Skip to main content

Legal

Privacy Policy

How we collect, use, share, and retain personal data, the lawful bases we rely on, and the rights available to you under UK and EU GDPR.

Version
1.0
Last reviewed
Governing law
England and Wales

This policy explains what personal data Etraders Group Ltd collects, why, how long we keep it, who we share it with, and what rights you have. It covers this website, our consultation and billing platform, and our services — including recruitment, which has additional protections set out in section 11.

1. Who Is Responsible for Your Data

Etraders Group Ltd, company number 17164332, is the controller for the personal data described in this policy, except where we act as a processor on a client's behalf (section 3).

Privacy contact: privacy@etradersgroup.online. Postal contact details are in the footer of every page. We have not appointed a statutory Data Protection Officer; the privacy contact above is responsible for data protection matters and will route your request to the right person.

2. The Two Roles We Act In

This distinction determines who you should contact about your data:

  • We are the controller for data about website visitors, enquirers, prospective and current clients, candidates we source ourselves, and our own suppliers and staff. We decide why and how it is processed, and this policy applies.
  • We are a processor for personal data inside systems we build or operate for a client — for example, a client's customer records or their own applicant pipeline. There we act only on that client's documented instructions under our Data Processing Agreement. If your data sits in a client's system, please contact that organisation; we will forward any request we receive.

3. What We Collect

Website Visitors

IP address, browser and device type, referring page, pages viewed, and approximate location derived from IP. When you use a protected public form, Google reCAPTCHA also processes browser, device, interaction, and network signals to distinguish people from automated abuse. Some of this is collected by strictly necessary cookies and server logs; analytics data is collected only with your consent. See our Cookie Policy.

Enquirers and Prospective Clients

Name, work email, phone number, company, website, and the content of your enquiry, including any budget, timeline, or project details you choose to give us.

Consultation and Project Data

Notes from calls and meetings, project documentation, and business information you share with us. We do not record calls by default. If we ever propose to, we will ask for your consent first and tell you how the recording will be used and how long it will be kept.

Clients and Billing

Billing contact details, billing address, VAT number, invoice records, and transaction identifiers. Card details are collected and processed directly by Stripe and never reach or rest on our systems. We receive only a token, the last four digits, the card brand, and the outcome of the transaction.

Candidates (Recruitment Services)

Name, contact details, CV, employment and education history, skills, right-to-work status, salary expectations, interview notes, our written technical assessment of you, and references where you have provided them. See section 11 for the additional protections that apply.

Data Obtained from Other Sources

Required disclosure under Article 14 UK/EU GDPR. Where we do not collect data from you directly, we may obtain it from: professional networking sites and public professional profiles (candidate sourcing); job boards and applicant tracking systems where you have applied; referrals from colleagues or previous candidates; publicly available company websites and business registries; and referees you have nominated. Where we source your data rather than receive it from you, we will tell you within one month of obtaining it, or at first contact if that is sooner, and identify the source.

4. Why We Process It, and Our Lawful Basis

PurposeDataLawful basis
Responding to an enquiry or briefContact and enquiry detailsArticle 6(1)(b) — steps prior to a contract; or 6(1)(f) legitimate interests in responding to business enquiries
Delivering contracted servicesClient and project dataArticle 6(1)(b) — performance of a contract
Taking payment and issuing invoicesBilling and transaction dataArticle 6(1)(b) — performance of a contract
Keeping accounting and tax recordsInvoices and transactionsArticle 6(1)(c) — legal obligation
Security, fraud prevention, bot detection, and service integrityLogs, IP, authentication events, browser and interaction signalsArticle 6(1)(f) — legitimate interests in protecting our systems and clients
Sending service updates to existing clientsContact detailsArticle 6(1)(f) — legitimate interests, with an opt-out in every message
Marketing to business prospectsBusiness contact detailsArticle 6(1)(f) — legitimate interests, subject to local rules; consent where required in your jurisdiction
Analytics cookiesUsage dataArticle 6(1)(a) — consent, and PECR / ePrivacy Article 5(3)
Sourcing and assessing candidatesCandidate dataArticle 6(1)(f) — legitimate interests, with a legitimate interests assessment on file; Article 6(1)(b) once you engage with a role
Diversity monitoring, where offeredSpecial category dataArticle 6(1)(f) plus Article 9(2)(b) or explicit consent under 9(2)(a). Always optional and never used in selection.

Where we rely on legitimate interests, we have balanced those interests against your rights and concluded that the processing is proportionate and would be reasonably expected. You can ask for a copy of that assessment at any time.

5. Who We Share Data With

We do not sell personal data, and we do not share it for third-party advertising. We share it with the sub-processors listed on our sub-processors page, which names each provider, what it is used for, and where it processes data. In summary, that covers form abuse prevention (Google reCAPTCHA), payment processing (Stripe), hosting, transactional email, and — where a specific engagement uses them — AI model providers configured so that your content is not used for training.

We also share data with our professional advisers where necessary, with a prospective purchaser in the event of a business sale (under confidentiality), and with authorities where we are legally required to. For recruitment, we never send your CV or details to a client without your explicit consent for that specific role.

6. International Transfers

Some providers process data outside the UK and EEA, principally in the United States. Where they do, we rely on one or more of: an adequacy decision covering the recipient; the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; or the EU Standard Contractual Clauses (2021/914) supported by a transfer risk assessment. We maintain Standard Contractual Clauses as a fallback with every provider, rather than relying on an adequacy framework alone. You can request a copy of the safeguards in place for any transfer by writing to our privacy contact.

7. How Long We Keep It

DataRetentionWhy
Enquiries that do not become clients24 months from last contactTo recognise a returning prospect and to evidence how we handled the enquiry
Client project records6 years after the engagement endsLimitation period for contractual claims
Invoices and financial records6 years after the end of the relevant financial yearStatutory accounting and tax obligations
Unsuccessful candidate records6 months after the recruitment process endsPeriod in which a claim arising from recruitment may be brought
Candidates in our talent pool24 months from last contact, renewable with your consentConsent, which you may withdraw at any time
Placed candidate records6 years after placementContractual and fee-related records
Marketing consent and preference recordsDuration of consent plus 2 yearsTo evidence that we honoured your choice
Website server and security logs12 monthsSecurity monitoring and incident investigation
Cookie consent records12 monthsTo evidence a valid consent decision

At the end of a retention period we delete the data or irreversibly anonymise it. Backups are purged on their own cycle, within 90 days.

8. Your Rights

Under UK and EU GDPR you have the right to:

  • Access — obtain a copy of the personal data we hold about you;
  • Rectification — have inaccurate or incomplete data corrected;
  • Erasure — have data deleted where there is no overriding lawful reason to keep it;
  • Restriction — limit how we use your data while a dispute about it is resolved;
  • Object — object to processing based on legitimate interests, and object to direct marketing at any time, absolutely;
  • Portability — receive data you gave us in a structured, machine-readable format;
  • Withdraw consent — at any time, where we rely on consent, without affecting processing already carried out;
  • Not be subject to solely automated decisions producing legal or similarly significant effects — see section 10.

To exercise any of these, write to privacy@etradersgroup.online. We respond within one month, extendable by two further months for genuinely complex requests, in which case we will tell you within the first month and explain why. There is no charge unless a request is manifestly unfounded or excessive.

9. Complaints

Please complain to us first. Write to privacy@etradersgroup.online with the details. We will acknowledge your complaint within 30 days and respond substantively without undue delay.

If you remain dissatisfied, you may complain to the UK Information Commissioner's Office (ICO), or to the supervisory authority in the EU or EEA country where you live, work, or where the alleged infringement occurred. Complaining to us first does not remove your right to go to a regulator or to seek a judicial remedy.

10. Automated Decision-Making and AI

We do not make decisions about you by solely automated means. In particular, no candidate is rejected, ranked, or scored by an automated system without a person reviewing and taking responsibility for the decision.

We do use AI tools to help find candidates, organise information, and draft material. Where AI assists, a person reviews the output and holds responsibility for any decision. You may ask how a decision about you was reached, ask for it to be reviewed by a different person, express your point of view, and contest the outcome. Full detail is in our AI Transparency Statement.

11. Additional Protections for Candidates

  • Your CV is never sent to a client without your explicit consent for that specific role. A general permission to represent you is not enough.
  • We collect only what is relevant to the role. We do not ask about health, disability, ethnicity, religion, political opinion, or trade union membership as part of assessment. Where we collect adjustment requirements to support you at interview, we use that data only for that purpose.
  • Where special category data is processed — for example, an adjustment you tell us about, or optional diversity monitoring — we rely on Article 9(2)(b) or your explicit consent, and hold an Appropriate Policy Document as required.
  • Criminal record and vetting checks are carried out only where a role legally requires them, and only with your knowledge.
  • Unsuccessful candidate data is deleted after 6 months unless you ask us to keep you on file, which is entirely your choice and reversible at any time.
  • You may ask for a copy of our written technical assessment of you. We will provide it, redacted only where it would reveal another person's personal data.

12. How We Protect Your Data

Encryption in transit (TLS) and at rest; role-based, least-privilege access; credentials held in a managed secret store and rotated; multi-factor authentication on administrative accounts; audit logging of access to client records; dependency and vulnerability scanning in our build pipeline; written confidentiality agreements with every member of staff and every subcontractor; and development against anonymised or synthetic data wherever feasible. No system is perfectly secure, but we will notify you and the relevant supervisory authority of a qualifying personal data breach within the statutory timeframes.

13. Information for California Residents

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and why, to access and delete it, to correct inaccuracies, to limit the use of sensitive personal information, and not to be discriminated against for exercising those rights. The categories we collect, our purposes, and our retention periods are set out in sections 3, 4, and 7 above; California treats business contact data as personal information, and it is covered.

We do not sell or share personal information as those terms are defined by the CCPA, and we do not process it for cross-context behavioural advertising. We honour Global Privacy Control signals as a valid opt-out request. To exercise a California right, write to privacy@etradersgroup.online; we will verify your identity before acting and you may use an authorised agent.

14. Children

Our services are for businesses and working professionals. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

15. Changes to This Policy

We will update this policy when our practices change. The version and last-reviewed date are shown at the top of this page. For material changes affecting how we use data we already hold, we will notify affected individuals directly by email before the change takes effect.