Last updated: 04/06/2024
AMO Consultancy Services Ltd is committed to conducting its business in accordance with all applicable data protection laws and regulations and in line with the highest standards of ethical conduct. We respect your privacy and protect your personal data, adopting a Personal Data Protection Policy that sets out how we seek to protect personal data.
As a company registered in England and Wales, we process personal data in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003. Where we process the personal data of individuals in the European Economic Area, we also comply with Regulation (EU) 2016/679.
The objective of Information Security is to ensure business continuity and minimize business damage by preventing and minimizing the impact of security incidents. Information assets must be protected to ensure
Protection against unauthorized disclosure.
Protection against unauthorized or accidental modification.
Ensuring information is accessible when required.
Person who has sent an application and/or has been contacted by AMO Consultancy Services Ltd regarding a job offer.
The individual who is the subject of personal data.
Entity that determines the purposes and means of processing personal data.
Entity that processes personal data on behalf of the Data Controller.
Person recruited by AMO Consultancy Services Ltd.
European Data Protection Regulation (EU) 2016/679.
Department involved in personnel management, recruitment, payroll, or staff relations.
Information relating to an identifiable person.
Operations performed on personal data, such as collection, recording, storage, etc.
AMO Consultancy Services Ltd and all subsidiaries.
Approve and oversee the Information Security and Privacy Policy, ensuring compliance and continuous improvement.
Manages day-to-day data protection responsibilities and ensures compliance with applicable regulations. Contact: [email protected].
Safeguard organizational assets and report any security breaches immediately.
We commit to collecting and processing Personal Data lawfully, fairly, and transparently. Personal Data collected includes:
Name, address, phone number, email.
Professional experience, resume details, etc.
Job title, company affiliation.
Social security number, payroll information, training records, etc.
To provide services, manage contracts, and communicate offers.
To manage job applications and recruitment processes.
To manage employment relationships, administer HR processes, and comply with legal obligations.
We store data only as long as necessary for the purposes outlined in this policy. Criteria for retention include:
Stored according to local authority limits.
Stored for up to 2 years unless consent for longer retention is provided.
Retained for the duration of employment and as required by law thereafter.
Prospective client contact data
Retained for up to 24 months from the date of collection or from our last meaningful contact with you, whichever is later, after which it is deleted or anonymised. Where an individual objects to processing or opts out, their details are retained on a suppression list indefinitely for the sole purpose of ensuring we do not contact them again.
We process personal data only where we have a lawful basis to do so.
Clients and suppliers. We process personal data where it is necessary for the performance of a contract, or to take steps at your request before entering into a contract.
Prospective clients. We process business contact details, including name, job title, business email address, business telephone number and employer, on the basis of our legitimate interests in promoting our services to organisations likely to have a use for them.
We have assessed this basis and consider it appropriate for the following reasons. The data we hold is limited to business contact information relating to a person’s professional role, not their private life. We contact individuals only in connection with their professional responsibilities, and only where our services are relevant to those responsibilities. We source data from reputable business data providers, listed below, and from publicly available professional sources. We do not process special category data for this purpose. Every marketing communication identifies us clearly and provides a simple means of opting out, which we act on immediately and permanently across all of our campaigns.
You have the right to object to this processing at any time. If you do, we will stop and add your details to our suppression list.
Candidates. We process personal data on the basis of taking steps at your request prior to entering into a contract of employment, and on the basis of our legitimate interests in assessing applications.
Employees. We process personal data to perform the employment contract, to comply with legal obligations, and on the basis of our legitimate interests in administering the employment relationship.
Data Subjects have the following rights:
The right to ask and obtain confirmation whether we are processing your Personal Data or not. If this is the case, you can access your Personal Data and obtain information such as the purpose of the processing, the categories of personal data concerned, etc.
The right to obtain from us the rectification of inaccurate Personal Data concerning you.
The right to obtain the erasure of your Personal Data, insofar as one of the reasons justifying this right applies to your situation.
The right to obtain the restriction of the Processing, where one of the grounds justifying the exercise of this right applies to your situation.
Object to data processing based on specific situations.
Receive data in a portable format.
Define directives for data after death.
To exercise these rights, contact: [email protected].
We will respond within one month, extendable by two months if necessary.
AMO Consultancy Services Ltd is the data controller for the personal data described in this policy. We are registered with the Information Commissioner’s Office under registration reference ZB024260.
Only authorized individuals and trusted service providers may access personal data as necessary. We ensure confidentiality and security through contracts and regular reviews.
We make every effort to ensure that the number of such individuals is kept as small as possible and to maintain the confidentiality and security of your Personal Data.
In this regard, we share with them only the information they need to provide the service and we ask them not to use your Personal Data for any other purpose. We always make our best efforts to ensure that all our trusted service providers with whom we work, maintain the confidentiality and security of your Personal Data. We also ensure that when our relationship with a trusted service provider comes to an end, that service provider deletes your Personal Data without delay.
We select our trusted service providers with great care, ensuring that they provide sufficient guarantees, including expertise, reliability and resources, to implement the technical and organizational measures to meet the requirements of applicable legislation, including security of processing. In this regard, we ensure that our trusted service providers process Personal Data only on our documented instructions. We also ensure that their personnel are committed to confidentiality or are subject to an appropriate legal obligation of confidentiality.
Internally, your personal data can only be accessed by the HR department or any other departments having a strict need to know. This access is under strict review by our Data Privacy Officer in order to ensure the Group’s compliance with applicable laws.
We engage carefully selected third-party partners and service providers who process personal data on our behalf in compliance with GDPR. From time to time, we appoint digital marketing agencies to conduct outreach and marketing activities on our behalf. As part of these activities, personal data may be processed in accordance with applicable data protection laws. Our appointed data processors include:
Lemlist SAS: Lemlist provides the platform we use to manage and send our business outreach communications. You can view their privacy policy at lemlist.com/privacy.
HubSpot, Inc.: 2 Canal Park, Cambridge, MA 02141, USA. HubSpot provides the customer relationship management platform on which we hold client and prospect records. You can view their privacy policy at legal.hubspot.com/privacy-policy.
Personal data is primarily stored within the United Kingdom and the European Economic Area.
Some of our service providers, including those listed under Data Access and Sharing, are based outside the UK and the EEA. Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place, such as an adequacy decision or the International Data Transfer Agreement or UK Addendum to the European Commission’s Standard Contractual Clauses.
We implement appropriate technical and organizational measures to protect data, including access controls, authentication processes, and regular policy reviews.
Cookies collect information about your activities on our website. You can manage cookies through your browser settings. We use Google Analytics for anonymized traffic data.
You can turn off cookies at any time in your browser settings, but some parts of the site may not work as well if you do.
Our website may contain links to third-party websites and social media platforms. We encourage you to review their privacy policies.
This policy is regularly reviewed and may be amended by the Directors to ensure ongoing viability, applicability, and legal compliance.