Privacy Policy

Last updated: July 2026

Introduction

Idonara ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our recruitment platform.

This platform is operated by AI Applied Ltd, a company registered in England and Wales. We are committed to ensuring that your privacy is protected in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Information We Collect

Personal Information

We may collect personally identifiable information that you voluntarily provide when using our platform:

  • Name, email address, and phone number
  • Employment history and professional qualifications
  • CV/resume documents and cover letters
  • Educational background and certifications
  • Skills, competencies, and work preferences
  • Interview recordings and assessment results (with consent)

Automatically Collected Information

When you access our platform, we may automatically collect:

  • Device information and browser type
  • IP address and approximate location
  • Usage data and interaction patterns
  • Cookies and similar tracking technologies

How We Use Your Information

We use the information we collect for the following purposes:

  • To provide and maintain our recruitment platform services
  • To process job applications and match candidates with opportunities
  • To facilitate CV analysis and candidate screening
  • To schedule interviews and manage the recruitment workflow
  • To communicate with you about your applications and account
  • To improve our services through aggregated, anonymised analytics
  • To comply with legal obligations and regulatory requirements
  • To detect and prevent fraud or security issues

AI Processing and Automated Decision-Making

Our platform uses artificial intelligence to assist in the recruitment process. This includes:

  • Automated CV parsing and information extraction
  • Skill matching and candidate-role compatibility scoring
  • Interview question generation based on role requirements
  • Bias detection and fairness monitoring

Important: While AI assists in processing applications, all final hiring decisions are made by human recruiters and hiring managers. You have the right to request human review of any automated assessment and to contest decisions made with AI assistance.

Identity & Right-to-Work Verification

Where a role requires it, we ask you to verify your identity online using Veriff, a DIATF-certified identity verification provider, to a UK Government GPG45 Medium level of confidence. This supports the recruiting organisation's statutory right-to-work check.

The check involves photographing an identity document (such as a passport or driving licence) and a short liveness check (a selfie or brief video) to confirm the document is genuine and belongs to you. Because this includes an image of your face, it is special category (biometric) data under Article 9 of the UK GDPR. We rely on Article 9(2)(b) of the UK GDPR (obligations in the field of employment law) together with Schedule 1, Part 1, paragraph 1 of the Data Protection Act 2018 as our lawful basis for this processing.

We keep the identity document images and biometric details for 30 days before reducing them to a verification outcome, which we retain for the duration of your employment plus 2 years, as required by the Immigration Act 2016. Veriff processes your data on servers within the European Economic Area, defaulting to Ireland, and does not process data on its own premises.

Veriff acts as our processor when running the identity check on our instructions. Separately, and under its own authority, Veriff also acts as an independent data controller for what it calls its "Permitted Business Purposes" — using verification data to improve its own machine-learning and fraud-detection models. That reuse is governed by Veriff's own privacy notice, not by our instructions. If you'd rather not verify online, you can ask your recruiter for an in-person, manual identity check instead.

Data Sharing and Disclosure

We may share your information with:

  • Recruiting Organisations: Companies using our platform to fill positions you apply for
  • Service Providers: Third-party vendors who assist in operating our platform (e.g., cloud hosting, email services)
  • Identity Verification Partner: Veriff, our DIATF-certified identity verification provider (see Identity & Right-to-Work Verification above)
  • Legal Requirements: When required by law, court order, or government request
  • Business Transfers: In connection with mergers, acquisitions, or asset sales

We do not sell your personal information to third parties for marketing purposes.

Google API Services

Some features of our platform allow you to connect your Google account — for example, syncing interview appointments with Google Calendar. Idonara's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • What we access: If you connect Google Calendar, we access your calendar events and availability solely to display your schedule and to create, update, or cancel interview appointments you arrange through the platform.
  • What we do not do: Google user data is never used to develop, improve, or train generalised artificial intelligence or machine-learning models, and is never transferred to any third-party AI service. The AI services we use (see AI Processing above) process recruitment documents such as CVs and role descriptions only — never data received from Google APIs.
  • No advertising or resale: We do not use Google user data for advertising and do not sell it to any third party.

The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. You can disconnect your Google account at any time from your account settings, which revokes our access to your Google data.

Data Security

We implement appropriate technical and organisational security measures to protect your personal data:

  • Encryption of data in transit and at rest (AES-256)
  • Multi-tenant data isolation ensuring organisational separation
  • Regular security audits and penetration testing
  • Access controls and authentication mechanisms
  • Employee training on data protection practices
  • ISO 27001 aligned security practices

Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required by law. Typical retention periods:

  • Active candidate profiles: Duration of recruitment process plus 2 years
  • Application records: 3 years from application date
  • Account data: Until account deletion plus 30 days
  • Audit logs: 7 years for compliance purposes
  • Identity verification — document images and biometric/liveness data: 30 days, then reduced to a verification outcome
  • Identity verification — statutory right-to-work outcome: Duration of employment plus 2 years

Your Rights (UK GDPR)

Under UK data protection law, you have the following rights:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Request limitation of how we use your data
  • Right to Data Portability: Receive your data in a machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Rights related to automated decision-making: Request human review of automated decisions

International Data Transfers

Your data is primarily processed within the United Kingdom and European Economic Area. Where we transfer data outside these regions (e.g., to use certain AI services), we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the UK Information Commissioner's Office. Our identity verification partner, Veriff, processes data within the European Economic Area (defaulting to Ireland) under the EU Standard Contractual Clauses (Modules 1 and 4); a UK International Data Transfer Agreement (IDTA) is being layered on to cover the UK-to-EEA transfer leg.

Cookies

We use cookies and similar technologies to improve your experience on our platform. Essential cookies are required for the platform to function. Analytics cookies help us understand usage patterns. You can manage your cookie preferences through your browser settings or our cookie consent mechanism.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact our Data Protection Officer:

AI Applied Ltd

Data Protection Officer

Email: privacy@idonara.com

Address: London, United Kingdom

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated.