Candidate (Job Applicant) Privacy Notice At Zilch Technology Limited (“Zilch”, “we”, “our”, “us”), we respect your privacy and are committed to protecting your personal data. We are registered with the UK data protection authority, the Information Commissioner’s Office (ICO), under registration number ZA522707. This privacy notice explains how we collect, use, store, and share your personal data when you apply for a role with us, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This notice applies to all job applicants and candidates during the recruitment process. If you are successful and join Zilch, a separate privacy notice will then apply. It is important that you read this Candidate Privacy Notice carefully so that you fully understand how and why we use your information. This privacy notice is provided in a layered format so you can click through to the specific areas set out below. Information we collect about you How we collect your information How we use your information Who we share your data with International transfers Retention of your data Automated decision-making Your legal rights Consequences of not providing information Data security How to contact us and make a complaint Changes to this notice 1. Information we collect about you Personal data, or personal information, means any information about an identified or identifiable individual. It does not include anonymous data, which cannot be linked back to the individual. When you apply for a job at Zilch, we may collect and process the following personal data: Basic and Contact Information Full name, title, and date of birth. Home address, personal email address, and phone number. Preferred pronouns. Application and Employment History CV, cover letter, application form responses. Details of your education, skills, qualifications, and work experience. Publicly available professional data (e.g., LinkedIn profile). Salary expectations and other information relating to compensation and benefits packages. Notice period. Referees’ names and contact details. Recruitment Process Data Interview notes, test results, assessments, and hiring manager feedback. Internal correspondence relating to your application. Any other information you give us, or observations we make through interviews, that are relevant for your application. Special Category Data (if you choose to provide it) Health or disability information (to make reasonable adjustments). Equal opportunity monitoring information such as ethnicity, gender identity, sexual orientation, or religion. Background Checks Data (collected only once you have accepted a job offer with Zilch) Information about criminal convictions and offences, where required by law. Credit history or directorship information, if relevant for senior or regulated roles. Proof of identity documents such as passport, visa, or work permit. Right to work check information, as required by law. Reference information from previous employers, managers or colleagues. 2. How we collect your information We may collect your personal data through: Direct interactions: When you apply via our careers page, email, or directly to our recruitment team. Recruitment platforms: We use Greenhouse, our Applicant Tracking System (ATS), to manage applications. Third parties: Recruitment agencies, background check providers, referees, or publicly available professional networking sites such as LinkedIn or job boards. Internal sources: Interviewers, hiring managers, or HR team members. 3. How we use your information We process your data for clear and specific purposes with lawful bases under UK GDPR. We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. PurposeLegal Basis• Assess your suitability, skills, and qualifications for the role.• Communicate with you about the recruitment process.• Operate our application tracking system, including generating analytics relating to recruiting.• Use recruitment tools such as note-taking, summaries, and analytics to optimise hiring.• Manage the performance of our recruitment process. • Check you references and vet information you give us in your CV. • Keep a copy of your application data if you let us know you want to be considered for other roles. Steps before entering into a contract with you. Legitimate interest in administering our relationship with you and operating our business. • Verify your identity• Conduct pre-employment background checks, as permitted or required by applicable law.• Carry out right-to-work and pre-employment checks.• Make reasonable adjustments for disabilities.• Retain records for compliance, reporting, and audit. • Protect our legal rights, such as in legal proceedings, obtaining legal advice and establishing or defending legal claims. Legal obligation• Monitor diversity, equality, and inclusion by collecting diversity data.Explicit consent 4. Who we share your data with Your data will only be shared where necessary and for lawful purposes, including: Across Zilch between the different teams taking part in your recruitment process, this includes, hiring managers, interviewers, and the HR/recruitment team. With third party service providers which provide us with services to store and manage applications, schedule interviews, and perform technical assessments of applications; like Greenhouse. With background checks providers that carry this activity on our behalf. We use Veremark (UK), and you can read their privacy policy for more information how they process your personal data at https://www.veremark.com/legal/privacy-policy . With recruitment agencies if your profile was originally provided by them. With you referees you have provided. With law firms or other advisors helping us to protect Zilch’s legal rights. With regulators or government bodies, for example, to demonstrate compliance with right-to-work requirements. 5. Who we share your data with Some of our service providers are based outside the UK, which means your personal data may be transferred or stored internationally. When this happens, we ensure it is protected by using appropriate safeguards, such as: Adequacy Decisions: Where the UK Government has confirmed that the country provides an adequate level of data protection. Approved Contracts: If no adequacy decision exists, we use UK-approved contracts, such as the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), to ensure your data remains protected to UK standards. 6. Retention of your data We keep your personal data only for as long as necessary to manage the recruitment process and comply with legal and regulatory obligations. If you are offered and accept a role with Zilch, the information collected during the recruitment process will become part of your employee record. You will receive a separate privacy notice at that stage. If your application is unsuccessful, or if you withdraw or decline an offer, we will keep your data for 24 months before securely deleting it, unless we are required by law to keep it longer. 7. Automated decision-making We do not use any automated decision-making or profiling during our recruitment process that have a legal or other significant effect on you as part of our recruitment. 8. Your legal rights Under the UK GDPR, you have the following rights: Access: Request a copy of your personal data. Rectification: Request corrections to inaccurate or incomplete data. Erasure: Ask us to delete your data, subject to legal requirements. Restriction: Request we limit how we process your data. Portability: Receive your data in a portable format. Object: To processing based on our legitimate interests. Withdraw consent: Where we rely on your consent, you can withdraw it at any time. To exercise these rights, please email [email protected] 9. Consequences of not providing information If you do not provide information necessary for evaluating your application, we may be unable to process your application or proceed with employment checks. 10. Data security We take the protection of your personal data very seriously. Zilch uses appropriate technical and organisational measures to keep your information secure and to prevent unauthorised access, loss, misuse, or alteration. When deciding on the right level of security, we consider the latest technology, industry best practices, and the potential risks to your data. Our measures are designed to safeguard your information and reduce the risk of harm that could result from a data breach. 11. How to contact us and make a complaint If you have any questions about this notice or how we handle your data, please contact us at: Email: [email protected] Address: 111 Buckingham Palace Road, London, England, SW1W 0SR United Kingdom. If you are not satisfied with our response, you have the right to lodge a complaint with the ICO: https://ico.org.uk 12. Changes to this notice We may update this notice from time to time to reflect changes in the law or our recruitment practices. The latest version will always be available on this page. Last Updated: October 2025