Candidate Privacy Policy

In order to recruit candidates, Dionach collects and processes personal information about you, the candidate.


Personal information means any information about you from which you can be identified, but it does not include information where your identity has been removed (anonymous data).

 

As the ‘controller’ of personal information, we are responsible for how that data is managed. The General Data Protection Regulation (GDPR), which applies in the United Kingdom and across the European Union, sets out our obligations to you and your rights in respect of how we manage your personal information.
As the ‘controller’ of your personal information, we will ensure that the personal information we hold about you is:

  • Used lawfully, fairly and in a transparent way
  • Collected only for valid purposes that we have clearly explained to you and not used in any way that is incompatible with those purposes
  • Relevant to the purposes we have told you about and limited only to those purposes
  • Accurate and kept up to date
  • Kept only as long as necessary for the purposes we have told you about
  • Kept securely

If you have any questions about this privacy policy or would like further explanation as to how your personal information is managed, then please contact us (see how to contact us below).

Personal Data We Process

Dionach may process several different categories of personal data about candidates as part of our recruitment and screening processes. The information we collect may come directly from you, from your interactions with our recruitment systems, from publicly available sources, or from third‑party background‑screening providers (where relevant).

1. Identification and Contact Information

We may collect and process:

  • Name
  • Postal address
  • Email address
  • Telephone number(s)
  • Date of birth and age
  • Photograph (such as that provided on a CV or identification document)
  • National Insurance number
  • Passport number or other identity document numbers
  • Driving licence number
  • Right‑to‑work documentation and visa information

2. Application and Employment‑Related Information

This includes:

  • Curriculum vitae (CV), cover letter, and any supporting documents you provide
  • Employment history
  • Education history
  • Professional qualifications and certifications
  • Employment references
  • Information provided during application forms
  • Interview notes and feedback from interviewers
  • Results from skills assessments, technical tests, written exercises, or other evaluations
  • Information gathered during telephone screenings or video interviews
  • Work samples or portfolio links (where provided)

3. System and Communication Data

When interacting with our recruitment systems (such as our Applicant Tracking System), we may process:

  • Candidate portal account details (where applicable)
  • Application timestamps and status updates
  • Communication logs (e.g., emails, messages exchanged through the ATS)
  • IP address and audit‑log activity associated with your application

4. Verification and Compliance Information

Where applicable to the role or required by law, we may collect:

  • Criminal‑record checks, cautions, or convictions
  • Background‑screening results from third‑party providers
  • Identity‑verification information
  • Sanctions‑list checks
  • Right‑to‑work verification results
  • Driving‑related convictions (if relevant to the role)
  • Security‑clearance information (where necessary)

5. Equal Opportunities and Monitoring Information

Where collected — and only with your explicit consent — we may process optional diversity‑monitoring information, including:

  • Gender
  • Ethnicity
  • Disability status
  • Sexual orientation
  • Nationality
  • Marital status
    This data is used for monitoring purposes only and does not influence hiring decisions.

6. Publicly Available Professional Information

Where relevant for recruitment, we may review:

  • Professional profiles on publicly available platforms (e.g., LinkedIn)
  • Professional websites, portfolios, or publications

 

Special Category Data

Some of the information we process is classified as ‘special category data’, which is more sensitive in nature. Where processed, we have a heightened duty of care and only do so where necessary and lawful. This may include:

  • Racial or ethnic origin
  • Religious or philosophical beliefs
  • Health‑related information, including medical history or sickness‑related details (only where relevant and lawfully obtained)
  • Criminal conviction and offence information
  • Disability information (e.g., for interview‑adjustment purposes)
  • Trade union membership (only if you disclose this voluntarily)

Special category data is handled with enhanced security measures and is only processed where strictly necessary for recruitment, legal obligations, or equality‑monitoring purposes (with consent).

Purposes of Processing Personal Information

In order to determine suitability for a role at Dionach we will process personal data for the following purposes:

  • Maintain records of recruitment with Dionach
  • Process criminal conviction and caution information, where relevant to your role
  • Regulatory requirements such as right to work
  • To conduct and support internal and external audits

Who Has Access to Your Personal Information

To operate our business and manage our recruitment processes, we rely on third‑party service providers who support us in processing your personal information. These third parties may have access to, or a duty of care over, your data in order to carry out their services on our behalf. They include:

  • Applicant Tracking System (ATS) providers, who help us manage and progress your application throughout the recruitment process.
  • Third‑party background‑check and screening providers, where relevant to the role or required by law.
  • Credit reference agencies, where applicable.
  • IT service providers, such as Microsoft for Office 365, who support our internal systems and infrastructure.

All third parties are required to process your personal information only in accordance with our instructions and in compliance with applicable data‑protection laws.

Retention of Personal Information

We will retain your personal data for a period of 18 months following the recruitment process decision. Please email us if you wish us to retain your details for longer if you wish to be considered for future opportunities as they arise.

Your Rights

You have the following rights:

  • Request access to a copy your personal information (also known as a “data subject access request”).
  • Request us to correct any mistakes in your information which we hold.
  • Request the erasure of personal information concerning you, in certain situations. Please note that if you ask us to delete any of your personal information
  • which we believe is necessary for us to comply with our contractual or legal obligations, this may affect our ability to provide employment to you.
  • Object to us processing of your personal information or withdraw consent. As with erasure, this may affect our ability to provide employment to you.
  • Otherwise restrict our processing of your personal information in certain circumstances.

For further information on each of those rights, including the circumstances in which they apply, see the Guidance from the UK Information Commissioner’s Office (ICO) on individuals’ rights under the GDPR.

Security of Personal Information

The confidentiality and security of your information is of paramount importance to us. We have appropriate organisational and technical security measures in place to prevent personal information from being accidentally lost, used or accessed in an unauthorised way. We limit access to your personal information to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.

 

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

How to Complain

We hope that we can resolve any query or concern you raise about our use of your information. Our contact details are below.
The GDPR also gives you right to lodge a complaint with a supervisory authority. The supervisory authority in the UK is the Information Commissioner who may be contacted at https://ico.org.uk/make-a-complaint or by phoning 0303 123 1113.

How to Contact Dionach

Please contact us if you wish to exercise one of your privacy rights or to complain by email at hr@dionah.com or by telephone on 01865877830. Our address is Dionach Ltd, Unipart House, Garsington Road, Oxford, OX4 2PG.

Policy Last Updated: 2026-01-23

Contact Us

Contact Us Reach out to one of our cyber experts and we will arrange a call