Employee data - Privacy policy

This notice applies to job applicants as well as past and current employees of Limitless Security Ltd. Any queries regarding this notice or how your personal data is handled by Limitless Security Ltd, please contact our Data Protection Officer. 


Lawful basis for processing:


The lawful basis we rely on for processing your personal data is article 6(1)(b) of the GDPR, which relates to processing necessary to perform a contract or to take steps at your request, before entering a contract. The lawful basis we rely on to process any information you provide as part of your application which is special category data, such as health, religious or ethnic information is article 9(2)(b) of the GDPR, which also relates to our obligations in employment  and the safeguarding of your fundamental rights and article 9(2)(h) for assessing your work capacity as an employee. And Schedule 1 part 1(1) and (2)(a) and (b) of the DPA2018 which relates to processing for employment, the assessment of your working capacity and preventative or occupational medicine


What information do we ask for, and why? 


We do not collect more information than is needed in order to fulfil our intended purposes; nor will we keep it for longer than is necessary. The information you provide is used to access your suitability for employment. There is no requirement for you to provide the information we request, however, it may affect your application if this is not supplied.  


Your rights in relation to your personal data:


  •  The right to be informed 


It is your right to know exactly why we process your personal information, who it may be shared with as well as how long it will be retained for. 


  • The right of access


You have the right to submit a Subject Access Request (SAR) to get a copy of the information we hold about you. 


  • The right to withdraw your consent, the right to erasure and the right to object 


If you wish to withdraw your consent, or erase it or tell us to stop processing your data then we will do so. Unless this was impossible to do so due to there being an overriding legal or regulatory obligation.


  • The right to rectification 


If the information we hold about you is out of date or inaccurate, please let us know. 


  • The right of data portability


The information you provide us with in your application form can be downloaded in XML format, which is structured, commonly-used and machine readable. The right of data portability will normally not apply to other employee data.


  • The right to lodge a complaint 


If you have a concern about the way we process your personal data, please do contact us so we can do our utmost to deal with your concern, However, you have the right to complain to the Information Commissioner’s Office (ICO), 


Information provided during the recruitment process and what Limitless Security Ltd will do with this information. 


Any information provided during the recruitment process will only be used for the intended purpose of processing your application with a view to offering an employment contract with us. Whether this be for statistical analysis or to fulfil any legal or regulatory requirements if necessary.


Any information provided will be held securely by Limitless Security Ltd and its data processors. Limitless Security Ltd will not share any of your information with any third party for marketing purposes. 


The information provided will be used to shortlist the application against the criteria for the role applied for as shown in the person specification/job description.


Application stage:


Limitless Security Ltd will require certain personal information such as name, contact details and also asks for previous work experience. Only authorised personnel will have access to all of this information. 


Equal Opportunities Monitoring:


All applicants will be asked to complete equal opportunities monitoring information when there is an offer made. This is not mandatory and any information that is provided will only be to produce and monitor equal opportunities statistics. 




Applications will be shortlisted against the person specification and job description. Our processes are not normally based on automated decision-making, but if you lack a key requirement, e.g. the right to work, your application may not be considered. 


Following shortlisting, those individuals selected will be invited to attend an interview. Notes will be taken and will be held on file until they are destroyed after the agreed timescale. 


Offer of Employment:


When a conditional offer of employment has been made and accepted, Limitless Security Ltd will issue emails/forms to aid in the gathering of further information. This information is required as Limitless Security Ltd are required to confirm the identity of their employees as well as confirm their right to work in the UK. It may also be necessary to ensure clearance by way of a Disclosure Check. Limitless Security Ltd will pay for any checks that are required.


Pre-Employment Health Questionnaire:


Any individual who is offered employment by Limitless Security Ltd will be asked to complete a Pre-Employment Health Questionnaire. This is in place to ensure that Limitless Security Ltd takes positive action regarding how an individuals health could be affected by their working conditions and/or duties. 


The information provided on this form is processed securely and confidentially. This is not mandatory but if this information is not made available this could hinder our ability to consider the implant on an individuals health and make any reasonable adjustments. 

What other information will Limitless Security Ltd require, once my employment has been confirmed?:


  • Bank account details – to process salary payments

  • P45 / HMRC Starter’s Checklist

  • An opt out form, if you chose to opt out from the auto enrolment pension scheme

  • Emergency contact details – in case there is an emergency at work

  • Any information related to possible conflicts of interest

  • Any relevant evidence of qualifications, memberships 

  • Medical information as detailed above 

  • Details of employment history

  • Right to work documentation as detailed above

  • Documentation for DBS check as detailed above


All personal data gathered during the recruitment process will be transferred to a personnel file and retained confidentially for the duration of employment and thereafter in line with Limitless Security Ltd retention schedule. 

Employment at Limitless Security Ltd


Data held on current employees:


Personal Data about employees is held in both paper and electronic form. The information is used to administer contracts of employment, payroll, pensions as well as training and appraisals, Any hard copy information is stored in secure cabinets at our registered address, 40 Church Drive, Bristol. 


At the end of your employment.:


Your information will normally be retained as part of your personnel file for the duration of your employment. At the end of your employment, information that is no longer required will be destroyed. Information we are required to retain for legal reasons or according to industry best practise will be archived and securely kept in accordance with our retention schedule. This includes copies of correspondence, fitness to work certificates, records of any security checks and references etc.


Certain data held electronically on an employee record, for example, dates of employment, and other information necessary to provide references as and when they are required, or required for audit purposes will be retained for 7 years (plus one year). At the end of the contract of employment, the majority of personal data will be deleted.


Sharing my personal data with others


Information is also shared with our accountant and HM Revenue & Customs and may also be shared with other authorities if legally required to do so. 


List of Approved Data Processors:

  • U-Check – They are an e-Umbrella Body that processes electronic Basic, Standard and Enhanced criminal record checks for England, Wales & Northern Ireland. They assist Limitless Security Ltd to make informed recruitment decisions fulfilling regulatory and compliance requirements

  • Occupational Health service – To gain any information required to ensure the wellbeing of employees

  • NEST – To process the auto enrolment scheme

  • Personnel and Payroll systems. Data is hosted securely and is not transferred outside of the company

  • HMRC/Inland Revenue