PRIVACY NOTICE
TAAS Consulting Ltd, trading as Product Partners
1. About this notice
This Privacy Notice explains how TAAS Consulting Ltd, trading as Product Partners (Product Partners, we, us or our), collects, uses, shares and protects personal data. It applies to candidates and prospective candidates, client and prospective-client contacts, referees, suppliers, website visitors and other people whose personal data we process in connection with our recruitment, executive search, talent advisory and related business activities.
For the purposes of UK data-protection law, TAAS Consulting Ltd is the controller of the personal data described in this notice, except where we expressly act as a processor on another organisation’s documented instructions.
2. Who we are and how to contact us
Legal entity: TAAS Consulting Ltd
Trading name: Product Partners
Website: https://product-partners.co.uk
Privacy contact: dom@product-partners.co.uk
We are not required to appoint a formal Data Protection Officer. Privacy enquiries and requests should be directed to the contact above.
3. The personal data we collect
Candidates and prospective candidates
Depending on the circumstances, we may collect:
Identity and contact information: name, location, contact details, online profile details and other identifiers
Professional information: CV, career history, job titles, responsibilities, skills, qualifications, education, compensation, notice period, work preferences, location and mobility
Search and assessment information: communications, interview and screening notes, suitability assessments, availability, role interests, application history and client feedback
Compliance information: identity, right-to-work, conflicts, references, background-check results and other checks where relevant, lawful and proportionate
Placement information: offers, agreed remuneration, start dates, contractual and invoicing information, and information needed to manage guarantees, rebates or disputes
Technical and communications data: email and message metadata, device or website information, and records generated through the platforms we use
Special-category or criminal-offence data: only where you choose to provide it or where collection is necessary, lawful and appropriately safeguarded
Clients, prospects, suppliers and other business contacts
We may collect names, roles, employers, professional contact details, business requirements, hiring plans, correspondence, meeting notes, contractual details, payment and transaction information, website usage data, and information relevant to establishing, managing or developing a professional relationship.
4. How we obtain personal data
We may obtain personal data directly from you and from third parties or public sources, including:
professional networking sites, company websites, conference materials, job boards, CV databases and other publicly accessible professional sources;
clients, candidates, referees, mutual contacts, recommendation and referral sources;
recruitment, sourcing, communications, scheduling, CRM, ATS and verification providers;
companies within which you work or previously worked, and publicly available corporate records; and
our website, email, telephone, video calls, forms and other interactions with us.
Where we collect your data from another source, we will provide privacy information within the period required by law, subject to any applicable exception. If you provide personal data about another person, you should ensure you are entitled to do so and, where appropriate, direct them to this notice.
5. How and why we use personal data
We may process personal data for the following purposes:
Recruitment and executive search: identify, assess and contact potential candidates; understand career objectives; match individuals with current or anticipated roles; present authorised candidate information to clients; arrange interviews; collect feedback; support offers and onboarding
Talent relationships: maintain and develop our professional network; consider candidates for future opportunities; provide relevant market or career communications; record preferences and prior interactions
Client services and business development: understand hiring needs; deliver assignments; identify relevant decision-makers; prepare proposals; manage client relationships; communicate about our services and relevant market developments
Verification and due diligence: confirm information, obtain references, support background or eligibility checks, prevent fraud, manage conflicts and protect candidates, clients and our business
Operations and administration: manage contracts, systems, suppliers, records, invoicing, payments, insurance, accounting, tax, service quality and internal reporting
Security and legal protection: protect systems and information; investigate incidents; establish, exercise or defend legal claims; enforce agreements; respond to lawful requests and meet legal or regulatory obligations
Website and communications: operate, secure and improve our website and communications, understand engagement and respond to enquiries
We may use information collected in connection with one recruitment opportunity to consider you for other opportunities where this is compatible with the original purpose and reasonably expected in the recruitment context. We do not sell personal data.
6. Our lawful bases
We rely on one or more of the following lawful bases, depending on the purpose and circumstances:
Legitimate interests: our interests, and those of clients and candidates, in operating a professional recruitment and executive-search business; identifying and assessing talent; filling roles; building professional relationships; developing our services; preventing fraud; securing our systems; recovering debts; and protecting legal rights. We balance these interests against the rights and reasonable expectations of individuals
Contract and pre-contractual steps: where processing is necessary to enter into or perform a contract with you, or to take steps at your request before doing so
Legal obligation: where processing is necessary to comply with legal, regulatory, tax, accounting, employment or other binding requirements
Consent: where we specifically ask for consent. You may withdraw consent at any time, without affecting processing already carried out lawfully
Where permitted, we may contact professional and corporate contacts about relevant services based on legitimate interests. We comply with applicable electronic-marketing rules and will honour objections and unsubscribe requests.
Special-category and criminal-offence data
We do not seek to collect sensitive information unnecessarily. Where we process special-category data, we will rely on an applicable condition, such as explicit consent, employment and social-security obligations, legal claims or substantial public interest. Criminal-offence data will only be processed where authorised by law and subject to appropriate safeguards.
7. When we share personal data
We may share personal data where reasonably necessary with:
clients and prospective clients in connection with a specific or anticipated recruitment requirement, normally after discussing the opportunity with the candidate and obtaining authorisation before identifying them;
candidates and other participants where necessary to manage a recruitment process;
service providers supporting recruitment, sourcing, CRM, ATS, communications, email, cloud storage, scheduling, document management, analytics, verification, accounting, payment, legal, insurance and IT security;
professional advisers, insurers, auditors, finance providers, debt-recovery providers and other parties protecting our legitimate business or legal interests;
regulators, courts, law-enforcement bodies, tax authorities and other public bodies where disclosure is required or permitted by law; and
a purchaser, investor, lender or successor in connection with an actual or proposed sale, reorganisation, financing or transfer of all or part of our business, subject to appropriate confidentiality controls.
Recipients may act as our processors, independent controllers or joint controllers depending on their role. Once a client receives candidate information for its own recruitment purposes, it will generally process that information as an independent controller under its own privacy arrangements.
8. International transfers
Some suppliers, clients or recipients may be located outside the United Kingdom. Where restricted transfers occur, we use an available lawful mechanism, which may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another safeguard permitted by law. We may also rely on a statutory exception where appropriate. Further information about relevant safeguards may be requested using the contact details above.
9. Retention
We retain personal data for no longer than reasonably necessary for the purposes described in this notice, taking account of the continuing recruitment relationship, the nature and sensitivity of the data, operational requirements, client and candidate expectations, legal limitation periods, contractual obligations, and the need to establish, exercise or defend claims.
Candidate and prospect records: ordinarily retained for up to three years after the last meaningful interaction. We may retain them for longer where there is an active relationship, a reasonable prospect of future relevant opportunities, a placement, an unresolved matter, consent, or another lawful reason
Placement, contractual and transaction records: generally retained for up to six years after the relevant relationship or transaction, and longer where required for tax, legal, regulatory, insurance or claims purposes
Client and supplier records: generally retained for the relationship and up to six years afterwards, subject to longer retention where justified
Suppression records: limited information may be retained as necessary to respect an objection, unsubscribe request or other restriction
Data may be deleted, anonymised or archived at different times across active systems and provider-managed backups. Backup copies may remain until overwritten in the ordinary backup cycle and will not normally be restored except for continuity, security or legal purposes.
10. Security
We use proportionate technical and organisational measures designed to protect personal data, including access controls, individual accounts, strong passwords, multi-factor authentication on core systems, encrypted devices and established cloud-service providers that support encryption in transit and at rest. Access is limited to people and providers with a legitimate need.
No method of transmission or storage is completely secure. Accordingly, while we take reasonable steps to protect personal data, we cannot guarantee absolute security. You are responsible for using secure methods when communicating with us and for keeping your own accounts and contact details secure.
11. Your rights
Depending on the circumstances, you may have rights to request access, correction, erasure, restriction or transfer of your personal data; to object to processing based on legitimate interests or for direct marketing; and to withdraw consent where consent is relied upon.
These rights are not absolute. We may need to verify your identity, request clarification, retain information where a legal basis or exemption applies, or refuse or limit a request where permitted by law. We will respond within the applicable legal timeframe. To exercise a right, contact dom@product-partners.co.uk.
12. Automated decision-making
We may use technology to assist with searching, organising or matching professional information. We do not make decisions producing legal or similarly significant effects about individuals solely through automated processing without appropriate human involvement, unless permitted by law and accompanied by required safeguards.
13. Cookies and website technology
Our website may use essential cookies and similar technology needed for security, functionality and preference management. We may also use analytics or other non-essential technologies to understand website use and improve performance. Where required, non-essential cookies will not be set without consent. You can manage choices through any cookie controls made available on the website and through your browser settings. Blocking cookies may affect website functionality.
Third-party websites and services linked from our site operate under their own privacy and cookie practices. We are not responsible for their content or handling of personal data.
14. Complaints
Please contact us first at dom@product-partners.co.uk so that we have an opportunity to address your concern. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority, at https://ico.org.uk/make-a-complaint/ or by using the contact details published on its website.
15. Changes to this notice
We may update this notice from time to time to reflect changes in our services, technology, suppliers, legal requirements or business practices. The current version will be published on our website with its effective or last-updated date. Material changes may be brought to your attention by an appropriate additional method where required.
16. Contact
Questions, objections, rights requests and privacy concerns should be sent to:
Email: dom@product-partners.co.uk
Contact: Dom Dickinson, Founder, Product Partners
TAAS Consulting Ltd trading as Product Partners • Last updated 11 August 2026