GuardVett Privacy Notice
Website preview. The wording has been approved for implementation. Factual publication checks remain in progress; this preview does not change existing agreements.
On this page
- 1 Who we are
- 2 Our role and the screening organisation’s role
- 3 Information we handle
- 4 Where information comes from
- 5 Why we use information as a controller
- 6 AI assistance and human decisions
- 7 Who receives information
- 8 Locations and international transfers
- 9 How long we keep information
- 10 Cookies and local device storage
- 11 Your rights
- 12 Providing information and making a complaint
1 Who we are
GuardVett is provided by ISO Consultants U.K. Limited, registered in England and Wales under company number 10766230. Our registered office is Lewis Building, 35 Bull Street, Birmingham, England, B4 6AF. In this notice, “we”, “us” and “ICUK” mean that company.
For privacy questions or requests, contact sales@guardvett.com and mark your message “Privacy”. Our business mailbox is hosted by Microsoft 365, which processes messages, attachments and related email metadata sent to or from that address. You may also write to our registered office. Please initially describe your request without attaching identity documents or screening records; we will explain any secure verification steps that are needed.
2 Our role and the screening organisation’s role
We are the controller of information used to run our business, manage customer relationships and accounts, bill for GuardVett, respond to enquiries and protect our service.
When an employer, recruitment business or other screening organisation uses GuardVett to manage a screening file, that organisation normally decides why and how the screening information is used. It is the controller, and ICUK processes the information on its documented instructions under our Data Processing Agreement. If our customer is itself a processor, the relevant roles and instructions must be documented in the customer agreement.
The organisation requesting your application or reference should give you its own privacy notice. That notice explains its screening purposes, lawful grounds, recipients, retention periods and decisions. This notice does not replace it. Contact that organisation first about a screening decision or your screening record. We can help identify the appropriate contact and assist the organisation with a rights request.
3 Information we handle
For our own business purposes, we handle names, work contact details, organisation and role, account identifiers, authentication and security information, subscription and invoice details, support correspondence, and records of agreements and preferences. Payment providers handle payment credentials; GuardVett uses payment references and subscription information to administer access.
When you access the service, technical information may include IP address, browser and device information, timestamps, requested pages, authentication events and error details. We use this information to operate and secure the service. Error reporting is designed to reduce personal information, but diagnostic information can still identify a user or activity.
Screening files may contain names, previous names, date of birth, contact and address history, photographs, identity and immigration documents, right-to-work information, employment and education history, gaps, references, SIA licence details, financial probity records, declarations, evidence, correspondence, decisions and audit records. Where the customer lawfully uses the relevant features, files may also contain health information and criminal offence or DBS information. A photograph is not automatically biometric data used for unique identification; the relevant processing determines that classification.
4 Where information comes from
We receive information directly from you, your organisation’s administrators, people submitting applications or references, and payment and service providers. Screening information can also be entered by the customer from documents, interviews, referees, employers, educational bodies, official checks and other sources it is entitled to use. The customer is responsible for explaining those sources and its use of them to the people concerned.
5 Why we use information as a controller
We use business contact and account information to answer enquiries, administer subscriptions, provide support and communicate about the service. Our lawful basis is our legitimate interest in supplying and managing a business service. Where an individual contracts with us personally, we also process information necessary to take requested pre-contract steps and perform that contract.
We process billing and transaction records to administer payments and comply with applicable accounting and tax duties. The bases are contract where applicable, legitimate interests in managing our commercial relationship, and legal obligation where a specific duty applies.
We use security and diagnostic records to detect misuse, investigate incidents, resolve faults and protect users and information. Our basis is our legitimate interest in maintaining a secure, reliable service. We assess necessity and the effect on individuals when relying on legitimate interests.
We use records needed to establish, exercise or defend legal claims on the basis of our legitimate interests in protecting legal rights, and to comply with legal duties where applicable. We use consent for optional marketing or non-essential tracking where the law requires it. You may withdraw consent without affecting the lawfulness of earlier processing. Service and security messages are separate from optional marketing.
Screening data is processed under the customer’s instructions. The customer must identify its own lawful basis and any additional condition for health, other special category or criminal offence information. Uploading data to GuardVett does not by itself establish those grounds.
6 AI assistance and human decisions
GuardVett uses document recognition and AI services to extract information, organise records, identify possible gaps or inconsistencies and assist a reviewer. Depending on the enabled workflow, these services can receive document text, relevant record context and document or page images. Provider details appear in the Subprocessor Register.
AI output can be incomplete or wrong. The screening organisation is responsible for checking evidence, making required attestations and deciding whether to employ, deploy or approve a person. GuardVett does not make an employment or deployment decision for the customer. Automated reminders, calculations and workflow statuses assist that process; they are not a substitute for a person’s assessment.
Ask the screening organisation for an explanation or human review of a decision affecting you. Our authorised processing instructions do not include using screening information to train general-purpose AI models. Provider retention is a separate issue from model training; do not assume that information is immediately deleted after an AI request.
7 Who receives information
Access is limited according to the service role and purpose. Information may be available to authorised customer users and to ICUK personnel who need it for support, operation, security or a legal duty. Customers control sharing with their own clients, auditors or advisers and are responsible for the authority to do so.
We use providers for hosting, databases, authentication, document storage, document recognition, AI analysis, email, payments and, where enabled, diagnostics. Our Subprocessor Register describes the screening-data providers and identifies services with a different or additional controller role. Referees and applicants receive the information needed for their communication or portal task, rather than general access to the customer’s files.
We may disclose relevant information to professional advisers, insurers, regulators, courts or law-enforcement bodies where lawful and necessary. If our business is reorganised or transferred, relevant information may be shared under appropriate confidentiality and data-protection arrangements, with notice where required. We do not sell screening information or authorise its use for advertising.
8 Locations and international transfers
The primary GuardVett production database and file storage are configured in London. Some suppliers are established outside the UK or may process information or provide support from other countries. A UK hosting region is not a promise that every operation, email, support interaction or supplier access remains in the UK.
Our Data Processing Agreement requires an applicable UK transfer mechanism for restricted transfers. Depending on the recipient and route, this may be an adequacy regulation or contractual safeguards such as the UK International Data Transfer Agreement or the UK Addendum to EU standard contractual clauses, supported by the required assessment. The Subprocessor Register records the supplier arrangements and items awaiting confirmation. Contact us for information about the safeguards applicable to your data and how to obtain a copy, with lawful redactions where necessary.
9 How long we keep information
We retain controller information only for as long as necessary for the relevant purpose. We consider whether an account or enquiry remains active, whether a support or security issue is unresolved, applicable accounting duties, claim periods, and whether a shorter or anonymised record will meet the need. Necessary legal or dispute records may outlast an account; this does not justify keeping unrelated screening documents.
The screening organisation sets the retention instructions for its screening records. The existing DPA describes configurable defaults of seven years after employment ends and twelve months for unsuccessful applicants. Those defaults are not a statement that every record must legally be kept that long. The customer must choose and apply an appropriate schedule, including shorter treatment of sensitive evidence where required.
Closing an account or cancelling payment does not itself instruct immediate destruction of every record. Return and deletion are handled under the DPA, including lawful retention exceptions. Backups, security logs and supplier copies follow their applicable retention and deletion arrangements. Contact us or the screening organisation for the retention criteria relevant to a particular record.
10 Cookies and local device storage
The marketing website currently retrieves fonts from Google Fonts. This causes your browser to contact Google to retrieve font styles and files, disclosing network request information such as your IP address. The legal pages use system fonts and do not make those font requests.
The service uses cookies and similar storage to maintain sign-in, secure sessions and remember essential workflow state. For example, local storage may remember which two-factor enrolment you have started. Blocking necessary storage may prevent sign-in or interrupt a workflow.
Any optional analytics or advertising technology must be described and controlled before it is introduced, with consent where required. Payment or other third-party pages may use their own cookies under their notices. A deployed cookie inventory, including names and lifetimes, must accompany publication of this notice; it is not sufficient to infer deployed tracking solely from the source code.
11 Your rights
Depending on the circumstances, you can request access, correction, erasure, restriction and data portability. You can withdraw consent where processing relies on it. We may need proportionate information to verify identity and will explain any applicable exception or limit. We respond within the period required by law, normally one month; we will explain any lawful extension or other adjustment that applies.
Your right to object: you can object to processing based on legitimate interests for reasons relating to your situation. We must stop unless the law permits us to continue, for example because of compelling grounds or legal claims. You can object to direct marketing at any time, and we will stop using your information for that purpose.
Contact sales@guardvett.com for requests concerning ICUK’s controller processing. For screening records, contact the screening organisation; if a request reaches us, we will assist or pass it to the appropriate controller as required by our role. A customer’s contract with us does not remove your statutory rights.
12 Providing information and making a complaint
Account and billing details are needed to supply and administer the service. Without required information, we may be unable to open an account, take payment or resolve a request. The screening organisation must explain which screening information it requires and what happens if you do not provide it.
Please contact us if you have a concern. You can also complain to the Information Commissioner’s Office at https://ico.org.uk/make-a-complaint/ or on 0303 123 1113. You do not have to exhaust our complaints process before approaching the ICO.
We will identify the effective date and version when this notice is published and explain material changes through an appropriate channel. A change of notice does not create a new lawful basis or remove existing rights.