Privacy Policy

Introduction

This privacy policy governs the collection, storage and use of personal information by Rocc Madden Limited (“Rocc Madden”, “we”, “us” or “our”).

We respect your privacy and are committed to ensuring that the personal information we collect is handled lawfully, transparently, and securely in accordance with applicable data protection legislation, including the UK GDPR, EU GDPR, and the UK Data Protection Act 2018.Further details of how we handle your personal information are set out in the following sections:

- Definitions
- Who we are-
- Where we collect your information from
- The personal information we collect about you
- How we use your personal information and our legal bases
- Sharing your information
- International transfers
- Data retention
- How we use cookies
- Security
- Your rights
- Changes to this Privacy Policy
- Third-party sites
- Complaints
 - Definitions

“You” refers to:

- Individuals applying for, considered for, or engaged in roles or assignments through us
- Individuals whose services are supplied via Rocc Madden to a client
- Contacts within client organisations
- Representatives of umbrella companies, personal service companies, MSPs, RPOs, or other organisations involved in the supply chain
- Website visitors, suppliers, or anyone who interacts with Rocc Madden

Additional terms:

“Hirer / Client” means any organisation to which we provide temporary or permanent recruitment or resourcing services.
“Candidate” means an individual applying for, or being considered for, a role.
“Consultant” means a contractor, freelancer, or individual whose services are supplied to a client through Rocc Madden.This privacy policy explains what personal information we collect, how we use it and your rights.

It does not cover:

- An actual or potential employer or hirer.
- An umbrella company or personal service company
- Any other organisation involved in the delivery of your servicesThose organisations will have their own privacy policies, and their use of your data will be governed by the relevant organisation’s privacy policy.
 
Who We Are

Rocc Madden Limited is the data controller of the personal information that we collect.We are a recruitment and resourcing business specialising in ERP, Cloud, Data and AI. We help clients with temporary and permanent hiring needs and support candidates and contractors in finding suitable roles. We may also deliver services under a statement of work and provide occasional industry updates and networking events.

Company Name: Rocc Madden Limited
Registered Number: 16796163
Registered Office: 3rd Floor, Crown House, 151 High Road, Loughton, Essex, IG10 4LG
Contact (Privacy): contact@roccmadden.com 

Where We Collect Your Information From

This privacy notice applies to the collection, storage and use of personal information collected by Rocc Madden Limited:

- via our website at www.roccmadden.com
- or any other websites operated by us (the “Site”),
- or as a result of you responding to an advertisement posted by us on a job board, online CV library or via social media;
- or as a result of us matching your CV, as uploaded by you onto a job board, publicly accessible CV library or social media profile (where made public for recruitment purposes), to a vacancy we are seeking to fill for one of our clients;
- or as a result of personal recommendations or referrals;
- or from company websites (where made public for recruitment purposes);
- or from your business card or professional details provided to us;
- or through interactions with us on social media;
- or through contact made offline, for example by telephone, SMS, WhatsApp, Microsoft Teams, email or post;
- or in the course of us providing temporary or permanent recruitment, resourcing, onboarding or compliance services (“Services”).

We may also obtain personal information about you from:

- background screening or vetting providers;
- managed service providers (MSPs), RPOs or other third parties involved in hiring processes;
- credit reference or fraud prevention agencies (where relevant);
- publicly accessible sources;
- information you have uploaded to LinkedIn or similar platforms.

 The Personal Information We Collect About You

Candidates and Consultants: the personal information we collect about you where “you” are a candidate or consultant supplied to a hirer. We may collect information about you when:

- you access and browse our website (including when you submit information through data entry fields on the Site);
- or you respond to an advert posted by us on a job board, CV library, LinkedIn or other social media platform;
- or we download or source details uploaded by you onto a job board, CV library or social media profile (where made public for recruitment purposes) in relation to a vacancy we are seeking to fill;
- or we obtain information uploaded by you to online professional profiles for internal market research;
- or you contact us by phone, SMS, WhatsApp, Microsoft Teams, email or other communication channels;
- or we provide recruitment, resourcing, onboarding or compliance services to you or to a hirer of your services;
- or we contact you with a view to providing our Services;
- or we provide onboarding services to a hirer of your services;
- or we receive your details through personal recommendations, referrals, business cards or via company websites.

Typically, we may collect the following information from or about you:

- your name;
- your contact information (email address, phone number, postal address);
- your gender;
- your date of birth;
- your bank details (for contractor payment administration);
- a copy of your passport, ID, visa or right-to-work documentation;
- your current and previous employment details, including job title and employer;
- recruitment-specific details such as your qualifications, certifications, education, skills, career history, salary expectations, work preferences, right-to-work status, citizenship, location or relocation preferences, referee details, and any other information required by law for us to provide our services;
- your CV and any information provided in application forms;
- any information which has been published or made available on a social media profile, CV library, company website or job board (whether by you or a third party);
- details of your umbrella company or personal service company (where applicable);
- assignment documentation and timesheet information;
- references from third parties such as previous employers or nominated referees;
- emergency contact details (for candidates or contractors);
- communication records, including emails, messages and call notes;
- the results of background screening or vetting checks we are asked or required to undertake (including criminal record checks, right-to-work checks, and any information relating to current and/or spent convictions provided during onboarding);
- health information where required by law or relevant to the role;
- equal opportunities and diversity information (collected only where required or where you have provided explicit consent).

Sensitive personal data is collected only where required by law or where you have provided explicit consent, or where another specific lawful basis under data protection law applies.

Client Contacts, MSPs, Umbrella Companies & Similar Organisations

Client contacts: the personal information we collect about you where “you” are a contact at one of our clients, an MSP, umbrella company, personal service company, or any similar organisation involved in the supply of a person’s services to a hirer. We may collect information about you when:

- we contact you with a view to providing our Services;
- or you contact us or email us expressing an interest in working with us;
- or you provide us with your business card or other professional details (including at meetings, events or through referrals);
- or you post information or advertisements on job boards or social media platforms;
- or we provide Services to you as an actual or potential hirer;
- or we complete contractual documentation relevant to the Services we provide.

We will usually collect the following information from or about you:

- your name;
- your job title, role and position within your organisation;
- your work contact information (email address and phone number);
- your organisation details;
- any opinion or feedback you share with us regarding candidates or consultants;
- any information shared with us relating to the Services we provide, including recruitment or resourcing requirements.

Website Users

We may also collect the following information when you use our website:

- your IP address;
- device and browser information;
- form submission details;
- usage and interaction information;
- newsletter or job alert sign-up information.
 
How we use your personal information and our lawful bases

Candidates and consultants: we collect, store and use your personal information for our legitimate interests, including:

- contacting you (via email, phone, SMS, WhatsApp, Teams or similar channels) about opportunities or assignments that may be of interest to you;
- matching your skills, experience and preferences to suitable vacancies and helping us to identify opportunities that align with your profile;
- presenting your details to clients for potential roles — we will always obtain verbal or written consent before doing so;
- providing a channel for you to submit your CV, respond to roles or register your interest;
- carrying out right-to-work checks and supporting other compliance steps;
- managing onboarding processes for assignments or placements;
- maintaining, updating and developing our internal database of candidates and clients;
- conducting market mapping, industry research and internal analysis;
- keeping in contact with you regarding suitable roles, updates, services or events;
- administering assignment-related documentation, timesheets and any associated processes.

We consider this processing necessary to provide our recruitment and resourcing services, including where it is required for the performance of a contract with you or to take steps at your request before entering into such a contract, and we do not believe it unduly prejudices your rights or freedoms.We also store and use your personal information to comply with legal obligations, including:

- carrying out right-to-work and immigration checks;
- complying with employment agency and employment business regulations;
- completing background screening or other checks required by law or requested by a client during onboarding.
Where checks are carried out specifically on behalf of a client, your personal data may also be governed by that client’s privacy policy. In certain circumstances, and only where required, we may request and process sensitive information with your explicit consent. This may include:
·         health information relevant to an assignment;
·         criminal record information;
·         equal opportunities or diversity information.You may withdraw your consent at any time, although doing so may affect our ability to provide certain recruitment services.

Client Contacts and Other Business Representatives

We collect, store and use personal information relating to client contacts and other business representatives (including MSPs, umbrella companies, personal service companies and similar organisations) for our legitimate business interests. This enables us to:

- deliver recruitment, resourcing and associated services;
- communicate with you regarding hiring requirements, assignments or resourcing plans;
- send relevant candidate or consultant profiles for review;
- manage and maintain ongoing business relationships;
- respond to enquiries and provide information about our services;
- administer and coordinate the delivery of the services we provide;
- support contract administration, assignment documentation and any related processes.

Using your information in this way allows you or your organisation to receive, request, review or administer the services that we provide. Where you represent an umbrella company, personal service company or similar organisation, this may also include communications relating to assignments, timesheets, rates, payment information and onboarding requirements.We consider this use of your information necessary to operate our services effectively and do not believe it unduly impacts your rights or freedoms.

Automated Decision-Making

We do not carry out decisions based solely on automated processing.

Sharing Your Information

We may share your personal information where necessary for the delivery of our recruitment, resourcing and related services, or where we are required to do so by law. This includes sharing information with:

- clients who are considering candidates or consultants for opportunities;
- MSPs, RPOs and other intermediaries involved in recruitment or assignment management;
- umbrella companies and personal service companies, where relevant to assignment arrangements;
- background screening, vetting and reference-checking providers;
- IT and system providers, including CRM/ATS platforms, website hosting, communications tools and email service providers;
- professional advisers, including accountants, auditors and legal advisers;
- payment processors or financial service providers involved in administering assignments;
- regulators, government bodies or authorities where disclosure is required by law or necessary to comply with regulatory obligations;
- fraud prevention or identity verification agencies;
- third parties involved in business transactions, including mergers, acquisitions or corporate restructuring.

Where we share your information with third-party suppliers, they are appointed as data processors and are only permitted to handle your information in accordance with our instructions and applicable data protection laws. They are not permitted to use or disclose your information for their own purposes.In certain limited circumstances, we may also share anonymous or aggregated information generated through our services for reporting or analytical purposes. This information does not identify you personally.Where information is shared with clients, hirers, umbrella companies, personal service companies, MSPs or RPOs, those organisations will process your personal information in line with their own privacy policies.

International Transfers

We may transfer or store personal information outside the UK or European Economic Area (EEA) where this is necessary for the delivery of our services. This may include transfers to countries such as the United States, South Africa, Japan and other non-UK/EEA locations as part of our recruitment, resourcing, onboarding or compliance activities.Where personal data is transferred internationally, we ensure that appropriate safeguards are in place to protect your information. These may include:

- adequacy regulations or adequacy decisions confirming equivalent data protection standards;
- standard Contractual Clauses (SCCs) approved by the UK or EU;
- contractual, technical and organisational safeguards implemented with third-party providers;
- use of secure cloud-based platforms that may operate global data centres but apply consistent security standards.

We recognise that some countries outside the UK/EEA may not provide the same level of protection for personal information. However, any transfer, processing or storage of personal data by us, or on our behalf, will continue to be handled in accordance with this privacy policy and applicable data protection legislation.

Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, taking into account our legal, regulatory, accounting and contractual obligations.When assessing how long to keep personal information, we consider the nature of the data, the purpose for which it is processed, the potential risk of harm from unauthorised use or disclosure, and any requirements under applicable law.In general:

- candidates who register but do not actively engage: retained for up to 2 years.
- candidates or consultants who are placed or engaged on assignments: retained for up to 7 years to comply with tax, financial, legal and contractual obligations.
- client and business contact information: retained for as long as the business relationship remains active.
- marketing data: retained until you choose to unsubscribe or opt out.We may keep information for longer where we are required to do so by law or where it is necessary to meet contractual or regulatory reporting obligations, resolve disputes or enforce agreements.When information is no longer required, it is securely deleted.

How We Use Cookies

We use cookies and similar technologies to support the functionality and performance of our website. These may be used to:

- enable essential website features;
- understand how visitors use our site;
- improve site performance and user experience;
- support marketing and analytics activities (where consent has been provided).You can manage or disable cookies through - - your browser settings or via our cookie banner.Further details can be found in our Cookie Policy.
 
 
Security

We have appropriate technical and organisational measures in place to safeguard personal information against:

- unauthorised access or disclosure;
- accidental loss or destruction;
- misuse or alteration.Security measures are reviewed and updated regularly to ensure that information is handled in a secure and responsible way.

Your Rights

Under applicable data protection laws, you have the right to:

- request access to the personal information we hold about you;
- request correction of inaccurate or incomplete information;
- request deletion of your personal data;
- request the restriction of certain types of processing;
- object to processing, including direct marketing;
- request the transfer of your data to another provider (data portability);
- withdraw consent at any time, where processing is based on consent.

You also have the right to raise any concerns with the relevant data protection authority. If you wish to exercise any of these rights, please contact us at contact@roccmadden.com.

Changes to This Privacy Policy

We may update this privacy policy from time to time.
Any changes will be available on this page, and the updated version will apply from the date of publication.
Last updated: 20th December 2025
 
Third-Party Sites

Our website may contain links to third-party websites.
We are not responsible for the privacy practices or content of those websites, and we encourage you to review their privacy policies before providing any personal information.
 
Complaints

If you have any concerns about how your personal data is handled, you can contact us at contact@roccmadden.com.
You may also lodge a complaint with the relevant data protection authority if you are not satisfied with our response.