Last updated: 6 August 2026
This policy applies to all personal data processed by BelloiteX (Belloite Ltd) in connection with this website, our recruitment portal, our AI assistant, and our ICT consulting services.
BelloiteX is the trading name of Belloite Ltd, an information, communication and technology (ICT) solutions firm registered in England and Wales. We are the data controller for personal data collected through this website and our associated services.
We have not appointed a formal Data Protection Officer (DPO) as we do not meet the thresholds that make this mandatory. All data protection enquiries are handled directly by the company's senior management. You may contact us at the details above for any matter relating to this policy.
This Privacy Policy describes how we collect, use, share, retain and protect personal data in connection with:
This policy does not cover personal data processed in the context of our business-to-business (B2B) client services or client employee data. Separate data processing agreements govern those relationships.
When you visit our website we automatically collect limited technical information to help us monitor site health and detect unusual activity. This data is used to send an internal notification to our team and is not stored in a persistent database.
When you book a free consultation or submit a contact form (including through our AI assistant), we collect the information you voluntarily provide:
Our website includes an AI-powered chat assistant named Bella. When you use this feature:
When you submit a job application through our careers portal, we collect the following personal data as part of the application form:
For applicants who progress to the pre-employment verification stage, we may request that you upload one or more of the following document categories via a secure, time-limited upload link sent to your registered email address:
These documents are stored in encrypted private cloud storage accessible only to authorised BelloiteX recruitment staff. Documents are not shared with third parties except where required by law. The upload links are cryptographically signed and expire automatically after seven days.
For applicants offered a position, we generate employment documentation (such as a zero-hours worker agreement) using the personal data already collected during the application process — specifically your name, home address, agreed job title, hourly rate, and engagement start date. This document is made available to you and to our internal recruitment team. It is not shared with any third party except for storage within our secure infrastructure.
| Purpose | Personal data used | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Send an internal visitor alert to our team | IP address, location, device, browser, page URL, referrer | Legitimate interest (monitoring site health and traffic) |
| Respond to and arrange consultations | Name, email, phone, service interest, preferred date/time, notes | Legitimate interest / steps towards contract |
| Send you a booking confirmation email with calendar invite | Name, email, service, date/time | Steps towards contract (pre-contractual necessity) |
| Generate an AI response in the chat assistant (Bella) | Your chat messages | Legitimate interest (providing the requested service) |
| Review chat transcripts to improve service quality | Chat transcript | Legitimate interest (service improvement) |
| Assess and process job applications | All application form data, CV, cover letter | Legitimate interest (recruitment) |
| Communicate application status updates to applicants | Name, email, job role, application status | Legitimate interest (recruitment communication) |
| Verify identity and proof of address at pre-employment stage | Photo ID, proof of address documents | Legitimate interest (due diligence); Legal obligation (where required by financial or regulatory sector clients) |
| Verify the right to work in the UK | Immigration status, right-to-work documents | Legal obligation (Immigration, Asylum and Nationality Act 2006) |
| Generate pre-employment contractual documentation | Name, address, job title, pay rate, start date | Steps towards contract (pre-contractual necessity) |
| Maintain internal records of recruitment activity | Application data, status history, notes, documents | Legitimate interest (business record-keeping) |
Our AI chat assistant (Bella) uses an automated language model to generate responses to your messages in real time. This is a standard AI text generation process and does not constitute automated decision-making under Article 22 of UK GDPR — it produces conversational responses only and does not make decisions with legal or similarly significant effects on you.
Our recruitment portal assigns application status labels (e.g. "reviewing", "shortlisted", "offer made") that are set manually by authorised staff. No hiring or rejection decisions are made by automated means. All decisions about whether to progress, shortlist, interview, make an offer to, or reject a candidate are made by a human being.
Document upload links and authentication tokens used in our recruitment system are generated automatically using cryptographic processes. These are operational security measures and do not affect any decision about your application.
We engage carefully selected third-party data processors to operate our website and services. Each processor acts under our instruction and under a data processing agreement where applicable. We do not sell data to third parties, and we do not permit processors to use your data for their own purposes.
For security reasons, we do not publish the specific names or commercial identities of our technology infrastructure providers, as doing so may facilitate targeted social engineering or phishing attempts against our users or staff. Instead, we describe each category of service and its data handling scope below.
| Service category | Purpose | Data involved | Transfer location |
|---|---|---|---|
| Cloud application hosting and serverless infrastructure | Hosts the website, processes API requests, runs server-side application logic | All data passing through the website and API | United States (with appropriate safeguards) |
| Encrypted private file storage | Securely stores uploaded CVs and verification documents | CV files, photo ID, proof of address, right-to-work documents | United States (with appropriate safeguards) |
| Transactional email delivery service | Sends application confirmations, status update emails, document request emails, consultation confirmations, and internal team notifications by email | Name, email address, application details, message content | United States (with appropriate safeguards) |
| AI language model provider | Processes chat messages in real time to generate AI responses for the Bella assistant | The text of messages you send in the chat | United States (with appropriate safeguards) |
| Business instant messaging platform | Delivers real-time internal team notifications for new bookings, enquiries and visitor alerts | Booking details, contact information, chat transcripts (for bookings), visitor data | United States (with appropriate safeguards) |
| IP geolocation service | Converts raw IP addresses into approximate geographic locations (city/country) for internal visitor alerts | IP address (no other data transmitted) | European Economic Area |
| Web font delivery network | Loads typefaces used across the website | Your IP address and browser user-agent (as part of a standard HTTP font request) | United States |
If you would like more information about any specific provider category or wish to object to a particular transfer, please contact us at hello@belloite.co.uk.
Several of our service providers are based in, or process data in, the United States. The UK has not granted an adequacy decision in respect of the United States as a whole. For transfers to US-based processors, we rely on one or more of the following safeguards:
Our IP geolocation provider processes data within the European Economic Area (EEA), which benefits from UK adequacy regulations.
You may request a copy of the relevant transfer safeguards for any specific processor by contacting us at hello@belloite.co.uk.
We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by law. The following schedules apply:
| Data category | Retention period | Basis for retention period |
|---|---|---|
| Visitor notification data (IP, location, device, page, referrer) | Not retained — dispatched as a one-time internal notification and not written to any persistent database | Minimal data principle; not required for any ongoing purpose |
| Consultation and contact enquiry details | Up to 2 years from the date of the enquiry or last contact, whichever is later | Legitimate interest in maintaining business records and responding to follow-up enquiries |
| AI chat transcripts (bookings / reviewed sessions) | Up to 12 months from the date of the conversation | Service quality review and business record |
| Job applications — unsuccessful outcome | Up to 6 months from the date we notify you of the outcome, then securely deleted | Enables us to respond to any dispute or query about the recruitment process; ICO guidance on recruitment records |
| Job applications — withdrawn by applicant before outcome | Up to 30 days from withdrawal, then deleted | Minimal retention in case of queries |
| CV and uploaded application files (unsuccessful applicants) | Deleted within 6 months of the application outcome | Proportionality; files are sensitive and not required once recruitment is concluded |
| Identity and proof-of-address documents (unsuccessful applicants) | Deleted within 6 months of the application outcome | Sensitive personal data; not required once verification stage is concluded without hire |
| Job applications — successful (hired) | Retained as part of the employment record for the duration of employment and for 6 years post-employment termination | Employment law obligations; Limitation Act 1980 (civil claims); HMRC record-keeping requirements |
| Right-to-work documents — hired employees | Retained for the duration of employment and for 2 years after employment ends, then securely destroyed | Home Office statutory right-to-work check requirements (Immigration, Asylum and Nationality Act 2006) |
| Pre-employment contractual documents (e.g. worker agreements) | Retained for the duration of the working relationship and for 6 years thereafter | Contractual record; Limitation Act 1980 |
| Chat history stored in your browser (localStorage) | Stored on your device only; persists until you clear your browser data or storage | We have no control over or access to this copy — it exists solely on your device |
At the end of any retention period, data is either permanently deleted from our systems or securely anonymised so that it can no longer be associated with any individual.
We do not use tracking cookies, advertising cookies, or any cookie-based analytics. The following browser storage mechanisms are used on this site:
bh_chat_v2 — stores your AI chat conversation history locally in your browser so that past conversations are visible when you return to the site. This data is stored entirely on your own device. We do not transmit, read, or have access to this local data. You can clear it at any time by clearing your browser's site data or local storage.bh_visited — a temporary flag set during your first page view of each browser session. It prevents our team from receiving duplicate visitor notifications within a single visit. This value is automatically deleted when you close the browser tab and is never transmitted to our servers or third parties.Our website loads typefaces from an external web font delivery network. When your browser requests a font file, your IP address and browser user-agent string are transmitted to that provider's servers as part of a standard HTTP request. This provider may log such requests in accordance with its own privacy policy. We have implemented the font loading in a way that minimises additional data sharing beyond what is inherent in a standard font file request. The provider does not set cookies via this mechanism.
When an applicant uses a document upload link, the time-limited token embedded in that link is read by our server to authenticate the request. The token is a cryptographically signed string and contains only your application identifier and the list of document types requested. It does not contain any plain-text personal data.
We implement a range of technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, loss, or destruction. These include:
No method of electronic transmission or storage is entirely free from risk. While we take all reasonable precautions, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours as required by UK GDPR, and we will inform affected individuals without undue delay where the breach is likely to result in a high risk to them.
As a data subject, you have the following rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. You may exercise any of these rights by contacting us at hello@belloite.co.uk. We will acknowledge your request promptly and respond within one calendar month. In complex cases we may extend this by a further two months, in which case we will notify you.
You may request a copy of the personal data we hold about you, along with information about how we use it, who we share it with, and how long we retain it. We will provide this at no charge in a commonly used electronic format unless the request is manifestly unfounded or excessive.
If the personal data we hold about you is inaccurate or incomplete, you have the right to ask us to correct or complete it. We will act on your request without undue delay.
You may request deletion of your personal data where:
This right does not apply where we are required to retain the data by law (for example, right-to-work records or employment records for tax purposes).
You may ask us to suspend our use of your data (while retaining it) where:
Where processing is based on your consent or on the performance of a contract, and is carried out by automated means, you may request a copy of your personal data in a structured, commonly used, machine-readable format (such as JSON or CSV). This right applies to data you have actively provided to us.
You have the right to object to processing carried out on the basis of our legitimate interest. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for a legal claim.
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. As described in Section 5, we do not make hiring or rejection decisions by automated means. If you believe an automated process has produced a decision with significant effect on you, please contact us immediately.
You may withdraw your application at any time by emailing hello@belloite.co.uk with your application reference number (included in your submission confirmation email) and a request to withdraw. Upon withdrawal, we will cease active consideration of your application. We will retain minimal records for up to 30 days to handle any queries, after which all associated data is deleted.
If your application is unsuccessful, we retain your data for up to 6 months (see Section 8). You may request early deletion of your application data at any time by contacting us. We will comply unless there is an active legal obligation or dispute that requires us to retain the data.
You may make a Subject Access Request (SAR) to receive a copy of all personal data we hold in connection with your application, including any notes our team has recorded, your application status history, and any documents you have uploaded. Submit your request to hello@belloite.co.uk.
We are required by UK law to verify that all persons we engage to work for us have the legal right to work in the United Kingdom before or on their first day of work. This verification involves checking and retaining copies of original identity and right-to-work documents. Failure to conduct these checks could result in a civil penalty under the Immigration, Asylum and Nationality Act 2006. We cannot waive this obligation.
If you submit an application for a role that is no longer available, or if we believe your profile may suit future vacancies, we may retain your application for up to 6 months and contact you if a relevant position arises. We will always make clear if we are doing this. You may opt out of this at any time.
Our website, services and recruitment portal are intended solely for use by adults (18 years of age or over) and businesses. We do not knowingly collect or process personal data from anyone under the age of 16. If you are under 16, please do not use this website, submit an application, or provide any personal data to us.
If you believe that a person under the age of 16 has submitted personal data to us, please notify us immediately at hello@belloite.co.uk. We will take steps to delete such data promptly.
We review and update this Privacy Policy periodically to reflect changes in our data processing activities, legal requirements, or guidance from the ICO. The "Last updated" date at the top of this page always reflects the most recent version.
Where a change is material — for example, if we introduce a new significant processing purpose or add a new category of third-party sharing — we will take reasonable steps to bring the change to your attention, which may include displaying a notice on our website or, where we hold your contact details, sending you an email.
Continued use of our website or services after a policy update constitutes acknowledgement of the revised policy. We encourage you to review this page periodically.
If you have a concern about how we handle your personal data, we ask that you contact us first so that we have the opportunity to address it:
We aim to respond to all privacy complaints within 14 days and to resolve them within 30 days. If you are not satisfied with our response, or if you believe we are processing your data unlawfully, you have the right to lodge a complaint directly with the Information Commissioner's Office (ICO), the UK's independent data protection authority: