Skip to content
placr

Privacy / Version 2.0

Privacy Notice

A precise account of who controls recruitment data, what Placr processes, and where responsibility sits.

Last updated
02 Aug 2026
Effective
02 Aug 2026
Document
v2.0

01 / Recruitment records

The recruiting organisation controls them

Your recruiter or hiring organisation normally decides why candidate information is used, who receives it, and how long it is retained.

02 / Placr's processing

We operate on documented instructions

Placr provides the software and ordinarily processes Customer-controlled recruitment information as a processor or service provider.

03 / Placr's business data

We control our own operations

Placr is responsible for account administration, billing, security, support, enquiries, and consent-based website measurement.

On this page

Recruitment involves personal information, often from more than one source and for more than one organisation. This Notice makes that chain visible: Placr provides the platform, while each recruiting Customer normally controls the candidate relationship and the decisions made with candidate data.

This Notice describes Placr's handling of personal information. It is not a substitute for the recruiting organisation's notice and does not change responsibilities imposed by applicable law or the data-processing terms agreed with a Customer.

Scope and who is responsible

This notice separates Placr's own use of information from recruitment processing controlled by Customers.

This Privacy Notice explains how personal information is handled when you visit useplacr.com, communicate with Placr, use a Placr account or workspace, connect a service, or interact with a Placr-hosted careers page, portal, application form, or other public tool.

Placr is recruitment software used by recruitment agencies and hiring teams (each a “Customer”). When a Customer uses Placr to source, store, assess, communicate with, shortlist, introduce, or place candidates, that Customer normally determines why and how the information is used. The Customer is the controller or business and Placr ordinarily acts for it as a processor or service provider.

Placr acts as controller for information used to run its own website and business, including account and contract administration, billing, service security, support, enquiries, and website measurement. The responsible Placr legal entity and notice address for a paid workspace are identified in the Customer's Order Form or other contracting document. You can contact Placr at[email protected].

Two notices may apply

If you are a candidate, worker, referee, client contact, or applicant, read the recruiting organisation's privacy notice as well as this one. Its notice should explain its purposes, lawful bases, recipients, retention, and contact details. Placr cannot replace that Customer notice.

Controller and processor role map

Responsibility follows the party deciding the purpose and essential means of each activity.

Activity
Customer recruitment records
Who decides
The recruitment agency or hiring organisation
Placr's usual role
Processor or service provider acting on documented instructions
Activity
Public job application
Who decides
The organisation advertising the role
Placr's usual role
Processor for intake and hosting; controller for Placr's own security records
Activity
Candidate disclosure to a client
Who decides
The Customer selecting the recipient and purpose
Placr's usual role
Processor carrying out the Customer's sharing instruction
Activity
Placr accounts, billing, security, and support
Who decides
Placr
Placr's usual role
Controller
Activity
Customer-selected integration
Who decides
The Customer and the connected provider under their arrangements
Placr's usual role
Processor when transmitting Customer Data as configured

Roles can differ for a particular feature, Customer, or law. The applicable data-processing agreement and Order Form control the contractual allocation for a paid workspace. If Placr is legally required to use information independently of a Customer's instructions, Placr acts as controller for that limited use and will comply with the law that applies to it.

Information we handle

The categories depend on how you interact with Placr and which features a Customer enables.

  • Account and business information: name, work contact details, employer, role, workspace, preferences, authentication information, permissions, and account activity.
  • Candidate and application information: CVs and documents, contact details, location, employment and education history, skills, qualifications, compensation or work preferences, right-to-work information, applications, interview details, availability, recruiter notes, assessments, communications, references, offers, placements, and status history.
  • Client and operational information: client contacts, roles, requirements, submissions, feedback, offers, placements, commercial records, tasks, reports, and workflow data entered by Customers.
  • Communications and connected content: email, calendar, messages, calls, meeting metadata, audio, transcripts, notes, attachments, and content received from a connected service when the Customer enables the relevant feature.
  • Technical and security information: IP address, device and browser information, session and cookie identifiers, timestamps, request and event logs, approximate location derived from IP, diagnostic data, and suspected abuse or security events.
  • Commercial and support information: plan, invoices, payment status, tax and billing details, demo requests, correspondence, support tickets, feedback, and survey responses. Payment card details are ordinarily handled by the payment provider rather than stored in full by Placr.

Customer Data may include sensitive or special-category information if a Customer chooses to collect it, such as health, disability, diversity-monitoring, criminal-record, national-identifier, immigration, or right-to-work information. Customers are responsible for ensuring that such collection is necessary, proportionate, clearly disclosed, legally permitted, access-restricted, and subject to any additional condition or safeguard the law requires.

Where information comes from

Information can come from you, a Customer, a connected service, or activity on the platform.

Depending on the relationship, Placr receives information:

  • directly from you when you apply, create an account, upload a document, communicate, request a demo, provide support information, or set preferences;
  • from a recruiting Customer, its Authorised Users, clients, referees, candidates, or workers as part of the Customer's recruitment activities;
  • from Customer-selected job boards, email and calendar accounts, communications tools, file imports, APIs, and other connected services;
  • from public or professional sources selected by the Customer, such as company websites or professional profiles, where the Customer is permitted to use the information; and
  • automatically from browsers, devices, cookies, logs, and use of the Service.

Where a Customer obtained information indirectly, the Customer is responsible for telling you the source and providing any notice required by law. Placr does not independently verify that Customer-supplied data is accurate, complete, or lawfully sourced.

Placr's purposes and legal grounds

This matrix applies when Placr uses information as controller for its own business operations.

Where applicable law uses the legal-basis concepts below, Placr relies on the ground shown. The precise ground can vary by context and jurisdiction. Where we rely on legitimate interests, we consider necessity, proportionality, and the impact on individuals. You may object as described in section 14.

Purpose
Provide accounts and contracted services
Information
Account, contact, workspace, support, and service activity
Usual ground
Contract performance or steps requested before a contract
Purpose
Authenticate users and protect the Service
Information
Account, device, session, log, and security-event data
Usual ground
Legitimate interests in security, fraud prevention, and service integrity; legal obligation where applicable
Purpose
Billing, tax, and financial administration
Information
Business contact, subscription, invoice, payment-status, and tax data
Usual ground
Contract performance and legal obligation
Purpose
Respond to enquiries and support
Information
Contact details, correspondence, diagnostics, and relevant account data
Usual ground
Contract performance, requested pre-contract steps, and legitimate interests in customer service
Purpose
Operate and improve Placr
Information
Feature usage, diagnostics, feedback, and aggregated or de-identified patterns
Usual ground
Legitimate interests in reliable, useful product operation
Purpose
Optional website measurement
Information
Consent-enabled cookie identifiers, pages, events, device, and approximate location
Usual ground
Consent where required
Purpose
Business communications
Information
Business contact, preferences, relationship, and engagement data
Usual ground
Consent or legitimate interests where electronic-marketing law permits
Purpose
Compliance, claims, and corporate transactions
Information
Information relevant to the legal, audit, dispute, or transaction need
Usual ground
Legal obligation and legitimate interests in establishing rights and operating the business

Where consent is the ground, you may withdraw it at any time without affecting processing that was lawful before withdrawal. Where information is required for an account, contract, security control, or legal obligation, we will explain the practical consequence if you do not provide it.

Customer-controlled recruitment processing

The Customer defines the purpose, legal basis, recipients, retention, and recruitment process.

When Placr acts as processor or service provider, the Customer's instructions — including its use and configuration of features — determine how Placr handles Customer Data. The Customer is responsible for its lawful basis or permission, notices, fairness, data minimisation, accuracy, rights handling, retention, disclosure, and compliance with recruitment, employment, equality, communications, and data-protection laws. Placr's DPA governs Placr's processor obligations for a paid workspace.

If you want to understand why your recruitment record exists, why you were contacted, which hiring clients received it, whether you are in a talent pool, or how long the record will be kept, contact the recruiting organisation first. It has the relationship and authority needed to answer those questions and act on the record. Placr will assist it as required by the DPA and applicable law.

Public applications and CV uploads

An unconfirmed CV is staged briefly; confirmation creates a Customer-controlled recruitment record.

If you upload a CV through a Placr-hosted careers page, Placr temporarily processes the file to validate it, check it for supported security conditions, extract relevant text, and pre-fill application details for you to review. The recruiting organisation cannot access the staged CV or extracted details through Placr until you confirm the application.

An unconfirmed upload expires after 24 hours and is removed through an automated cleanup process. When you confirm, the CV and submitted details are disclosed to the recruiting organisation, a candidate and application record are created, and that organisation's privacy notice and retention policy apply. The application page identifies the recruiting controller and provides its notice details where configured.

CV extraction is intended to reduce form filling. Review pre-filled details before confirming. If you do not want your CV read automatically, use a manual route offered by the recruiting organisation or contact it directly. Withdrawing an application does not always require immediate deletion where the controller has another lawful reason to retain limited information; the recruiting organisation must explain its position.

AI-assisted processing

AI helps organise and surface information; people remain responsible for consequential decisions.

Placr includes tools that may extract CV data, generate summaries or drafts, support search, identify potential candidate-to-role matches, structure notes, and assist other recruitment workflows. These tools can make mistakes, omit context, or reflect limitations in source data and models. Their outputs are suggestions for human review, not verified facts or a determination that a person should be hired or rejected.

Where a feature requires it, relevant content may be sent to contracted AI, transcription, or embedding providers acting under service restrictions. Placr aims to limit content to what is reasonably needed for the task and applies technical, contractual, and access controls appropriate to its role. Provider and transfer arrangements for a paid workspace are governed by the applicable DPA.

Placr does not make the Customer's final hiring or employment decision and does not authorise Customers to use AI output as the sole basis for a decision with legal or similarly significant effects unless the use is expressly lawful and all required safeguards are in place. The Customer is responsible for notices, impact assessments, bias and accuracy review, human oversight, explanation, contestability, and its actual decision. Ask the recruiting organisation if you want information about AI in its process.

Communications, meetings, and recordings

Customers decide when communication and recording features are used and must notify participants.

Customers may connect communication channels or enable features for email, calendar events, messages, calls, meetings, notes, audio, or transcription. The Customer determines the business purpose, participants, channel, and whether recording or transcription is appropriate. It is responsible for giving any required notice and obtaining consent or other authority under the laws that apply to the participants and location.

Placr processes enabled communication content to provide the requested feature and may derive transcripts, speaker labels, summaries, action items, or links to recruitment records. Placr does not use ordinary meeting audio to identify a person through a reusable biometric voiceprint. Any future biometric identification feature would require separate assessment, safeguards, and clear notice before activation.

Recipients and service providers

Information is disclosed only for service delivery, Customer instructions, business operations, or law.

Depending on the activity, recipients may include:

  • the relevant Customer workspace, its Authorised Users, and hiring clients or other recipients the Customer chooses and authorises;
  • providers supporting cloud hosting, databases, storage, security, authentication, file scanning, email, communications, AI, transcription, embeddings, analytics, bot prevention, support, billing, and product operations;
  • Customer-selected connected services, job boards, email or calendar providers, communications tools, and integrations as configured by the Customer;
  • Placr affiliates and personnel who need access for their role and are subject to confidentiality duties;
  • auditors, insurers, banks, lawyers, accountants, investors, and professional advisers under appropriate duties; and
  • a potential buyer, investor, successor, court, regulator, law-enforcement body, or other competent authority where disclosure is reasonably necessary and lawful.

Placr does not sell personal information and does not use Customer Data for third-party behavioural advertising. Service providers may process information only for authorised services and under the contractual and legal restrictions applicable to their role.

Customer-selected recipients and downstream use

The Customer, not Placr, chooses business recipients for candidate information.

When a recruiter shares a candidate

A Customer instruction to share, publish, export, download, email, or transmit candidate information is an instruction to Placr to carry out that disclosure. The Customer determines the recipient, purpose, lawful basis, content, access period, and any confidentiality or candidate restriction.

Once the Customer exports information or discloses it to a Customer-selected recipient, that recipient's storage, use, onward sharing, and retention are controlled by the Customer's arrangements and applicable law, not this Notice. Placr provides platform access controls where the relevant feature supports them, but cannot control copies made outside Placr, forwarding by the Customer or recipient, incorrect recipient details, or a recipient's independent conduct.

Contact the recruiting organisation to ask who received your information, to object to a proposed disclosure, or to request revocation. Placr will support the Customer's lawful instructions and remains responsible for its own security and processor obligations; this allocation does not excuse a breach by Placr of duties that apply directly to it.

International processing and transfers

Information may be processed in other countries, with safeguards where transfer law requires them.

Placr, Customers, recipients, and service providers may process information in countries other than the one where it was collected. Those countries may have different data-protection laws. Placr applies the transfer arrangements required for transfers for which Placr is responsible, which may include an adequacy decision, approved contractual clauses or addenda, a transfer assessment, supplementary security measures, or another lawful mechanism.

For Customer-controlled recruitment processing, the applicable Order Form and DPA describe the contractual arrangements for Placr and its subprocessors. A Customer remains responsible for its own transfers, including disclosures to overseas clients, Customer-selected providers, connected services, and recipients outside Placr. Contact the Customer for its transfer details or Placr for information about safeguards applicable to Placr's controller processing.

Retention and deletion

Retention follows the purpose, Customer instructions, legal requirements, disputes, and secure lifecycles.

Record
Unconfirmed public CV upload
Usual retention approach
Expires after 24 hours and is removed through automated cleanup
Who controls it
Placr operates the staging lifecycle
Record
Confirmed candidate and application record
Usual retention approach
Customer-configured policy, documented instructions, and applicable legal holds
Who controls it
Recruiting Customer
Record
Workspace and account information
Usual retention approach
Subscription lifecycle, agreed return period, closure, security, and legal requirements
Who controls it
Placr for its account records; Customer for workspace content
Record
Billing and tax records
Usual retention approach
The period required by finance, tax, audit, and claims law
Who controls it
Placr
Record
Security, access, and audit records
Usual retention approach
A proportionate period based on incident detection, integrity, dispute, and legal needs
Who controls it
Placr for platform records; Customer for its exported records
Record
Demo, enquiry, and marketing records
Usual retention approach
Until no longer needed for the relationship, consent is withdrawn, or an objection applies, subject to limited suppression records
Who controls it
Placr

Placr keeps personal information only for as long as reasonably needed for the purpose, Customer's documented instructions, service security and integrity, dispute handling, and applicable law. Customers can configure candidate retention and use supported export, restriction, withdrawal, and anonymisation tools. The Customer is responsible for selecting and operating a lawful retention policy.

Deletion from active systems may not immediately remove restricted backup copies, immutable security records, or information subject to a lawful legal hold. Those copies remain protected, are not returned to ordinary use, and are deleted or overwritten under the applicable lifecycle unless law requires longer retention. Placr may preserve minimal suppression data needed to respect an opt-out or prevent re-contact.

Your choices and rights

Rights depend on applicable law and on whether Placr or a Customer controls the record.

Depending on the applicable law and circumstances, you may have rights to receive information, access and obtain a copy, correct, delete, restrict or object to processing, request portability, withdraw consent, opt out of certain communications, and ask for safeguards relating to significant automated decisions. Some rights are subject to legal conditions, exemptions, identity verification, other people's rights, legal holds, or overriding lawful grounds.

  • For recruitment records: contact the recruitment agency or hiring organisation first. It is normally the controller and can identify the record, purpose, recipients, and applicable retention.
  • For Placr account, website, support, or business information: email[email protected].
  • For marketing: use the unsubscribe method in the message or contact Placr. A minimal suppression record may be kept so the preference can be honoured.

We may request information reasonably needed to verify identity and authority and may route a request to the relevant Customer. Placr will assist Customers with processor-held information as required by contract and law. You may complain to the competent data-protection regulator in the country or region that applies to you, and we encourage you to contact the relevant controller first so it can address the concern.

Cookies and website measurement

Essential storage keeps the site secure; optional analytics remains off until enabled.

Placr uses essential cookies or similar storage for security, authentication, session continuity, load and abuse protection, and saving privacy choices. These are necessary for the relevant function. We also use Google Analytics for website and careers-page measurement. Analytics storage is denied by default and is enabled only through the cookie controls where consent is required. Placr does not enable advertising storage or personalised advertising through those controls.

Separately from cookie-based analytics, Placr keeps an aggregate count of how many people view each job advert on a careers page and how many begin an application, so the recruiter advertising the role can tell whether it is reaching candidates. This measurement uses no cookies and does not identify you. To avoid counting the same visit repeatedly, Placr derives a one-way, keyed digest from your IP address and browser user-agent; the key changes every day, so the digest cannot be linked back to you, matched to an application, or followed from one day to the next. Only the digest, the referring website’s domain name, and the time are stored, and those records are deleted on a rolling retention schedule. This is done on the basis of legitimate interests in understanding whether a job advert is working.

You can accept or reject optional analytics and revisit your choice through the cookie-preferences control in the site footer. Browser settings can also restrict storage, although blocking essential storage may prevent sign-in or other functions. Customer-connected websites and third-party services may use their own technologies under their own notices.

Security

Placr uses layered safeguards, but no connected system can promise zero risk.

Placr uses technical and organisational measures designed to protect personal information appropriate to the nature of the Service and Placr's role. Measures include encrypted transport for public traffic, access and tenant authorisation controls, private document access, protection for selected sensitive fields, security logging, rate limiting, and checks around public file intake. Access is limited according to role and operational need.

No system is completely secure. Customers also control important safeguards, including their users, devices, identity and email accounts, permissions, integrations, recipient details, exports, and onward disclosures. Please report suspected misuse or a security concern promptly. More information is available on the Security page.

Children, changes, and contact

The Service is business recruitment software; material notice changes receive an appropriate update.

Placr's website and business accounts are not directed to children. A Customer may recruit young workers or receive an application from a minor only where lawful. That Customer is responsible for age-appropriate notices, permissions, safeguards, and any parental or guardian involvement required by the applicable law. Do not submit a child's information through Placr unless the recruiting organisation has lawfully requested it and explained the processing.

We may update this Notice when the Service, providers, processing, or legal requirements change. We will post the revised date and use an appropriate additional notice for material changes where required. Earlier versions and Customer-specific terms may remain relevant to earlier processing or a signed agreement.

Privacy contact

Email[email protected]for privacy questions or rights requests. For a paid workspace, the responsible Placr legal entity and notice address are stated in the Order Form. For recruitment records, also contact the recruiting organisation identified on the application page, portal, message, or its own privacy notice.

End of Privacy Notice · Version 2.0

Back to top ↑

Ready to put people first?

See how Placr gives your recruiters, candidates, and clients the experience they deserve.