Privacy Policy
Last updated: 21 September 2026
Onboardly provides a WhatsApp-based recruitment compliance platform for recruitment agencies and employers. This policy explains what personal data we handle, why, and the rights you have.
1. Who we are
Onboardly ("we", "us", "our") operates the Onboardly compliance automation platform. For the personal data of candidates and referees processed through the platform, our customers (the recruitment agencies and employers who use Onboardly) are the data controllers and Onboardly acts as their data processor. For account and billing data relating to our customers themselves, Onboardly is the controller.
If you have any questions about this policy or how your data is handled, contact us using the details at the end of this page.
2. Information we collect
Depending on how Onboardly is used, we may process the following categories of personal data:
- Account data — recruiter name, work email, organisation, and authentication details.
- Candidate data — name, contact details (including WhatsApp number), and the compliance documents you collect, such as passports, Right to Work evidence, DBS certificates, professional registrations, and training certificates.
- Reference data — referee names, email addresses, organisations, and the content of their responses.
- Communications — WhatsApp messages, emails, and uploads exchanged through the platform.
- Usage data — log data, device and browser information, and analytics about how the dashboard is used.
3. How we use your information
We use personal data to provide and operate the compliance workflow, specifically to:
- Collect, request, and track compliance documents from candidates via WhatsApp.
- Validate documents using AI and OCR and flag items for manual review.
- Request, validate, and chase employment references.
- Generate compliance packs and maintain an audit trail of actions taken.
- Provide support, secure the service, and improve our product.
4. Legal bases for processing
Where UK/EU data protection law applies, we and our customers rely on one or more of the following legal bases: performance of a contract; legitimate interests (operating and improving the service and meeting compliance obligations); consent (for example, a candidate consenting before any documents are collected, and separate explicit consent for DBS checks); and compliance with a legal obligation. Special category and criminal-records data (such as DBS information) is processed under the additional conditions required by law.
5. WhatsApp and third-party processors
Onboardly relies on trusted sub-processors to deliver the service. Each is bound by data protection obligations and processes data only on documented instructions:
- Twilio — WhatsApp messaging delivery.
- Supabase — application database and authentication.
- Amazon Web Services (S3) — encrypted document storage, hosted in the UK (eu-west-2).
- Anthropic — AI and OCR document validation.
- OpenAI — AI and OCR document validation.
- Mindee — OCR document validation.
- Resend — transactional and reference emails.
- Vercel — application hosting.
- Stripe — subscription billing and payment processing for recruiter accounts. Candidate compliance documents and messages are not shared with Stripe.
6. Sharing and disclosure
We do not sell personal data. We share it with the sub-processors listed above, with the customer who controls the relevant candidate or referee data, and where required to comply with the law, enforce our terms, or protect the rights and safety of users. Where a customer connects their own integrations (for example via Zapier), personal data is also shared with those tools at the customer's direction and subject to those providers' own terms.
7. International transfers
Some of our sub-processors may process data outside the UK. Where this happens, we rely on appropriate safeguards, such as adequacy decisions, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses.
8. Data retention
DBS certificate documents carry extra sensitivity and a shorter retention period: they are deleted 7 days after they are stored.
Other compliance documents and candidate data are kept while the recruiter's account collecting them stays active. If a recruiter asks to delete their account, it is scheduled for deletion after a 30-day grace period, during which the request can be cancelled. Customers can also request deletion of candidate data they control at any time, subject to any overriding legal retention requirement.
9. Automated checks
Documents you or your recruiter upload are read by AI and OCR document-validation software. A confident, clear read may be automatically accepted or rejected; a read the software is not confident about is sent to a person at the recruitment agency for manual review — it is never automatically rejected. You can ask your recruiter to have a person review any automated outcome.
10. Security
We use technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit and at rest, access controls, and audit logging. No system is perfectly secure, but we work to protect your data and to respond promptly to any incident.
When a recruiter signs in from a browser we have not confirmed before, we email a one-time security code to that account's own email address and ask for it before letting the sign-in continue. We keep a record that the browser was confirmed, and when. We do this on the basis of our legitimate interest in keeping accounts secure.
We delete the record of a sent one-time security code within 24 hours, whether or not it was used.
11. Your rights
Subject to applicable law, individuals have rights over their personal data, including the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request erasure of your data.
- Object to or restrict certain processing.
- Request portability of data you provided.
- Withdraw consent at any time where processing is based on consent.
- Complain to the Information Commissioner's Office (ICO) — https://ico.org.uk/make-a-complaint/.
12. Cookies
Onboardly uses cookies and local/session storage that are strictly necessary to operate the dashboard (such as keeping you signed in) and to remember a small number of preferences (such as your chosen appearance). We do not use cookies for analytics or advertising. See our Cookies page (/cookies) for the full list.
13. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the date at the top of this page and, where appropriate, notify you.
14. Contact us
If you have questions about this policy or wish to exercise your rights, please contact us at admin@rca-onboardly.com. Candidates and referees should contact the recruitment agency or employer who is collecting their information in the first instance.