Skip to main content

Recruitment privacy

Applicant privacy notice

Last reviewed: 11 August 2026

Information used during recruitment

We may use your contact details, candidate profile, application answers, employment history, gap explanations, interview and assessment records, references and evidence required for safer recruitment. We will explain any additional evidence request in the candidate portal.

Why we use it

We use applicant information to administer applications, assess suitability through human review, communicate decisions, meet safer-recruitment responsibilities and establish or defend legal rights. We do not use AI candidate scoring or automated rejection.

Sensitive information and documents

Do not include detailed health information unless it is specifically requested through an appropriate process. Candidate uploads are evidence submissions, not verification. DBS and right-to-work evidence still require the applicable original, face-to-face or prescribed check.

Access and security

Candidates can access only their own records. Authorised recruitment staff must use multi-factor authentication before accessing candidate information. Document downloads, status changes, verification and deletion are audited.

BrightHR handover

If you are approved and an employee record is created, authorised staff complete a controlled handover to BrightHR, which remains the permanent employee and HR system. The application reference is used as an opaque reconciliation reference. Recruitment documents are not sent through undocumented APIs.

Retention

Drafts, unsuccessful applications, audit evidence and temporary conditional-offer documents have separate approved retention periods. Temporary documents are securely deleted after the required checks and reconciled handover. Real document uploads will remain disabled until those periods and the malware-scanning process are approved.

Questions and rights

To ask a privacy question or exercise a data-protection right, email office@lintern.care. We may need to verify your identity before acting on a request.