← techbrief.ai
legal

Privacy Policy

Last updated: June 2026 · Governed by UK GDPR and the Data (Use and Access) Act 2025

1. Who we are

TechBrief.ai (“TechBrief”, “we”, “us”) is a specialist technology recruitment agency operating in the United Kingdom. We act as the data controller for personal data processed through this website and our recruitment activities.

Contact us about data protection at valentin@techbrief.ai.

2. Data we collect and why

2a. Contact form submissions

When you submit your email address via our contact form, we collect:

  • Your email address
  • The date and time of submission

We use this solely to respond to your enquiry. We do not add you to marketing lists without your explicit consent.

2b. Website visits

Our hosting provider (Vercel) may collect standard server logs including IP addresses, browser type, and pages visited. This data is used for security and performance monitoring only and is not used to identify you personally. We do not operate any analytics or tracking on this website.

2c. Candidate data (sourced via LinkedIn)

As a recruitment agency, we may source candidate profiles from publicly available professional networks, including LinkedIn, using AI-assisted tooling. If you are sourced as a candidate for a specific open role, we may process:

  • Your name and professional headline
  • Your LinkedIn profile URL
  • Your work history and stated skills
  • Your contact details where publicly available

We will provide you with this privacy notice within 30 days of sourcing your profile (as required by Article 14, UK GDPR), and no later than our first communication with you.

We only source candidate data in connection with a specific, active open position — not to build a general talent database. We will not contact you for roles unrelated to the one we sourced you for without obtaining your separate consent.

3. Our legal basis for processing

ActivityLegal basis
Responding to contact form enquiriesLegitimate interests (Article 6(1)(f)) — responding to a business enquiry you initiated
Sourcing and contacting candidates for a specific roleLegitimate interests (Article 6(1)(f)) — filling an active vacancy using publicly available professional profile data
Server/security logsLegitimate interests (Article 6(1)(f)) — protecting the security and integrity of our service

We have conducted a Legitimate Interests Assessment (LIA) for candidate sourcing activities, balancing our interest in filling specialist roles against candidate privacy rights. You may request a copy of this assessment by contacting us.

4. Who we share your data with

We use the following third-party processors. Each is engaged under a Data Processing Agreement (DPA) that meets the requirements of Article 28, UK GDPR:

ProcessorPurposeLocation
Vercel Inc.Website hosting and serverless infrastructureUnited States
Resend Inc.Transactional email delivery (contact form)United States
PlacementFlowAI-assisted candidate sourcing and recruitment workflow automationUnited States

We do not sell your data. We do not share your data with clients without your knowledge. Candidate profiles are only submitted to a hiring company after we have spoken with you and you have confirmed interest in the role.

5. International data transfers

Our processors (Vercel, Resend, and PlacementFlow) operate in the United States. We transfer data to them under the EU–US Data Privacy Framework, for which the European Commission issued an adequacy decision in July 2023 (reaffirmed July 2025). Transfers are additionally protected by Standard Contractual Clauses (SCCs) as a fallback safeguard.

You may request details of the specific safeguards applied to your data at any time.

6. How long we keep your data

Data typeRetention period
Contact form email address6 months from submission, or until you ask us to delete it
Sourced candidate profile (role not filled or candidate declined)12 months from last contact, then deleted or anonymised
Candidate data where a placement was madeDuration of engagement plus 6 years (legal and financial record-keeping obligations)
Server/infrastructure logsUp to 30 days (Vercel default retention)

We apply the principle of storage limitation — we delete data as soon as we no longer have a legitimate reason to hold it.

7. Your rights

Under UK GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you (Subject Access Request)
  • Rectification — ask us to correct inaccurate data
  • Erasure — ask us to delete your data (“right to be forgotten”)
  • Restriction — ask us to stop actively processing your data while a dispute is resolved
  • Portability — receive your data in a machine-readable format
  • Object — object to processing based on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your rights

To exercise any of these rights, email valentin@techbrief.ai. We will respond within one calendar month.

If you are a candidate we sourced via LinkedIn and have not been contacted, you may ask us to confirm whether we hold your data and request deletion at any time.

8. Automated decision-making

We use AI tooling (PlacementFlow) to assist in ranking and matching candidates to open roles. This tooling produces a shortlist score and recommendation, but no fully automated decision is made about you — a human reviewer assesses all AI-generated shortlists before any candidate is contacted or submitted to a client. This is consistent with the requirements of the Data (Use and Access) Act 2025 and ICO guidance on AI-assisted recruitment.

9. Cookies

This website does not use tracking or analytics cookies. We do not use advertising pixels or any third-party behavioural tracking. No cookie consent banner is presented because none is required.

If you use our contact form, a standard browser session may be created for security purposes. This does not persist after you close the tab.

10. Security

We implement appropriate technical and organisational measures to protect personal data, including encrypted data transmission (TLS/HTTPS), access controls, and regular review of our sub-processors' security posture. In the event of a data breach affecting your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay.

11. Changes to this policy

We may update this policy as our services evolve or as regulatory requirements change. The “Last updated” date at the top will always reflect the most recent version. For material changes affecting candidates, we will provide direct notice where we hold your contact details.

12. Complaints

If you are unhappy with how we have handled your data, please contact us first at valentin@techbrief.ai. If you remain unsatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

  • Website: ico.org.uk/make-a-complaint
  • Phone: 0303 123 1113