Privacy Policy
Last updated: 22 February 2025
1. Introduction
ScreenSmart ("we", "us", "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, store, and share personal information when you use our AI-powered recruitment platform and related services (the "Service").
We are registered in England and Wales. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, ScreenSmart is the data controller in respect of the personal data we collect directly from users of our website, and a data processor on behalf of our employer clients in respect of candidate data processed through our platform.
2. Information We Collect
We may collect and process the following categories of personal data:
2.1 Information you provide directly
- Name, email address, phone number, and company details when you register for an account, request a demo, or contact us.
- Payment and billing information when you subscribe to our Service.
- Any correspondence or communications you send to us.
2.2 Candidate data (processed on behalf of employers)
- Candidate names, contact details (phone numbers, email addresses), and application information.
- Conversational data from interactions via WhatsApp, SMS, or other messaging channels facilitated through our platform.
- Screening responses, interview scheduling preferences, and assessment results.
- CVs, employment history, qualifications, and other information submitted during the recruitment process.
2.3 Technical and usage data
- IP address, browser type, device information, and operating system.
- Pages visited, features used, time spent on our website, and other analytics data.
- Cookies and similar tracking technologies (see Section 8).
3. How We Use Your Information
We process personal data for the following purposes and on the following lawful bases:
- Performance of a contract: To provide, maintain, and improve our Service; to process candidate applications on behalf of employer clients; to facilitate AI-driven screening, scheduling, and communication.
- Legitimate interests: To analyse usage patterns and improve our platform; to ensure the security of our Service; to communicate with you about updates or changes; to provide customer support.
- Consent: To send you marketing communications (where you have opted in); to place non-essential cookies on your device.
- Legal obligation: To comply with applicable laws, regulations, and legal processes.
4. AI and Automated Decision-Making
Our Service uses artificial intelligence to assist with recruitment processes, including candidate screening, communication, and scheduling. We want to be transparent about how this works:
- Our AI assists employers in managing recruitment workflows but does not make final hiring decisions autonomously. All significant employment decisions remain with the employer.
- AI-generated screening results and candidate assessments are provided as recommendations to support human decision-making.
- Under UK GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. If you believe an automated decision has significantly affected you, please contact us.
5. Data Sharing and Transfers
We may share personal data with:
- Employer clients: Candidate data is shared with the employer on whose behalf we process applications.
- Service providers: Trusted third-party providers who help us operate the Service (e.g., cloud hosting, messaging providers, analytics services). These providers are bound by data processing agreements.
- ATS providers: Where our platform integrates with an employer's applicant tracking system, data may be transferred to that system.
- Legal requirements: Where required by law, to comply with legal obligations, or to protect our rights.
Where personal data is transferred outside the United Kingdom, we ensure appropriate safeguards are in place in accordance with UK GDPR, such as standard contractual clauses approved by the Information Commissioner's Office (ICO) or transfers to countries with an adequacy decision.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements:
- Account data: Retained for the duration of your account and for a reasonable period thereafter.
- Candidate data: Retained in accordance with the employer client's instructions and applicable retention policies. Typically, candidate data is retained for no longer than 12 months after the conclusion of the recruitment process, unless a longer period is required.
- Technical data: Retained for up to 24 months for analytics and security purposes.
7. Your Rights
Under the UK GDPR, you have the following rights in relation to your personal data:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data in certain circumstances.
- Right to restrict processing: Request that we limit how we use your data.
- Right to data portability: Receive your data in a structured, commonly used, and machine-readable format.
- Right to object: Object to processing based on legitimate interests or for direct marketing purposes.
- Rights related to automated decision-making: Request human review of decisions made solely by automated means.
To exercise any of these rights, please contact us using the details in Section 10. We will respond to your request within one month. If you are a candidate whose data has been processed on behalf of an employer, we may direct your request to the relevant employer.
9. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption of data in transit and at rest, access controls, regular security assessments, and staff training. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.
10. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:
ScreenSmart
Email: privacy@screensmart.ai
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated. The ICO can be contacted at ico.org.uk.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically. Where changes are significant, we will notify you by email or through a notice on our website.