Policies

Privacy Policy

Data Protection & Privacy Policy (“Policy”)

1. Introduction

Senovo IT Ltd (“we”, “us” or “our”) is strongly committed to protecting and respecting your privacy.

Senovo IT Group is a leading IT consulting service provider. It was founded in 2013 and is currently present in 15 countries, bringing talent, drive and innovation to national and international projects. We provide business solutions and assistance to IT professionals in finding suitable assignments based on their skills and expertise.

For the purposes of applicable data protection law, including the UK Data Protection Act 2018 and the EU/UK General Data Protection Regulation (together, “GDPR”), Senovo IT Ltd is the data controller of your personal data. Where we share your data with other group companies, those companies may act as joint controllers or processors depending on the context.

We are registered as a data controller with the Information Commissioner’s Office (ICO) in the UK.

This Policy sets out the essential details of how we collect, use and process your personal data, including through our website and services.


2. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, regulatory, tax, accounting or reporting requirements.

If we have no contact with you following the expiry of a 7-year period, we will archive and may delete your file. We may also pseudonymise certain data (replace identifiers with artificial values) to ensure we do not re-enter you into our systems inadvertently.

Retention periods are determined based on:

  • the nature and sensitivity of the data;

  • applicable legal/regulatory requirements;

  • business needs such as whether an introduction or assignment has been arranged.


3. Data Collection and Use

A) Purposes of processing and legal bases

We process personal data in order to provide our recruitment and IT consulting services. This may include: contacting you about assignment opportunities, assessing suitability, updating our databases, arranging payments, and developing our services.

We rely on the following legal bases under GDPR:

  • Contract: where processing is necessary to perform a contract with you or to take steps at your request before entering into a contract.

  • Legal obligation: where we are required to comply with law.

  • Legitimate interests: where we have a business reason to process your data that is not overridden by your rights (e.g. managing our database, providing services to clients, keeping in contact).

  • Consent: where you have explicitly given consent (e.g. to receive marketing communications, or to accept cookies for analytics). Consent is always collected via a clear affirmative action (for example ticking a box on a form or via our cookie consent banner) and can be withdrawn at any time.

We do not rely on implied or blanket consent.

B) Information we collect

  • Information you give us: via forms on our site (www.senovo-it.com), emails, calls, CVs, event registrations, etc.

  • Information we collect automatically: such as IP address, browser type, pages visited (see “Cookies” below).

  • Information from third parties: e.g. LinkedIn, job boards, referrals, clients, professional contacts.

The categories of individuals whose data we collect include candidates, placed professionals, clients, suppliers, and referees.

C) Special category data

We generally do not seek special category (sensitive) data. If such data is required, we will only process it under an applicable GDPR condition (for example explicit consent, legal obligation, or for the establishment, exercise or defence of legal claims).


4. Your Rights

Under GDPR, you have the following rights:

  • To be informed about how we use your data.

  • To access the personal data we hold about you.

  • To request correction of inaccurate data.

  • To request erasure of your data where there is no good reason for processing.

  • To restrict or object to processing, including where we rely on legitimate interests.

  • To withdraw consent at any time (without affecting prior lawful processing).

  • To data portability in certain circumstances.

  • Not to be subject to decisions based solely on automated processing.

  • To lodge a complaint with the Information Commissioner’s Office (ICO) or another supervisory authority.

You can exercise your rights by contacting us at dpo@ametrosgroup.com.


5. Data Transfers

We may transfer your personal data outside the UK or EEA. When we do, we ensure appropriate safeguards are in place, such as adequacy decisions, Standard Contractual Clauses, or Binding Corporate Rules.


6. Data Security

We have implemented appropriate technical and organisational measures to prevent personal data from being accidentally lost, used or accessed in an unauthorised way. Access is limited to those with a business need, who are bound by confidentiality.

However, please note that data transmission over the internet is not fully secure and we cannot guarantee the security of data transmitted electronically.


7. Cookies

Our website uses cookies and similar technologies.

We use a consent management platform provided by CookieYes Limited (“CookieYes”) to obtain and record your preferences. When you first visit our website, you will see a cookie banner that allows you to accept or reject different categories of non-essential cookies (such as analytics).

  • Strictly necessary cookies are required for our site to function and are always active.

  • Non-essential cookies (e.g. Google Analytics) are only set if you give consent through the CookieYes banner.

CookieYes sets its own cookie to remember your consent choices so that they are respected on future visits.

You can change or withdraw your consent at any time by clicking the “Cookie Settings” link in the footer of our website.

For full details of the cookies we use, their purpose and duration, please see our Cookie Policy.


8. Changes to this Policy

We may update this Policy from time to time. Any changes will be posted on our site and, where appropriate, notified to you by email. Please review this Policy periodically.


9. Contact

If you have questions or wish to exercise your data rights, please contact:

Data Protection Contact

Email: dpo@ametrosgroup.com

Address: Unit 110 Coppergate House, 10 White’s Row, London, E1 7NJ, UK

If you are not satisfied with our response, you have the right to lodge a complaint with the ICO at https://ico.org.uk/concerns/.