Privacy Notice
Get Me A Techie — Privacy Notice
Last updated: 20 July 2026 · Version 1.0
1. About This Notice
1.1 This Privacy Notice ("Notice") describes how Get Me A Techie ("Get Me A Techie", "we", "us", "our") collects, uses, stores, discloses and otherwise processes your personal data when you access or use our website at getmeatechie.com, our related applications and our technology recruitment introduction services (together, the "Service").
1.2 This Notice is issued pursuant to Articles 13 and 14 of the UK General Data Protection Regulation (the "UK GDPR") as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018, and as supplemented by the Data Protection Act 2018 (the "DPA 2018"). References in this Notice to "UK data protection law" shall be construed accordingly.
1.3 Article 13 UK GDPR applies where we collect personal data directly from you. Article 14 UK GDPR applies where we obtain personal data about you from sources other than directly from you. Both Articles require us to make certain mandatory information available to you at the time of collection or, in the case of Article 14 data, within a reasonable period of obtaining it. This Notice is designed to satisfy those requirements.
1.4 We are committed to processing your personal data lawfully, fairly and transparently. Please read this Notice carefully before using the Service. If you have any questions about how we handle your data, please contact us using the details in Section 2 and Section 21 below.
1.5 Where we update this Notice, the revised version will be posted at this URL with an updated effective date. Material changes will be communicated to you in advance in the manner described in Section 20 below.
2. Who We Are — Controller and Contact Details
2.1 The Data Controller (as defined in Section 3 below) responsible for your personal data is:
Get Me A Techie Ltd
A company registered in England and Wales
Company Registration Number: 17349022
Trading as: Get Me A Techie
Website: getmeatechie.com
2.2 For all data protection enquiries, or to exercise any of your rights set out in Section 13 below, please contact our Data Protection Point of Contact:
Email: catherine@getmeatechie.com
2.3 We aim to acknowledge all data protection enquiries within five (5) working days.
3. Key Definitions
3.1 In this Notice, the following terms have the meanings given below:
"Controller"
The natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data (Article 4(7) UK GDPR). For the purposes of this Notice, the Controller is Get Me A Techie Ltd, trading as Get Me A Techie.
"Processor"
A natural or legal person who processes personal data on behalf of the Controller pursuant to a written data processing agreement, and who is contractually prohibited from processing that data for any purpose other than providing the contracted services (Article 4(8) UK GDPR). Our Processors are listed in Section 10.
"Data Subject"
An identified or identifiable natural person to whom personal data relates (Article 4(1) UK GDPR). You are a Data Subject in relation to any personal data we hold about you.
"Personal Data"
Any information relating to an identified or identifiable natural person. This includes, but is not limited to, name, email address, location, online identifiers such as IP addresses, and any data contained within a CV or job description (Article 4(1) UK GDPR).
"Special Category Data"
Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a natural person's sex life or sexual orientation (Article 9(1) UK GDPR). For the purposes of this Notice, this term also encompasses personal data relating to criminal convictions and offences, which is governed by Article 10 UK GDPR and section 10 and Schedule 1 DPA 2018.
"Processing"
Any operation or set of operations performed upon personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction (Article 4(2) UK GDPR).
"UK GDPR"
The General Data Protection Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018, as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (SI 2019/419), as supplemented by the Data Protection Act 2018.
4. Personal Data We Collect and How We Obtain It
4.1 We collect personal data in the following ways:
(a) Information you provide to us directly, when creating an account, uploading a CV or job description, communicating with us, or otherwise using the Service;
(b) Information generated automatically when you use the Service (such as technical and usage data); and
(c) Information derived or inferred by us from the above.
4.2 If you are a Candidate (Techie), we collect:
(a) Your name, email address and password-protected account credentials;
(b) Your CV, résumé or career portfolio and all contents thereof, which may include your employment history, educational background, skills, professional qualifications, salary expectations, desired location, work-style preferences, and any other information you choose to include;
(c) Any additional information you voluntarily provide as part of your profile; and
(d) Where applicable, Special Category Data as described in Section 5 below.
4.3 If you are a Company (Client), we collect:
(a) The name and contact details (including email address) of your nominated representative(s);
(b) Your company name, registered address and, where applicable, company registration number;
(c) Billing email address and payment details (processed via Stripe — see Section 10); and
(d) Details of the roles and positions you post on the Service.
4.4 For all users, we collect the following data automatically:
(a) Account and authentication data managed via Amazon Cognito (our identity provider), including log-in credentials, session tokens and multi-factor authentication records;
(b) Technical data, including IP address, device type, browser type and version, operating system, time-zone setting, and referring URLs; and
(c) Usage data, including pages visited, features accessed, session duration and interaction logs.
(d) Cookie and tracking data as described in Section 16 below.
4.5 Where we process personal data about you that we have not obtained directly from you (for example, where a company uploads information about a candidate, or where a candidate's CV contains references to third parties), we will, where required by Article 14 UK GDPR, take reasonable steps to provide those individuals with the information required by that Article within a reasonable period of obtaining the data (and in any event within one month), unless one of the exemptions in Article 14(5) applies.
5. Special Category Data
5.1 CVs and candidate profiles uploaded to the Service may contain Special Category Data. Whilst we do not require candidates to include Special Category Data, and actively encourage candidates to review and, where not strictly necessary, redact such information before uploading, it is inherent in the nature of a CV that it may inadvertently disclose such information. Special Category Data encountered on the Service may include, without limitation:
(a) Information concerning health or disability, such as declared medical conditions, adjustments requested, or employment gaps attributable to ill health;
(b) Racial or ethnic origin, such as nationality, country of birth or diversity monitoring information voluntarily disclosed;
(c) Religious or philosophical beliefs, for example where disclosed as part of a career history or explained gap in employment;
(d) Trade union membership, for example where referenced in an employment history;
(e) Data concerning sex life or sexual orientation, where voluntarily disclosed by the candidate; and
(f) Information relating to criminal convictions or offences, for example where a candidate discloses the outcome of a Disclosure and Barring Service (DBS) check, or a spent or unspent conviction.
5.2 Where Special Category Data is encountered or processed by us, we rely on the following conditions in addition to a lawful basis under Article 6 UK GDPR:
(a) Health data (Article 9(2)(b) UK GDPR and paragraph 1 of Schedule 1 DPA 2018): processing necessary for the purposes of carrying out obligations and exercising specific rights in the field of employment, social security and social protection, where authorised by an Appropriate Policy Document. Alternatively, Article 9(2)(a) UK GDPR (explicit consent), where the candidate has clearly and voluntarily disclosed such information.
(b) Diversity data — racial or ethnic origin, religion, sexual orientation (Article 9(2)(a) UK GDPR): explicit consent, where the data subject has voluntarily included such information in their CV or profile and it is apparent from context that they have chosen to disclose it for the purpose of their application.
(c) Criminal conviction data (section 10 and Schedule 1 Part 2 DPA 2018): processing in connection with employment and recruitment, subject to an Appropriate Policy Document being in place.
5.3 Special Category Data is subject to heightened technical and organisational security measures within our systems (see Section 17). It is accessible only on a strict need-to-know basis. It is not disclosed to companies, other candidates or third parties beyond what is strictly necessary for the placement process.
5.4 If you do not wish Special Category Data to be processed by us, you should not include it in your CV or profile. If you have already submitted such data and wish to have it removed, please contact us at catherine@getmeatechie.com.
6. Our Lawful Bases for Processing
6.1 We process personal data only where we have a valid and identified lawful basis for doing so under Article 6 UK GDPR. We do not rely on any single lawful basis across all our processing activities; the applicable lawful basis depends on the specific purpose for which data is processed, as set out below.
(a) Performance of a contract — Article 6(1)(b) UK GDPR
Processing is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. This lawful basis applies to:
(i) the creation and management of your account;
(ii) the generation and hosting of your anonymised candidate profile or job advertisement;
(iii) the operation of the matching and introduction process;
(iv) the processing of placement agreements; and
(v) the taking and processing of placement fees (for companies).
(b) Compliance with a legal obligation — Article 6(1)(c) UK GDPR
Processing is necessary for compliance with a legal obligation to which we are subject as a controller. This lawful basis applies to:
(i) accounting, tax and VAT record-keeping obligations under the Companies Act 2006, the Income Tax (Earnings and Pensions) Act 2003, and HMRC requirements;
(ii) compliance with court orders, regulatory requirements or requests from competent authorities; and
(iii) obligations arising under employment law and other applicable statutory regimes.
(c) Legitimate interests — Article 6(1)(f) UK GDPR
Processing is necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by your interests or fundamental rights and freedoms. We have conducted documented Legitimate Interests Assessments (LIAs) in respect of the following purposes and are satisfied that our interests are not overridden, having regard to the nature of the processing and the reasonable expectations of users of a service of this type:
(i) Operating, securing and continuously improving the Service;
(ii) Detecting, preventing and investigating fraud, misuse, unauthorised access and other security incidents;
(iii) Sending you service-related communications relating to your account or the Service;
(iv) Enforcing our Terms of Service and exercising our contractual and legal rights; and
(v) Maintaining internal analytics and business intelligence records.
You have the right to object to processing based on legitimate interests at any time. Please see Section 13(f) below.
(d) Consent — Article 6(1)(a) UK GDPR
Where we process your personal data on the basis of your freely given, specific, informed and unambiguous consent, indicated by a clear affirmative action. This lawful basis applies to:
(i) direct marketing communications (where you have opted in); and
(ii) non-essential cookies, analytics and advertising technologies (subject to your cookie preferences — see Section 16).
You may withdraw your consent at any time by contacting us at catherine@getmeatechie.com or using our Cookie Preference Centre. Withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal.
6.2 Where we rely on Special Category Data processing conditions, these are set out separately in Section 5.3 above and are additional to the Article 6 lawful basis.
7. How We Use Your Personal Data
7.1 We use your personal data only for the purposes described in this Notice and for which we have a valid lawful basis. Those purposes are as follows:
(a) Providing and managing the Service
Creating and administering your account; verifying your identity; processing your CV or job description; generating your anonymised profile or job advertisement; facilitating the introduction and placement process; and providing customer support. Lawful basis: performance of a contract; legitimate interests.
(b) The recruitment and introduction process
Matching candidates to companies on the basis of skills, experience and requirements; managing the placement process; and, where a placement agreement is signed and the conditions in Section 8 are satisfied, disclosing the relevant identifying contact details. Lawful basis: performance of a contract.
(c) Processing payments
Where a company owes a placement fee, processing payment via Stripe. Lawful basis: performance of a contract.
(d) Service security and integrity
Preventing, detecting and investigating fraud, cyberattacks, unauthorised access and other security incidents; maintaining the integrity and availability of the Service. Lawful basis: legitimate interests; legal obligation.
(e) Legal compliance
Meeting our obligations under applicable law, including responding to lawful requests from regulators, law enforcement agencies or courts; maintaining required records; and complying with applicable tax and employment law requirements. Lawful basis: legal obligation.
(f) Service communications
Sending you service-related communications, including account notifications, updates to this Notice, and information about changes to the Service. Lawful basis: legitimate interests.
(g) Marketing communications (where consented)
Sending you marketing communications about our services where you have given your prior consent to receive them. You may opt out at any time. Lawful basis: consent.
(h) Analytics and service improvement
Understanding how users interact with the Service and using aggregate, anonymised data to improve features and performance. Lawful basis: legitimate interests; consent (for cookie-based analytics).
(i) Establishing, exercising and defending legal claims
Processing data as necessary to bring or defend legal proceedings, including in connection with placement fee disputes, data subject rights claims or regulatory investigations. Lawful basis: legitimate interests; legal obligation.
8. Anonymisation and Disclosure of Contact Details
8.1 The Service is built on a privacy-first model. All candidate profiles and company job advertisements published on the Service are pseudonymised: names, direct contact details (including email addresses, telephone numbers and social media identifiers) and other identifying information are withheld from public-facing profiles.
8.2 A candidate's or a company's identifying contact details will not be disclosed to the other party at any stage of the introduction process unless and until all of the following conditions have been satisfied:
(a) a formal placement has been agreed between the candidate and the company;
(b) a written placement agreement has been duly executed by the company using our electronic signature platform (BoldSign); and
(c) the applicable placement fee has been confirmed as payable by the company in accordance with our Terms of Service.
8.3 Upon satisfaction of all the conditions in clause 8.2:
(a) we will disclose to the relevant company the candidate's name and direct contact details, solely for the purpose of completing the agreed placement; and
(b) we will disclose to the relevant candidate the name and direct contact details of the company contact person, solely for the purpose of completing the agreed placement.
8.4 During all earlier stages of the recruitment process — including, without limitation, initial candidate matching, shortlisting, the submission of anonymised profiles, and any interview-arrangement stages facilitated through the Service — no identifying contact details will be disclosed without the express written consent of both the candidate and the company.
8.5 We will never sell, rent or otherwise make available your personal data (including contact details) to any third party for commercial purposes.
9. Artificial Intelligence Processing
9.1 We use AI-powered tools to assist in the processing of documents uploaded to the Service. These tools are used solely as assistive technology to support the work of human operators; they do not replace human oversight or make autonomous decisions about any individual.
9.2 The AI tools currently in use on the Service are:
(a) Amazon Textract: an AWS machine learning service used to extract text and structured data from CVs, résumés and job descriptions uploaded in PDF or image format; and
(b) Amazon Bedrock: an AWS generative AI service used to assist in structuring, summarising and anonymising the extracted text in order to generate candidate profiles and job advertisements in a standardised format.
9.3 The role of AI in the Service is strictly limited to the following assistance functions:
(a) Extracting text from uploaded documents for the purpose of creating a structured profile;
(b) Assisting in the anonymisation of personal data within those profiles; and
(c) Presenting a structured draft profile to you for your review and approval prior to publication.
9.4 We confirm that:
(a) AI processing does not make any automated decision that produces a legal effect, or any other significantly similar effect, on any Data Subject;
(b) No decision about whether to match, shortlist, introduce or reject a candidate or a company is made solely by an AI system;
(c) All AI-generated profiles, summaries and job advertisements are reviewed and approved by the relevant user before publication; and
(d) No placement decision is made without meaningful human involvement.
9.5 Amazon Web Services, Inc. processes personal data through Amazon Bedrock as our Processor, pursuant to the AWS Data Processing Addendum, which incorporates appropriate safeguards for the processing of personal data including obligations of confidentiality and restrictions on use.
9.6 For further information about your rights in relation to automated processing, please see Section 14 below.
10. Who We Share Your Personal Data with
10.1 We do not sell, rent or trade your personal data to any third party under any circumstances.
10.2 We share personal data only with the following categories of recipients, and only to the extent necessary for the stated purpose:
(a) Service Providers (Processors)
Third parties who process personal data on our behalf pursuant to written data processing agreements. They are contractually prohibited from using personal data for any purpose other than performing the services contracted:
(i) Amazon Web Services, Inc. ("AWS") — cloud infrastructure, hosting, data storage, and AI processing services (including Amazon Cognito for authentication, Amazon Textract for document text extraction, and Amazon Bedrock for AI-assisted profile generation). Primary processing regions: UK / EU.
(ii) Stripe, Inc. / Stripe Payments Europe Limited — payment processing, payment authentication and billing record management.
(iii) BoldSign (a product of Syncfusion, Inc.) — electronic signature services, placement agreement management and execution.
(iv) Google LLC — email and collaboration services (Google Workspace) and, subject to your cookie preferences, advertising analytics.
(b) Professional Advisers
Our solicitors, barristers, accountants and auditors, where necessary, subject to obligations of professional confidentiality.
(c) Regulatory and Law Enforcement Authorities
Where disclosure is required by law, by a court order or by a regulatory requirement, or where we believe disclosure is necessary to protect the rights, safety or property of Get Me A Techie, our users or others, we may disclose personal data to relevant authorities. We will, where lawful and practicable to do so, notify you of such a disclosure.
(d) Acquirer or Successor Entity
In the event of a business sale, merger, restructuring or change of ownership, subject to the provisions of Section 18 below.
10.3 We do not share your personal data with any other third parties unless you have provided your prior express written consent, or unless we are otherwise required to do so by applicable law.
11. International Data Transfers
11.1 Your personal data is primarily stored and processed within the United Kingdom or the European Economic Area. However, certain Processors and their sub-processors may be established in, or process data in, countries outside the United Kingdom.
11.2 The United Kingdom left the European Union on 31 January 2020. Since that date, transfers of personal data from the United Kingdom to third countries have been governed by Chapter V of the UK GDPR, as supplemented by sections 17A to 17C of and Schedule 21 to the DPA 2018. Where we transfer personal data to a country that is not subject to a UK Adequacy Regulation made under section 17A DPA 2018, we ensure that one or more of the following appropriate safeguards is in place before making the transfer:
(a) A UK International Data Transfer Agreement ("IDTA"), being the standard form of agreement for international data transfers from the United Kingdom approved by the Secretary of State under section 119A DPA 2018 (effective 21 March 2022);
(b) A UK Addendum to EU Standard Contractual Clauses, being the international data transfer addendum to the European Commission's standard contractual clauses issued by the Information Commissioner's Office (ICO) under section 119A DPA 2018 (the "UK Addendum"); and/or
(c) A UK Adequacy Regulation, where the Secretary of State has determined that the destination country, territory or international organisation ensures an adequate level of protection for personal data.
11.3 The following international transfers are currently in place in connection with the Service:
| Recipient | Country | Transfer Mechanism | Further Detail |
|---|---|---|---|
| Amazon Web Services, Inc. | United States | IDTA / UK Addendum | AWS Customer Agreement DPA |
| Stripe, Inc. | United States | IDTA / UK Addendum | Stripe Data Processing Addendum |
| Google LLC | United States | IDTA / UK Addendum | Google Workspace Data Processing Terms |
| BoldSign (Syncfusion, Inc.) | United States | IDTA / UK Addendum | BoldSign Data Processing Agreement |
11.4 You may obtain a copy of the relevant transfer safeguards applicable to any international transfer by contacting us at catherine@getmeatechie.com.
12. How Long We Keep Your Personal Data
12.1 We retain personal data for no longer than is necessary for the purpose or purposes for which it was collected, taking into account applicable legal, regulatory, accounting and reporting requirements. The following retention schedule applies:
| Category of Personal Data | Retention Period | Legal Basis for Retention |
|---|---|---|
| Candidate account data and profile (active) | Duration of active account + 12 months after closure | Performance of contract; Legitimate interests |
| CV and uploaded documents (active profile) | Duration of active account | Performance of contract |
| Candidate and company contact details following placement | 7 years from date of placement | Legal obligation (HMRC / Companies Act 2006) |
| Placement agreements and fee records | 7 years from date of agreement | Legal obligation (HMRC / Companies Act 2006) |
| Electronic signature records (BoldSign) | 7 years from date of execution | Legal obligation (contract / evidence) |
| Billing and payment records | 7 years from end of relevant financial year | Legal obligation (HMRC VAT / tax) |
| Security and fraud logs | 12 months from the logged event | Legitimate interests (security) |
| Cookie and analytics data | As set out in the Cookie Notice | Consent |
| Correspondence / support tickets | 3 years from date of last communication | Legitimate interests (claims / defence) |
| Legal claims correspondence | Duration of claim + 6 years | Legal obligation; Legitimate interests |
| Criminal conviction data (if processed) | To be confirmed — seek legal advice | Schedule 1 DPA 2018 / Appropriate Policy Document |
12.2 At the expiry of the applicable retention period, personal data will be securely and permanently deleted or anonymised in accordance with our internal data retention and deletion policy. Where data is anonymised (rendered incapable of identifying any individual), the anonymised data may be retained indefinitely for statistical or analytical purposes, as it will no longer constitute personal data for the purposes of UK GDPR.
12.3 In certain circumstances, we may be required by law or by ongoing legal proceedings to retain personal data beyond the periods set out in the schedule above. In such cases, we will retain the minimum amount of data necessary for the minimum period required by the applicable obligation, and will restrict access to that data accordingly.
12.4 For further information about the relationship between retention periods and account deletion, please see Section 19 below.
13. Your Rights
13.1 Under UK data protection law, you have the following rights in relation to your personal data. These rights are not absolute and are subject to certain exemptions and qualifications under the UK GDPR and DPA 2018:
(a) Right of access — Article 15 UK GDPR
You have the right to obtain confirmation of whether we process personal data about you and, if so, to receive a copy of that personal data together with supplementary information about the processing (commonly referred to as a "Subject Access Request" or "SAR"). There is generally no fee for this; see clause 13.3 for exceptions.
(b) Right to rectification — Article 16 UK GDPR
You have the right to require us, without undue delay, to correct any inaccurate personal data we hold about you and to complete any incomplete personal data.
(c) Right to erasure — Article 17 UK GDPR
You have the right, in certain circumstances, to require us to delete your personal data (the "right to be forgotten"). This right applies where, for example, the personal data is no longer necessary for the purpose for which it was collected, you withdraw consent and no other lawful basis applies, or the data has been processed unlawfully. This right is subject to exemptions, including where retention is necessary for compliance with a legal obligation, or for the establishment, exercise or defence of legal claims.
(d) Right to restriction of processing — Article 18 UK GDPR
You have the right to require us to restrict our processing of your personal data in certain circumstances, for example where you contest the accuracy of the data (while we verify it), where you have objected to processing based on legitimate interests (while we assess that objection), or where the processing is unlawful but you prefer restriction to erasure. Where processing is restricted, we may retain your personal data but will not process it further without your consent (save in limited circumstances).
(e) Right to data portability — Article 20 UK GDPR
Where processing is based on your consent or on the performance of a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used and machine-readable format (such as CSV) and, where technically feasible, to have that data transmitted directly to another controller.
(f) Right to object — Article 21 UK GDPR
You have the right to object at any time to the processing of your personal data where that processing is based on our legitimate interests (Article 6(1)(f) UK GDPR). We must cease processing unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless processing is necessary for the establishment, exercise or defence of legal claims. Where you object to processing for direct marketing purposes, we will cease such processing unconditionally and immediately.
(g) Rights in relation to automated decision-making — Article 22 UK GDPR
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects. Please see Section 14 below for further detail.
(h) Right to withdraw consent
Where we process your personal data on the basis of your consent, you may withdraw that consent at any time by contacting us at catherine@getmeatechie.com or using our Cookie Preference Centre. Withdrawal of consent does not affect the lawfulness of any processing carried out prior to withdrawal.
13.2 How to exercise your rights: To exercise any of the above rights, please submit a written request to us:
Email: catherine@getmeatechie.com
We will acknowledge your request promptly and respond substantively within one (1) calendar month of receiving it. Where your request is complex or you have submitted multiple requests, we may extend this period by up to a further two (2) calendar months, in which case we will notify you within the initial one-month period and explain the reasons for the extension.
13.3 We will not charge a fee for handling a rights request unless it is manifestly unfounded or excessive (in particular, because of its repetitive character). In such cases, we may charge a reasonable fee (taking into account our administrative costs) or refuse to act on the request. We will notify you of our decision and the reasons for it.
13.4 We may need to verify your identity before processing your request. We may ask you to provide one or more forms of identification and will handle any such identity documents securely.
Right to appoint a representative — Article 80 UK GDPR
13.5 You may authorise a representative — such as a solicitor, family member, or data rights organisation — to submit a data subject rights request or lodge a complaint on your behalf. We may ask the representative to provide evidence of their authority to act on your behalf (such as a signed letter of authority, power of attorney or other written authorisation). We will correspond with the representative as if corresponding with you directly, unless you have specified otherwise.
Right to complain to the ICO — Article 77 UK GDPR
13.6 If you consider that we have processed your personal data in a manner which infringes UK data protection law, you have the right to lodge a complaint with the Information Commissioner's Office (the "ICO"), which is the independent supervisory authority responsible for data protection in the United Kingdom. You also have the right to an effective judicial remedy against us or against the ICO under Articles 78 and 79 UK GDPR.
13.7 Whilst we would welcome the opportunity to address your concerns before you approach the ICO, and encourage you to contact us first, you are under no obligation to do so and may contact the ICO directly at any time.
13.8 The full contact details of the ICO are as follows:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113 (local rate) or 01625 545 745
Website: www.ico.org.uk
Online complaint form: https://ico.org.uk/make-a-complaint/
13.9 If you are based in the European Economic Area, you may alternatively lodge a complaint with the supervisory authority in your country of habitual residence, place of work or place of the alleged infringement.
14. Automated Decision-making and Profiling
14.1 Article 22 UK GDPR confers on Data Subjects the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning them or which similarly significantly affects them, subject to certain exceptions.
14.2 We confirm that we do not make any decision about any individual Data Subject based solely on automated processing (including profiling) that produces a legal effect or any other similarly significant effect in relation to that individual, within the meaning of Article 22(1) UK GDPR.
14.3 Our AI tools, including Amazon Bedrock (described in Section 9), are used solely to assist human operators in extracting and structuring information from uploaded documents. All material decisions arising from or in connection with the Service — including, in particular, decisions about whether to match, introduce, shortlist, or place a candidate — involve meaningful human review and approval, and are not delegated to automated systems.
14.4 Notwithstanding the above, if you believe or suspect that a decision has been made about you through a process that constitutes solely automated processing within the meaning of Article 22 UK GDPR, you have the right to:
(a) request that the decision be reviewed by a competent human being;
(b) express your point of view in relation to the decision; and
(c) contest the decision.
To exercise any of these rights, please contact us at catherine@getmeatechie.com, explaining the decision you are contesting and the reasons for your concern.
15. Children's Privacy
15.1 The Service is designed and intended exclusively for use by adults engaged in, or seeking, employment in the technology sector. We do not knowingly collect, solicit or process personal data from individuals under the age of 18 years.
15.2 By creating an account or otherwise using the Service, you represent and warrant to us that you are at least 18 years of age.
15.3 We do not conduct any profiling, marketing or targeted advertising directed at children or young persons under the age of 18.
15.4 If you have reason to believe that an individual under the age of 18 has provided personal data to us, or has created an account with us, please contact us immediately at catherine@getmeatechie.com. Upon receipt of credible information to that effect, we will take prompt steps to verify the age of the relevant account holder and, where appropriate, to suspend the account and securely delete the associated personal data.
16. Cookies and Similar Technologies
16.1 We use cookies and similar tracking technologies (such as web beacons and pixel tags) on the Service. A cookie is a small text file placed on your device by a web server when you visit a website. Cookies enable us to recognise your browser, remember your preferences, maintain your session and collect information about your use of the Service.
16.2 We use the following broad categories of cookies:
(a) Strictly necessary cookies: These cookies are essential for the operation of the Service and cannot be switched off in our systems. They are usually set in response to actions you take, such as logging in, completing forms or setting privacy preferences. You cannot opt out of strictly necessary cookies without impairing the functionality of the Service. No consent is required for these cookies under the Privacy and Electronic Communications Regulations 2003 (PECR).
(b) Analytics and performance cookies: These cookies help us understand how visitors interact with the Service, including which pages are most visited, where errors occur and how users navigate the site. We use this information to improve the Service. These cookies are set only with your prior consent.
(c) Advertising and targeting cookies: These cookies may be set by third-party partners, including Google, to build a profile of your interests and serve relevant advertising. They are based on uniquely identifying your browser and device. These cookies are set only with your prior consent.
16.3 Full details of all cookies used on the Service — including each cookie's name, purpose, duration and third-party provider — are set out in our separate Cookie Notice, available at:
https://getmeatechie.com/cookies
16.4 You can manage your cookie preferences at any time using our Cookie Preference Centre, accessible from the footer of the website, or through the settings of your web browser. Please be aware that disabling certain cookies may impair some features of the Service.
16.5 Our use of cookies is governed by PECR and, where applicable, the UK GDPR. We will not place non-essential cookies on your device without your prior, freely given, specific and informed consent, which may be withdrawn at any time.
17. Security
17.1 We implement a range of appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in accordance with our obligations under Article 32 UK GDPR. Our security measures include, but are not limited to, the following:
(a) Encryption in transit: all communications between your device and our servers are encrypted using Transport Layer Security (TLS) protocols of a current and appropriate version, preventing interception of data in transit;
(b) Encryption at rest: personal data stored within our systems is encrypted at rest using industry-standard symmetric encryption;
(c) Access controls: logical access controls and role-based access management (RBAC) are in place to restrict access to personal data to those members of staff and contractors who require such access for the performance of their duties;
(d) Multi-factor authentication: mandatory multi-factor authentication (MFA) is required for all administrative and staff access to systems and platforms containing personal data;
(e) Security testing: we conduct periodic vulnerability assessments, penetration testing and code reviews as appropriate to identify and remediate security weaknesses;
(f) Business continuity: we maintain data backup procedures and business continuity plans to ensure the ongoing availability and integrity of personal data;
(g) Staff training: all staff and contractors with access to personal data receive regular training on their data protection and information security obligations; and
(h) Incident response: we maintain a documented personal data breach response procedure in accordance with Articles 33 and 34 UK GDPR, including processes for identifying, assessing, containing and notifying breaches.
17.2 We review our security measures periodically and update them as necessary to reflect evolving threats, technological developments and best practice guidance (including guidance published by the ICO and the National Cyber Security Centre (NCSC)).
17.3 No method of transmission over the internet, or method of electronic storage, is entirely secure, and absolute security cannot be guaranteed. However, we take our obligations under Article 32 UK GDPR seriously and are committed to implementing security measures that are appropriate to the risk presented by the processing we carry out.
17.4 In the event of a personal data breach that is likely to result in a risk to your rights and freedoms as a Data Subject, we will notify you and/or the ICO as required under Articles 33 and 34 UK GDPR, without undue delay and, in the case of notification to the ICO, within 72 hours of becoming aware of the breach.
17.5 If you become aware of any actual or suspected security vulnerability, data breach or other security concern relating to the Service, please contact us immediately at catherine@getmeatechie.com.
18. Business Transfers and Change of Ownership
18.1 In the event that Get Me A Techie or its operating entity undergoes a corporate transaction — including, without limitation, a merger, acquisition, joint venture, restructuring, sale of all or substantially all of its business or assets, or change of control (each a "Business Transfer") — personal data held by us in connection with the Service may constitute part of the assets transferred or otherwise be reviewed in the due diligence process connected with that transaction.
18.2 In connection with any Business Transfer, we will take the following steps:
(a) We will, to the extent practicable, ensure that any acquirer or successor entity agrees to process your personal data in a manner consistent with this Notice, or, if material changes to the processing are anticipated, to provide you with advance notice of those changes prior to the transfer taking effect;
(b) Personal data will continue to be subject to the protections afforded under UK GDPR and DPA 2018 at all times, including following any Business Transfer; and
(c) Where required by applicable law, we will seek your consent before transferring your personal data to a new Controller as a result of a Business Transfer.
18.3 If a Business Transfer results in a material change to the purposes for which your personal data is processed, or to this Notice, we will inform you by email (using the email address associated with your account) or by prominent notice on the Service at least 30 days before the changes take effect, giving you an opportunity to exercise your rights under Section 13 above, including the right to request deletion of your personal data before the transfer occurs.
18.4 During any due diligence process connected with a potential Business Transfer, access to personal data will be restricted to those individuals who strictly require it and will be subject to appropriate confidentiality obligations.
19. Account Deletion and Legal Retention Obligations
19.1 You may request deletion of your account at any time using the account-deletion feature within the Service (available from your account settings page), or by contacting us at catherine@getmeatechie.com.
19.2 Upon receipt of a valid account deletion request, we will take the following steps:
(a) Your public profile, CV, uploaded documents and user-generated content will be removed from the live Service promptly, and in any event within thirty (30) calendar days of the receipt of your request;
(b) Your account credentials and authentication data will be removed from our live production systems within thirty (30) calendar days of the receipt of your request; and
(c) We will cease to use your personal data for any active operational or commercial purpose.
19.3 Important: Account deletion does not result in the immediate and complete deletion of all personal data associated with your account. We are subject to legal and regulatory obligations which require us to retain certain categories of personal data beyond the date of account deletion, as set out in Section 12 above. In particular, the following data categories will be retained notwithstanding your deletion request:
(a) Placement records and the associated contact details of candidates and companies involved in a completed placement: retained for seven (7) years from the date of the relevant placement, in order to meet our obligations under HMRC, the Companies Act 2006 and applicable employment law;
(b) Financial and billing records, including records of payments made and placement fees invoiced: retained for seven (7) years from the end of the relevant financial year, pursuant to HMRC and Companies Act 2006 requirements;
(c) Electronic signature records of placement agreements executed via BoldSign: retained for seven (7) years from the date of execution, for contractual and evidentiary purposes; and
(d) Any other personal data which we are required by law, regulation or court order to retain beyond the date of account deletion.
19.4 All personal data retained solely for legal compliance purposes following account deletion will be:
(a) stored securely, with access restricted to those personnel with a specific need to access it in connection with the relevant legal obligation;
(b) not used for any commercial, marketing or operational purpose; and
(c) deleted permanently at the expiry of the applicable retention period.
19.5 We will, at the point at which you initiate your account deletion request, provide you with clear information about which categories of data will be retained following deletion, and for how long.
20. Changes to This Notice
20.1 We may update or amend this Notice from time to time to reflect changes to our data processing activities, changes in applicable law, or updated guidance from the ICO or other relevant authorities.
20.2 The date at the top of this Notice indicates when it was last updated. We encourage you to review this Notice periodically.
20.3 Where changes to this Notice are material — for example, where they affect the lawful basis on which we process your data, introduce new categories of processing, or otherwise significantly affect your rights — we will notify you in advance by:
(a) sending an email to the email address associated with your account, at least fourteen (14) days before the changes take effect; and/or
(b) displaying a prominent notice on the Service when you next log in, at least fourteen (14) days before the changes take effect.
20.4 Where any material change requires your consent under applicable law, we will seek that consent before the change takes effect and will not process your personal data under the new terms unless and until that consent is obtained.
20.5 Continued use of the Service after the effective date of any updated Notice constitutes your acknowledgement that you have read and understood the revised Notice, subject always to any consent requirements under applicable law.
21. How to Contact Us and Complain to the ICO
21.1 If you have any questions, comments or concerns about this Notice, or about the way in which we process your personal data, please contact us:
Get Me A Techie — Data Protection Team
Email: catherine@getmeatechie.com
21.2 If you have a complaint about the manner in which we have handled your personal data, we request that you contact us in the first instance using the details above so that we have the opportunity to investigate and resolve your complaint. We will:
(a) acknowledge receipt of your complaint within five (5) working days; and
(b) provide a substantive written response within twenty (20) working days, or such longer period as may be necessary for complex matters (in which case we will keep you informed of progress and the expected timeline).
21.3 If you remain dissatisfied with our response to your complaint, or if you wish to escalate your complaint directly to the relevant supervisory authority, you have the right to do so without restriction. The supervisory authority for the United Kingdom is:
Information Commissioner's Office (ICO)
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113 (local rate) | 01625 545 745 (national rate)
Fax: 01625 524 510
Website: www.ico.org.uk
Live chat: Available at www.ico.org.uk
Online complaints form: https://ico.org.uk/make-a-complaint/
Email (for general enquiries): casework@ico.org.uk
21.4 The ICO is the independent authority responsible for upholding information rights in the United Kingdom, and has the power to investigate complaints, issue assessment notices, enforcement notices and penalty notices, and impose administrative fines of up to £17.5 million or 4% of total annual worldwide turnover (whichever is higher) for the most serious infringements.
21.5 If you are ordinarily resident in, or the alleged infringement took place in, a member state of the European Economic Area, you may alternatively lodge a complaint with the supervisory authority in that member state.
This Privacy Notice was last reviewed and approved on 19 July 2026 by Catherine Welling, Founder
© Get Me A Techie Ltd trading as Get Me A Techie. All rights reserved.
Questions about how we handle your data? Contact us, or email catherine@getmeatechie.com.