Recruitment Privacy Notice
Last updated: 31 March 2026
This Privacy Notice (together with any other documents referred to herein) explains how ZeptoLab UK Limited (“ZeptoLab” or “We”) collects, uses, and processes your personal data in connection with our recruitment processes, whether you apply for our openings via LinkedIn, Workable, or any other online application platform used by ZeptoLab. Please read the following carefully to understand our views and practices regarding your personal data and how We will treat it.
ZeptoLab UK Limited acts as the data controller of your personal data. ZeptoLab is also established within the European Union through its affiliate companies who act as data processors.
Where you apply for a job opening via the application function on a job site or similar online service provider (“Partner” or “Partners”), you should note that the relevant Partner may retain your personal data and may also collect data from Us regarding the progress of your application.
In case you applied through Workable, We use Workable Software Limited as a data processor to assist with our recruitment process. Workable is only entitled to process your personal data in accordance with our instructions.
Where you apply via LinkedIn, LinkedIn Ireland Unlimited Company (or the relevant LinkedIn affiliate, depending on your region) acts as a processor on our behalf and processes your personal data solely for recruitment purposes in accordance with our instructions and applicable data protection legislation.
Any use of your personal data by the relevant Partner will also be governed by that Partner’s privacy notice:
Workable: https://www.workable.com/privacy
LinkedIn: https://www.linkedin.com/legal/privacy-policy
We may also work with other Partners from time to time. Where this is the case, your personal data will be processed in accordance with the relevant Partner’s privacy notice. We encourage you to review the privacy policies and notices of any such Partners before submitting your application.
Your Personal Data
Information We Collect From You
We collect and process some or all of the following types of information from you:
- Information that you provide when you apply for a role. This includes information provided through an online job site, via email, in person during interviews and/or by any other method.
- In particular, We process personal details such as name, email address, address, telephone number, qualifications, information relating to your employment history, skills and experience that you provide to Us.
- If you contact Us, We may keep a record of that correspondence.
- A record of your progress through any hiring process that We may conduct.
Information We Collect From Other Sources
We may obtain personal data about you from third-party sources to identify suitable candidates for our job openings, including publicly available information about you that you have published on the Internet, such as LinkedIn and other social media profiles.
We may search various databases – some publicly available and others not, which may include your personal data (including your CV), to find possible candidates to fill our job openings. Where We find you in this way, We will obtain your personal data from these sources.
We may receive your personal data from a third party who recommends you as a candidate for a specific job opening or for our business more generally.
If We identify you through these sources, We will collect only the data necessary for recruitment assessment.
Uses Made of Your Information
Lawful Bases And Purposes of Processing
We will only use your personal data when We have a lawful basis to do so. Our lawful basis for each purpose for which We use your personal data is specified below.
| Purpose or Activity | Type of Information | Lawful Basis for Processing |
| Managing the recruitment process for current vacancies, including receiving and reviewing applications, conducting interviews and assessments | Identification and contact information; professional and employment-related information; recruitment assessment information | Legitimate interest in assessing applications, conducting interviews, selecting candidates, and recruitingcandidates for our business |
| Identifying and sourcing potential candidates for current job openings, including through publicly available sources, referrals and recruitment platforms | Identification and contact information; professional and employment-related information; publicly available information | Legitimate interest in identifying suitable candidates and filling job openings |
| Communicating with candidates throughout the recruitment process | Identification and contact information; recruitment communications | Legitimate interest in arranging interviews and providing candidates information about the status of applications |
| Maintaining recruitment records, managing disputes and responding to legal or regulatory requests | Recruitment records; correspondence and decision-making records | Legitimate interest |
| Carrying out pre-engagement checks and taking steps prior to entering into an employment or engagement contract following a conditional offer | Identification and contact information; verification and pre-engagement information | Performance of a contract |
| Considering unsuccessful candidates for future suitable positions and retaining recruitment records for that purpose | Identification and contact information; professional and employment-related information; recruitment assessment information | Consent |
| Complying with legal and regulatory obligations related to recruitment and employment, including compliance with tax legislation, judicial, law enforcement and government authorities’ requests | Identification information; compliance and record-keeping information | Legal obligation |
Use of Recruitment Technology
We may use Partners’ technologies to support and manage our recruitment processes. While these tools may use automated features to assist with the handling and review of applications, all applications are reviewed by our recruitment team. All decisions as to who We will engage to fill the job opening will be made by our staff.
Disclosure of Your Information
As set out above, We pass your information to our Partners, including Workable, who use it only in accordance with our instructions and as otherwise required by law.
Where you have applied to a job opening through another Partner, We may disclose data about the status and outcome of your application to such Partner. The Partner shall be the data controller of this data and shall therefore be responsible for complying with all applicable law in respect of the use of that data following its transfer by Us.
How We Store Your Personal Data
Security
We take appropriate technical and organisational measures to ensure that all personal data is kept secure including security measures to prevent personal data from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal data to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where We are legally required to do so.
Unfortunately, the transmission of information via the internet is not completely secure. Although We will do our best to protect your personal data, We cannot guarantee the security of your data transmitted through any online means, therefore any transmission remains at your own risk.
Where We store your personal data
Where We store your personal data in our own systems, it is stored within the United Kingdom (“UK”) and the European Economic Area (“EEA”).
The data that We collect from you and process using Partners' services may be transferred to, and stored at, a destination outside the UK and the EEA. It may also be processed by staff operating outside the UK or the EEA who work for Us or for one of our suppliers. Such staff may be engaged in, among other things, the provision of support services.
In particular, your data may be accessible to (i) Partners' personnel in the USA or (ii) may be stored by Partners hosting service provider on servers in the USA as well as in the EU. We have implemented appropriate safeguards for these transfers, including Standard Contractual Clauses approved by the European Commission and the UK Information Commissioner’s Office, between Us and Partners. These safeguards are designed to help protect your privacy rights and give you remedies in the unlikely event of a misuse of your personal data.
If you would like further information please contact Us (see ‘Contact’ below). We will not otherwise transfer your personal data outside of the UK and the EEA or to any organisation (or subordinate bodies) governed by public international law or which is set up under any agreement between two or more countries.
How Long We Keep Your Personal Data
If your application is successful and you are hired by ZeptoLab, your personal data will be retained as part of your profile. If your application is unsuccessful, We will retain your personal data for up to twenty-four (24) months from your profile creation (or as otherwise required by applicable law in your jurisdiction).
In case We retain personal data where this is necessary to comply with legal or regulatory obligations, or to establish, exercise or defend legal claims, the data will be retained for the duration required by applicable law or until the relevant matter is resolved.
Your personal data will be deleted on one of the following events:
- Expiry of the retention period stated above; or
- Receipt of a written request by you (or another person engaged by you) to us.
Your Rights
Subject to applicable data protection laws, and in particular under the GDPR and the UK GDPR, you have a number of important rights free of charge. In summary, those include rights to:
- Access to your personal data and to certain other supplementary information that this Privacy Notice is already designed to address
- Require Us to correct any mistakes in your information which We hold
- Require the erasure of personal data concerning you in certain situations
- Receive the personal data concerning you which you have provided to Us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
- Object at any time to processing of personal data concerning you for direct marketing
- Object in certain other situations to our continued processing of your personal data
- Otherwise restrict our processing of your personal data in certain circumstances
- Claim compensation for damages caused by our breach of any data protection laws
- Withdraw consent where We are relying on consent to process your personal data
For further information on each of those rights, including the circumstances in which they apply, see the Guidance from the UK Information Commissioner’s Office (ICO) on individual rights under the UK GDPR.
If you would like to exercise any of those rights, please:
- Contact Us using our contact details below,
- Let Us have enough information to identify you,
- Let Us have proof of your identity and address, and
- Let Us know the information to which your request relates.
We will respond to your request within one month, although this may be extended by a further two months in complex cases, in which case We will inform you.
How To Complain
We hope that We can resolve any query or concern you raise about Our use of your information.
The EU GDPR and the UK GDPR also give you the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner’s Office (www.ico.org.uk). In the EEA, you may lodge a complaint with the supervisory authority in the EU Member State where you work, normally live, or where any alleged infringement of data protection laws occurred.
Updates To This Notice
We may update this Privacy Notice from time to time. If We make material changes, We will provide a prominent notice on our website before the changes take effect. Where required by law, We will seek your consent for such changes. This Privacy Notice states its effective date at the top.
Contact
If you have any questions regarding this Privacy Notice, our privacy practices, or our use of your personal data, you may contact Us at:
ZeptoLab UK Limited
27 Old Gloucester St, Holborn, London WC1N 3AX
+447703973953