Skip to content
ISO 9001 Certified·
Cyber Essentials Certified·
REC Corporate Member·
Public Sector Framework Supplier·
UK Wide
LEGAL

Privacy Policy

invitise Ltd · Version 2.9 · Last updated 4 September 2026

What We Do

invitise Ltd provides contract, SOW, permanent, temporary, and interim recruitment and outcome solutions to clients seeking to recruit professional staff across a range of specialist areas.

invitise Ltd also operates:

  • M-IFS (Multi-Faith Inclusive Framework Standard) — an independent workplace accreditation assessing organisations' religious and cultural inclusion practices

All services are delivered in line with applicable UK data protection law and invitise Ltd's ISO 9001 certified Quality Management System, whose certified scope includes the M-IFS accreditation line.

What Does This Policy Cover?

This Privacy Policy explains:

  • The types of personal data we collect about you
  • How and why we collect and use your personal data
  • How long we keep your personal data
  • When, why, and with whom we share your personal data
  • The legal basis we have for processing your personal data
  • Your rights and choices regarding your personal data
  • How we may contact you and how you can contact us

This Privacy Policy may be updated from time to time. Please check this page periodically to stay informed of any changes.

Who Are You?

We collect and process personal data from the following types of individuals:

  • Candidates (existing or prospective)
  • Clients (existing or prospective)
  • Users of our website
  • Referees or emergency contacts provided by candidates or staff
  • Suppliers to our organisation
  • invitise employees, contractors, or interim workers

Who Is the Data Controller?

invitise Ltd is the Data Controller and determines the purposes and means of processing personal data.

  • Company No: 13345316
  • VAT No: 381151123
  • Head Office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
  • Contact No: +44 (0)345 163 0135
  • Email: dataprotection@invitise.com
  • ICO Registration No: ZB058757

Our Data Protection Officer is Fahim Rashid (Managing Director). Data protection enquiries and requests can be sent to dataprotection@invitise.com.

What Is Personal Data?

Personal data means any information relating to an identified or identifiable individual, including:

  • Names, contact details, and identifiers
  • Employment history, qualifications, and role information
  • CVs and application data
  • Special category data (e.g. health, religious belief, diversity information), processed only where lawful and necessary

Legal Basis for Processing Personal Data

We primarily rely on legitimate interests as our lawful basis for processing personal data, including in relation to:

  • Recruitment and talent services
  • Client and supplier relationship management
  • Website users and business contacts

Where required, we may also rely on contractual necessity, legal obligation, or explicit consent (e.g. for special category data). We carry out legitimate interest assessments where appropriate.

How We Use Your Data

For candidates and individuals:

  • Matching skills and experience with opportunities
  • Providing recruitment, coaching, mentoring, and career-related services
  • Personalising communications and support
  • Conducting eligibility and compliance checks

For clients and suppliers:

  • Managing contractual and commercial relationships
  • Resolving queries, disputes, or compliance matters
  • Ensuring operational security and continuity

M-IFS Accreditation Scheme

Where you apply for, or hold, M-IFS accreditation, we process:

  • Applicant contact data (name, job title, work email, phone) for the individuals you nominate to manage the application
  • Evidence you submit against the published criteria (documents, images, links, descriptions)
  • Incidental personal data that may appear within evidence (for example, a photograph including a member of staff)
  • Anonymous staff survey responses, where used, which carry no identifiers

Applicant contact data is processed under contract, being the assessment you have asked us to carry out. Incidental personal data within evidence is processed under legitimate interests, being the operation of a credible certification scheme, minimised at the first opportunity. Where evidence would incidentally reveal an individual's religion or belief, we rely on Article 9(2)(g) UK GDPR (substantial public interest) read with Schedule 1 Part 2 paragraph 8 of the Data Protection Act 2018 (equality of opportunity or treatment).

Evidence files are encrypted at rest, access is logged, and the client evidence portal is accessed only via a unique, expiring, revocable link. Evidence is retained for three years after certification expires or a decision is made, then the stored files are deleted automatically; the assessment record (verdicts, decisions, certificates) is kept for six years. AI assists our assessors with documentary evidence only: identifying details are redacted first, and images are never sent to any AI system.

Applicants receive our M-IFS Data Protection and Confidentiality Statement and Data Processing and Sharing Agreement, which set this out in full and are provided at proposal stage. This section is a summary for website visitors; those documents take precedence for M-IFS applicants and certified organisations.

Automated Processing and Profiling

To match candidates with suitable opportunities efficiently, we use software — including automated tools and AI-assisted matching — that ranks and suggests how well a candidate's skills and experience fit a role, and that helps us prioritise and organise our work. This supports our consultants' decisions; it does not replace them. A member of our team always makes the final decision on shortlisting, representation and placement, so there is no solely automated decision-making producing legal or similarly significant effects under Article 22 of the UK GDPR. Some of that AI assistance is provided by specialist AI companies acting as our processors, so we are clear about what reaches them. Before anything is sent, our system removes the details that identify you: your name, contact details, postcode, address and any web links. What remains is professional content, such as your skills and experience, labelled with a reference number rather than your name, so the AI provider cannot tell who you are. We hold the key linking that reference back to you, so we continue to treat it as your personal data and protect it accordingly. Those providers are contractually barred from using it to train their models, and where they process outside the UK it is covered by Standard Contractual Clauses with the UK Addendum. We never send identity documents, right-to-work evidence or other compliance images to any AI service. You can ask us about this processing, or object to it, at any time using the contact details above.

Where We Source Personal Data

We may obtain personal data from direct interactions with you, publicly available sources (e.g. LinkedIn, job boards), referrals or third-party introductions, and reputable third-party data providers. Occasionally we may purchase data from reputable providers; such data is processed under legitimate interest, and individuals will be informed of their rights including the right to object or request deletion.

Who We Share Your Data With

We do not sell your personal data. We share it only where necessary, with:

  • Clients and hiring organisations, where we put you forward for a role
  • Umbrella companies, payroll providers and accredited suppliers involved in a placement
  • Background-screening, right-to-work and compliance partners, where a role requires it
  • Service providers who process data on our behalf (processors) — including IT, hosting, email, our recruitment system, marketing and data-cleansing providers, and the AI providers described above — who act only on our documented instructions under a data processing agreement
  • Professional advisers (e.g. legal, accounting, insurance) where necessary
  • Regulators, law enforcement or other authorities where we are required to by law

invitise Ltd remains the data controller at all times; our processors may not use your data for their own purposes.

Data Retention Period

We keep personal data only as long as we need it for the purpose it was collected, plus any period required to meet legal, regulatory or contractual obligations or to establish, exercise or defend legal claims. In practice:

  • Candidate CVs and CV content: kept while you are active with us and automatically minimised after 24 months of no meaningful contact — your CV document and CV text are deleted, while your core contact and searchable details (name, contact details, role, skills) are retained so we can still tell you about relevant opportunities.
  • Candidate records: where we have had no meaningful contact, we contact you at around 4.5 years to ask whether you wish to remain on our database, and delete your record at around 5 years of inactivity.
  • Placement and compliance documents (identity, right-to-work and onboarding evidence for candidates we place): kept for 6 years after the engagement ends, or 7 years where the placement was made through a public sector framework whose audit terms require it — the periods needed to meet client audit rights and to establish, exercise or defend legal claims. Where onboarding documents are collected but no placement proceeds, they are deleted after 6 months. After removal, a minimal skeleton record is kept as proof of timely deletion.
  • Client, supplier and contractual records: kept for the duration of the relationship and then as required for legal and regulatory purposes.
  • Client and prospect business contacts (name, work email, job title, work phone): kept for 5 years from the last meaningful engagement (any reply, call, meeting, enquiry or placement resets the clock). Contacts are reviewed at 4.5 years and, if still dormant, deleted at 5 years, and are removed sooner if we learn they have left the organisation or the work address is no longer valid. Every marketing message carries an opt-out, and objections are honoured immediately.
  • M-IFS evidence: deleted automatically three years after certification expires or a decision is made. The M-IFS assessment record is kept for six years.
  • Financial and tax records: retained for 6 years in line with UK tax and company law.

Our recruitment system automatically applies the candidate CV-minimisation and record-review/deletion periods above. Data that is no longer needed is securely deleted or anonymised.

Our Podcast, Cyber Heard

If you take part in our podcast as a guest, this section explains what happens to your information. It applies to guests, not to listeners.

What we record and publish: your name, your job title and employer, your voice, your image where the episode is filmed, and everything you say. We publish on our own website and podcast feed, Apple Podcasts, Spotify, YouTube, LinkedIn, X and Instagram, and we use short clips and quotations to promote the episode. That list is the whole of it: if we ever want to publish it somewhere else, we will tell you first.

On what basis: with your agreement, which we ask for in writing before recording and keep on record. Taking part is never a condition of a placement, a contract or anything else between us and you or your employer, and declining changes nothing.

Transcription: episode audio is sent to an automated transcription provider acting as our processor, to produce captions, a searchable transcript and an article version. That provider does not use it to train its models and retains nothing once the transcript is produced.

Other platforms: once an episode is published on Apple Podcasts, Spotify, YouTube, LinkedIn, X or Instagram, that platform handles it under its own terms, in its own right rather than on our behalf. What they do with listening and viewing data is governed by their terms, not ours.

If you change your mind: tell us and we will take the episode down from our own website and feed and from the channels we control, normally within five working days, and stop using clips from it. We will be straight with you about the limits: copies already downloaded or shared by other people cannot be recalled, and podcast apps, search engines and caches take time to catch up.

How long: published episodes stay available until withdrawn. Raw recordings and working files are kept while the episode is in production and for a reasonable period afterwards in case a correction is needed, then deleted.

International Data Transfers

Personal data may be processed outside the UK or EEA only where an adequacy decision applies, or appropriate safeguards are in place. In practice, where we use providers based in the United States — including our AI providers — we rely on the European Standard Contractual Clauses as amended by the UK International Data Transfer Addendum, and we check that safeguard against each provider's own agreement rather than assuming it. We keep a register of every provider, what it processes and the safeguard relied on.

Cookies and IP Address Policy

IP Addresses: Collected for system administration, security, and statistical analysis. They do not directly identify individuals.

Cookies: Used to improve website functionality and user experience. You can manage cookies through browser settings. Further guidance is available at allaboutcookies.org.

Marketing Communications

We may send recruitment, service-related, or professional communications where you have engaged with us professionally, or submitted a CV, enquiry, or application. Marketing is conducted under legitimate interests and soft opt-in rules, with a clear right to opt out at any time via email links or by contacting us directly.

Fees for Excessive Data Requests

We may charge a reasonable fee for manifestly unfounded, excessive, or repeated data requests.

Your Rights

You have the following rights concerning your personal data: be informed; access your data; rectify inaccurate data; request erasure (subject to legal obligations); restrict processing; data portability; object to processing (including marketing); and withdraw consent.

If You Are in the United States

We run a permanent search desk for clients in New York from our United Kingdom company. We have no United States entity, office or staff. Because we are a UK controller, UK data protection law governs your information wherever you live, and every right and commitment set out above applies to you in full. The following are the United States commitments that sit alongside them.

New York SHIELD Act: where we hold private information about a resident of New York, we maintain a data security programme with reasonable administrative, technical and physical safeguards, as required by the New York Stop Hacks and Improve Electronic Data Security Act. In practice that is the same programme described in this policy: encryption of sensitive fields, access control, supplier due diligence, staff training, retention limits and incident response, assessed under our ISO 9001 certified management system and Cyber Essentials certification.

If there is a breach: where a security breach affects the private information of a United States resident, we will notify you directly and without unreasonable delay, and we will notify the relevant State authorities where the law requires it. For New York residents that means the New York State Attorney General, the Department of State Division of Consumer Protection and the Division of State Police. You do not need to contact a United Kingdom regulator about a United States breach, and we will not route you to one.

Where your data is held: our systems are hosted in the United Kingdom and the European Economic Area, so information you give us is transferred out of the United States to us. We apply UK data protection standards to it throughout.

Pay history: we never ask a candidate for their current or past pay for a New York role, and our systems do not present that question, in line with the New York City salary history ban. Nothing in our process makes an automated decision about you: a person always decides on shortlisting and representation.

California: the California Consumer Privacy Act applies to businesses above revenue and volume thresholds that we are well below, so it does not apply to us. We will say so plainly if that ever changes.

Complaints

If you have concerns about how your data is processed, please contact us at dataprotection@invitise.com. We answer every complaint ourselves first, wherever you live.

In the United Kingdom: you also have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk.

In the United States: the Information Commissioner's Office is a United Kingdom regulator and is not the right route for you. Contact us first. If you are not satisfied, a New York resident may complain to the New York State Attorney General's Bureau of Internet and Technology at ag.ny.gov, and residents of other States may complain to their own State Attorney General. Complaints about unfair or deceptive practices may also be made to the Federal Trade Commission at reportfraud.ftc.gov.

The 24-hour rule. Why slow Cyber Hiring is now a board risk. Cover and sample spreads of the invitise executive briefing.
New executive briefing · May 2026

The 24-hour rule Why slow Cyber Hiring is now a board risk

A 16-page invitise briefing for cyber, risk and people leaders. Why the hiring window has narrowed, what 24-hour mobilisation actually requires, and the four conditions that have to be true for next-morning on-site to mean something.

55%

of senior cyber roles take 6 months or longer to fill in the UK.

46 days

longer than other IT roles, senior cyber vacancies stay open.

68%

of large UK businesses now own cyber at board level.

We'll email you the PDF. No marketing list. See our privacy policy. Protected by Cloudflare Turnstile.