how We comply).
- Right of access — to obtain a copy of the personal data We hold about you.
- Right to rectification — to have inaccurate or incomplete data corrected.
- Right to erasure — to have your data deleted in certain circumstances.
- Right to restrict processing — to limit how We use your data in certain circumstances.
- Right to object — to certain processing, including direct marketing.
- Right to data portability — to receive your data in a portable format for transfer to another organisation.
- Right to withdraw consent — at any time, where Our processing is based on your consent.
- Rights in relation to automated decision-making and profiling — to the extent applicable. As stated above, Our services do not include solely automated decision-making producing legal or similarly significant effects.
We will respond without undue delay and in any event within one month of receipt of your request, extended by up to two further months where necessary taking into account the complexity and number of requests. There is normally no charge; a reasonable fee may be charged, or the request refused, where it is manifestly unfounded or excessive.
Applies to: Germany
Sections 32 to 37 BDSG contain limited exceptions to and restrictions on certain of these rights. Where such an exception applies to your request, We will tell you.
Applies to: Switzerland
You have the following rights.
- Right to information — to be informed about the collection of your personal data (this notice forms part of how We comply).
- Right of access (Article 25 FADP) — to obtain confirmation of whether We process personal data concerning you, and the information necessary for you to exercise your rights.
- Right to rectification (Article 32 FADP) — to have inaccurate personal data corrected.
- Right to request deletion or destruction of your personal data.
- Right to object to a particular processing activity, and to request that a disclosure to third parties be prohibited.
- Right to data portability (Article 28 FADP) — to request the release of your personal data in a commonly used electronic format, or its transfer to another controller, where We process it by automated means with your consent or in connection with a contract.
- Right to a note of contestation attached to your data, where neither the accuracy nor the inaccuracy of the data can be established.
- Rights in relation to automated individual decision-making (Article 21 FADP) — to be informed of, and to request review of, any decision taken solely by automated processing which has a legal consequence for you or affects you significantly. As stated above, Our services do not include such decisions.
Access is provided free of charge and We will respond within 30 days of receipt of your request, or will tell you within that period when a response will follow. In the circumstances set out in Articles 26 and 27 FADP We may refuse, restrict or defer a response, and where We do so We will tell you why.
Applies to: United States
State privacy laws give residents of certain states rights over their personal information, and the rights available under law depend on the state in which you reside. As a matter of Our practice, We make the following rights available to all individuals in the United States whose personal information We hold.
- Right to know — to confirm whether We process personal information about you, and to obtain the categories of information collected, the sources, the purposes, and the categories of recipients.
- Right of access — to obtain a copy of the specific pieces of personal information We hold about you, in a portable format where technically feasible.
- Right to correct — to have inaccurate personal information corrected.
- Right to delete — to have your personal information deleted, subject to the exceptions provided by law, including where We are required to retain it.
- Right to opt out of sale or sharing — although, as stated above, We do not sell or share personal information.
- Right to limit the use of sensitive personal information — to direct Us to limit Our use of sensitive personal information to what is necessary to provide Our services.
- Right to opt out of profiling in furtherance of decisions producing legal or similarly significant effects — although, as stated above, We do not make such decisions by automated means alone.
- Right to appeal — to appeal a decision We make in response to any of the requests above.
- Right to non-discrimination — We will not discriminate against you, deny you services, or treat you differently as a candidate or worker because you exercised any of these rights.
We will confirm receipt within ten business days and respond within forty-five days, which may be extended by a further forty-five days where reasonably necessary, in which case We will tell you why. There is no charge unless a request is manifestly unfounded or excessive.
You may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your written permission, and may require you to verify your own identity directly with Us. If We deny your request in whole or in part, you may appeal by writing to gdpr@trinnovo.com with the subject line "Privacy Rights Appeal". We will respond within the period required by your state's law and, if We deny the appeal, We will provide you with a means of contacting your state Attorney General.
How to Exercise Your Rights
To exercise any of the rights described above, please contact gdpr@trinnovo.com.
Before responding, We will take reasonable steps to verify your identity, which may require you to provide information We already hold about you. We will not use information provided for verification for any other purpose.
Right to Object
Direct marketing
You can object to the processing of your personal data for direct marketing at any time. This includes any profiling related to direct marketing. This is an absolute right and there are no exemptions or grounds for Us to refuse. Every marketing communication We send includes a means of declining further communications.
Applies to: Switzerland
This is provided for by Article 3 paragraph 1 letter o of the Unfair Competition Act.
Applies to: United States
We will honor your request promptly and in any event within the period required by the CAN-SPAM Act and applicable state law.
All other processing
Applies to: United Kingdom, European Economic Area
Where We process your personal data on the basis of Our legitimate interests, you may object at any time on grounds relating to your particular situation. We will stop that processing unless We can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.
Applies to: Switzerland
You may object to Our processing of your personal data at any time. Where you do so, We will cease the processing concerned unless We can establish a justification under Article 31 FADP, being an overriding private or public interest or a provision of law, or unless the processing is necessary for the establishment, exercise or defence of legal claims.
Applies to: United States
You may object to Our use of your personal information at any time by contacting Us. Where the law gives you a right to opt out, to limit the use of sensitive personal information, or to require deletion, We will honor that request as described above.
You should be aware that some processing is necessary in order for Us to provide recruitment and staffing services to you. Where you object to processing that is necessary for the performance of a contract with you, or that We are required by law to carry out, We may be unable to continue an onboarding process or to place you in an assignment. We will explain the position to you before taking any such step, and objecting will never affect the exercise of your other rights.
Complaints
If you are unhappy with the way in which We have handled your personal data, please first contact Us at gdpr@trinnovo.com.
You also have the right to complain to the supervisory authority in your jurisdiction.
dataprotection.ie
datenschutz-berlin.de
edoeb.admin.ch
Applies to: United States
You may contact the Attorney General of your state. Residents of California may contact the California Privacy Protection Agency.
Applies to: European Economic Area
You may lodge a complaint with the supervisory authority in the Member State of your habitual residence, your place of work, or the place of the alleged infringement, whether or not that authority is listed above.
Applies to: United Kingdom, European Economic Area
You also have the right to an effective judicial remedy under Article 79 of the applicable GDPR.
Applies to: Switzerland
You may in addition bring civil proceedings before the competent Swiss court under Articles 32 FADP and 28 et seq. of the Civil Code.
Changes to this Notice
We review this notice at least annually and update it as Our business and the regulatory environment evolve. The most recent version is always available on Our websites. Material changes are notified appropriately.
If You Do Not Agree
This notice explains how We process your personal data. It is not a contract and We do not ask you to agree to it.
If, having read this notice, you do not wish Us to process your personal data for the purposes described, please tell Us. Where the processing concerned is necessary for Us to provide recruitment and staffing services to you, We may be unable to continue an onboarding process or to place you in an assignment. If
you would like to discuss this with us, please contact us either by email at complianceteam@trinnovo.com or by calling us on +44 (0) 208 049 1998.
