Last updated: 18 July 2026
This policy explains how Hornsman Security Recruitment (The Hornsman Group Ltd, "we", "us") collects, uses, and protects personal information. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The Hornsman Group Ltd (company no. 17249812) is a London recruitment practice and private events host, and is the data controller for personal data you provide. For any privacy question, contact [email protected].
We only collect what you choose to give us when you contact us by email or WhatsApp, or when you register with us as a candidate. This website does not use forms, cookies, analytics, or tracking of any kind.
Enquiries: your name, contact details, and the content of your message.
Candidates: where you register with us, the information needed to represent and vet you, including work history, references, right-to-work status, and the background checks and vetting required for security roles.
We use your data to respond to you and to provide recruitment services. Our lawful bases are the performance of our arrangement with you, your consent (for sensitive vetting information), our legitimate interest in making placements, and our legal obligations.
Access is limited to the Director. Where professionally necessary, for example, legal advice or introducing a candidate to a prospective client with the candidate's consent, data may be shared in confidence. We do not sell, trade, or share your data for marketing.
Enquiries reach us by email (Proton Mail) and WhatsApp (operated by Meta), and are then held on our own equipment in the United Kingdom. Sensitive vetting information is held securely and is not stored on any public or online system. Where a provider processes data outside the UK, we rely on appropriate safeguards recognised under UK data protection law.
Sensitive vetting information is deleted once a placement is completed and the final fee has been paid, or earlier at your request. We keep only the limited records the law requires, principally financial records for six years, after which those are deleted too. You may ask us to remove your data at any time and we will action it promptly, unless a legal obligation requires us to keep a specific record.
Under UK GDPR you may:
· request a copy of the personal data we hold about you
· ask us to correct anything inaccurate
· ask us to delete your data ("right to be forgotten")
· withdraw your consent at any time
· object to how we process your data
· lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) if you believe your rights have been breached.
To exercise any of these, email [email protected]. We respond within one month.
We take reasonable steps to keep your data secure, including access controls, strong authentication, secure email handling, and reputable providers. No system is ever completely immune to risk, but we treat your data with the same care we extend to every client relationship.
If we change how we handle data, for example by introducing analytics or a new third-party service, we will update this policy and revise the "Last updated" date above before any new processing begins. Where a material change affects information you have already given us, we will notify you directly.