Legal

Privacy policy

Last updated: September 2026

Who we are

Stapha is a hiring and matching platform for UK social care, operated by Stapha Ltd ([company number to be inserted]), registered in England and Wales. We are the data controller for the personal data described in this policy.

If you have any questions about how we handle your data, contact us at hello@stapha.co.uk.

What data we collect

Care workers (candidates). When you create an account and use Stapha, we collect:

  • Account information: your name, email address, and password (stored as a secure hash).
  • Profile information: location or postcode, employment history, job preferences, and care specialisms.
  • Compliance Passport documents: passport photos (for right-to-work verification), CVs, and LinkedIn profile URLs (for care experience verification). These are stored in a private, encrypted storage bucket and are never publicly accessible.
  • Screening responses: your answers to role-specific screening questions submitted as part of a job application.
  • Application records: which jobs you have applied for, at what stage each application is, and any fit-band scores generated from your responses.
  • Employer reviews: ratings and optional written feedback you leave about past employers during onboarding.

Employers. When you register a care home or group on Stapha, we collect:

  • Account information: contact name, work email address, and password.
  • Organisation details: care home name, address, CQC rating (where provided), staff retention figures (where voluntarily disclosed), and a description of the home.
  • Job postings: role titles, pay rates, shift patterns, compliance requirements, and any associated screening configuration.

How and why we use your data

We process your personal data on the following legal bases under UK GDPR:

  • Contract performance. We need certain data — your account details, profile, applications, and job postings — to provide the Stapha service you signed up for. Without it we cannot create your account, match you with roles, or process applications.
  • Legitimate interests. We use application and matching data to improve our platform, detect abuse, and send transactional communications (application confirmations, stage updates). We have assessed that our legitimate interests are not overridden by your rights.
  • Legal obligation. We support right-to-work compliance by providing a secure space for candidates to upload identity documents. We do not ourselves verify these documents automatically; a Stapha staff member or the hiring employer reviews them manually.
  • Consent. Where we send non-essential communications or use data for purposes beyond the above, we will ask for your consent separately and you may withdraw it at any time.

Special category data

Right-to-work documents (such as a passport photo) may reveal nationality, which is sensitive personal data under UK GDPR. We collect this solely to support pre-employment right-to-work checks, store it in a private encrypted bucket, and restrict access to the candidate and the employer they have chosen to share it with. We never sell, license, or share it with third parties beyond those listed below.

Who we share your data with

We do not sell your personal data. We share it only in the following limited circumstances:

  • Other Stapha users. When you apply for a role, the employer gains access to your profile, screening responses, and — if you choose to share — your Compliance Passport. You control which employers can see your passport and can revoke access at any time.
  • Supabase. Our database, authentication, and file storage run on Supabase infrastructure hosted in the European Economic Area (AWS EU West). Supabase processes data on our behalf as a data processor under a Data Processing Agreement.
  • Resend. We use Resend to send transactional emails (application confirmations, stage notifications). Resend is US-based; transfers are safeguarded by Standard Contractual Clauses approved by the UK Information Commissioner.
  • Legal compliance. We may disclose data if required to do so by law, court order, or to protect the rights, property, or safety of Stapha, our users, or the public.

How long we keep your data

  • Active accounts: we retain your data for as long as your account is active.
  • Deleted accounts: we delete or anonymise your profile data within 30 days of account deletion. Application records may be retained for up to 12 months in anonymised form for platform analytics.
  • Compliance Passport documents: deleted within 30 days of account deletion or within 30 days of an employer revoking access (whichever is earlier).
  • Unsuccessful candidate data held by an employer: employers are required under our Terms of Service to delete data about unsuccessful candidates within 6 months, in line with ICO guidance on recruitment records.

Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten") where there is no legitimate reason for us to continue processing it.
  • Restrict processing while a dispute about accuracy or legitimate interest is resolved.
  • Portability — receive your data in a structured, machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.

To exercise any of these rights, email hello@stapha.co.uk. We will respond within one calendar month.

Complaints

If you are unhappy with how we have handled your data, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We would appreciate the opportunity to address your concern first, so please contact us before escalating to the ICO.

Changes to this policy

We may update this policy as the platform evolves. Material changes will be communicated by email or via a notice on the platform. The date at the top of this page shows when it was last revised.