← Home

Privacy Notice

Effective 26 May 2026. This notice explains how Hone handles personal data. It is written to comply with the UK General Data Protection Regulation and the Data Protection Act 2018.

1. Who we are

Hone (“Hone”, “we”, “us”) is a UK-based business providing a CV search and shortlisting workspace for healthcare recruitment agencies. For questions about this notice, contact privacy@hone.co.uk.

2. Our two roles

Hone acts in two different capacities depending on the data:

  • Controller for data about the recruiter using Hone — account details, billing information, support correspondence, usage telemetry.
  • Processor for candidate and client data that a recruiter uploads to their workspace. In that case the recruiter is the controller; they decide why and how candidate data is processed, and they are responsible for having a lawful basis to collect, retain and contact candidates. Hone processes that data on the recruiter’s documented instructions under a data processing addendum.

This notice covers our controller role. For Hone’s obligations as processor, recruiters should refer to their order form and DPA, or request a copy at privacy@hone.co.uk.

3. Data we collect (as controller)

  • Account data: name, work email address, password hash, profile photo, role, the workspace(s) you belong to.
  • Billing data: company name, billing address, VAT number, tax status, invoice history. Card details are handled by our payment processor; we do not store them.
  • Usage and technical data: pages visited, features used, search queries, IP address, browser and device information, error and audit logs.
  • Support data: messages and attachments you send us.
  • Cookies: see our Cookie policy.

4. Purposes and legal bases

  • To provide the Service (contract): authenticate you, render your workspace, store your data, send transactional emails.
  • To keep the Service secure and reliable (legitimate interests): detect abuse, debug errors, maintain audit trails, prevent fraud.
  • To bill you (contract and legal obligation): generate invoices, collect payment, comply with tax-record requirements.
  • To improve the Service (legitimate interests): analyse aggregated usage, prioritise features, fix bugs.
  • To communicate product updates (legitimate interests; opt-out available): occasional product emails and release notes to active customers.
  • Optional cookies and analytics (consent): only loaded if you consent via the cookie banner.

5. Retention

  • Account data: for the life of your subscription plus 90 days after termination.
  • Billing records and invoices: 6 years to meet UK tax-record requirements.
  • Security and audit logs: 12 months rolling.
  • Candidate and client data inside your workspace: retained according to the retention policy your workspace administrator configures. You control deletion at any time.

6. Sub-processors

We use a small number of vetted third parties to deliver the Service (hosting, authentication, email delivery, error monitoring, payments). The current list is published at /legal/sub-processors and is updated when it changes. Where required, we have data processing agreements in place with each of them.

7. International transfers

Production data is hosted in the UK / EEA. Where a sub-processor unavoidably processes data outside the UK, we rely on the UK International Data Transfer Addendum to the EU SCCs, or the EU Standard Contractual Clauses, together with appropriate technical and organisational safeguards.

8. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict or object to our processing of your personal data, the right to data portability, and the right to withdraw consent at any time where we rely on it. To exercise these rights contact privacy@hone.co.uk. We aim to respond within one calendar month. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.

If you are a candidate whose CV has been uploaded by a recruiter using Hone and you want to exercise rights over that data, please contact the recruiter directly — they are the controller for it. If you cannot identify the recruiter, contact us and we will help route your request.

9. Security

We encrypt data in transit (TLS) and at rest. Database access is enforced at row level (RLS) so workspace data is isolated by tenant. All administrative actions are written to an immutable audit trail. We follow least-privilege access for our staff and review access regularly.

10. Changes to this notice

We may update this notice from time to time. The “Effective” date at the top reflects the most recent change. Material changes will be highlighted in-app or by email.

11. Contact

Privacy enquiries: privacy@hone.co.uk.