Warning: Undefined array key "background_color" in /home/sevenlabs/public_html/fortiva.sevensevenlab.co.uk/wp-content/plugins/elementor/includes/conditions.php on line 87

Warning: Undefined array key "background_color" in /home/sevenlabs/public_html/fortiva.sevensevenlab.co.uk/wp-content/plugins/elementor/includes/conditions.php on line 87

Warning: Undefined array key "background_color" in /home/sevenlabs/public_html/fortiva.sevensevenlab.co.uk/wp-content/plugins/elementor/includes/conditions.php on line 87

Warning: Undefined array key "background_color" in /home/sevenlabs/public_html/fortiva.sevensevenlab.co.uk/wp-content/plugins/elementor/includes/conditions.php on line 87
fortiva

GDPR Policy

1. Introduction

At Fortiva, we take data protection and privacy seriously. As a talent acquisition and advisory partner specialising in the construction and engineering sectors, we collect, process, and store personal data as part of our recruitment services.

We are committed to protecting the rights of individuals in line with the General Data Protection Regulation (GDPR) and applicable data protection laws in the countries where we operate.

This policy outlines how we manage personal data and ensure compliance with the GDPR in all our recruitment activities.

2. Scope

This GDPR Policy applies to all personal data processed by Fortiva in relation to candidates, clients, employees, suppliers, and other stakeholders. It covers data collection, processing, storage, and sharing as part of our talent acquisition and advisory services.

3. Key Definitions

  • Personal Data:
    Any information that relates to an identified or identifiable individual (data subject), such as names, contact details, CVs, job history, and any other information used in the recruitment process.

  • Data Subject:
    An individual whose personal data is processed by Fortiva.

  • Processing:
    Any operation performed on personal data, including collection, storage, use, and sharing.

  • Data Controller:
    Fortiva, responsible for determining the purposes and means of processing personal data.

  • Data Processor:
    Any third party that processes personal data on behalf of Fortiva.

4. Data Collection

Fortiva collects personal data from the following sources:

  • Direct from Candidates:
    This includes CVs, cover letters, contact information, and other details voluntarily provided through applications, interviews, or communications.

  • Publicly Available Sources:
    Such as LinkedIn, job boards, and other professional networks.

  • Referrals and Recommendations:
    From previous employers, references, or professional contacts.

  • Clients and Partners:
    Personal data shared as part of recruitment assignments or contractual agreements.

5. Lawful Basis for Processing Personal Data

We will only process personal data where there is a lawful basis under the GDPR, which includes:

  • Consent:
    Where the data subject has provided explicit consent for us to process their personal data (e.g., signing up to receive job alerts or submitting a CV).

  • Legitimate Interests:
    Processing necessary for the legitimate interests of Fortiva or a third party, such as fulfilling recruitment services, provided that the individual’s rights do not override these interests.

  • Contractual Necessity:
    Where processing is necessary for entering into or fulfilling a contract (e.g., client contracts for talent acquisition services).

  • Legal Obligation:
    To comply with legal requirements, such as tax, employment, or immigration regulations.

6. Data Use and Processing

Fortiva will only use personal data for the following purposes:

  • Recruitment:
    To match candidates to job opportunities within the construction and engineering sectors, including evaluating qualifications, conducting interviews, and communicating with candidates.

  • Client Services:
    To fulfil our contractual obligations to clients by providing them with suitable candidates for their roles.

  • Communication:
    To send relevant information about job opportunities, market insights, and recruitment updates, only where consent has been obtained.

  • Legal and Compliance:
    To comply with applicable laws, resolve disputes, or enforce agreements.

7. Data Sharing

We may share personal data with third parties, including:

  • Clients:
    We will share candidate details with clients where it is necessary to consider them for a role, subject to the candidate’s consent.

  • Service Providers:
    Trusted third-party providers that assist us in our business operations (e.g., payroll services, cloud storage, or background check providers) under strict confidentiality agreements.

  • Legal or Regulatory Authorities:
    If required to comply with legal obligations or protect the rights, property, or safety of individuals.


Fortiva ensures that any third parties with whom we share personal data comply with the GDPR and provide adequate safeguards to protect the data.

8. Data Storage and Security

We are committed to maintaining the security and confidentiality of personal data. This includes:

  • Data Encryption:
    All personal data stored electronically is encrypted both in transit and at rest.

  • Access Controls:
    Only authorized personnel have access to personal data, and their access is restricted based on job roles.

  • Regular Audits:
    We conduct regular reviews of our data processing activities and security measures to ensure compliance with the GDPR.

  • Data Retention:
    Personal data will only be retained for as long as necessary for the purposes for which it was collected. We have specific retention periods for different types of data (e.g., CVs will be retained for 7 years unless the candidate requests deletion sooner).

9. Data Subject Rights

Under the GDPR, data subjects have the following rights regarding their personal data:

  • Right to Access:
    Individuals have the right to request a copy of their personal data held by Fortiva.

  • Right to Rectification:
    If any data is inaccurate or incomplete, individuals have the right to request corrections.

  • Right to Erasure (“Right to be Forgotten”):
    Individuals can request that their personal data be deleted when it is no longer necessary for the purposes for which it was collected or if they withdraw consent.

  • Right to Restriction:
    Individuals can request that the processing of their data be restricted under certain conditions.

  • Right to Data Portability:
    Individuals have the right to receive their personal data in a structured, commonly used, and machine-readable format and transmit it to another data controller.

  • Right to Object:
    Individuals can object to the processing of their personal data based on legitimate interests or direct marketing.


Requests to exercise any of these rights can be made by contacting our Data Protection Officer at info@fortiva.co.uk and we will respond within one month of receiving the request.

10. Breach Notification

In the event of a personal data breach, Fortiva will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required under the GDPR. If the breach poses a high risk to the rights and freedoms of individuals, we will also inform the affected individuals without undue delay.

11. Data Protection Officer (DPO)

Fortiva has appointed a Data Protection Officer to oversee compliance with this policy and the GDPR. The DPO is responsible for monitoring data protection activities, addressing queries, and responding to data subject requests.

Contact details for the DPO:

Email:                     info@fortiva.co.uk

Phone:                   +44 (0) 333 305 8816    

Address:               Unit 3, Building 2, The Colony, Wilmslow, SK9 4LY.

12. Review and Updates

This GDPR Policy will be reviewed regularly to ensure it remains up-to-date and compliant with any changes to data protection laws. We will notify relevant stakeholders of any significant changes to this policy.

13. Conclusion

At Fortiva, we are dedicated to protecting the privacy and rights of all individuals whose personal data we process. By adhering to the GDPR and maintaining the highest standards of data protection, we ensure that our recruitment services are conducted lawfully and transparently.