Worst parts of this document
Cross-Border Transfer
30Heading present but text cuts off before explaining legal bases like SCCs or adequacy decisions.
User Control & Rights
40References GDPR but provides no concrete steps, forms, or timelines for exercising access, deletion, or portability rights.
Third-Party Sharing
50Lists multiple vendors but states the notice does not apply to them and omits Data Processing Agreement references.
Health & Behavioral Data
50Acknowledges collection of special categories but provides no enhanced safeguards or explicit consent triggers.
Security & Breach Notification
50No mention of security measures or breach notification timelines.
Collects special category and financial data based on voluntary provision and legitimate interest.
68We process this data for recruitment purposes... on the grounds of our legitimate interest as a business that is premised on finding and developing the best entrepreneurial talent
The policy outlines GDPR alignment and reasonable recruitment retention but relies on broad legitimate interest for profile scraping, shares data with numerous vendors without detailing contractual safeguards, and omits explicit cross-border transfer mechanisms and user control processes.