🛡️ GDPR Compliance

Your data.
Your rights. Our commitment.

ScoutRex is fully aligned with the EU General Data Protection Regulation (GDPR). We built privacy-by-design into every product, every process, and every line of code.

GDPR Compliant
Privacy by Design
Data Subject Rights Supported
EU Data Residency Available

📋What is GDPR?

The General Data Protection Regulation (GDPR) is EU Regulation 2016/679, which came into force on 25 May 2018. It is one of the world's strongest data protection frameworks, giving individuals in the European Economic Area (EEA) extensive rights over their personal data and imposing strict obligations on organisations that process it.

GDPR applies to ScoutRex because we process personal data of individuals located in the EEA, including job seekers using JobRex and HR professionals using HireRex: regardless of where ScoutRex itself is based.

🤝Our Commitment

ScoutRex treats GDPR not as a compliance checkbox, but as a core product value. Privacy by design is embedded in how we build, deploy, and operate our platforms.

Privacy by Design

Data minimisation, purpose limitation and privacy controls are built into every feature from day one, not bolted on after launch.

Lawful Basis for All Processing

Every processing activity is mapped to a valid legal basis under Article 6 GDPR before it goes into production.

Data Subject Rights Platform

Candidates and company users can exercise all GDPR rights directly from their account dashboard, no email needed.

Vendor Due Diligence

All third-party processors are assessed for GDPR compliance before onboarding. Data Processing Agreements are in place with every sub-processor.

Breach Response Plan

We maintain a documented incident response plan that ensures regulatory notification within 72 hours where legally required.

Regular Audits

Internal privacy audits are conducted quarterly. Our Records of Processing Activities (RoPA) are kept up to date.

📂Data We Collect

We collect only the personal data necessary for the specific purposes described below. We do not sell personal data to third parties.

  • JobRex (Candidates): Name, email address, CV/résumé data, work history, skills, location preferences, and job search activity. Optionally: profile photo, LinkedIn URL, and diversity data if voluntarily provided.
  • HireRex (Companies): Contact name, business email, company name and size, job vacancy details, and hiring activity logs.
  • Website visitors: IP address (pseudonymised), browser type, pages visited, and session duration, collected via cookies with consent.
  • Communications: Email correspondence and support tickets if you contact us.

Special category data

ScoutRex does not require you to provide special category data (e.g. race, health, religion) as defined in Article 9 GDPR. If a candidate voluntarily adds such information to their profile, it is processed under explicit consent and can be withdrawn at any time.

🔑Your Rights Under GDPR

If you are located in the EEA, UK, or Switzerland, you have the following rights. All can be exercised via your account settings or by contacting privacy@scoutrex.com.

👁️

Right of Access

Request a copy of all personal data we hold about you, including how it is being used (Art. 15).

✏️

Right to Rectification

Ask us to correct inaccurate or incomplete personal data without undue delay (Art. 16).

🗑️

Right to Erasure

Request deletion of your personal data where we no longer have a lawful basis to retain it ("right to be forgotten") (Art. 17).

⏸️

Right to Restriction

Ask us to pause processing of your data while a dispute about accuracy or lawfulness is resolved (Art. 18).

📤

Right to Portability

Receive your personal data in a structured, machine-readable format and transfer it to another service (Art. 20).

🚫

Right to Object

Object to processing based on legitimate interests or direct marketing, we will stop unless compelling grounds override your interests (Art. 21).

🤖

Automated Decision-Making

Request human review of any significant decision made solely by automated means, including AI-based candidate ranking (Art. 22).

↩️

Withdraw Consent

Withdraw any consent you have given at any time. Withdrawal does not affect the lawfulness of prior processing (Art. 7(3)).

We will respond to all rights requests within 30 days. Complex requests may take up to 3 months with notice. There is no charge for standard requests.

🔒Data Security Measures

ScoutRex implements appropriate technical and organisational measures under Article 32 GDPR to protect personal data against unauthorised access, disclosure, alteration, or destruction.

  • Encryption in transit: All data is transmitted over TLS 1.2+ (HTTPS). API endpoints are certificate-pinned.
  • Encryption at rest: Database storage is AES-256 encrypted. Backups are encrypted and stored in geographically separate locations.
  • Access control: Role-based access control (RBAC) with least-privilege principles. Employee access to personal data is logged and audited.
  • Pseudonymisation: Candidate data used in AI model training is pseudonymised and never linked back to identifiable profiles.
  • Penetration testing: Annual third-party penetration tests and continuous automated vulnerability scanning.
  • Breach notification: Documented incident response plan with 72-hour supervisory authority notification commitment where required by Art. 33.

🌍International Data Transfers

Where personal data is transferred outside the EEA, we ensure adequate safeguards are in place in accordance with Chapter V GDPR:

  • EU Standard Contractual Clauses (SCCs): We use the European Commission's 2021 SCCs with all non-EEA processors.
  • Adequacy decisions: Transfers to countries recognised by the European Commission as providing adequate protection (e.g. UK under the UK GDPR adequacy decision) are permitted without additional safeguards.
  • Transfer Impact Assessments (TIAs): We conduct TIAs before transferring data to high-risk jurisdictions and implement supplementary measures where necessary.

EU data residency option

Enterprise customers can request that their data be stored and processed exclusively within the EU. Contact privacy@scoutrex.com to activate this option.

🗓️Data Retention

We retain personal data only for as long as necessary for the purpose it was collected, or as required by law (Article 5(1)(e) GDPR, storage limitation).

  • Active accounts: Data is retained for the duration of the account relationship.
  • Deleted accounts: Personal data is fully anonymised or erased within 30 days of account deletion, except where legal obligations require longer retention.
  • Financial records: Invoicing and transaction data retained for 7 years as required by applicable accounting law.
  • Support tickets: Retained for 2 years to support follow-up requests and service improvement.
  • Application logs: Server logs containing IP addresses are purged after 90 days.

🍪Cookies & Tracking

We use cookies in accordance with the ePrivacy Directive (Cookie Law) and GDPR. A cookie consent banner is displayed on your first visit.

  • Strictly necessary cookies: Required for the website and platform to function (login sessions, security). No consent needed.
  • Analytics cookies: Used to understand how visitors interact with our website, only set with your consent.
  • Preference cookies: Remember your settings such as dark mode and language preferences, only set with your consent.
  • Marketing cookies: ScoutRex does not use third-party advertising or remarketing cookies.

You can update your cookie preferences at any time via the Cookie Preferences link in our footer.

👤Data Protection Officer

ScoutRex has appointed a Data Protection Officer (DPO) responsible for overseeing our GDPR compliance programme. You may contact the DPO directly for any privacy-related concerns:

Contact our DPO

Email: privacy@scoutrex.com
Subject line: "GDPR, [Your Request Type]"
We aim to acknowledge all DPO contacts within 2 business days.

📣Complaints & Supervisory Authority

If you believe we have not handled your personal data in accordance with GDPR, we encourage you to contact us first at privacy@scoutrex.com so we can try to resolve the matter directly.

You also have the right to lodge a complaint with the supervisory authority in the EU member state where you live, work, or where the alleged infringement occurred. For example:

  • Ireland: Data Protection Commission (DPC), dataprotection.ie
  • Germany: Bundesbeauftragter für den Datenschutz (BfDI)
  • France: Commission Nationale de l'Informatique et des Libertés (CNIL)
  • UK: Information Commissioner's Office (ICO), ico.org.uk

Privacy questions?

Our privacy team is here to help. Reach out with any GDPR or data protection questions.

📧 Contact Privacy Team