This is the full-product Bontra Privacy Policy. It applies once Bontra is in active use as a recruitment platform.
1. Introduction and how to contact us
This Privacy Policy explains how Bontra collects, uses, stores, and protects your personal data when you use the Bontra recruitment platform. It covers both job-seeking candidates and hiring companies, and it applies to anyone who creates a Bontra account, submits a job description, has their profile introduced to a hirer, or otherwise uses Bontra's services.
Data controller: Bontra Limited, a company registered in England and Wales (company number 17046966), with its registered office at 24D Lupus Street, Pimlico, London, SW1V 3DZ ("Bontra", "we", "us", "our").
Data protection contact: Harry McAlister. Email: [email protected].
Bontra is not required to appoint a formal Data Protection Officer under Article 37 of the UK GDPR (we do not meet the "large scale" or "systematic monitoring" thresholds). Harry McAlister is the designated data protection contact and handles all subject access, erasure, rectification, and complaint requests.
ICO registration: Bontra is registered with the UK Information Commissioner's Office under registration number ZC112550.
Employment agency status: Bontra is an employment agency within the meaning of section 13(2) of the Employment Agencies Act 1973. Our activities are subject to the Conduct of Employment Agencies and Employment Businesses Regulations 2003. This has implications for how long we keep your data - see §9 (Data retention) and §12 (Employment agency status and record-keeping obligation) below.
If you have any questions about this policy, want to exercise any of the rights described in §10, or want to lodge a complaint, please email [email protected].
2. Who this policy applies to
Bontra is used by three kinds of people, and not every section of this policy is relevant to everyone. Use the guide below to find the sections that apply to you.
If you are a candidate (a job seeker using Bontra to find insurance roles):
- §3.1 covers the data we collect about you
- §4 covers the lawful basis for each activity
- §5 covers our AI-driven matching and your rights around automated decisions
- §6 covers how and when we share your profile with hiring companies
- §8 covers our processor categories
- §9 covers how long we keep your data
- §10 covers your UK GDPR rights
- §11 covers withdrawing consent and deleting your account
- §12 covers our employment agency status and the 1-year record-keeping obligation
If you are a hiring company user (using Bontra on behalf of a company to hire candidates):
- §3.2 covers the data we collect about your company and about you personally
- §4 covers the lawful basis for each activity
- §7 covers how we share company information with candidates
- §8 covers our processor categories
- §9 covers how long we keep your data
- §10 covers your UK GDPR rights
- §11 covers terminating your account
If you are a waitlist signup (you joined the Bontra waitlist before launch):
- The waitlist privacy policy deployed at
/privacycontinues to apply to your waitlist entry until you create a Bontra account. When you create an account, this full policy takes over, and you are asked to consent to it at that point.
If you are a website visitor (you are reading the Bontra website but have not signed up for anything):
- Only §8 (cookieless website analytics) applies to you. We do not collect personally identifiable information from website visitors who have not actively submitted a form or signed up for an account.
3. What data we collect
3.1 Candidate data
When you sign up to Bontra as a candidate, we collect:
- Identity and contact: full name, email address, phone number, and any professional profile link you choose to provide, such as a LinkedIn profile URL.
- CV and profile data: the CV file you upload, and structured profile fields we derive from it to provide the recruitment service. These typically include your employment history, job titles, dates, employers, qualifications, specialisations, and any other information you have chosen to include in your CV.
- Structured logistics answers: responses to our intake questions, such as employment status, notice period, job search status, current location, willingness to relocate, preferred locations, remote work preferences, maximum office days, salary expectations, work authorisation status, and working pattern preferences.
- Consent and audit records: timestamps and IP addresses at the moments you grant or withdraw consent, to evidence that consent was validly obtained.
- Authentication data: your email address and password are managed by our authentication provider (see §8). We do not store your password in plain text or in any retrievable form. We store a synced copy of your name, email, and (where provided) phone number in our database to operate your account and provide the service.
3.2 Company data
When you sign up to Bontra on behalf of a hiring company, we collect:
- About the company: company name, industry, location, company size, and description.
- Expected email domains: the email domains associated with the company, which we use to auto-link new company users to the right Bontra company record.
- About you personally: your full name, work email address, your role or title at the company.
- Hirer Commercial Terms acceptance audit: if you accept the Hirer Commercial Terms on behalf of your company, we record the version you accepted, the timestamp, your IP address, and your browser user agent. This creates an evidential record of the commercial contract.
- Job descriptions: the job descriptions you upload, authorise us to use, or that are otherwise publicly available, and the structured role fields we derive from them.
- Feedback on candidates: any feedback you provide about candidates we introduce to you, used to improve our matching accuracy.
3.3 Technical and analytics data
For all users and visitors, we collect:
- IP address and user agent: at the time of consent grant, rate limit checking, and security auditing.
- Cookieless analytics: we do not store persistent identifiers on your device for analytics. We collect aggregated page view data, referrer, approximate device and browser type, and operational metric events only. No PII from Bontra accounts is sent to the analytics provider.
- Functional browser storage: limited
localStorageandsessionStorageentries used to remember your theme preference, preserve a safe sign-up redirect. These support requested product behaviour and are not used for advertising or cross-site tracking. - Session tokens: managed by our authentication provider (see §8). These are
HttpOnlycookies plus browser-managed auth/session cookies required for sign-in and session continuity. You do not need to consent to these essential cookies under PECR because they are strictly necessary for the service to function.
3.4 Data we do not collect
- Special category data (UK GDPR Art. 9): we do not deliberately collect data about racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, sex life, or sexual orientation. If your CV contains incidental references to such categories (for example, mentioning a role at a religious charity), we do not extract or process that data as a feature of your profile, and our matching system does not use it.
- Children's data: Bontra is for adults aged 18 and over. You confirm your age at the start of onboarding. We do not knowingly collect data from anyone under 18.
- Biometric or genetic data: we do not collect biometric identifiers or genetic information.
- Criminal conviction data (Art. 10): we do not ask for and do not process data about criminal convictions or offences.
- Voice recordings or transcripts: we do not currently collect audio recordings or call transcripts as part of the recruitment service.
4. Why we collect this data and our lawful basis
We only collect and use your personal data where we have a lawful basis under Article 6 of the UK GDPR. The table below sets out each processing activity, the lawful basis, and whether your active consent is required.
| # | Purpose | What data | Lawful basis | UK GDPR article | Required / optional |
|---|---|---|---|---|---|
| 1 | Platform Terms acceptance - giving you access to the Bontra platform | Name, email, account metadata | Contract necessity | Art. 6(1)(b) | Required for all users |
| 2 | Privacy Policy acknowledgement - processing your data as described here | As below, per activity | Contract necessity | Art. 6(1)(b) | Required for all users |
| 3 | Hirer Commercial Terms acceptance (company users only) - the commercial contract between Bontra and the hirer | Company name, company user identity, acceptance audit fields | Contract necessity | Art. 6(1)(b) | Required for company users |
| 4 | Screening and profile building (candidates) - extracting structured profile information from your CV and collecting your logistics question responses | CV text, logistics question responses | Consent | Art. 6(1)(a) | Required for candidates |
| 5 | Matching (candidates) - comparing your profile and preferences with role requirements and using limited internal quality review to keep matching accurate and fair (see §5) | Extracted profile, logistics answers, match indicators | Consent | Art. 6(1)(a) | Required for candidates |
| 6 | Data sharing (candidates) - disclosing your de-anonymised profile, candidate contact details, and a generated CV preview copy, or extracted-text fallback where the preview copy is unavailable, when a verified UK-based organisation hiring for insurance-specific roles or insurance-service functions chooses to view the full profile for a specific introduction whose role requirements align with the preferences you have specified. Recipients outside this sector-and-role category would require your separate, explicit consent before any disclosure | De-anonymised profile including PII, candidate contact details at full-profile review, and generated CV preview copy or extracted-text fallback at full-profile review | Consent | Art. 6(1)(a) | Required for candidates |
| 7 | Employment agency record retention - retaining introduction and placement records for 1 year after the introduction, even after account deletion, as required by the Conduct of Employment Agencies and Employment Businesses Regulations 2003 Reg. 29 | Date of introduction, hirer identity, placement outcome, pseudonymised candidate reference | Legal obligation | Art. 6(1)(c) | Mandatory |
| 8 | Fee and commission records - retaining contract and fee records for the limitation period | Fee invoices, payment records, contractual correspondence | Legitimate interest (fee dispute protection) | Art. 6(1)(f) | Applies to company accounts only |
| 9 | Consent verifiability - storing the IP address, user agent, and timestamp at each consent grant moment, to demonstrate valid consent | IP, user agent, timestamps | Legitimate interest | Art. 6(1)(f) | All consent grants |
| 10 | Website analytics (cookieless) - understanding aggregate usage via our analytics provider | Page views, device type, referrer - no PII | Legitimate interest | Art. 6(1)(f) | All website visitors |
| 11 | Error monitoring - capturing frontend and backend exceptions via our monitoring provider | Stack traces (no PII) | Legitimate interest | Art. 6(1)(f) | All users and visitors |
| 12 | Service and transactional emails - sending account notifications, introduction emails, interview coordination, and service updates under PECR Reg. 22(3) soft opt-in | Email address, notification content | Contract necessity + PECR soft opt-in | Art. 6(1)(b) + PECR 22(3) | All users, unsubscribable via footer link |
You can withdraw any consent at any time. See §11 for how consent withdrawal works and what happens afterwards.
Why consent and not legitimate interest for candidate-facing processing?
We treat the screening, matching, and data-sharing activities (rows 4, 5, 6) as consent-based rather than legitimate-interest-based. This is a deliberate choice grounded in ICO guidance: legitimate interest is not appropriate where there is a significant power imbalance (candidates depend on us to access opportunities) or where the data could incidentally include special category information extracted from CV text. Consent gives candidates meaningful control - you can refuse consent, and you can withdraw it.
Why contract and not consent for ToS and Privacy Policy?
We treat Platform Terms acceptance (row 1) and Privacy Policy acknowledgement (row 2) as contract necessity rather than consent. Article 7(4) of the UK GDPR warns against bundling consent with service access - if acceptance were consent-based, you would not be able to use the service without consenting, which undermines the "freely given" requirement. Contract necessity is the appropriate basis because these are preconditions for using the service you have asked to use.
5. Automated processing and AI-assisted matching
Bontra uses automated tools to help organise candidate information and identify roles that appear relevant. Under Article 22 of the UK GDPR, you have specific rights in relation to automated decision-making. This section explains the legal effect of our tools and the safeguards around them.
5.1 CV profile extraction
When you upload your CV, we use AI-assisted tools, including the processors listed in §8, to turn CV text into structured profile fields such as employment history, job titles, dates, employers, qualifications, specialisms, and other career information you chose to include.
- What extraction does: it helps build your editable Bontra profile from information you provided.
- What extraction does not do: it does not make hiring decisions, it does not decide whether a company should interview or hire you, and it does not disclose your data to companies by itself.
- Your control: you can review your profile information and ask us to correct errors. Extraction is profile building, not a verdict on you.
- Processor retention: where a processor receives CV or job-description text to provide this service, the processor handling and retention periods are disclosed in §8 and §9.
5.2 Matching support
We compare candidate profiles and preferences with role requirements to help us identify potentially relevant introductions. The comparison may consider professional experience, required qualifications, sector specialism, location, salary expectations, working pattern, right-to-work information, and similar role-relevance factors.
- No solely automated significant decision: Bontra does not make a decision producing legal or similarly significant effects about you solely by automated means. Automated matching supports introductions; it does not automatically hire, reject, or blacklist candidates.
- No protected-characteristic matching: we do not deliberately collect or use special category data such as race, religion, health, sex life, sexual orientation, political views, or trade union membership as matching factors.
- Quality review: authorised Bontra staff may review candidate and role data to correct obvious extraction or matching errors before an introduction is made. This is a quality-control safeguard, not a separate hiring decision.
- Candidate-facing explanation: we may show match quality or role-relevance information in plain language. We do not publish internal scoring methods.
- Hiring company decision: hiring companies remain responsible for their own interview, selection, pre-employment check, and hiring decisions.
- You have the right to human review: if you believe an automated output has produced an incorrect or unfair result, email [email protected] and we will review the case manually.
5.3 Quality improvement
As disclosed in our lawful basis table (row 5), your matching consent allows limited access-controlled review of candidate data, role data, and matching outcomes to improve accuracy, fairness, and reliability. We do not share your CV or extracted profile with external parties for training or analysis purposes, we do not use your data for market research or sales targeting, and we do not use company feedback to create negative statements about individual candidates.
5.4 Your Article 22 rights
Because some of our processing is automated, you have the right to:
- Request human intervention - ask a real person to review a decision
- Express your point of view - explain why an automated outcome is wrong
- Contest a decision - challenge an outcome you disagree with
To exercise any of these rights, email [email protected] with a brief explanation. We will respond within one calendar month.
6. Sharing your data with hiring companies (candidates)
This section applies to candidates. It explains exactly how, when, and under what conditions your profile and personal data are shared with hiring companies.
6.1 You control when your data is shared
Your profile data is only shared with hiring companies if you have granted the data_sharing consent purpose (bundled into the Privacy Policy checkbox at sign-up). Without this consent, we will not share identifying information about you with any company.
Which hiring companies? The companies with whom we may share your profile are verified UK-based organisations hiring for insurance-specific roles or insurance-service functions whose role requirements align with the specialisms, role types, and geographical preferences you have specified during onboarding. The recipient category may include insurers, reinsurers, brokers, managing general agents, insurance intermediaries, financial-services firms, corporates, professional-services firms, or public-sector bodies, but only where the role or function is insurance-specific or insurance-service related.
We do not share your data for unrelated non-insurance roles, and we do not share your data with recruiters or recruitment agencies other than Bontra itself. If we ever expanded into a new non-insurance sector, we would obtain your separate, explicit consent before sharing your data with employers in that new sector.
6.2 Staged disclosure
We share candidate data in graduated stages, each with different conditions:
- Initial non-identifying summary: before a company chooses to view the full profile for a specific introduction, it may see a short summary of a potentially relevant candidate, such as broad experience range, specialism, approximate location, and relocation preferences. This summary does not include name, email, phone number, exact location, or exact employer names.
- Redacted profile: where a company has engaged with Bontra and confirmed interest, we may share a more detailed non-identifying profile, such as named qualifications, employer types rather than employer names, and specific experience indicators. This still does not include contact details.
- Full profile review: only after a formal introduction is created and the company chooses to view the full profile for that specific introduction may it receive your de-anonymised profile, full career history, role-relevance rationale, candidate contact details, and a generated CV preview copy or extracted-text fallback. The CV preview copy and candidate contact details are available only through authenticated access after that per-candidate full-profile action, and only while the company has current Hirer Terms. Your original uploaded CV remains available to you from your own profile, but is not provided to companies. We do not include the original CV or CV preview copy in public pages, unauthenticated links, outreach emails, or bulk introduction emails. At the full-profile stage, the company becomes an independent data controller for the data it receives.
6.3 Every disclosure is logged
Every PII disclosure to a company is recorded in our disclosure audit records. Those records capture who received what data, when, and for which role. You can request a copy of your disclosure history as part of your data subject access request.
6.4 Verified recipients only
We do not send candidate PII to generic or personal email domains. Before any full-profile disclosure, we verify that the recipient is an authorised company contact and record the disclosure in our audit records.
6.5 Follow-up emails to companies
After an introduction, Bontra sends a bounded sequence of up to three follow-up emails to the hiring company, asking for feedback on the introduction and the candidate's progress. This sequence is part of our introduction service and is covered by the company's contractual acceptance of Platform Terms and Hirer Commercial Terms. You do not see these follow-up emails.
6.6 Once your data is with a company
When a hiring company chooses to view the full profile for a specific introduction, that company becomes an independent data controller (not a joint controller with Bontra) for the copy of your full profile, including any downloaded CV preview copy or extracted-text fallback, it then holds. If the company later sets up an interview or moves you to a later hiring stage, the same controller model applies to the contact details it then receives. This is the model established by your data_sharing consent (row 6 of §4) and the company's Hirer Commercial Terms acceptance. It means:
- Bontra remains the controller for the data we retain about you
- The hiring company becomes a separate, independent controller for its own copy and is responsible in its own right for how it handles that copy
- You have the same UK GDPR rights against the hiring company (access, rectification, erasure) as you do against Bontra
- If you make an erasure request to Bontra, our erasure power is limited to the data in our own systems. We erase (or anonymise, subject to the retention exceptions in §9 and §12) the copy we hold, and under Art. 19 we notify each hiring company that received your data of your erasure request, asking them to delete their copy. Art. 19 notification is the limit of what we can do once a company holds an independent copy: we cannot reach into a recipient's systems or compel a company to comply promptly - you retain the right to contact them directly to exercise your rights against them
6.7 Prospecting outreach to potential hiring companies
To help candidates find suitable roles, Bontra may contact potential hiring companies in the insurance-specific recipient category described in §6.1 and show them non-identifying candidate summaries of the kind described in §6.2. These summaries do not include name, contact details, exact employer names, or exact location. The purpose is to invite relevant employers to engage with Bontra before any identifying candidate data is shared.
Formal introductions with identifying profile data are only made to companies that have completed Bontra's company onboarding, accepted the applicable legal terms, and have an authorised user. Only after those conditions are met can a full-profile introduction become possible.
6.8 Lawful basis for prospecting outreach
Prospecting outreach to potential hiring companies uses contract necessity (UK GDPR Art. 6(1)(b)) as the lawful basis. Your contract with Bontra is the matching service: we help you find roles by matching your profile to opportunities. Contacting relevant hiring companies with non-identifying candidate summaries is part of delivering that service.
To stop Bontra from including you in prospecting outreach, request account deletion per §11 or email [email protected] to object. On receiving your request, we will remove your profile from active outreach and stop including your profile in future prospecting activity.
7. Sharing company data (company users)
This section applies to hiring company users. It covers how information about your company and your role is shown to candidates.
7.1 Company name visibility
- In anonymous listings: when your roles are listed on candidate-facing pages before an introduction is made, your company name is not displayed. Candidates see the role content, seniority, location, and specialisation, but not the hiring company's identity.
- At introduction: when a candidate is introduced to your role and the candidate expresses interest, your company name and the introducing contact are disclosed to the candidate as part of the introduction email.
- Post-introduction: the candidate retains your company name and contact information as part of the introduction workflow.
7.2 Job description sharing
The job descriptions you upload, authorise us to use, or that are otherwise publicly available are used to identify role requirements and create candidate-facing role summaries. Your uploaded text may be stored, indexed, and retained while the role is active. After the role closes, the stored text is retained for the periods set out in §9.
7.3 Company user identity
Your name and role title may be included in introduction and outreach emails sent by Bontra on behalf of the company. We do not share your email address with candidates unless you explicitly opt into direct candidate communication.
7.4 Company confidentiality obligations
If you receive candidate data via an introduction, you take on independent controller obligations as described in §6.6. The Bontra Platform Terms and Hirer Commercial Terms include specific confidentiality undertakings you must follow.
8. Processor categories and international transfers
We use a small number of carefully chosen third-party service providers to operate Bontra. Each provider is bound by a Data Processing Agreement (DPA) that obliges them to protect your data to UK GDPR standards, and each transfer of data outside the UK uses an approved transfer mechanism (UK-US Data Bridge, UK Addendum to EU Standard Contractual Clauses, or equivalent).
8.1 Processor categories
| Processor category | Purpose | What is sent | Location | Transfer mechanism |
|---|---|---|---|---|
| Authentication and account provider | Authentication, session management, email verification, OAuth | Email, name, password hash, session tokens, OAuth identifiers | US | UK-US Data Bridge + SCCs as fallback |
| AI-assisted processing provider | Extraction and drafting support for CV text, job-description text, and non-identifying candidate summaries | CV text, job-description text, and non-identifying candidate summary inputs | US | UK-US Data Bridge + SCCs with UK Addendum |
| Application hosting and secure data storage provider | Application hosting and secure data storage | Personal data stored in the Bontra service | US | UK-US Data Bridge + SCCs |
| Transactional and service email provider | Transactional and service email delivery | Recipient email addresses, email content | US / EU | UK-US Data Bridge + SCCs |
| Analytics and operational metrics provider | Cookieless website analytics and operational metrics | Page views, device and browser type, referrer, and operational metric events. No PII from Bontra accounts | EU | No transfer outside EEA for analytics data |
You can request the current vendor list, including any pending processor changes, by emailing [email protected].
8.2 AI processor retention
Our current AI-assisted processing provider retains API request and response logs for 30 days for abuse and safety monitoring purposes, then deletes them. We have made the following arrangements to ensure this is compatible with UK GDPR:
- The provider's commercial terms prohibit training its models on API data sent by Bontra
- Bontra reduces direct contact details in text sent for AI processing where this is compatible with the service being provided
- The DPA and SCCs with UK Addendum govern all transfers
- The provider operates under a formal information security programme
8.3 Why these providers and not others?
We chose each provider on the basis of technical fit, data protection maturity, and transfer-mechanism availability. We specifically avoid providers that lack a UK GDPR-compatible DPA or that cannot demonstrate an adequate transfer mechanism to the UK. We periodically review our processor list and will notify users if we add, remove, or materially change a processor category listed here.
8.4 Processor changes
If we add a new material processor category, or materially change how an existing category handles personal data, we will update this Privacy Policy and (where the change is material) notify registered users via email. If you object to a new processor, you may delete your account.
9. Data retention
We keep your personal data only as long as necessary for the purposes set out in this policy, or as required by law. This section sets out the retention period for each category of data.
| Category | Retention period | Legal basis |
|---|---|---|
| Active candidate account data (profile, CV, logistics, consent records) | Lifetime of the account, plus 30 days after account deletion (soft-delete window) | Contract + consent (Art. 6(1)(a), (b)) |
| Active company account data (company profile, company user profile) | Lifetime of the account, plus 30 days after account deletion | Contract (Art. 6(1)(b)) |
| Hirer Commercial Terms acceptance audit fields | Lifetime of the account, plus 6 years after account deletion (contract limitation period) | Legitimate interest + legal obligation (fee dispute protection) |
| Introduction and placement records (date, hirer identity, placement outcome) | Minimum 1 year from introduction date, even if account is deleted, with candidate PII anonymised or pseudonymised after account deletion where possible | Legal obligation (Conduct Regulations 2003 Reg. 29, Art. 6(1)(c)) |
| Fee and commission records | 6 years after invoice issue (contract limitation period) | Legitimate interest (Art. 6(1)(f)) |
| AI processor API logs (CV, job-description, and non-identifying summary text processed by the AI-assisted processing provider) | 30 days (processor-side retention), then deleted | Legitimate interest - provider abuse/safety monitoring |
| Consent records (including IP and user agent at grant time) | Lifetime of the account, plus 30 days after account deletion | Legitimate interest - consent verifiability under Art. 7(1) |
| Email disclosure log (which companies received which candidate data and when) | 7 years from the disclosure date. After you delete your account, your name and identifier are removed from these records (redacted to a non-reversible placeholder), but the event that "a disclosure was made to company X about role Y on date Z" is kept for 7 years as audit evidence. After 7 years the row is automatically and permanently deleted by our scheduled data retention job. | Legitimate interest + Art. 17(3)(e) defence of legal claims (UK Limitation Act 1980) + UK Conduct of Employment Agencies and Employment Businesses Regulations 2003 record retention |
| Admin audit log (who did what as an admin, and on which account) | 7 years from the action date, same handling as the email disclosure log. After you delete your account, your identifier is removed from these records (redacted to a non-reversible placeholder) but the audit entry "an admin performed action X on date Y" is kept. After 7 years the row is automatically and permanently deleted. | Legitimate interest (accountability, security audit trail) + Art. 17(3)(e) defence of legal claims |
| Waitlist data (if you joined the waitlist pre-launch and did not create an account) | 6 months after Bontra's full launch, then deleted | Consent (waitlist privacy policy, being retired) |
| Cookieless analytics | Aggregated data, no per-user retention (no persistent identifiers stored) | Legitimate interest |
9.1 What "account deletion" actually means
When you delete your Bontra account:
- Immediately: your account is soft-deleted. You are logged out. Your profile stops being matched against new jobs. Any active introductions are cancelled. Consent records are marked as withdrawn. You cannot log in.
- Within 30 days: your data enters the hard-delete pipeline. Your CV, profile, matching data, and consent records are permanently deleted from our active database, subject to the legal obligations in the next paragraph.
- Exception - employment agency records: we are legally required under Reg. 29 of the Conduct of Employment Agencies and Employment Businesses Regulations 2003 to retain records of introductions and placements for at least 1 year after they occur. We retain the minimum necessary data (date of introduction, hirer identity, placement outcome, a pseudonymised reference to you) and anonymise your identifying information where possible.
- Exception - fee records: where you are a company and fees are payable, we retain the fee invoices and contract records for 6 years (the contractual limitation period for fee disputes).
- Exception - audit logs (7 years): we keep a minimal audit trail of actions taken while your account was active, specifically (a) a log of disclosures we made on your behalf to hiring companies (which company, which role, what data categories were shared, which Bontra admin authorised it), and (b) a log of administrative actions performed by our staff on your account. After you delete your account, your name, email, and identifier are removed from these records - what remains is the event itself, with your identifier replaced by a non-reversible placeholder so the record can no longer be linked back to you. We keep these redacted records for 7 years as audit evidence, and then our automated data retention job permanently deletes them. These records do not contain your CV, profile data, or any other content you submitted. The legal basis is UK data protection law Article 17(3)(e) (defence of legal claims - the UK limitation period for contract claims is 6 years; we retain for 7 to provide a small buffer) combined with our obligations as an employment agency under the Conduct of Employment Agencies and Employment Businesses Regulations 2003.
9.2 What about third parties who already have my data?
Once we have shared your data with a hiring company via an introduction, that company holds its own copy as an independent controller. When you exercise erasure against Bontra, we will send a CANDIDATE_DATA_DELETION_REQUEST email to each hiring company that received your data, requesting they also delete their copy (as required by Art. 17(2)). We cannot compel the company to comply - you retain the right to contact each company directly.
10. Your rights under UK GDPR
You have a number of rights in relation to your personal data. This section explains what each right means and how to exercise it with Bontra.
10.1 Right of access (Article 15)
You have the right to ask us whether we are processing your personal data and, if we are, to receive a copy of the data along with information about how we use it. We provide this as a self-service data export:
- As a candidate, you can download an export of your account data from your profile page. Your original CV file is downloadable separately from the same page.
- As a company user, email [email protected] to request a company data export.
- Responses are provided within one calendar month of the request
The export includes: identity, your onboarding answers (location, work authorisation, salary expectations, working pattern, etc.), the text we extracted from your CV, your consent records, IP addresses and user agents at consent grant moments, and any disclosure or audit log entries referring to you. Your original CV file is downloadable separately from your profile page. The structured professional profile we derive from your CV for matching is described at category level in §3.1; internal scoring methods are not included.
10.2 Right to rectification (Article 16)
If any data we hold about you is inaccurate or incomplete, you have the right to have it corrected. For most profile fields you can edit your profile directly. For data you cannot edit (extraction outputs you disagree with, system-generated fields), email [email protected].
10.3 Right to erasure / right to be forgotten (Article 17)
You can request deletion of your personal data. As a candidate, you can do this from your account settings. As a company user, email [email protected].
Erasure is subject to the exceptions in §9 and §12 - specifically, we are legally required to retain minimum introduction records for at least 1 year under the Conduct Regulations 2003. We will delete or anonymise all other data within the 30-day soft-delete window.
10.4 Right to restrict processing (Article 18)
You have the right to ask us to stop processing your data in certain circumstances - for example, while we investigate a rectification request, or while you contest the accuracy of data we hold. Email [email protected] with the basis for your request.
10.5 Right to data portability (Article 20)
You have the right to receive your data in a structured, commonly used, machine-readable format. Two affordances on your profile page fulfil this right together:
- The JSON export described in §10.1 contains your user-provided account data and the text we extracted from your CV.
- The original CV file you uploaded is downloadable in its original format (
.pdf,.docx, or.txt).
Both are machine-readable and reusable with another service.
10.6 Right to object (Article 21)
You have the right to object to processing based on legitimate interest. If you object to our legitimate-interest processing (analytics, error monitoring, consent verifiability logging), we will assess whether we have compelling legitimate grounds that override your interests, and we will stop processing unless we do. Email [email protected] with the basis for your objection.
10.7 Rights in relation to automated decisions (Article 22)
See §5.4 above. You have the right to request human intervention, express your point of view, and contest automated outcomes.
10.8 Right to withdraw consent (Article 7(3))
For any processing based on consent (screening, matching, data sharing), you have the right to withdraw consent at any time. Because the three consent-based purposes are interdependent, withdrawal is exercised via account deletion. See §11.
10.9 Right to lodge a complaint with the ICO
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) - see §14 for details. We hope you will contact us first so we have the opportunity to address your concerns.
10.10 How to exercise any of these rights
Email [email protected] with a brief description of your request. We will respond within one calendar month. If your request is particularly complex we may extend the deadline by a further two months, in which case we will tell you the reason within the original month.
We do not charge a fee for responding to these requests. We may ask for identity verification to ensure we are dealing with the correct person.
11. Withdrawing consent and deleting your account
11.1 Candidates
All four candidate-facing consent purposes (screening, matching, data_sharing, and the bundled contract-based terms_of_service and privacy_policy acceptances) are withdrawn together, via a single action: deleting your Bontra account. This is deliberate - the three consent-based purposes are interdependent (you cannot usefully grant matching without screening data, and you cannot share without matching), so a single withdrawal mechanism is proportionate under Article 7(3), which requires withdrawal to be "as easy as" giving consent.
To delete your candidate account:
- From the candidate dashboard: Settings → Delete account
- Or email [email protected] and we will delete the account on your behalf within one calendar month
What happens immediately:
- Your account is soft-deleted and you are logged out
- All consent records are marked as withdrawn with a timestamp
- Your profile stops appearing in any matching run
- Active introductions are cancelled
- Bontra stops sending you any emails (except legally required transactional notices such as erasure confirmation)
What happens within 30 days:
- Your CV, profile, matching data, and personal data are permanently deleted from our active database
- Copies in backups are overwritten as backups rotate
- Minimum introduction records are retained per §9 and §12 for the legal 1-year window
- Fee records for any placements you were part of are retained for 6 years
- We send a
CANDIDATE_DATA_DELETION_REQUESTemail to any hiring companies that received your data, asking them to delete their copies
11.2 Company users
Company user deletion is slightly different because the Hirer Commercial Terms contract has surviving obligations:
- Your individual account is deleted following the same soft-delete then hard-delete pattern
- The company record remains, as do the company's Hirer Commercial Terms obligations (fee commitments for past introductions, anti-circumvention window, confidentiality of candidate data)
- If another user from the same company is linked, the company continues to operate with Bontra normally
- If no other user is linked, the company becomes "dormant" and Bontra admin may suspend matching or introductions until a new authorised user signs up
To delete your company user account, email [email protected].
11.3 Withdrawing from analytics or error monitoring only
Analytics and error monitoring are based on legitimate interest, not consent. If you object to them, email [email protected] explaining the basis for your objection. We assess each objection on its merits and will stop processing unless we have compelling legitimate grounds that override your rights. In practice, cookieless analytics has a very low privacy impact and we expect most objections to be accommodated by excluding your sessions from our analytics collection entirely.
12. Employment agency status and record-keeping obligation
This section is a specific legal disclosure required by our regulatory status.
12.1 Bontra is an employment agency
Bontra is an employment agency within the meaning of section 13(2) of the Employment Agencies Act 1973. This means our activity is the finding of workers (candidates) for employers (hiring companies) - we introduce candidates to employers, and when a candidate is hired, they are employed by the employer, not by Bontra.
We are not an employment business - we do not employ candidates directly, we do not pay wages, and we do not supply candidates on a contract basis.
The licensing requirements of the Employment Agencies Act 1973 were repealed in Great Britain by the Deregulation and Contracting Out Act 1994, so Bontra does not hold an agency licence - none is required. We are, however, subject to the conduct obligations in the Conduct of Employment Agencies and Employment Businesses Regulations 2003.
12.2 Regulation 29 record-keeping obligation
Regulation 29 of the Conduct of Employment Agencies and Employment Businesses Regulations 2003 requires us to keep records of:
- The dates and details of requests from hirers (companies) for workers (candidates)
- The dates and details of candidates introduced or placed with hirers
- Copies of written terms agreed with hirers and workers
- Details of any fees or commissions received
These records must be kept for at least one year from creation.
12.3 What this means for your erasure rights
Regulation 29 creates a legal obligation that overrides the right to erasure under Article 17 of the UK GDPR, per Article 17(3)(b) which disapplies erasure where processing is necessary for compliance with a legal obligation.
In practice, when you exercise your right to erasure:
- We will retain the minimum necessary introduction record for at least 1 year from the date of introduction: date, hirer identity, placement outcome, and a pseudonymised reference to you
- We will anonymise your identifying information (name, contact details) from the introduction record where possible, so the fact of the introduction is preserved without continuing to identify you
- We will delete all other data held about you within the 30-day soft-delete window, per the ordinary erasure process
After 1 year from the date of introduction, the minimum record can be fully deleted. Fee and commission records remain for 6 years under the contractual limitation period (Article 6(1)(f) legitimate interest).
12.4 Inspection by the Employment Agency Standards Inspectorate
The Employment Agency Standards Inspectorate (EAS), part of the UK Department for Business and Trade, has statutory powers to inspect our records and investigate complaints. If EAS requests records about you in the course of a lawful inspection, we may be required to disclose them. We will minimise any such disclosure to what is strictly necessary.
12.5 Reasonable adjustments under the Equality Act 2010
As an employment service-provider we are subject to sections 20-21 of the Equality Act 2010, which require us to make reasonable adjustments where a provision, criterion, or practice puts disabled candidates at a substantial disadvantage. Our onboarding uses a CV upload and intake questions designed to be accessible to candidates who are d/Deaf, hard of hearing, have speech impediments, or have anxiety disorders that make voice calls difficult. If you need any other adjustment, please contact [email protected] and we will work with you to provide an equivalent alternative.
13. Changes to this policy
13.1 When we update this policy
We may update this Privacy Policy from time to time to reflect:
- Changes in the processing activities we perform
- Changes in our processor categories (for example, if we replace one analytics provider with another)
- Changes in the law or regulatory guidance
- Clarifications or corrections requested by users or regulators
13.2 How we notify you of changes
Material changes to this Privacy Policy will be notified to registered users by email or in-product notice. Non-material changes (typographical corrections, clarifications that do not affect substantive obligations) may be made without a notification.
The "Version" and "Effective date" fields at the top of this document will always reflect the current version. A version history is maintained in the source repository.
13.3 Re-consent for material changes
Where a material change requires fresh acceptance or consent, we will ask you to review and accept the updated Privacy Policy before the affected processing continues.
13.4 No retroactive changes
We will not apply any new terms retroactively in a way that reduces your rights for data collected before the change. If a change would reduce your rights, the old terms continue to apply to data collected under the old version until you either accept the new version or delete your account.
14. Complaints to the ICO
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) if you are unhappy with how we handle your personal data.
- ICO website: https://ico.org.uk/make-a-complaint/
- ICO phone: 0303 123 1113
- ICO address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would prefer that you contact us first at [email protected] so we have the opportunity to resolve your concerns directly. But you are under no obligation to do so - you may go straight to the ICO if you prefer.