Heyday Medical Recruitment (“we”, “us”, “our”) is committed to protecting your privacy and handling your personal data transparently, responsibly, and in accordance with the UK GDPR, Data Protection Act 2018, and all relevant healthcare and recruitment regulations.
This Privacy Policy outlines how we collect, use, store, and protect your personal information when you visit our website, register as a candidate, or engage with our recruitment services.
1. Information We Collect
We may collect and process the following categories of data:
A. Candidate Information:
- Full name, contact details, date of birth
- National Insurance Number
- Professional registration (e.g., NMC, GMC numbers)
- Right to work documentation (passport, visa, etc.)
- DBS (Disclosure & Barring Service) status
- Training and certifications (e.g., Manual Handling, Infection Control)
- Employment history, CV, references
- Health and vaccination records (where necessary for placement)
B. Client Information:
- Name, company name, email address
- Contact numbers, job role/title
- Billing and contract details
C. Website Usage Data:
- IP address, browser type, cookies
- Pages visited, time on site, referral URL
2. How We Use Your Data
We use your information to:
- Match candidates with suitable healthcare vacancies
- Process applications and verify compliance (e.g., DBS, right-to-work)
- Maintain accurate candidate records for audit/compliance
- Communicate with clients and job seekers
- Meet legal and regulatory obligations (NHS Frameworks, CQC, etc.)
- Improve our services and website functionality
3. Lawful Basis for Processing
We process personal data based on:
- Consent (e.g., receiving job alerts)
- Contractual necessity (e.g., candidate placements)
- Legal obligations (e.g., safeguarding, DBS checks)
- Legitimate interest (e.g., recruitment matching, service improvement)
4. Sharing Your Information
We may share data with:
- NHS Trusts, private healthcare clients, care providers
- Compliance service providers (DBS check facilitators, training providers)
- Payroll and payment processors
- Legal and regulatory bodies when required by law
We never sell or rent your data to third parties.
5. Data Retention
We retain candidate data for up to 6 years after the end of your engagement with us, in line with NHS and CQC audit requirements. You may request earlier deletion, where legally permissible.
6. Your Rights (UK GDPR)
You have the right to:
- Access, correct, or delete your data
- Restrict or object to processing
- Withdraw consent at any time
- Lodge a complaint with the ICO (Information Commissioner’s Office)
7. Security Measures
We implement strict technical and organisational measures to protect your data:
- Encrypted file storage and secure databases
- Role-based access control
- Regular system audits and compliance checks
8. Cookies
Our website uses cookies to enhance your user experience. You can manage cookie preferences through your browser settings or our cookie banner.
9. Contact Us
For data protection inquiries or to exercise your rights, contact:
Privacy Contact Person
Heyday Medical Recruitment
📧 info@heydaymedical.co.uk