Stone & Co People Management

Privacy Policy

Last updated: 9 January 2026

Stone and Co – People Management (“we”, “us”, “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our website or engage with our services.

We operate as a global HR and talent acquisition consultancy and handle personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.


1. Who We Are

Data Controller:
Stone and Co – People Management

Company Number: 16506361
Email: office@stoneandcopeople.com

If you have any questions about this policy or how we handle your data, you can contact us using the email address above.


2. Personal Data We Collect

We may collect and process the following categories of personal data:

a) Information You Provide Directly

  • Name
  • Email address
  • Company name and job title
  • CVs, resumes, cover letters, and career history
  • Enquiry details submitted via contact forms
  • Any other information you choose to provide

b) Recruitment & Talent Data

Where relevant, we may process:

  • Employment history
  • Skills, qualifications, and experience
  • Right-to-work information (where legally required)
  • Referee details (only with appropriate consent)

c) Website Usage Data

  • IP address
  • Browser type and version
  • Pages visited and time spent on the site
  • Referring URLs

This data is collected via cookies and analytics tools.


3. How We Use Your Personal Data

We use personal data only where we have a lawful basis to do so, including to:

  • Respond to enquiries and provide consultancy services
  • Deliver recruitment and talent acquisition services
  • Match candidates with suitable opportunities
  • Communicate with clients and candidates
  • Improve our website and services
  • Meet legal or regulatory obligations

4. Lawful Bases for Processing

Our lawful bases under UK GDPR include:

  • Consent
  • Contractual necessity
  • Legitimate interests
  • Legal obligation

You may withdraw consent at any time.


5. Sharing Your Data

We do not sell personal data.

We may share data where necessary with:

  • Clients engaging our HR or recruitment services
  • Trusted service providers (e.g. IT, CRM, email platforms)
  • Legal or regulatory authorities where required by law

All third parties are required to process data securely and lawfully.


6. International Data Transfers

As a global consultancy, personal data may be transferred outside the UK.

Where this occurs, we ensure:

  • Appropriate safeguards are in place
  • Transfers comply with UK GDPR
  • Standard Contractual Clauses or equivalent protections are used

7. Data Retention

We retain data only for as long as necessary:

  • Enquiry data: up to 24 months
  • Candidate data: typically up to 24 months, unless consent is renewed
  • Client records: retained in line with contractual and legal requirements

Data is securely deleted or anonymised when no longer required.


8. Cookies & Analytics

Our website uses cookies to:

  • Ensure functionality
  • Analyse performance
  • Improve user experience

You can control cookies through your browser settings.


9. Your Data Protection Rights

You have the right to:

  • Access your personal data
  • Request correction
  • Request erasure
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time

To exercise your rights, contact:
📧 office@stoneandcopeople.com


10. Data Security

We apply appropriate technical and organisational security measures, including controlled access and secure systems. While no system is entirely risk-free, we take data protection seriously.


11. Complaints

If you are dissatisfied, you may complain to the UK Information Commissioner’s Office (ICO):
Website: https://ico.org.uk
Helpline: 0303 123 1113


12. Changes to This Policy

We may update this policy from time to time. The latest version will always be available on our website.


Confidence & Compliance Note

This policy aligns with:

  • UK GDPR
  • Data Protection Act 2018
  • ICO guidance for recruitment and consultancy businesses