Official English legal document
PRIVACY POLICY
How YokeConnect collects, uses, shares and protects personal data
YokeConnect Ltd, company number 17334598, registered office: The Pagoda, 30 Avenue Road, Bournemouth, BH2 5SL, United Kingdom
This is the approved, authoritative English legal document. Contact support@yokeconnect.com if you need help understanding any term.
Website: https://yokeconnect.com | Email: admin@yokeconnect.com
1. Who we are
YokeConnect Ltd operates the YokeConnect hospitality hiring platform. We are a company registered in England and Wales under company number 17334598. Our registered office is The Pagoda, 30 Avenue Road, Bournemouth, BH2 5SL, United Kingdom.
For privacy questions, rights requests or data-protection complaints, contact admin@yokeconnect.com.
2. Scope of this policy
This policy applies to visitors to https://yokeconnect.com, waitlist members, Candidates, Employers, Authorised Users, prospective users, support contacts and other people whose personal data is processed through YokeConnect.
It covers the public website, waitlist, authenticated web Platform, business verification, subscriptions, jobs, applications, messaging, document workflows, support and administration. It does not describe a native mobile application or YokeCourses because neither is part of the launch service. We will update this policy before activating materially different processing, including live AI CV processing, third-party analytics or training services.
3. Our data-protection roles
YokeConnect acts as controller when it decides why and how personal data is processed for Account creation, profile and job discovery, Platform security, subscription management, communications, moderation, business verification, support, compliance and service administration.
An Employer normally acts as a separate controller for Candidate data it accesses, exports, records or uses for its own recruitment, onboarding, employment or workforce-management purposes. YokeConnect may act as processor for limited Employer-directed activities described in the Data Processing Agreement. The factual processing determines the legal role; a contract label does not override reality.
4. Personal data we collect
People / context | Data categories |
|---|---|
Website visitors and waitlist members | Name, email, country or region, user type, waitlist answers, referral or invitation details, marketing preferences, enquiry content, IP and device data, user-agent information, timestamps, security records and consent versions. |
Candidates | Name, email, phone number, country, region, town or city, professional summary, role preferences, work history, skills, qualifications, certificates, languages, nationality, driving status, mobility, availability, preferred locations, portfolio links, GHS.cv data, uploaded CV or approved professional files, applications, screening answers, interview and offer records, messages, blocks, reports and account activity. |
Employers and Authorised Users | Name, job title, email, phone number, legal and trading name, business type, registration and VAT numbers, addresses, website, public contact details, Venue category and size, branding, job postings, Candidate searches, applications, hiring decisions, messages, verification risk and review records, user roles, permissions and account activity. |
Payments and subscriptions | Stripe customer, payment, invoice and subscription identifiers; billing name and address; amount, currency, tax, payment status, renewal, cancellation, refund, entitlement and promotional-code records. Complete card numbers are processed by Stripe and are not stored by YokeConnect. |
Documents and right-to-work evidence | Approved professional documents, document type, issue and expiry information, access records and application-scoped right-to-work evidence where the feature permits it. Files are stored privately and are not publicly accessible. |
Messages, support and moderation | Conversation participants, message content and metadata, read status, reports, blocks, support enquiries, attachments, complaint records, investigation notes, moderation actions, reasons and audit history. |
Technical and security data | Session and authentication records, IP or IP-derived/hash data, device and browser details, request metadata, login and registration events, rate-limit events, security challenges, error and operational logs, audit events and access records. |
Location and maps | Country, region, town or city, preferred work location, approximate or job coordinates, location search text and map requests. Candidate exact residential addresses are not shown on maps. |
5. Data we do not request at launch
YokeConnect does not request or accept passports, visas, BRP or eVisa documents, national identity cards, share codes, National Insurance documents, proof of address or similar government identity documents for Candidate or Employer registration. Prohibited identity files should not be uploaded and may be rejected or deleted.
We do not intentionally request special-category data such as health, race or ethnicity, religious or philosophical beliefs, political opinions, trade-union membership, genetic data, biometric identification data, sex-life or sexual-orientation data, or criminal-offence data. Do not include such information in a CV, message or document unless it is genuinely necessary and lawful. If it is incidentally supplied, we limit processing to what is necessary to operate the requested feature, protect users or comply with law.
Nationality is collected as professional and mobility information but is not used by YokeConnect to make solely automated hiring decisions.
6. How we obtain personal data
We receive data directly from you, from other Platform users interacting with you, from your use of the Services, from payment and hosting providers, and from public business sources such as Companies House. Employers may provide information about job applications, interviews, offers, hires, references or reports. We may infer limited operational information such as Account status, risk indicators or approximate location from the information and technical data available to us.
7. Why we use personal data and our lawful bases
Purpose | Typical lawful basis |
|---|---|
Create and manage Accounts; verify email; provide profiles, jobs, search, applications, messaging, subscriptions and support. | Performance of a contract or steps requested before a contract. Legitimate interests for visitors and business contacts where no contract exists. |
Process payments, invoices, refunds, promotional entitlements and renewals. | Performance of a contract; legal obligations for tax and accounting; legitimate interests in preventing payment abuse. |
Make Candidate profiles and selected information visible in accordance with visibility and application choices. | Performance of a contract; legitimate interests in operating a direct hospitality hiring network. |
Review Employers, jobs, reports and suspicious activity; prevent fraud, misuse, spam, exploitation and security incidents. | Legitimate interests in a safe and secure Platform; legal obligations where applicable. |
Send verification, service, security, application, support, payment and legal notices. | Performance of a contract; legitimate interests; legal obligations. |
Send marketing or promotional messages. | Consent where required. For existing business contacts, legitimate interests may apply where electronic-marketing law permits. You can opt out at any time. |
Comply with law, respond to authorities, establish or defend legal claims and maintain audit records. | Legal obligation and legitimate interests in legal protection. |
Improve reliability, debug errors, measure operational performance and develop features without third-party behavioural tracking. | Legitimate interests in improving and securing the Services, balanced against user rights. |
Handle data-protection complaints and rights requests. | Legal obligation and legitimate interests in accountability. |
Where we rely on legitimate interests, we assess the purpose, necessity and impact on individuals. You may object to processing based on legitimate interests; we will consider whether compelling grounds require it to continue.
8. Candidate visibility and recruitment data
When full discovery features are enabled, Candidate profiles are discoverable by default unless the Candidate selects a private or limited setting. Employers may see professional information relevant to recruitment. Candidates control whether particular documents or application-scoped evidence are shared. Exact home addresses are not displayed.
Once an Employer lawfully accesses or exports Candidate data for its own recruitment, it becomes responsible for its use as an independent controller. Employers must provide their own privacy information where required. YokeConnect cannot erase copies held independently by an Employer, but we may assist with contact or evidence where appropriate.
9. Right-to-work evidence and professional documents
Permitted right-to-work evidence is stored in private Cloudflare R2 object storage, with ownership and access metadata in Neon PostgreSQL. Access is limited to the Candidate, authorised application-context Employers and narrowly authorised YokeConnect personnel where support, safety, legal or technical access is necessary. Download access should be time-limited.
YokeConnect does not approve the evidence or perform the Employer's statutory check. Employers remain responsible for lawful right-to-work verification and for information they retain outside YokeConnect.
10. Messages and communications
Messages are stored in Neon PostgreSQL when messaging is enabled. They are encrypted in transit and protected by provider-managed encryption at rest, but are not end-to-end encrypted. We do not give administrators routine unrestricted access to all conversations. Authorised access may occur for reported content, support, security, legal compliance or protection of rights.
A sender may be able to hide or soft-delete a message from normal view, but an underlying record may remain for integrity, safety, legal or backup reasons.
11. Payments
Stripe processes card and payment-method details, fraud signals and payment authentication. YokeConnect stores Stripe identifiers, amounts, tax, invoice, subscription, entitlement and status records. Stripe acts under its own privacy information for some payment activities and as our processor for contracted payment services.
12. AI and automated decisions
YokeConnect uses the OpenAI API only when a Candidate deliberately selects an AI writing-assistance action. Only the text submitted for that action is sent to OpenAI. Deterministic CV importing remains enabled and does not use OpenAI. Candidates must not submit passports, visas, right-to-work evidence, bank details or other identity documents to the writing assistant. AI suggestions are optional, must be reviewed by the Candidate and do not make automated hiring decisions.
YokeConnect does not make solely automated decisions at launch that produce legal or similarly significant effects on Candidates or Employers. Risk flags and search ranking may support human or user decisions, but final Account moderation and hiring decisions involve human judgement or the relevant Employer.
13. Cookies, storage and analytics
The launch Platform uses essential cookies and browser storage for authentication, security, language, preferences, navigation and reliability. No Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, Hotjar, Mixpanel, PostHog or equivalent advertising or behavioural analytics tracker is installed at launch.
Cloudflare may set conditional security cookies when Access, Turnstile or a security challenge is used. Stripe may use necessary fraud-prevention and payment cookies on its hosted pages. Map pages send requests to OpenStreetMap-related services and external asset CDNs. See the Cookie Notice for the current inventory and choices.
14. Who we share personal data with
Recipient / provider | Purpose and main processing location |
|---|---|
Vercel | Frontend hosting, deployment and edge delivery. Primary processing facilities in the United States with global edge delivery. |
Microsoft Azure | API and application hosting in UK West, with provider support and operational functions that may be global. |
Neon | Managed PostgreSQL. The live database is hosted on AWS eu-west-2 in London; provider operations may be global. |
Cloudflare | DNS, security edge, Access, Turnstile and private R2 document storage. Cloudflare operates globally. The launch R2 bucket uses Automatic location and does not guarantee UK or EU-only storage. |
Postmark | Transactional email delivery and bounce or complaint events through US and global infrastructure. |
Zoho Mail | Human-operated support and administration mailboxes. The account uses the EU data centre, with possible support or subprocessors elsewhere. |
Stripe | Payment, subscription, invoicing, authentication and fraud prevention through global infrastructure. |
OpenAI | Optional Candidate-initiated CV writing assistance. Only text selected by the Candidate for enhancement is sent through OpenAI infrastructure, which may process data outside the UK or EEA under contracted transfer safeguards. Deterministic CV importing does not use OpenAI. |
OpenStreetMap Foundation / Nominatim | Map tiles and geocoding. Requests may include IP, device, referrer, timestamps and location search text. Infrastructure includes UK, Netherlands and global caches. |
unpkg and cdnjs | Delivery of Leaflet map presentation assets from global content-delivery networks. |
Companies House | Advisory lookup of public UK company information during Employer review. We send company identifiers, not Candidate private data. |
GitHub and development tools | Source control and deployment workflow for developer and administrator data. Production user data should not be placed in source control. |
Google Search Console and Bing Webmaster Tools | Search ownership, crawling and search-performance administration. No client-side behavioural tracking script is installed for these tools. |
Professional advisers, insurers, authorities and transaction counterparties | Legal, accounting, insurance, regulatory, law-enforcement, dispute and genuine corporate transaction purposes, subject to confidentiality and legal safeguards. |
We do not sell personal data. We do not allow advertisers to access private Candidate or Employer account data.
15. International transfers
Some providers and recipients operate outside the United Kingdom and European Economic Area. Where restricted-transfer rules apply, we use an available lawful mechanism such as adequacy regulations or decisions, the UK International Data Transfer Agreement or UK Addendum, EU Standard Contractual Clauses, and supplementary technical and organisational measures. Provider DPAs and transfer terms apply according to the contracted service.
Cloudflare R2 Automatic location is not a residency guarantee. Until a jurisdiction-restricted bucket is implemented, uploaded files may be processed outside the UK or EEA under Cloudflare's contractual safeguards.
16. Retention
We keep personal data only for as long as reasonably necessary for the purpose collected, legal obligations, security, disputes and legitimate business needs. Current operational periods are:
Category | Typical retention |
|---|---|
Active Account and structured profile | For the life of the Account. After verified closure, normally removed from public or user access promptly and deleted or anonymised from active systems within 90 days, unless a longer period is required below. |
Uploaded CV or resume file | A retention date of up to 6 months from upload is applied to the uploaded file, unless it is replaced, refreshed, required for an active application or retained lawfully for a dispute. Structured profile data is treated separately. |
Other professional documents and right-to-work evidence | While required for the active Account or relevant application, then deleted or de-identified within 90 days after the purpose ends or a verified deletion request, unless law or a dispute requires longer retention. |
Messages | While relevant Accounts remain active and normally up to 24 months after Account closure or the last relevant activity. Reported or disputed messages may be retained for up to 6 years where necessary. |
Jobs, applications, interviews and hiring records | Normally for the active recruitment process and up to 24 months after closure, unless a complaint, legal obligation or dispute requires longer. |
Waitlist, invitation and promotional records | Normally up to 24 months after conversion, expiry or last interaction, or until marketing consent is withdrawn where consent is the basis. |
Support, complaints, reports and moderation | Normally 24 months after closure; up to 6 years for material disputes, safeguarding, fraud or legal claims. |
Registration security events | Normally 90 days, unless retained longer for an active security, fraud or legal matter. |
Audit and administrative records | Normally 24 months; up to 6 years where required for accountability, disputes or legal claims. |
Payment, invoice, tax and accounting records | Normally 6 years after the relevant financial year or transaction, or longer if law requires. |
Backups | Deleted data may remain until provider backup or point-in-time recovery cycles expire. Backup copies are protected and are not used for ordinary business purposes. If restored, applicable deletions are re-applied where practicable. |
Retention may be shortened or extended where the data is inaccurate, duplicated, subject to a valid request, needed for a live claim, required by law, or technically held in a provider recovery cycle. We periodically review retained data and may anonymise information for statistical use.
17. Security
Controls include HTTPS/TLS, server-issued HttpOnly and Secure session cookies, backend authorisation, role and permission controls, verified-email policies, CSRF and host controls, rate limiting, Cloudflare security services, private object storage, time-limited file access, provider-managed encryption at rest, audit records, health checks and restricted administrative access.
No online service is completely secure. We maintain incident-response and complaint processes and will notify regulators and affected people where law requires. You must use a strong unique password, protect your device and report suspected compromise promptly.
18. Your rights
Depending on applicable law, you may have rights to:
receive information about processing and access a copy of your personal data;
correct inaccurate or incomplete data;
request deletion in appropriate circumstances;
restrict processing;
object to processing based on legitimate interests or to direct marketing;
receive portable data that you provided where the legal conditions apply;
withdraw consent without affecting earlier lawful processing; and
challenge certain automated decisions and request human involvement where applicable.
To exercise a right, email admin@yokeconnect.com. There is no complete automated portability or deletion tool at launch, so verified requests are handled manually. We may ask for information needed to confirm identity and authority. We normally respond within one month, subject to lawful extensions or exemptions.
Deleting YokeConnect data does not automatically delete copies already lawfully held by an Employer as an independent controller. Contact the Employer directly for those copies; we may assist where appropriate.
19. Data-protection complaints
You may make a data-protection complaint by emailing admin@yokeconnect.com with enough information for us to understand the concern. We will acknowledge receipt within 30 days, take appropriate steps to investigate without undue delay, keep you informed where necessary and communicate the outcome.
You may also complain to the Information Commissioner's Office. The ICO website is https://ico.org.uk and its postal address is Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. We ask that you contact us first so we have an opportunity to resolve the issue, but this does not remove your right to contact the ICO.
20. Marketing
Marketing messages are separate from transactional or service communications. You can unsubscribe using the link in a marketing email or by contacting us. We may still send necessary messages about your Account, security, applications, payments, terms or legal changes.
21. Age
Candidate Accounts are intended for people aged 16 or over. Employer users must be 18 or over and authorised by the business. We do not knowingly provide Candidate Accounts to children under 16. If we learn that data was collected contrary to this rule, we will investigate and delete or restrict it as appropriate.
22. Changes to this policy
We may update this policy when the Platform, providers, laws or processing change. The current version and date will be published on YokeConnect. We will give additional notice where a change is material or consent is required.
23. Contact
YokeConnect Ltd
Company number: 17334598
Registered office: The Pagoda, 30 Avenue Road, Bournemouth, BH2 5SL, United Kingdom
Email: admin@yokeconnect.com
Website: https://yokeconnect.com