top of page

Privacy Policy

Privacy Policy and Data Protection (UK GDPR) Notice · Last updated 1 October 2026

This is our Privacy Policy and our data protection notice under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR), each as amended by the Data (Use and Access) Act 2025. It explains what personal information we collect, why we use it, who we share it with, how long we keep it and what rights you have.

If you are a candidate, please also see our Candidate Terms of Engagement. If you are a client, our Terms and Conditions of Business set out how clients must protect the candidate information we share with them.

1. Who we are

Stratosphere Executive Ltd ("Stratosphere", "we", "us") is an executive search and recruitment consultancy, operating as an employment agency. We are registered in England and Wales, company number 13771634. Our registered office is Ground Floor, 1 Crown Walk, Jewry Street, Winchester, Hampshire, SO23 8BB.

For the personal information described in this policy we are the "controller", meaning we decide how and why it is used.

Our Data Protection Lead is responsible for how we handle personal information. You can contact them at any time about anything in this policy:

  • Email: contact@stratospheregroup.co.uk (marked for the attention of the Data Protection Lead)

  • Telephone: 020 7031 9929

  • Post: Data Protection Lead, Stratosphere Executive Ltd, Ground Floor, 1 Crown Walk, Jewry Street, Winchester, Hampshire, SO23 8BB

2. Who this policy applies to

This policy applies to:

  • candidates – people we identify, approach or interview, or who contact us about roles or their career;

  • client and prospective client contacts – people at organisations that use, or may use, our services;

  • referees and other third parties whose details are given to us;

  • website visitors and people who contact us through our website; and

  • suppliers and other business contacts.

3. The personal information we collect

Candidates

  • Identity and contact details: name, address, telephone number, email address and professional profile links.

  • Career information: CV, employment history, education, qualifications, professional memberships, skills and career interests.

  • Package and preferences: current and desired salary and benefits, notice period, location and mobility, and any organisations you have asked us not to approach.

  • Anonymised profiles: summaries of your experience and salary expectations that we prepare with you, from which your name and contact details are removed.

  • Confirmation information: your confirmation of your identity, of any qualifications or professional memberships a role requires, and that you are willing to be put forward for it, which we obtain before introducing you to an employer by name. Employers are responsible for their own pre-employment checks, including right-to-work checks, unless they ask us to provide screening as an additional service.

  • Screening and assessment information: where an employer asks us to provide pre-employment screening or psychometric assessment as an additional service, the information needed for those checks and assessments and their results. We will always tell you before any check or assessment takes place.

  • Assessment information: our interview and meeting notes, your suitability for particular roles, feedback from clients, and references where you have agreed we may take them.

  • Records of our communications with you, and of your agreement to our Candidate Terms and to each introduction.

Client and business contacts

  • Name, job title, employer, business contact details and records of our communications.

  • Information about your hiring requirements, and billing and account contacts.

Website visitors

  • Technical information such as IP address (from which approximate location can be inferred), browser and device type, and pages viewed, collected through cookies and similar technologies (see section 14).

  • Anything you type into a contact or CV upload form or send us by email.

Referees and other third parties

  • Name, contact details, job title and relationship to the candidate.

4. Where we get your information from

  • From you – when you send us a CV, complete a form, speak to us or correspond with us.

  • From publicly available sources – we identify potential candidates through sources such as professional networking sites, company websites, professional directories and industry publications.

  • From clients – for example details of a role, or feedback about a candidate.

  • From other people – such as referees you have named, or someone who recommends you to us.

  • Automatically – when you use our website.

If we obtain your information from someone other than you, we will tell you who we are, what information we hold, why, and where it came from, when we first contact you and in any event within one month of obtaining it.

5. How we use your information and our legal basis

We must have a legal basis under the UK GDPR for each use of personal information. The list below sets out our main uses and the basis we rely on.

Identify, approach and assess candidates; keep a database of candidates; match candidates to roles

Who it concerns: Candidates

Our legal basis: Legitimate interests – our interest, and our clients' interest, in finding suitable people for roles, and the candidate's interest in hearing about relevant opportunities. Where you ask us to act for you, steps taken at your request before entering into a contract.

Share an anonymised profile with employers, and share your name, CV and details with a specific employer once you have agreed

Who it concerns: Candidates

Our legal basis: Legitimate interests in placing suitable candidates with employers who are recruiting. We will not share your name, contact details or CV with an employer without first obtaining your agreement to that employer.

Confirm a candidate's identity, relevant qualifications and willingness to be put forward before introducing them

Who it concerns: Candidates

Our legal basis: Legal obligation (the Conduct of Employment Agencies and Employment Businesses Regulations 2003) and legitimate interests.

Carry out pre-employment screening or psychometric assessment, where an employer has asked us to as an additional service

Who it concerns: Candidates

Our legal basis: Legitimate interests – ours and the employer's – in helping the employer make an informed appointment. We tell you before any check or assessment takes place and share the results only with that employer. For criminal record checks, see section 6.

Enter into and perform contracts with clients; invoice and collect fees

Who it concerns: Client contacts

Our legal basis: Contract, and legitimate interests in running our business and dealing with the individuals at our clients.

Business development – contacting business contacts about our services

Who it concerns: Client and prospective client contacts

Our legal basis: Legitimate interests in promoting our services to relevant people (see section 7). We rely on consent where the law requires it.

Operating, securing and improving our website

Who it concerns: Website visitors

Our legal basis: Legitimate interests in running a secure and effective website. Consent for any cookies that require it (see section 14).

Tax, accounting, company law and employment agency record-keeping; responding to regulators, courts or lawful requests

Who it concerns: Everyone

Our legal basis: Legal obligation.

Establishing, exercising or defending legal claims, including fee disputes

Who it concerns: Everyone

Our legal basis: Legitimate interests in protecting our legal position.

Handling data protection requests and complaints

Who it concerns: Everyone

Our legal basis: Legal obligation and legitimate interests.

Where we rely on legitimate interests, we have considered whether our interests are outweighed by your rights and freedoms, and you have the right to object (see section 12). You do not have to give us personal information, but if you do not, there may be limits on what we can do for you.

6. Special category and criminal offence data

We do not ask for, and do not need, information about your health, race or ethnic origin, religion, sexual orientation, trade union membership or political opinions in order to provide our services, and we ask you not to include it in your CV. If you volunteer it, we will only use it where the law permits and will not share it with an employer unless you ask us to.

We do not routinely collect information about criminal convictions or offences. Where an employer asks us to arrange a criminal record (DBS) check as part of our screening service, we do so only where the role justifies it and the law allows, with your consent, through an authorised checking provider. We share the result only with that employer and keep it only for as long as needed to complete the check.

7. Direct marketing

We may contact business contacts about our services by email, telephone or post where we have a legitimate interest in doing so, the message is relevant to their business and job role, and we comply with PECR. In particular:

  • we will email a person at a limited company, LLP or other corporate body in their business capacity without prior consent only where the law allows; we will obtain consent, or rely on the "soft opt-in" where it applies, for sole traders, most partnerships and other individual subscribers;

  • every marketing message will identify us and include a simple, free way to opt out;

  • we check numbers against the Telephone Preference Service and Corporate Telephone Preference Service before making marketing calls; and

  • you have an absolute right to object to direct marketing at any time. Tell us or use the opt-out link and we will stop, keeping your details on a suppression list so that we do not contact you again.

We do not sell your personal information to anyone.

8. Who we share your information with

We only share personal information where we need to, and we do not sell it. Depending on the circumstances, we share it with:

  • Employers (our clients) – anonymised profiles and, once you have agreed to a specific employer, your name, CV and details, as described in section 5. You can ask us at any time not to share your details with an employer, or with a particular employer. Our Terms and Conditions of Business require clients to keep candidate information confidential, to use it only to consider the candidate, and to delete it when it is no longer needed.

  • Service providers acting on our instructions (our "processors") – our CRM and candidate database provider, website host, cookie consent provider, screening and psychometric assessment providers, email and cloud storage providers, accounting software provider, and any AI-based software tools we use (see section 13). We have written contracts with them that require them to protect your information and use it only on our instructions. We also use professional networking platforms, including their recruiter tools, to identify and contact candidates; these platforms are separate controllers of the information you put on them, and their own privacy policies apply.

  • Professional advisers – such as our accountants, lawyers and insurers.

  • Regulators, courts, law enforcement and other authorities where we are required or permitted by law to do so.

  • A buyer or successor – if our business or part of it is sold or restructured, we may transfer information to the new owner, who will be required to use it in line with this policy.

9. Transfers outside the UK

Some of our service providers, including our CRM provider and our website host, transfer information outside the UK. Where they do, we make sure the transfer is protected as UK law requires – for example because the destination country is covered by UK adequacy regulations (including the UK–US data bridge for certified US organisations), or because the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses is in place. You can ask us for details of the safeguards we use.

10. How long we keep your information

We keep personal information only for as long as we need it for the purposes described in this policy, including legal, tax, accounting and regulatory requirements.

For candidates, this reflects how executive search works: we may want to reconnect with someone years after we first spoke to them, so we do not delete candidate records after a fixed period. Instead, at least every five years, we review our candidate database and remove or anonymise information that is clearly no longer accurate or relevant, or that relates to someone who is no longer a plausible candidate for roles we handle. You can ask us to delete your information at any time, and we will do so unless we need to keep it for a legal reason.

  • Candidate records (CV, notes, communications): for as long as you remain a potential candidate for roles we handle, reviewed at least every 5 years.

  • Records of agreed terms, vacancy details and introductions, required under the Conduct Regulations: at least 1 year after we last provide services to the person concerned, and up to 6 years where needed to deal with any fee dispute.

  • Client and business contact records: for the duration of our relationship and 6 years afterwards.

  • Invoices, accounting and tax records: 6 years from the end of the relevant financial year.

  • Screening and assessment results: until the results have been passed to the employer and any related query is resolved, and no more than 6 months.

  • Website enquiries that do not lead to a relationship: 12 months.

  • Records relating to a complaint, dispute or legal claim: until the matter is resolved, plus 6 years.

  • Marketing opt-outs (suppression list): for as long as needed to make sure we honour your request.

11. Keeping your information secure

We use appropriate technical and organisational measures to protect personal information against unauthorised or unlawful processing and against accidental loss, destruction or damage. These include encryption and two-factor authentication on our devices and systems wherever available, access controls, secure storage, and care in checking recipients before information is sent. No internet-based system can be guaranteed to be completely secure.

If a personal data breach occurs, we will investigate and contain it. Where it is likely to result in a risk to individuals we will report it to the ICO within 72 hours of becoming aware of it, and where the risk is high we will also tell the people affected without undue delay.

12. Your rights

Under UK data protection law you have the right to:

  • be informed about how we use your information (this policy);

  • access a copy of the personal information we hold about you;

  • have inaccurate information corrected and incomplete information completed;

  • have your information erased in certain circumstances;

  • restrict our use of your information in certain circumstances;

  • data portability – receive certain information you gave us in a portable format, or have it sent to another organisation, where we process it by automated means on the basis of consent or contract;

  • object to our use of your information where we rely on legitimate interests, and object at any time to direct marketing; and

  • withdraw consent at any time, where we rely on your consent. This does not affect what we did before you withdrew it.

To exercise any of these rights, contact us using the details in section 1. We do not normally charge a fee. We will ask for proof of identity if we need it, and may ask for further information to help us find what you are asking about. We will respond within one month; this can be extended by up to two further months if your request is complex or you have made several requests, and we will tell you if so. The time limit is paused while we wait for information we reasonably need from you. We will carry out reasonable and proportionate searches for the information you have asked for. Some rights are subject to exemptions, and if we cannot fully meet a request we will explain why.

If you make a request through someone else, such as a solicitor, we will need to check they are authorised to act for you.

13. Automated decision-making and AI tools

We may use software, including artificial intelligence (AI) tools, to help us read and organise CVs, search our database and identify candidates who may match a role. These tools support our consultants; they do not decide whether you are put forward for, or offered, a role. A member of our team reviews the results and makes the decision.

We do not make decisions about you based solely on automated processing that have a legal or similarly significant effect on you. If we ever introduce this, we will update this policy first and put in place the safeguards required by law, including your right to ask for human review of the decision and to contest it. Where a supplier's product uses AI to process your information on our behalf, it may only do so on our instructions and under a written contract that requires it to keep your information secure.

14. Cookies and similar technologies

Our website uses cookies – small files placed on your device – and similar technologies. When you first visit our website, a cookie banner asks for your choice.

  • Strictly necessary cookies are set by our website host to make the website work securely (for example, to maintain your session and protect against fraud). These do not require consent.

  • Other cookies, such as analytics, preference or marketing cookies, are only used if you agree to them through our cookie banner. You can accept all cookies, deny all cookies other than strictly necessary ones, or choose which types to allow. Selecting "More Information" on the banner shows the services we use, what each one does and how long its cookies last.

You can change or withdraw your consent at any time through the privacy settings available on every page of our website, or delete or block cookies through your browser settings, although parts of the site may not then work properly.

15. Information about other people

If you give us information about someone else, such as a referee, please make sure they know you are doing so and are happy for you to, and show them a copy of, or link to, this policy.

16. Children

Our services are for working professionals. Our website is not intended for anyone under the age of 18 and we do not knowingly collect information from children.

17. Links to other websites

Our website may link to other websites, such as professional networking sites. We are not responsible for their content or privacy practices, so please read their privacy policies.

18. Complaints

We want to put things right if you are unhappy with how we have handled your personal information. You can complain to us at any time by email, telephone or post using the details in section 1. You do not need to use any special wording or mention data protection.

When we receive a complaint we will acknowledge it within 30 days, investigate it without undue delay, keep you informed of progress, and tell you the outcome and any action we are taking. If someone is complaining on your behalf we will need to check they are authorised to do so.

You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office, whether or not you have complained to us first:

  • Website: www.ico.org.uk/make-a-complaint

  • Telephone: 0303 123 1113

  • Post: Information Commissioner's Office, 4th Floor, No. 3 Circle Square, 5 Hawkshaw Street, Manchester, M1 7BL

19. Changes to this policy

We review this policy regularly and may update it. The current version is always available on our website and shows the date it was last updated. If we make significant changes that affect how we use your information, we will take reasonable steps to tell you.

bottom of page