Red Snapper Group

Privacy Notice

20th August 2026

Who we are

Red Snapper Group Ltd is the data controller for this notice, together with its subsidiary companies and our associate company. Each is registered with the Information Commissioner’s Office.

CompanyICO registration reference
Red Snapper Recruitment LimitedZ9838283
Red Snapper Media LimitedZA069291
Red Snapper Managed Services LimitedZA518026
Red Snapper Learning LtdZA275777
999 Learning LimitedZB028331

Our address is Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA. Our telephone number is 020 3119 3300.

We have appointed a Data Protection Officer. You can contact the DPO at dpo@redsnappergroup.co.uk.

Who this notice covers

This is the central privacy notice for the Red Snapper Group. Our other websites link to it.

It explains how we handle personal data about:

  • Visitors to our websites
  • Candidates and applicants for roles we recruit for
  • Learners and delegates on our training courses
  • Clients, and the staff of our clients
  • Suppliers, and the staff of our suppliers
  • Anyone who contacts us by phone, email or through a form

It does not cover our own employees, workers and contractors. They receive a separate privacy notice.

On some contracts we deliver services for a public body, for example a police force, a probation service or a local authority. In those cases the commissioning body is usually the data controller for the service user data, and we act as their processor. The commissioning body’s own privacy notice applies to that data. Contact us if you are not sure which notice applies to you.

The information we collect

Website visitors

  • Device and connection data, including IP address, browser type and operating system
  • Pages you visit and how you reached the site
  • Cookie data, as described in the cookies section below

Candidates and applicants

  • Name, address, telephone number and email address
  • CV, work history, qualifications and references
  • Right to work documentation
  • Vetting and clearance information, where a role requires it
  • Interview notes, assessment results and screening outcomes
  • Recordings, transcripts and scores from an AI screening interview, where you opt in

Some of the roles we recruit for are in policing, offender management and other regulated settings. For those roles we also collect criminal offence data, including criminal convictions, cautions and the results of vetting or DBS checks. We collect this only where the role requires it and where the law allows us to.

Learners and delegates

  • Name, employer, job role and contact details
  • Course bookings, attendance and completion records
  • Assessment results and certification
  • Accessibility or dietary requirements you tell us about

Clients and suppliers

  • Name, job role and business contact details
  • Contract, order and invoice records
  • Correspondence with us

Everyone who contacts us

  • The content of your message or call
  • Call recordings, as described below
  • Marketing preferences

We may also collect special category data, for example health information you give us so that we can make an adjustment for you, or diversity monitoring data where you choose to provide it.

How we collect it

We collect personal data:

  • Directly from you, when you use our websites, apply for a role, book a course or contact us
  • From your employer or your client, where they engage us
  • From recruitment job boards and professional networking sites
  • From referees, former employers and background check providers
  • From vetting and disclosure bodies, where a role requires a check
  • Automatically, through cookies and analytics on our websites

Why we use it and our lawful basis

What we doWhyLawful basis
Run and secure our websitesTo deliver the site and prevent misuseLegitimate interests
Handle your enquiryTo answer youLegitimate interests, or steps before a contract
Recruit for rolesTo assess suitability and place candidatesSteps before a contract, and legitimate interests
Check right to work and vettingTo meet legal and contractual requirementsLegal obligation, and substantial public interest for criminal offence data
Deliver training and certificationTo provide the course you or your employer bookedContract
Manage client and supplier relationshipsTo deliver and receive servicesContract, and legitimate interests
Record callsQuality, training, dispute resolution and legal complianceLegitimate interests, legal obligation, and contract where relevant
Send marketingTo tell you about our servicesConsent, or legitimate interests for existing business contacts
Meet accounting, tax and audit dutiesBecause the law requires itLegal obligation
Prevent fraud and protect our systemsTo keep data and people safeLegitimate interests

Where we rely on legitimate interests, we balance our interests against your rights. You can ask us for the assessment we carried out.

Where we rely on consent, you can withdraw it at any time. Withdrawing consent does not affect anything we did before you withdrew it.

Special category and criminal offence data

We only handle special category data where a further condition applies. Usually this is your explicit consent, a legal obligation in employment or equalities law, or the establishment or defence of a legal claim.

We handle criminal offence data only where the law allows it, and under our data protection policy. For recruitment this is normally because the role is exempt from the Rehabilitation of Offenders Act 1974, or because a client contract requires vetting to a defined standard.

Call recording

We record calls to and from our organisation for the following purposes:

  • Quality assurance, to monitor and improve our service
  • Staff training and professional development
  • Dispute resolution, to keep an accurate record
  • Legal compliance, to meet our regulatory duties

Recordings are stored securely. Only authorised staff can access them. We keep them in line with our retention schedule.

Our lawful bases for recording calls are legitimate interests under Article 6(1)(f) UK GDPR, legal obligation under Article 6(1)(c), and where relevant performance of a contract under Article 6(1)(b).

Cookies and analytics

Our websites use cookies. Our cookie tool separates them into two groups.

Strictly necessary cookies make the site work. Examples are session management and security.

Marketing cookies help us measure and target our advertising.

We ask for your choice before we set any marketing cookie. You can change your choice at any time in the cookie tool.

Automated decision-making and AI

Automated decision-making takes place when an electronic system uses personal data to make a decision without human involvement.

We do not make decisions about you based solely on automated processing that would have a legal or similarly significant effect on you. We will tell you if this changes.

For some job applications we offer an AI screening interview. You choose whether to take part. If you opt in, the AI feature within our recruitment system assesses your responses and produces a score. A member of our recruitment team reads and reviews that score, and a person decides whether your application progresses.

If you take part, you can ask us how the score was produced and what it was used for. You can also give your view on the outcome, and ask us to reconsider it. Contact dpo@redsnappergroup.co.uk.

We do not use special category data in the AI screening interview.

Who we share it with

We share personal data with:

  • Clients, where you are a candidate we are putting forward
  • Our recruitment system provider, which also supplies the AI screening feature
  • Our IT, hosting and communications providers
  • Vetting, background check and right to work verification providers
  • Professional advisers, including solicitors, auditors and bankers
  • Other companies in the Red Snapper Group, where the service requires it
  • Government bodies, regulators and law enforcement, where the law requires it
  • A buyer or successor, in the event of a sale or restructure of the business

We put a written contract in place with every processor. We do not allow them to use your data for their own purposes.

You can ask us to identify the provider behind any of these services. Contact dpo@redsnappergroup.co.uk.

Sending data outside the UK

Some of our providers are outside the UK. Where we transfer personal data outside the UK, we use one of the following safeguards:

  • UK adequacy regulations
  • The UK International Data Transfer Agreement
  • Standard Contractual Clauses with the UK International Data Transfer Addendum
  • Binding corporate rules

You can ask us for a copy of the safeguard that applies to a specific transfer.

How long we keep it

We keep personal data only for as long as we need it, including to meet legal, accounting and reporting requirements.

As a general rule we keep records for six years. This reflects the period in which a legal claim can normally be brought, and the periods that tax and accounting law require.

Some records are kept for a shorter or longer period. To decide the right period we consider the amount and sensitivity of the data, the risk of harm from unauthorised use or disclosure, the purpose we hold it for, whether we can achieve that purpose another way, and what the law requires. Our retention schedule sets the period for each type of record. You can ask us for the period that applies to your data.

We may anonymise data so that it can no longer identify you. We can use anonymised data without further notice to you.

How we protect it

We have technical and organisational measures in place to prevent personal data being lost, misused, altered or accessed without authorisation.

We limit access to staff and providers who need it for their role. They are under a duty of confidentiality.

We have procedures for handling a suspected personal data breach. We will notify you and the ICO where the law requires it.

Your rights

In certain circumstances you have the right to:

  • Ask for access to the personal data we hold about you
  • Ask us to correct data that is inaccurate or incomplete
  • Ask us to erase your data
  • Ask us to restrict how we use your data
  • Object to our use of your data, including for direct marketing
  • Ask us to transfer your data to you or to another organisation
  • Withdraw your consent, where we rely on it

To use any of these rights, contact dpo@redsnappergroup.co.uk. Please tell us which right you want to use.

We may ask you for information to confirm your identity. This protects your data from being disclosed to someone else.

You do not pay a fee. If a request is clearly unfounded or excessive, we may charge a reasonable fee or refuse it. We will explain our reasons if we do.

We respond within one month. If your request is complex, or if you make several requests, we may extend this by up to two further months. We will tell you within one month if we need to extend, and why.

How to complain to us

If you have a question or concern about this notice, or about how we handle your personal data, contact our Data Protection Officer at dpo@redsnappergroup.co.uk.

You also have the right to complain to us if you believe we have infringed your rights in relation to your personal data. Send your complaint to the Data Protection Officer at dpo@redsnappergroup.co.uk.

You do not need to raise the matter informally first. You do not need to use a particular form. If you prefer, you can complain by post to Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA, or by telephone on 020 3119 3300. We accept a data protection complaint however you send it.

When we receive a data protection complaint, we will:

  • Acknowledge it no later than 30 days after we receive it
  • Take appropriate steps to respond without undue delay, which may include making enquiries and keeping you informed of progress
  • Tell you the outcome without undue delay, and tell you how to escalate if you remain dissatisfied

Complaints about our services, rather than about your personal data, follow our Complaints Policy. You can request a copy from compliance@rsg.ltd.

How to complain to the ICO

You also have the right to complain to the Information Commissioner’s Office. The ICO is the UK supervisory authority for data protection.

Information Commissioner’s Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF

Helpline: 0303 123 1113 Website: https://www.ico.org.uk

We would ask you to raise your complaint with us first, so that we have a chance to put things right.

Changes to this notice

We review this notice at least once a year. We may update it at any time. Where a change is substantial, we will make that clear on our websites.

The date at the top of this notice shows when we last updated it.