Legal

Privacy notice

Last updated: 5 May 2026

Plain-English summary. I'm Brian Gillingham, a UK-based recruitment consultant. I receive job specs and CVs from clients, score them with my Mermoid platform, and return a ranked, citation-backed report within 24 hours. CVs and job specs are deleted 7 days after delivery; audit reports kept 18 months for tribunal defensibility unless you ask me to delete sooner. I never sell or share your data with third parties.

1. Who is the data controller?

Brian Gillingham, t/a ProperFit Hire, Lincoln, LN2 2HL, United Kingdom. ICO registration: ZC140339 at the time of writing; enquiries to brian@properfithire.co.uk.

2. What data is processed?

3. Lawful basis (UK GDPR)

4. Retention

5. Where data is stored

Mermoid runs on a virtual machine in the European data residency (Switzerland North, EU-equivalent under the UK adequacy regulations for Switzerland). Persistent storage of CV contents and account data lives only on this VM — never in third-party clouds.

The scoring engine (cohort ranking, retention prediction, skills compliance) is fully deterministic and runs on the VM only — no LLM inference touches the scoring path.

Generative features — cover-letter writing, CV-line AI rewrites, structured-CV extraction at /me/profile-setup, STAR writeups, interview-prep packs and the candidate chatbot — DO send text to LLM providers (see Sub-processors below). For each LLM call:

6. Sub-processors

Full transparent list. Each section says what data the sub-processor sees, and why we use them.

No analytics that track individuals. No advertising trackers. No data brokers. We commit to listing every new sub-processor here within 14 days of adoption.

7. Your rights

Under UK GDPR you can exercise the rights of access, rectification, erasure, restriction, portability, and objection. To exercise any of these, email me. I respond within 30 days (typically same-day). You also have the right to complain to the UK Information Commissioner's Office.

8. Automated decision-making

Mermoid's scoring is decision-support, not solely automated decision-making. Final hiring decisions are always made by a human (the customer's hiring manager). Per the ICO's April 2026 guidance, where a human merely "rubber stamps" the AI ranking that becomes ADM under Article 22; my reports are designed to support meaningful human review with citations and signal evidence so the human can substantively challenge any rank position.

9. Candidate-specific notice

If you are a candidate whose CV has been processed: contact me directly to request access, correction, or erasure. I will respond within 30 days. I do not contact candidates directly without my customer's authorisation.

Data Protection contact:
Brian Gillingham
brian@properfithire.co.uk
Lincoln, LN2 2HL, United Kingdom