1. Data we collect
We process account and contact details; Global Mobility Profile fields; CVs and candidate-provided citizenship, work-right, sponsorship, registration and relocation claims; applications, saved roles, invitations, messages and consent history; employer company, job and ATS/source declarations, plus retained historical campaign records; agency role data; provider evidence and lead activity; affiliate attribution; billing identifiers; and security, device and usage events.
2. Purposes and legal bases
We use data to provide accounts and requested services, enforce contracts, secure and moderate the platform, meet legal duties, manage payments and communications, and pursue proportionate legitimate interests such as fraud prevention and service health. Optional employer discovery and provider contact/sharing use explicit consent where the product requires it. Marketing and non-essential analytics follow applicable consent and suppression controls.
3. Discovery, matching and sharing
Employer discovery consent is off by default. Only consent-visible, active candidates can be returned to entitled direct employers. Withdrawing consent stops future discovery, but cannot retract data already shared through an application, accepted introduction or message.
Compatibility uses candidate and job data plus current verified or self-attested mobility facts to produce separate explanatory signals and missing-information prompts. It does not determine immigration eligibility or hiring. Relocation Help requires both contact and specialist-sharing consent. Matched approved specialists can review the request details and notes before acceptance. Contact details become available after confirmed card payment and acceptance while consent remains active.
4. AI-assisted processing
Candidate extraction submits candidate-owned text to the configured provider to generate grounded drafts. Nothing is written until the candidate accepts selected suggestions. Provider use is enabled only where the deployment confirms the required no-training contract; provider storage is disabled for those requests. Other optional AI features may have different configurations, which will be disclosed at the point of use.
5. Recipients and international processing
Recipients may include consent-authorised employers, requested relocation providers, agencies after candidate introduction consent, and vendors supporting hosting, databases, email, security, payments, analytics, error monitoring and configured AI. Examples actually used in the codebase may include Stripe, Vercel, PostHog, Sentry, Supabase, MongoDB, Cloudflare and OpenAI; the active deployment may use only a subset. Appropriate transfer safeguards are used where required.
6. Retention, deletion and audit
We keep live data only while needed for the service and stated purposes. Candidate extraction drafts have dedicated expiry and purge controls. Qualified provider leads are scheduled for retention review after 365 days and purge after 730 days unless a lawful need requires adjustment. Closed accounts may leave minimal audit, payment, dispute, fraud, security and communications-suppression records.
Deletion may first deactivate or soft-delete records before permanent removal from live systems and scheduled backup expiry. Users may access, correct, export, object, restrict, withdraw consent or request deletion where applicable by using account controls or emailing support@globalsponsorhub.com.
7. Communications and controls
Transactional messages follow account and service events. Marketing preferences and suppression records are maintained so opt-outs remain effective. Cookie and analytics controls are described in the Cookie Policy. Complaints may be raised with us and, where applicable, a data-protection authority.
Questions: support@globalsponsorhub.com · All legal documents
