Privacy Notice

Last updated: 14 June 2026

This notice explains how The Leverage Lab UK ("we", "us", "our") processes personal data when providing the BEDROX recruitment automation platform to recruitment agencies ("Clients"). We are committed to handling all personal data lawfully, transparently, and securely in accordance with UK GDPR and the Data Protection Act 2018.

1. Who We Are

The Leverage Lab UK
Email: hello@theleveragelabuk.com

In relation to candidate personal data processed through BEDROX, each recruitment agency (our Client) is the Data Controller. The Leverage Lab UK acts as the Data Processor, processing candidate data solely on the instructions of the Client. Each Client is responsible for their own ICO registration and for providing candidates with their own privacy notice.

2. What Personal Data We Process

On behalf of our Clients, we process the following categories of candidate personal data:

We also process limited personal data about Client contacts (agency staff) for account management purposes, including name, email address, and login credentials (stored as a one-way hash).

3. Lawful Basis for Processing

4. How We Use Personal Data

We process candidate data to provide the BEDROX service, which includes:

We do not use candidate data for any purpose beyond providing the service, and we do not sell, share, or transfer candidate data to third parties except as set out in Section 6 (Sub-Processors).

5. Data Retention

Candidate records are retained for the following periods, after which they are automatically flagged for deletion:

Data TypeRetention PeriodReason
Rejected / No Response candidates12 months from applicationUK recruitment industry standard
Invited / Pending candidates24 months from applicationOngoing recruitment relationship
Onboarding records6 years from placementHMRC payroll requirement
Timesheet records6 years from week endingHMRC payroll requirement
Compliance documents2 years after expiryRight-to-work / licence audit
Client account dataDuration of contract + 12 monthsAccount management

Clients may request early deletion of any candidate record at any time via the BEDROX erasure tool, subject to the HMRC retention carve-out above.

6. Sub-Processors

We use the following third-party sub-processors to deliver the BEDROX service. All sub-processors are contractually bound to handle data securely and only as instructed.

Sub-ProcessorPurposeData LocationLink
SupabaseDatabase hosting — stores all candidate, job, and account dataEU (West Europe)Privacy Policy
NetlifyApplication hosting and serverless functionsUSA (SCCs in place)Privacy Policy
OpenAIAI scoring — CV text is sent to OpenAI to generate a match score. No CV data is used to train OpenAI models (API data retention: 30 days then deleted).USA (SCCs in place)Privacy Policy
ResendTransactional email — sends automated outcome emails to candidatesUSA (SCCs in place)Privacy Policy
Google (Gmail API)Email intake — reads CV emails from the Client's Gmail inboxUSA (SCCs in place)Privacy Policy
CalendlyInterview scheduling — Calendly booking links are included in invite emailsUSA (SCCs in place)Privacy Policy
TallyJob intake forms — used to create new job postingsEU (Belgium)Privacy Policy
StripePayment processing — processes Client subscription paymentsUSA / EU (SCCs in place)Privacy Policy

SCC = Standard Contractual Clauses (the EU/UK-approved mechanism for international data transfers).

7. Data Security

We implement the following technical and organisational measures to protect personal data:

8. Your Rights

Candidates whose data is processed through BEDROX should direct rights requests to the recruitment agency (Data Controller) that received their application. The agency is responsible for fulfilling those requests.

Client contacts (agency staff) have the following rights under UK GDPR:

To exercise any of these rights, contact us at hello@theleveragelabuk.com. We will respond within 30 days.

9. Data Processing Agreement

As a Data Processor, we offer a Data Processing Agreement (DPA) to all Clients on request. The DPA governs how we process candidate data on the Client's behalf and includes the sub-processor list above. Contact hello@theleveragelabuk.com to request a copy.

10. Complaints

If you have a concern about how we handle personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Website: ico.org.uk
Phone: 0303 123 1113

11. Changes to This Notice

We may update this notice from time to time. We will notify active Clients of material changes. The latest version is always available at this URL.

Contact us
The Leverage Lab UK
hello@theleveragelabuk.com
← Back to BEDROX