RysUp ("we", "us") provides HR advisory and recruitment support services to businesses. This policy explains what personal data we collect, why, and how we handle it, in line with UK GDPR and the Data Protection Act 2018.
When you enquire about or use our services, we may collect: your name and contact details, your business's name and size, and - where you become a client - HR-related data about your employees necessary to provide advice (e.g. names, roles, dates relevant to contracts, disciplinary or absence matters). For recruitment support, this may also include candidate details such as CVs, application materials, and interview notes.
We also collect basic technical information automatically when you visit our website, such as your browser type and general location, to keep the site secure and understand how it's used.
To respond to enquiries, deliver the HR advisory or recruitment service you've engaged us for, produce documents and advice on your behalf, and meet our own legal and contractual obligations.
Our website does not currently use tracking cookies or third-party analytics. If this changes in future, we'll update this policy and, where required, ask for your consent first.
Where we process personal data about your employees or job candidates on your behalf, we act as a data processor and you remain the data controller. We only use that data to deliver the services you've instructed, and do not use it for any other purpose.
Data is stored digitally using reputable, access-controlled business tools (such as encrypted cloud storage and email), and is not kept in physical form beyond what's needed for a short working period. We limit access to the two of us, and take reasonable technical and organisational measures to protect data against unauthorised access, loss, or misuse.
In the unlikely event of a data breach that risks your rights or freedoms, we'll notify the Information Commissioner's Office and any affected individuals in line with our legal obligations under UK GDPR.
Clients with portal access can store employee records, org hierarchy, CPD and training logs, absence and disciplinary history, documents, and key compliance dates within the portal. This is generally more detailed and more current than the data we hold for advisory purposes alone, since it's built and maintained directly by you.
Portal accounts are protected by login credentials specific to your business. You're responsible for keeping these secure and for controlling which of your own staff have access - we recommend only giving portal access to people who genuinely need it. We log access to the portal for security purposes.
Portal data is retained for as long as your portal subscription is active. If you cancel, we'll retain your data for a short period to allow export, then delete it, unless you ask us to do so sooner or we're required to retain it for a legal reason.
Some of the business tools we use to store and process data may be provided by companies based outside the UK. Where this happens, we only use providers that offer appropriate safeguards for your data, such as adequacy decisions or standard contractual clauses recognised under UK GDPR.
We do not sell personal data. We may share data with service providers who support our operations (e.g. document storage, payment processing, portal hosting), under appropriate agreements. For recruitment support, candidate data is shared only with you, the hiring business, unless you instruct us otherwise.
We retain personal data only as long as necessary for the purposes described, or as required by law. Candidate data from recruitment engagements is retained only for the duration of the hiring process plus a short period afterwards, unless you ask us to delete it sooner or retain it for a specific lawful reason.
We won't send you marketing emails unless you've asked us to, and you can opt out of any future communications at any time by contacting us or using the unsubscribe link where provided. This doesn't affect service-related messages necessary to deliver work you've engaged us for.
Our services are aimed at businesses, not individuals, and we don't knowingly collect data about children. If you believe a child's data has been shared with us in error, please contact us and we'll remove it.
Under UK GDPR you have rights to access, correct, delete, or restrict use of your personal data, object to certain processing, and request that your data be moved to another provider (data portability). To exercise any of these, contact us using the details below - we'll respond within one month.
If you're not satisfied with how we've handled your data, you have the right to complain to the Information Commissioner's Office (ico.org.uk), the UK's data protection regulator.
Questions about this policy: hello@rysup.co.uk