Privacy Policy
Last updated: 31 January 2026
Privacy, in plain English
- ✓ We only collect data needed to run Talent Direct.
- ✓ Your email and account details are used to give you access and communicate with you.
- ✓ We do not sell your data. Ever.
- ✓ We use secure systems and reputable providers.
- ✓ You stay in control. You can access, correct or delete your data at any time.
Questions or requests? Email info@kelloch.org.uk
This Privacy Policy explains how Talent Direct (part of Kelloch Consultancy) ("we", "us", "our") collects, uses and protects personal data when you use our web application and related services ("the App").
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are (Data Controller)
Data Controller: Talent Direct (part of Kelloch Consultancy)
Contact email: info@kelloch.org.uk
We are responsible for deciding how and why your personal data is processed.
2. What This Policy Applies To
This policy applies to people who:
- visit or use the App
- create an account
- submit forms or enquiries
- communicate with us through the App
It does not cover third-party websites or services linked from the App.
3. Personal Data We Collect
We only collect data that is necessary for the App to function.
Information you provide
- Name
- Email address
- Account or profile details
- Messages or enquiries you send us
Information collected automatically
- IP address
- Device and browser type
- Usage data (pages visited, actions taken)
4. How We Use Your Data
We use your data to:
- provide and operate the App
- manage user accounts and access
- respond to enquiries or support requests
- improve performance and security
- meet legal and regulatory obligations
We do not sell personal data.
5. Lawful Bases for Processing (UK GDPR)
We rely on the following lawful bases:
- Contract – to provide the service you sign up for
- Legitimate interests – to operate, secure and improve the App
- Legal obligation – where UK law requires us to retain records
- Consent – where you have actively opted in (for example, marketing emails)
6. Authentication and Accounts
Talent Direct uses Supabase to manage user authentication and accounts.
When you create an account or log in, Supabase processes:
- your email address
- authentication credentials (stored securely in encrypted form)
- login and access timestamps
This processing is necessary to:
- authenticate users
- manage access to protected areas of the App
- maintain security and prevent misuse
Supabase acts as a data processor on our behalf and processes data only in accordance with our instructions and UK GDPR requirements.
7. Cookies and Analytics
The App may use essential cookies required for it to function properly.
Where analytics or non-essential cookies are used, these are:
- clearly disclosed
- disabled unless you consent
- used only to understand usage and improve the App
You can control cookies via your browser settings at any time.
8. Sharing Your Data
We only share personal data with trusted service providers where necessary to run the App (for example hosting, authentication, or email delivery).
All processors are required to:
- process data only on our instructions
- keep data secure
- comply with UK GDPR requirements
9. Data Storage and Transfers
Your data is stored securely.
If any data is processed outside the UK, appropriate safeguards are in place, such as UK-approved Standard Contractual Clauses.
10. Data Retention
We keep personal data only for as long as necessary:
- account data: until you delete your account or request erasure
- enquiries: up to 24 months
- legal or financial records: as required by UK law
11. Security Measures
We use appropriate technical and organisational measures, including:
- encrypted connections (HTTPS)
- restricted access to data
- secure authentication systems
If a data breach occurs that poses a risk to your rights, we will notify the UK Information Commissioner's Office (ICO) and affected users within 72 hours where required.
12. Your Rights Under UK GDPR
You have the right to:
- access your personal data
- request correction of inaccurate data
- request erasure
- restrict or object to processing
- withdraw consent at any time
- lodge a complaint with the Information Commissioner's Office (ICO)
To exercise your rights, email info@kelloch.org.uk.
13. Complaints
If you are unhappy with how we handle your data, please contact us first.
You also have the right to complain to the UK Information Commissioner's Office (ICO).
14. Children
The App is intended for users aged 18 and over.
We do not knowingly collect data from children.
15. Changes to This Policy
We may update this policy from time to time.
The latest version will always be available on this page with an updated date.
16. Contact
Questions about this policy or your data:
Email: info@kelloch.org.uk
Privacy Policy | UK GDPR compliant | Talent Direct (part of Kelloch Consultancy)