Privacy Policy
Last updated: 3 August 2026
Axiom People is built on privacy. Our entire purpose is to let professionals be found for the right opportunity without being exposed. This policy explains, in plain terms, what personal data we collect, why, how we protect it, how long we keep it, and the rights you have over it.
1. Who we are
Axiom People is a privacy-first talent network for professionals across Ireland and the United Kingdom, operated by Tailormade Recruitment Ltd, trading as Axiom People ("we", "us"), a company registered in Ireland. For the personal data we process through this platform, we act as the data controller. We serve users in Ireland and the United Kingdom: we comply with the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018 for EU and Irish users, and with the UK GDPR and the UK Data Protection Act 2018 for users in the United Kingdom.
For any privacy question, or to exercise your rights, contact us at derek@axiompeople.com.
2. Who this policy covers
This policy applies to three groups:
- Candidates — professionals who register or are invited to join.
- Employers — firms that use the platform to find talent.
- Referees — people a candidate invites to confirm their professional experience.
3. The data we collect
From candidates
- Identifying data (kept private): your name, email, phone, current employer, and any LinkedIn URL or CV you provide.
- Professional data (shown to employers only in anonymised form): your role/headline, specialism, qualifications, years of experience, general location, salary expectation, and an anonymised summary.
- Fit-profile data (optional): your responses to our fit assessment about working style, preferences and motivations.
- Account data: your login email and an encrypted password.
From employers
- Company name, contact name, email, the roles you are hiring for, and account credentials.
From referees
- Your name, email and stated relationship to the candidate (provided by the candidate when inviting you), and the response you choose to give (confirmation, optional comments, and whether you are willing to work with the person again).
From The Going Rate
- Salary lookups: we record which combination of sector, experience, qualification and location was looked up, and never who looked it up. No account, name or email is required to use the tool.
- Salary contributions (optional): if you choose to enter your own salary, it is stored anonymously and used only in aggregate to sharpen published ranges. It is never linked to you.
- Assisted-profile requests (optional): if you ask us to draft a starter profile for you, we store the LinkedIn URL and/or email you provide, together with the cohort you looked up, and a record of your consent. We use these solely to prepare a draft profile from the LinkedIn text you choose to provide, and send it to you for approval. We do not automatically scrape or harvest LinkedIn. Nothing is published until you approve it, and you can ask us to delete the request at any time.
4. How we use your data, and our lawful basis
Under the EU GDPR and Irish Data Protection Act 2018 — and, for users in the United Kingdom, the UK GDPR and UK Data Protection Act 2018 — we rely on the following lawful bases:
- Consent — candidates consent to join and to have an anonymised profile created, and separately consent where they ask us to draft a starter profile from their public LinkedIn. You may withdraw consent at any time.
- Legitimate interests — operating a recruitment matching service: building anonymised profiles, presenting them to vetted employers, and facilitating introductions you approve. We balance this against your rights, and our privacy-by-design model is central to that balance.
- Contract — providing the account and services you sign up for.
- Legal obligation — where we must retain or disclose data to comply with law.
We do not sell your data, and we do not use it for advertising.
5. Our anonymity model — the core promise
Employers browsing the platform see anonymised profiles only: your headline, specialism, experience, qualifications, salary band and summary. They do not see your name, your current or previous employer, your contact details, your CV, or your photograph.
Your identity is revealed to a specific employer only when you personally approve an introduction to that employer. You may also block named employers from seeing your profile at all. These protections are enforced at the database level, independently tested.
6. Peer verification — how referee data is handled
If you choose to request peer verification, you provide the name and email of a referee. We email that referee a private request to confirm your professional experience. Important protections:
- Referee contact details are visible only to you and to us — never to employers.
- The request is worded to confirm professional experience, and does not state that you are seeking a new role.
- Employers see only the number of completed verifications (e.g. "verified by 3 peers") and, where the referee has agreed, the referee's stated relationship to you — never the referee's name or contact details.
- Referees respond via a private link, provide only what they choose, and can ignore the request entirely.
Referees: your data is used solely to record the reference you provide. If you do not wish to respond, simply ignore the email and no record of a response is created. You may contact us at any time to have your details removed.
7. Who processes data on our behalf
We use carefully chosen processors, bound by data-processing terms, to run the platform:
- Supabase — secure database and authentication, hosted in the EU (Ireland region).
- LetsHost — website hosting (Ireland).
- Resend — email delivery (EU region) for platform notifications and verification requests.
Where any processing involves transfer outside the EEA, we ensure appropriate safeguards are in place. Our data is hosted in the EU by design. Personal data relating to UK users is processed in the EU (Ireland); this transfer relies on the data-protection arrangements in place between the UK and the EU. Where a processor is located outside both the UK and the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or the UK International Data Transfer Agreement.
8. How we protect your data
- Identifying data is stored separately from anonymised profiles, with strict database-level access controls (row-level security).
- Passwords are encrypted; connections are secured.
- Access to identifying data is limited to what is necessary to operate the service.
- Our access controls are independently tested to confirm that identities, documents and messages are not exposed.
9. How long we keep your data
We keep data only as long as necessary:
- Candidate data — for as long as your profile is active, and for up to 24 months after your last activity, after which it is deleted or anonymised, unless you ask us to remove it sooner.
- Referee data — for up to 12 months from the verification request, then deleted.
- Registration enquiries — for up to 12 months if not converted to an account.
- Going Rate requests — assisted-profile requests and range-alert sign-ups are kept for up to 12 months if they do not become an account, then deleted. Anonymous salary contributions carry no identifying data and are retained in aggregate.
- Employer data — for the duration of the relationship and a reasonable period afterward for legal and accounting purposes.
These retention periods are kept under review and may be adjusted. If you want your data removed at any time, contact us and we will action it.
10. Your rights
Under the EU and UK GDPR you have the right to: access your data; correct it; erase it ("right to be forgotten"); restrict or object to processing; data portability; and to withdraw consent at any time. To exercise any of these, email derek@axiompeople.com and we will respond within one month.
You also have the right to lodge a complaint with your supervisory authority if you are unhappy with how we handle your data — in Ireland, the Data Protection Commission (www.dataprotection.ie); in the United Kingdom, the Information Commissioner’s Office (www.ico.org.uk).
11. Data breaches
We take security seriously. In the event of a personal data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority — the Data Protection Commission in Ireland, or the Information Commissioner’s Office where UK users are affected — within 72 hours where required, and will inform affected individuals without undue delay where the risk is high.
12. Changes to this policy
We may update this policy as the platform evolves. The "last updated" date above shows the current version, and we will notify registered users of material changes.
13. Contact
Questions, requests, or concerns: derek@axiompeople.com.
This policy is provided in good faith and is kept under review. It does not constitute legal advice. We recommend professional legal review for your specific circumstances.