Hospital & healthcare recruitment · 10 years' industry experience
info@axiomarise.com+44 7799519387
Call +44 7799519387

Privacy notice

Your information, treated with care.

This notice explains how Axiom Arise Ltd collects, uses, shares and protects personal information in its recruitment services, in line with current UK data protection law.

Our perspective

We use personal information only where there is a clear recruitment or business purpose, a valid legal basis and appropriate safeguards.

01

Data controller

Axiom Arise Ltd, 66 Paul Street, London, EC2A 4NA, United Kingdom.

02

Privacy contact

Questions and rights requests can be sent to info@axiomarise.com.

03

Legal framework

UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025 and PECR, as applicable.

04

Last updated

27 July 2026. We review this notice when our services or legal obligations change.

01

Who this notice covers

This notice applies to candidates, prospective candidates, temporary workers, contractors, referees, client contacts, website visitors and people who contact or are referred to Axiom Arise.

Axiom Arise Ltd normally acts as the data controller for the recruitment information described here. This means we decide why and how that information is used. Where a client gives us documented instructions for a specific processing activity, our role may differ and we will explain that where relevant.

02

The UK laws we follow

Our main obligations arise under the UK General Data Protection Regulation and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. We also follow the Privacy and Electronic Communications Regulations 2003 for electronic marketing, cookies and similar technologies.

As a recruitment business, we also consider applicable requirements under the Employment Agencies Act 1973 and the Conduct of Employment Agencies and Employment Businesses Regulations 2003. These rules may require us to obtain, check and keep certain information about work-seekers, hirers, vacancies and assignments.

03

Information we may collect

We collect only information that is relevant to providing recruitment services, operating our business and meeting legal or regulatory responsibilities.

  • Identity and contact details, including name, address, email, telephone number, date of birth and identification documents where needed.
  • Career and professional information, including CVs, employment history, skills, qualifications, registrations, references, availability, salary expectations and role preferences.
  • Recruitment activity, including applications, interview notes, assessments, communications, offers, placements and feedback.
  • Compliance information, including right-to-work evidence, professional registration, training, identity checks and role-appropriate background screening.
  • Payment, payroll or contractual information where relevant to a placement or engagement.
  • Client information, including business contact details, hiring requirements, vacancy information, interview feedback and contractual communications.
  • Technical information supplied when someone uses our website, such as IP address, browser type and basic security logs.
04

Where information comes from

Most information comes directly from you through a form, CV, application, email, telephone call or recruitment conversation. We may also receive information from referees, former employers, clients, professional bodies, compliance providers, job boards, public professional profiles or another person who refers you with your knowledge.

If we obtain your details from another source, we will provide privacy information within the period required by law unless an exemption applies.

05

Why we use information and our lawful bases

UK law requires a valid lawful basis for every use of personal information. The basis depends on the purpose and context.

  • Steps before a contract or performance of a contract: to register candidates, discuss roles, arrange assignments, manage offers and deliver agreed recruitment services.
  • Legitimate interests: to identify and assess relevant talent, respond to hiring requirements, maintain professional relationships, prevent fraud, improve services and operate our business. We balance these interests against the rights and reasonable expectations of the person concerned.
  • Legal obligation: to complete or support right-to-work checks, keep records required of recruitment businesses, respond to lawful authorities and meet tax, employment or regulatory duties.
  • Consent: where the law requires it or where you have a genuine choice, such as certain marketing, optional diversity information or some uses of sensitive information. Consent can be withdrawn at any time.
  • Vital interests: only in a rare emergency where using information is necessary to protect someone’s life or safety.
06

Health, equality and other sensitive information

Health information, ethnicity, religion, trade union membership, sexual orientation and similar information receive extra protection as special category data. We use this information only where both an Article 6 lawful basis and a separate Article 9 condition apply.

Depending on the situation, the additional condition may be explicit consent, obligations and rights in employment, substantial public interest under the Data Protection Act 2018, protection of vital interests, or the establishment, exercise or defence of legal claims. Information about reasonable adjustments is kept limited to what is needed to support an accessible recruitment process or placement.

07

DBS and criminal offence information

Some hospital, care and regulated roles may lawfully require a Disclosure and Barring Service check. We request or handle criminal offence information only where the role is eligible and UK law authorises the processing.

Where required, we use an appropriate Schedule 1 condition under the Data Protection Act 2018, limit access, record the decision carefully and maintain an appropriate policy document. DBS certificate information is used only for the purpose for which it was obtained and is normally not retained for longer than six months unless a lawful, exceptional reason requires longer retention.

08

When we share information

We do not sell personal information. Candidate information may be shared with a prospective employer after we have discussed the relevant opportunity and there is an appropriate lawful basis.

We may also share limited information with payroll or umbrella providers, compliance and screening providers, professional bodies, referees, insurers, legal or professional advisers, technology and communications suppliers, and public authorities where required by law. Service providers must process information under appropriate contractual, confidentiality and security obligations.

09

International transfers

Some technology or service providers may process information outside the United Kingdom. Before making a restricted transfer, we use a lawful transfer mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another safeguard permitted by UK law.

Where required, we also assess whether the destination and circumstances provide essentially equivalent protection and adopt supplementary safeguards.

10

How long we keep information

We keep personal information only for as long as it is needed for the purpose collected, legal and regulatory duties, and the establishment or defence of legal claims.

The period depends on the nature and sensitivity of the information, the status of an application, placement or business relationship, possible legal claims and any mandatory employment, tax, safeguarding or recruitment-business record-keeping period. We review records and securely delete or anonymise information when it is no longer needed. You may ask us for more detail about the criteria relevant to your information.

DBS certificate information is normally not retained for longer than six months unless a lawful, exceptional reason requires longer. Where possible, we retain only the check date, level and outcome rather than a certificate copy.

11

How we protect information

We use proportionate technical and organisational measures designed to protect information against loss, misuse, unauthorised access, alteration or disclosure. These include access controls, secure systems, staff confidentiality, processor contracts, data minimisation, retention controls and incident-response procedures.

No online service can promise absolute security. If a personal data breach presents a risk to people, we will assess it promptly and notify the Information Commissioner’s Office and affected individuals where the law requires.

12

Your data protection rights

Depending on the circumstances, you may have the right to be informed, access a copy of your information, correct inaccurate or incomplete information, request erasure, restrict processing, object to processing, and receive certain information in a portable format.

You may withdraw consent at any time where consent is the basis used. You also have rights concerning solely automated decisions with legal or similarly significant effects. These rights are not absolute and a legal exemption may apply. We normally respond within one month after verifying identity and clarifying the request where necessary.

13

Human recruitment decisions

Axiom Arise does not make final recruitment or placement decisions based solely on automated processing. Technology may help organise information or identify possible matches, but a person reviews the context and candidates can ask for an explanation or raise a concern.

14

Marketing, cookies and external services

We send electronic marketing only where permitted by the Privacy and Electronic Communications Regulations and UK data protection law. Every marketing message will provide a simple way to opt out.

This website does not intentionally use advertising or behavioural analytics cookies. Essential security and hosting technologies may operate where necessary to provide the site. The interactive Google map is not loaded until you choose to load it; doing so sends technical information such as your IP address and browser data to Google under Google’s own privacy terms.

15

Questions, complaints and the ICO

To exercise a right or raise a privacy concern, email info@axiomarise.com or write to Axiom Arise Ltd, 66 Paul Street, London, EC2A 4NA, United Kingdom. Please describe the request clearly. We may ask for reasonable proof of identity before disclosing information.

We would welcome the opportunity to resolve a concern first. You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection, through ico.org.uk or by calling 0303 123 1113.

16

Changes to this notice

We may update this notice when our services, suppliers or legal obligations change. The latest version will always be published on this page with its review date. Material changes will be highlighted or communicated where appropriate.