PRIVACY NOTICE

TAAS Consulting Ltd, trading as Product Partners

1. About this notice

This Privacy Notice explains how TAAS Consulting Ltd, trading as Product Partners (Product Partners, we, us or our), collects, uses, shares and protects personal data. It applies to candidates and prospective candidates, client and prospective-client contacts, referees, suppliers, website visitors and other people whose personal data we process in connection with our recruitment, executive search, talent advisory and related business activities.

For the purposes of UK data-protection law, TAAS Consulting Ltd is the controller of the personal data described in this notice, except where we expressly act as a processor on another organisation’s documented instructions.

2. Who we are and how to contact us

Legal entity: TAAS Consulting Ltd

Trading name: Product Partners

Website: https://product-partners.co.uk

Privacy contact: dom@product-partners.co.uk

We are not required to appoint a formal Data Protection Officer. Privacy enquiries and requests should be directed to the contact above.

3. The personal data we collect

Candidates and prospective candidates

Depending on the circumstances, we may collect:

Identity and contact information: name, location, contact details, online profile details and other identifiers

Professional information: CV, career history, job titles, responsibilities, skills, qualifications, education, compensation, notice period, work preferences, location and mobility

Search and assessment information: communications, interview and screening notes, suitability assessments, availability, role interests, application history and client feedback

Compliance information: identity, right-to-work, conflicts, references, background-check results and other checks where relevant, lawful and proportionate

Placement information: offers, agreed remuneration, start dates, contractual and invoicing information, and information needed to manage guarantees, rebates or disputes

Technical and communications data: email and message metadata, device or website information, and records generated through the platforms we use

Special-category or criminal-offence data: only where you choose to provide it or where collection is necessary, lawful and appropriately safeguarded

Clients, prospects, suppliers and other business contacts

We may collect names, roles, employers, professional contact details, business requirements, hiring plans, correspondence, meeting notes, contractual details, payment and transaction information, website usage data, and information relevant to establishing, managing or developing a professional relationship.

4. How we obtain personal data

We may obtain personal data directly from you and from third parties or public sources, including:

professional networking sites, company websites, conference materials, job boards, CV databases and other publicly accessible professional sources;

clients, candidates, referees, mutual contacts, recommendation and referral sources;

recruitment, sourcing, communications, scheduling, CRM, ATS and verification providers;

companies within which you work or previously worked, and publicly available corporate records; and

our website, email, telephone, video calls, forms and other interactions with us.

Where we collect your data from another source, we will provide privacy information within the period required by law, subject to any applicable exception. If you provide personal data about another person, you should ensure you are entitled to do so and, where appropriate, direct them to this notice.

5. How and why we use personal data

We may process personal data for the following purposes:

Recruitment and executive search: identify, assess and contact potential candidates; understand career objectives; match individuals with current or anticipated roles; present authorised candidate information to clients; arrange interviews; collect feedback; support offers and onboarding

Talent relationships: maintain and develop our professional network; consider candidates for future opportunities; provide relevant market or career communications; record preferences and prior interactions

Client services and business development: understand hiring needs; deliver assignments; identify relevant decision-makers; prepare proposals; manage client relationships; communicate about our services and relevant market developments

Verification and due diligence: confirm information, obtain references, support background or eligibility checks, prevent fraud, manage conflicts and protect candidates, clients and our business

Operations and administration: manage contracts, systems, suppliers, records, invoicing, payments, insurance, accounting, tax, service quality and internal reporting

Security and legal protection: protect systems and information; investigate incidents; establish, exercise or defend legal claims; enforce agreements; respond to lawful requests and meet legal or regulatory obligations

Website and communications: operate, secure and improve our website and communications, understand engagement and respond to enquiries

We may use information collected in connection with one recruitment opportunity to consider you for other opportunities where this is compatible with the original purpose and reasonably expected in the recruitment context. We do not sell personal data.

6. Our lawful bases

We rely on one or more of the following lawful bases, depending on the purpose and circumstances:

Legitimate interests: our interests, and those of clients and candidates, in operating a professional recruitment and executive-search business; identifying and assessing talent; filling roles; building professional relationships; developing our services; preventing fraud; securing our systems; recovering debts; and protecting legal rights. We balance these interests against the rights and reasonable expectations of individuals

Contract and pre-contractual steps: where processing is necessary to enter into or perform a contract with you, or to take steps at your request before doing so

Legal obligation: where processing is necessary to comply with legal, regulatory, tax, accounting, employment or other binding requirements

Consent: where we specifically ask for consent. You may withdraw consent at any time, without affecting processing already carried out lawfully

Where permitted, we may contact professional and corporate contacts about relevant services based on legitimate interests. We comply with applicable electronic-marketing rules and will honour objections and unsubscribe requests.

Special-category and criminal-offence data

We do not seek to collect sensitive information unnecessarily. Where we process special-category data, we will rely on an applicable condition, such as explicit consent, employment and social-security obligations, legal claims or substantial public interest. Criminal-offence data will only be processed where authorised by law and subject to appropriate safeguards.

7. When we share personal data

We may share personal data where reasonably necessary with:

clients and prospective clients in connection with a specific or anticipated recruitment requirement, normally after discussing the opportunity with the candidate and obtaining authorisation before identifying them;

candidates and other participants where necessary to manage a recruitment process;

service providers supporting recruitment, sourcing, CRM, ATS, communications, email, cloud storage, scheduling, document management, analytics, verification, accounting, payment, legal, insurance and IT security;

professional advisers, insurers, auditors, finance providers, debt-recovery providers and other parties protecting our legitimate business or legal interests;

regulators, courts, law-enforcement bodies, tax authorities and other public bodies where disclosure is required or permitted by law; and

a purchaser, investor, lender or successor in connection with an actual or proposed sale, reorganisation, financing or transfer of all or part of our business, subject to appropriate confidentiality controls.

Recipients may act as our processors, independent controllers or joint controllers depending on their role. Once a client receives candidate information for its own recruitment purposes, it will generally process that information as an independent controller under its own privacy arrangements.

8. International transfers

Some suppliers, clients or recipients may be located outside the United Kingdom. Where restricted transfers occur, we use an available lawful mechanism, which may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another safeguard permitted by law. We may also rely on a statutory exception where appropriate. Further information about relevant safeguards may be requested using the contact details above.

9. Retention

We retain personal data for no longer than reasonably necessary for the purposes described in this notice, taking account of the continuing recruitment relationship, the nature and sensitivity of the data, operational requirements, client and candidate expectations, legal limitation periods, contractual obligations, and the need to establish, exercise or defend claims.

Candidate and prospect records: ordinarily retained for up to three years after the last meaningful interaction. We may retain them for longer where there is an active relationship, a reasonable prospect of future relevant opportunities, a placement, an unresolved matter, consent, or another lawful reason

Placement, contractual and transaction records: generally retained for up to six years after the relevant relationship or transaction, and longer where required for tax, legal, regulatory, insurance or claims purposes

Client and supplier records: generally retained for the relationship and up to six years afterwards, subject to longer retention where justified

Suppression records: limited information may be retained as necessary to respect an objection, unsubscribe request or other restriction

Data may be deleted, anonymised or archived at different times across active systems and provider-managed backups. Backup copies may remain until overwritten in the ordinary backup cycle and will not normally be restored except for continuity, security or legal purposes.

10. Security

We use proportionate technical and organisational measures designed to protect personal data, including access controls, individual accounts, strong passwords, multi-factor authentication on core systems, encrypted devices and established cloud-service providers that support encryption in transit and at rest. Access is limited to people and providers with a legitimate need.

No method of transmission or storage is completely secure. Accordingly, while we take reasonable steps to protect personal data, we cannot guarantee absolute security. You are responsible for using secure methods when communicating with us and for keeping your own accounts and contact details secure.

11. Your rights

Depending on the circumstances, you may have rights to request access, correction, erasure, restriction or transfer of your personal data; to object to processing based on legitimate interests or for direct marketing; and to withdraw consent where consent is relied upon.

These rights are not absolute. We may need to verify your identity, request clarification, retain information where a legal basis or exemption applies, or refuse or limit a request where permitted by law. We will respond within the applicable legal timeframe. To exercise a right, contact dom@product-partners.co.uk.

12. Automated decision-making

We may use technology to assist with searching, organising or matching professional information. We do not make decisions producing legal or similarly significant effects about individuals solely through automated processing without appropriate human involvement, unless permitted by law and accompanied by required safeguards.

13. Cookies and website technology

Our website may use essential cookies and similar technology needed for security, functionality and preference management. We may also use analytics or other non-essential technologies to understand website use and improve performance. Where required, non-essential cookies will not be set without consent. You can manage choices through any cookie controls made available on the website and through your browser settings. Blocking cookies may affect website functionality.

Third-party websites and services linked from our site operate under their own privacy and cookie practices. We are not responsible for their content or handling of personal data.

14. Complaints

Please contact us first at dom@product-partners.co.uk so that we have an opportunity to address your concern. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority, at https://ico.org.uk/make-a-complaint/ or by using the contact details published on its website.

15. Changes to this notice

We may update this notice from time to time to reflect changes in our services, technology, suppliers, legal requirements or business practices. The current version will be published on our website with its effective or last-updated date. Material changes may be brought to your attention by an appropriate additional method where required.

16. Contact

Questions, objections, rights requests and privacy concerns should be sent to:

Email: dom@product-partners.co.uk

Contact: Dom Dickinson, Founder, Product Partners

TAAS Consulting Ltd trading as Product Partners • Last updated 11 August 2026