Privacy Policy

Last updated: 23 June 2026

This Privacy Policy explains how Priovera ("Priovera", "we", "us", "our") handles personal data when you visit our website, request access to the Design Partner programme, or use the Priovera service. It is written to reflect UK data protection law, in particular the UK GDPR and the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR) for cookies and marketing.

This page is maintained by Priovera as app-owned editable content and is not an independent certification or legal advice.

1. Who we are

Priovera is a hiring decision-support service operated from the United Kingdom. Our registered legal entity, company number, and registered office address will be confirmed here before general availability. For any privacy enquiry in the meantime, please use the contact details in section 12.

2. Controller and processor roles

  • When you visit our website, contact us, or join the Design Partner waitlist, Priovera is the data controller for the limited personal data you provide to us.
  • When a hiring organisation uses Priovera to evaluate candidates, that hiring organisation is the data controller for the candidate and employee personal data they upload. Priovera acts as a data processor on their documented instructions, under a written data processing agreement that meets Article 28 UK GDPR.

3. Personal data we process

3.1 Website and waitlist (we are the controller)

  • Contact details you submit: name, work email, organisation, role.
  • Messages and enquiries you send us.
  • Limited technical data such as IP address, device and browser data, and pages visited, used for security and to operate the site.

3.2 Customer use of the service (the customer is the controller)

  • Hiring-team account data: name, work email, organisation, role.
  • Job descriptions and Hiring Blueprints uploaded by the customer.
  • Candidate application materials provided by the customer, such as CVs and answers to screening questions.
  • Reviewer activity, comments, and audit records.

4. Lawful bases for processing

Where Priovera is the controller, we rely on the following lawful bases under Article 6 UK GDPR:

  • Legitimate interests for operating and securing our website, responding to enquiries, and managing the Design Partner programme. You can object at any time.
  • Consent for non-essential cookies and any direct marketing emails, in line with PECR. You can withdraw consent at any time.
  • Legal obligation where we need to retain records to comply with UK law.

When Priovera acts as a processor for a customer, the lawful basis for processing candidate data is determined by the customer as controller. Customers are expected to rely on legitimate interests for recruitment activity or another appropriate basis, and to provide candidates with a recruitment privacy notice covering the use of Priovera.

5. How we use personal data

We process personal data to: operate and secure the Priovera service; structure job descriptions; generate Hiring Blueprints; evaluate applications against the customer's Hiring Blueprint; surface prioritised review queues; maintain a full audit trail of decisions; respond to enquiries; and run the Design Partner programme.

6. No solely automated decisions about candidates

Priovera is a decision-support tool. It surfaces evidence and a recommendation, but does not make hiring decisions and does not auto-reject candidates. Hiring decisions are made by the customer's human reviewers, so processing through Priovera is not intended to produce a decision based solely on automated processing within the meaning of Article 22 UK GDPR.

7. Sharing and subprocessors

We do not sell personal data. We share personal data only with vetted subprocessors that help us run the service, for example our cloud hosting, database, email delivery, and AI inference providers. A current list of subprocessors, the hosting regions, and the safeguards for any international transfers will be published here. Customers can request the current subprocessor list at any time using the contact details in section 12.

8. International data transfers

Where personal data is transferred outside the UK, we rely on a valid transfer mechanism under the UK GDPR, such as UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate supplementary measures where required. Specific transfer details for each subprocessor will be documented in our subprocessor list.

9. Retention

We keep personal data only for as long as needed for the purposes set out above. For customer data processed through the service, each hiring organisation configures a default candidate-data retention window (for example 30, 60, 90, or 180 days, or manual deletion only) and Priovera deletes or anonymises candidate records accordingly. Account and audit records are retained for the lifetime of the customer organisation, then deleted on instruction or within a reasonable period after the contract ends, subject to any legal retention requirements.

10. Security

We implement appropriate technical and organisational measures designed to protect personal data, including encryption in transit, access controls, environment separation, and logging. No system is fully secure, and security is a shared responsibility with customers who control their own accounts, role assignments, and data they upload.

11. Your rights

Under UK GDPR you have rights to access, rectification, erasure, restriction, objection, and data portability, and the right not to be subject to a decision based solely on automated processing where it produces legal or similarly significant effects.

If you are a candidate whose application is being processed through Priovera, please contact the hiring organisation you applied to in the first instance, as they are the controller of your application data. We will support customers in responding to your request.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint.

12. Cookies and analytics

We use strictly necessary cookies to operate the site. Any non-essential cookies or similar technologies, such as analytics, will be set only with your consent in line with PECR. Where we offer a cookie banner, you can change your choice at any time using the controls provided.

13. Contact

For privacy questions, data-subject requests, or our current subprocessor list, email privacy@priovera.io. A named Data Protection Officer or UK representative will be appointed and published here where required.

14. Changes

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent change. Material changes will be communicated to active customers in advance where practicable.