Recruitment involves personal information, often from more than one source and for more than one organisation. This Notice makes that chain visible: Placr provides the platform, while each recruiting Customer normally controls the candidate relationship and the decisions made with candidate data.
This Notice describes Placr's handling of personal information. It is not a substitute for the recruiting organisation's notice and does not change responsibilities imposed by applicable law or the data-processing terms agreed with a Customer.
Scope and who is responsible
This notice separates Placr's own use of information from recruitment processing controlled by Customers.
This Privacy Notice explains how personal information is handled when you visit useplacr.com, communicate with Placr, use a Placr account or workspace, connect a service, or interact with a Placr-hosted careers page, portal, application form, or other public tool.
Placr is recruitment software used by recruitment agencies and hiring teams (each a “Customer”). When a Customer uses Placr to source, store, assess, communicate with, shortlist, introduce, or place candidates, that Customer normally determines why and how the information is used. The Customer is the controller or business and Placr ordinarily acts for it as a processor or service provider.
Placr acts as controller for information used to run its own website and business, including account and contract administration, billing, service security, support, enquiries, and website measurement. The responsible Placr legal entity and notice address for a paid workspace are identified in the Customer's Order Form or other contracting document. You can contact Placr at[email protected].
Two notices may apply
If you are a candidate, worker, referee, client contact, or applicant, read the recruiting organisation's privacy notice as well as this one. Its notice should explain its purposes, lawful bases, recipients, retention, and contact details. Placr cannot replace that Customer notice.
Controller and processor role map
Responsibility follows the party deciding the purpose and essential means of each activity.
- Activity
- Customer recruitment records
- Who decides
- The recruitment agency or hiring organisation
- Placr's usual role
- Processor or service provider acting on documented instructions
- Activity
- Public job application
- Who decides
- The organisation advertising the role
- Placr's usual role
- Processor for intake and hosting; controller for Placr's own security records
- Activity
- Candidate disclosure to a client
- Who decides
- The Customer selecting the recipient and purpose
- Placr's usual role
- Processor carrying out the Customer's sharing instruction
- Activity
- Placr accounts, billing, security, and support
- Who decides
- Placr
- Placr's usual role
- Controller
- Activity
- Customer-selected integration
- Who decides
- The Customer and the connected provider under their arrangements
- Placr's usual role
- Processor when transmitting Customer Data as configured
| Activity | Who decides | Placr's usual role |
|---|---|---|
| Customer recruitment records | The recruitment agency or hiring organisation | Processor or service provider acting on documented instructions |
| Public job application | The organisation advertising the role | Processor for intake and hosting; controller for Placr's own security records |
| Candidate disclosure to a client | The Customer selecting the recipient and purpose | Processor carrying out the Customer's sharing instruction |
| Placr accounts, billing, security, and support | Placr | Controller |
| Customer-selected integration | The Customer and the connected provider under their arrangements | Processor when transmitting Customer Data as configured |
Roles can differ for a particular feature, Customer, or law. The applicable data-processing agreement and Order Form control the contractual allocation for a paid workspace. If Placr is legally required to use information independently of a Customer's instructions, Placr acts as controller for that limited use and will comply with the law that applies to it.
Information we handle
The categories depend on how you interact with Placr and which features a Customer enables.
- Account and business information: name, work contact details, employer, role, workspace, preferences, authentication information, permissions, and account activity.
- Candidate and application information: CVs and documents, contact details, location, employment and education history, skills, qualifications, compensation or work preferences, right-to-work information, applications, interview details, availability, recruiter notes, assessments, communications, references, offers, placements, and status history.
- Client and operational information: client contacts, roles, requirements, submissions, feedback, offers, placements, commercial records, tasks, reports, and workflow data entered by Customers.
- Communications and connected content: email, calendar, messages, calls, meeting metadata, audio, transcripts, notes, attachments, and content received from a connected service when the Customer enables the relevant feature.
- Technical and security information: IP address, device and browser information, session and cookie identifiers, timestamps, request and event logs, approximate location derived from IP, diagnostic data, and suspected abuse or security events.
- Commercial and support information: plan, invoices, payment status, tax and billing details, demo requests, correspondence, support tickets, feedback, and survey responses. Payment card details are ordinarily handled by the payment provider rather than stored in full by Placr.
Customer Data may include sensitive or special-category information if a Customer chooses to collect it, such as health, disability, diversity-monitoring, criminal-record, national-identifier, immigration, or right-to-work information. Customers are responsible for ensuring that such collection is necessary, proportionate, clearly disclosed, legally permitted, access-restricted, and subject to any additional condition or safeguard the law requires.
Where information comes from
Information can come from you, a Customer, a connected service, or activity on the platform.
Depending on the relationship, Placr receives information:
- directly from you when you apply, create an account, upload a document, communicate, request a demo, provide support information, or set preferences;
- from a recruiting Customer, its Authorised Users, clients, referees, candidates, or workers as part of the Customer's recruitment activities;
- from Customer-selected job boards, email and calendar accounts, communications tools, file imports, APIs, and other connected services;
- from public or professional sources selected by the Customer, such as company websites or professional profiles, where the Customer is permitted to use the information; and
- automatically from browsers, devices, cookies, logs, and use of the Service.
Where a Customer obtained information indirectly, the Customer is responsible for telling you the source and providing any notice required by law. Placr does not independently verify that Customer-supplied data is accurate, complete, or lawfully sourced.
Placr's purposes and legal grounds
This matrix applies when Placr uses information as controller for its own business operations.
Where applicable law uses the legal-basis concepts below, Placr relies on the ground shown. The precise ground can vary by context and jurisdiction. Where we rely on legitimate interests, we consider necessity, proportionality, and the impact on individuals. You may object as described in section 14.
- Purpose
- Provide accounts and contracted services
- Information
- Account, contact, workspace, support, and service activity
- Usual ground
- Contract performance or steps requested before a contract
- Purpose
- Authenticate users and protect the Service
- Information
- Account, device, session, log, and security-event data
- Usual ground
- Legitimate interests in security, fraud prevention, and service integrity; legal obligation where applicable
- Purpose
- Billing, tax, and financial administration
- Information
- Business contact, subscription, invoice, payment-status, and tax data
- Usual ground
- Contract performance and legal obligation
- Purpose
- Respond to enquiries and support
- Information
- Contact details, correspondence, diagnostics, and relevant account data
- Usual ground
- Contract performance, requested pre-contract steps, and legitimate interests in customer service
- Purpose
- Operate and improve Placr
- Information
- Feature usage, diagnostics, feedback, and aggregated or de-identified patterns
- Usual ground
- Legitimate interests in reliable, useful product operation
- Purpose
- Optional website measurement
- Information
- Consent-enabled cookie identifiers, pages, events, device, and approximate location
- Usual ground
- Consent where required
- Purpose
- Business communications
- Information
- Business contact, preferences, relationship, and engagement data
- Usual ground
- Consent or legitimate interests where electronic-marketing law permits
- Purpose
- Compliance, claims, and corporate transactions
- Information
- Information relevant to the legal, audit, dispute, or transaction need
- Usual ground
- Legal obligation and legitimate interests in establishing rights and operating the business
| Purpose | Information | Usual ground |
|---|---|---|
| Provide accounts and contracted services | Account, contact, workspace, support, and service activity | Contract performance or steps requested before a contract |
| Authenticate users and protect the Service | Account, device, session, log, and security-event data | Legitimate interests in security, fraud prevention, and service integrity; legal obligation where applicable |
| Billing, tax, and financial administration | Business contact, subscription, invoice, payment-status, and tax data | Contract performance and legal obligation |
| Respond to enquiries and support | Contact details, correspondence, diagnostics, and relevant account data | Contract performance, requested pre-contract steps, and legitimate interests in customer service |
| Operate and improve Placr | Feature usage, diagnostics, feedback, and aggregated or de-identified patterns | Legitimate interests in reliable, useful product operation |
| Optional website measurement | Consent-enabled cookie identifiers, pages, events, device, and approximate location | Consent where required |
| Business communications | Business contact, preferences, relationship, and engagement data | Consent or legitimate interests where electronic-marketing law permits |
| Compliance, claims, and corporate transactions | Information relevant to the legal, audit, dispute, or transaction need | Legal obligation and legitimate interests in establishing rights and operating the business |
Where consent is the ground, you may withdraw it at any time without affecting processing that was lawful before withdrawal. Where information is required for an account, contract, security control, or legal obligation, we will explain the practical consequence if you do not provide it.
Customer-controlled recruitment processing
The Customer defines the purpose, legal basis, recipients, retention, and recruitment process.
When Placr acts as processor or service provider, the Customer's instructions — including its use and configuration of features — determine how Placr handles Customer Data. The Customer is responsible for its lawful basis or permission, notices, fairness, data minimisation, accuracy, rights handling, retention, disclosure, and compliance with recruitment, employment, equality, communications, and data-protection laws. Placr's DPA governs Placr's processor obligations for a paid workspace.
If you want to understand why your recruitment record exists, why you were contacted, which hiring clients received it, whether you are in a talent pool, or how long the record will be kept, contact the recruiting organisation first. It has the relationship and authority needed to answer those questions and act on the record. Placr will assist it as required by the DPA and applicable law.
Public applications and CV uploads
An unconfirmed CV is staged briefly; confirmation creates a Customer-controlled recruitment record.
If you upload a CV through a Placr-hosted careers page, Placr temporarily processes the file to validate it, check it for supported security conditions, extract relevant text, and pre-fill application details for you to review. The recruiting organisation cannot access the staged CV or extracted details through Placr until you confirm the application.
An unconfirmed upload expires after 24 hours and is removed through an automated cleanup process. When you confirm, the CV and submitted details are disclosed to the recruiting organisation, a candidate and application record are created, and that organisation's privacy notice and retention policy apply. The application page identifies the recruiting controller and provides its notice details where configured.
CV extraction is intended to reduce form filling. Review pre-filled details before confirming. If you do not want your CV read automatically, use a manual route offered by the recruiting organisation or contact it directly. Withdrawing an application does not always require immediate deletion where the controller has another lawful reason to retain limited information; the recruiting organisation must explain its position.
AI-assisted processing
AI helps organise and surface information; people remain responsible for consequential decisions.
Placr includes tools that may extract CV data, generate summaries or drafts, support search, identify potential candidate-to-role matches, structure notes, and assist other recruitment workflows. These tools can make mistakes, omit context, or reflect limitations in source data and models. Their outputs are suggestions for human review, not verified facts or a determination that a person should be hired or rejected.
Where a feature requires it, relevant content may be sent to contracted AI, transcription, or embedding providers acting under service restrictions. Placr aims to limit content to what is reasonably needed for the task and applies technical, contractual, and access controls appropriate to its role. Provider and transfer arrangements for a paid workspace are governed by the applicable DPA.
Placr does not make the Customer's final hiring or employment decision and does not authorise Customers to use AI output as the sole basis for a decision with legal or similarly significant effects unless the use is expressly lawful and all required safeguards are in place. The Customer is responsible for notices, impact assessments, bias and accuracy review, human oversight, explanation, contestability, and its actual decision. Ask the recruiting organisation if you want information about AI in its process.
Communications, meetings, and recordings
Customers decide when communication and recording features are used and must notify participants.
Customers may connect communication channels or enable features for email, calendar events, messages, calls, meetings, notes, audio, or transcription. The Customer determines the business purpose, participants, channel, and whether recording or transcription is appropriate. It is responsible for giving any required notice and obtaining consent or other authority under the laws that apply to the participants and location.
Placr processes enabled communication content to provide the requested feature and may derive transcripts, speaker labels, summaries, action items, or links to recruitment records. Placr does not use ordinary meeting audio to identify a person through a reusable biometric voiceprint. Any future biometric identification feature would require separate assessment, safeguards, and clear notice before activation.
Recipients and service providers
Information is disclosed only for service delivery, Customer instructions, business operations, or law.
Depending on the activity, recipients may include:
- the relevant Customer workspace, its Authorised Users, and hiring clients or other recipients the Customer chooses and authorises;
- providers supporting cloud hosting, databases, storage, security, authentication, file scanning, email, communications, AI, transcription, embeddings, analytics, bot prevention, support, billing, and product operations;
- Customer-selected connected services, job boards, email or calendar providers, communications tools, and integrations as configured by the Customer;
- Placr affiliates and personnel who need access for their role and are subject to confidentiality duties;
- auditors, insurers, banks, lawyers, accountants, investors, and professional advisers under appropriate duties; and
- a potential buyer, investor, successor, court, regulator, law-enforcement body, or other competent authority where disclosure is reasonably necessary and lawful.
Placr does not sell personal information and does not use Customer Data for third-party behavioural advertising. Service providers may process information only for authorised services and under the contractual and legal restrictions applicable to their role.
Customer-selected recipients and downstream use
The Customer, not Placr, chooses business recipients for candidate information.
When a recruiter shares a candidate
A Customer instruction to share, publish, export, download, email, or transmit candidate information is an instruction to Placr to carry out that disclosure. The Customer determines the recipient, purpose, lawful basis, content, access period, and any confidentiality or candidate restriction.
Once the Customer exports information or discloses it to a Customer-selected recipient, that recipient's storage, use, onward sharing, and retention are controlled by the Customer's arrangements and applicable law, not this Notice. Placr provides platform access controls where the relevant feature supports them, but cannot control copies made outside Placr, forwarding by the Customer or recipient, incorrect recipient details, or a recipient's independent conduct.
Contact the recruiting organisation to ask who received your information, to object to a proposed disclosure, or to request revocation. Placr will support the Customer's lawful instructions and remains responsible for its own security and processor obligations; this allocation does not excuse a breach by Placr of duties that apply directly to it.
International processing and transfers
Information may be processed in other countries, with safeguards where transfer law requires them.
Placr, Customers, recipients, and service providers may process information in countries other than the one where it was collected. Those countries may have different data-protection laws. Placr applies the transfer arrangements required for transfers for which Placr is responsible, which may include an adequacy decision, approved contractual clauses or addenda, a transfer assessment, supplementary security measures, or another lawful mechanism.
For Customer-controlled recruitment processing, the applicable Order Form and DPA describe the contractual arrangements for Placr and its subprocessors. A Customer remains responsible for its own transfers, including disclosures to overseas clients, Customer-selected providers, connected services, and recipients outside Placr. Contact the Customer for its transfer details or Placr for information about safeguards applicable to Placr's controller processing.
Retention and deletion
Retention follows the purpose, Customer instructions, legal requirements, disputes, and secure lifecycles.
- Record
- Unconfirmed public CV upload
- Usual retention approach
- Expires after 24 hours and is removed through automated cleanup
- Who controls it
- Placr operates the staging lifecycle
- Record
- Confirmed candidate and application record
- Usual retention approach
- Customer-configured policy, documented instructions, and applicable legal holds
- Who controls it
- Recruiting Customer
- Record
- Workspace and account information
- Usual retention approach
- Subscription lifecycle, agreed return period, closure, security, and legal requirements
- Who controls it
- Placr for its account records; Customer for workspace content
- Record
- Billing and tax records
- Usual retention approach
- The period required by finance, tax, audit, and claims law
- Who controls it
- Placr
- Record
- Security, access, and audit records
- Usual retention approach
- A proportionate period based on incident detection, integrity, dispute, and legal needs
- Who controls it
- Placr for platform records; Customer for its exported records
- Record
- Demo, enquiry, and marketing records
- Usual retention approach
- Until no longer needed for the relationship, consent is withdrawn, or an objection applies, subject to limited suppression records
- Who controls it
- Placr
| Record | Usual retention approach | Who controls it |
|---|---|---|
| Unconfirmed public CV upload | Expires after 24 hours and is removed through automated cleanup | Placr operates the staging lifecycle |
| Confirmed candidate and application record | Customer-configured policy, documented instructions, and applicable legal holds | Recruiting Customer |
| Workspace and account information | Subscription lifecycle, agreed return period, closure, security, and legal requirements | Placr for its account records; Customer for workspace content |
| Billing and tax records | The period required by finance, tax, audit, and claims law | Placr |
| Security, access, and audit records | A proportionate period based on incident detection, integrity, dispute, and legal needs | Placr for platform records; Customer for its exported records |
| Demo, enquiry, and marketing records | Until no longer needed for the relationship, consent is withdrawn, or an objection applies, subject to limited suppression records | Placr |
Placr keeps personal information only for as long as reasonably needed for the purpose, Customer's documented instructions, service security and integrity, dispute handling, and applicable law. Customers can configure candidate retention and use supported export, restriction, withdrawal, and anonymisation tools. The Customer is responsible for selecting and operating a lawful retention policy.
Deletion from active systems may not immediately remove restricted backup copies, immutable security records, or information subject to a lawful legal hold. Those copies remain protected, are not returned to ordinary use, and are deleted or overwritten under the applicable lifecycle unless law requires longer retention. Placr may preserve minimal suppression data needed to respect an opt-out or prevent re-contact.
Your choices and rights
Rights depend on applicable law and on whether Placr or a Customer controls the record.
Depending on the applicable law and circumstances, you may have rights to receive information, access and obtain a copy, correct, delete, restrict or object to processing, request portability, withdraw consent, opt out of certain communications, and ask for safeguards relating to significant automated decisions. Some rights are subject to legal conditions, exemptions, identity verification, other people's rights, legal holds, or overriding lawful grounds.
- For recruitment records: contact the recruitment agency or hiring organisation first. It is normally the controller and can identify the record, purpose, recipients, and applicable retention.
- For Placr account, website, support, or business information: email[email protected].
- For marketing: use the unsubscribe method in the message or contact Placr. A minimal suppression record may be kept so the preference can be honoured.
We may request information reasonably needed to verify identity and authority and may route a request to the relevant Customer. Placr will assist Customers with processor-held information as required by contract and law. You may complain to the competent data-protection regulator in the country or region that applies to you, and we encourage you to contact the relevant controller first so it can address the concern.
Security
Placr uses layered safeguards, but no connected system can promise zero risk.
Placr uses technical and organisational measures designed to protect personal information appropriate to the nature of the Service and Placr's role. Measures include encrypted transport for public traffic, access and tenant authorisation controls, private document access, protection for selected sensitive fields, security logging, rate limiting, and checks around public file intake. Access is limited according to role and operational need.
No system is completely secure. Customers also control important safeguards, including their users, devices, identity and email accounts, permissions, integrations, recipient details, exports, and onward disclosures. Please report suspected misuse or a security concern promptly. More information is available on the Security page.
Children, changes, and contact
The Service is business recruitment software; material notice changes receive an appropriate update.
Placr's website and business accounts are not directed to children. A Customer may recruit young workers or receive an application from a minor only where lawful. That Customer is responsible for age-appropriate notices, permissions, safeguards, and any parental or guardian involvement required by the applicable law. Do not submit a child's information through Placr unless the recruiting organisation has lawfully requested it and explained the processing.
We may update this Notice when the Service, providers, processing, or legal requirements change. We will post the revised date and use an appropriate additional notice for material changes where required. Earlier versions and Customer-specific terms may remain relevant to earlier processing or a signed agreement.
Privacy contact
Email[email protected]for privacy questions or rights requests. For a paid workspace, the responsible Placr legal entity and notice address are stated in the Order Form. For recruitment records, also contact the recruiting organisation identified on the application page, portal, message, or its own privacy notice.
End of Privacy Notice · Version 2.0
Back to top ↑