BookKeptevidence chain
Legal

Privacy notice

What we do with personal data, said specifically. A compliance product that is vague about its own data handling has answered the question badly.

Version 1.0 · 15 August 2026

These are drafts pending legal review. They describe the system accurately, which is the hard half, but they have not been reviewed by a solicitor.

The two roles, because they are different

This matters more than anything else on the page, and it is the thing most privacy notices blur.

Whose dataWho decides what happens to itOur role
Workers, candidates and client contacts inside an agency's bookThe agencyProcessor. We act on the agency's instructions and nothing else. See the data processing agreement.
The agency's own staff who sign in, and anybody who contacts usUsController. That is what this notice covers.

If you are a contractor or candidate and want to know what an agency holds about you, ask the agency. They are the controller and they hold the relationship. We will help them answer, and the product has a subject access export built in for exactly that.

Who we are

COM Computing Limited, registered office 37 York Road, Douglas, Isle of Man IM2 3AY. Contact for anything on this page: corey@comcomputing.im.

What we hold as controller

Our lawful basis is the contract with your agency, and our legitimate interest in running, securing and supporting the service.

What the product holds as processor

Listed plainly, because an agency's DPO will ask and because a vague answer is worse than a long one. On a worker or candidate the system can hold: name, email, phone, postal address, postcode, date of birth, National Insurance number, personal service company name and number, VAT number, right-to-work check records and evidence, Key Information Documents, timesheets and hours, pay and charge rates, and the audit trail of every compliance act.

National Insurance numbers and dates of birth are held because right-to-work and payroll records require them. They are not special category data under UK GDPR, but they are the kind of data a breach would matter for, and they are treated accordingly.

Where it is hosted

Today the application and database run in a United States region. For UK and Isle of Man personal data that is a restricted international transfer, and it needs the appropriate safeguards in place before an agency's real records are loaded. We are stating it here rather than burying it, and moving the deployment to a UK or EU region is on the list before the first production customer. If you are evaluating BookKept, ask us where this stands.

The marketing site and documentation are served separately from the application.

Who else touches it

Sub-processorWhat forWhat they see
RailwayApplication and database hostingEverything stored, at rest and in transit
ResendTransactional email: approval requests, alerts, set-password linksRecipient address and message content
AnthropicOptional CV enrichment onlyThe CV text submitted for extraction, when the feature is switched on

The Anthropic feature is optional and off without an API key. When it is off, the talent pool runs entirely on human-entered data. Anything a model produced is marked as such on the record, so a reader can always tell what was extracted rather than entered.

We do not sell data, we do not share it for advertising, and no customer's data is used to train any model.

How long it is kept

As processor, retention is the agency's decision and the product enforces it as a scheduled, logged act rather than a quiet delete. The default for candidate records follows ICO recruitment guidance of no longer than necessary, with 24 months as the shipped default, which each agency can change.

As controller: staff account records for the life of the subscription plus 12 months; enquiries for 24 months; logs for 90 days. Audit events are never edited or deleted, because an audit trail that can be altered is not one; on offboarding they leave with the agency's bundle.

How it is protected

Your rights

You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, object to processing based on legitimate interests, and complain to a regulator. For data held by an agency inside the product, direct the request to that agency.

The Isle of Man has its own data protection regime, applying GDPR standards, supervised by the Isle of Man Information Commissioner. If you are in the UK you may also complain to the ICO.

Changes

Material changes to this notice will be told to subscribing agencies directly rather than only posted here.