Privacy Policy
Last updated: 9 January 2026
Stone and Co – People Management (“we”, “us”, “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our website or engage with our services.
We operate as a global HR and talent acquisition consultancy and handle personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Data Controller:
Stone and Co – People Management
Company Number: 16506361
Email: office@stoneandcopeople.com
If you have any questions about this policy or how we handle your data, you can contact us using the email address above.
2. Personal Data We Collect
We may collect and process the following categories of personal data:
a) Information You Provide Directly
- Name
- Email address
- Company name and job title
- CVs, resumes, cover letters, and career history
- Enquiry details submitted via contact forms
- Any other information you choose to provide
b) Recruitment & Talent Data
Where relevant, we may process:
- Employment history
- Skills, qualifications, and experience
- Right-to-work information (where legally required)
- Referee details (only with appropriate consent)
c) Website Usage Data
- IP address
- Browser type and version
- Pages visited and time spent on the site
- Referring URLs
This data is collected via cookies and analytics tools.
3. How We Use Your Personal Data
We use personal data only where we have a lawful basis to do so, including to:
- Respond to enquiries and provide consultancy services
- Deliver recruitment and talent acquisition services
- Match candidates with suitable opportunities
- Communicate with clients and candidates
- Improve our website and services
- Meet legal or regulatory obligations
4. Lawful Bases for Processing
Our lawful bases under UK GDPR include:
- Consent
- Contractual necessity
- Legitimate interests
- Legal obligation
You may withdraw consent at any time.
5. Sharing Your Data
We do not sell personal data.
We may share data where necessary with:
- Clients engaging our HR or recruitment services
- Trusted service providers (e.g. IT, CRM, email platforms)
- Legal or regulatory authorities where required by law
All third parties are required to process data securely and lawfully.
6. International Data Transfers
As a global consultancy, personal data may be transferred outside the UK.
Where this occurs, we ensure:
- Appropriate safeguards are in place
- Transfers comply with UK GDPR
- Standard Contractual Clauses or equivalent protections are used
7. Data Retention
We retain data only for as long as necessary:
- Enquiry data: up to 24 months
- Candidate data: typically up to 24 months, unless consent is renewed
- Client records: retained in line with contractual and legal requirements
Data is securely deleted or anonymised when no longer required.
8. Cookies & Analytics
Our website uses cookies to:
- Ensure functionality
- Analyse performance
- Improve user experience
You can control cookies through your browser settings.
9. Your Data Protection Rights
You have the right to:
- Access your personal data
- Request correction
- Request erasure
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
To exercise your rights, contact:
📧 office@stoneandcopeople.com
10. Data Security
We apply appropriate technical and organisational security measures, including controlled access and secure systems. While no system is entirely risk-free, we take data protection seriously.
11. Complaints
If you are dissatisfied, you may complain to the UK Information Commissioner’s Office (ICO):
Website: https://ico.org.uk
Helpline: 0303 123 1113
12. Changes to This Policy
We may update this policy from time to time. The latest version will always be available on our website.
Confidence & Compliance Note
This policy aligns with:
- UK GDPR
- Data Protection Act 2018
- ICO guidance for recruitment and consultancy businesses
