homepage
Recruitment Services
permanent legal Recruitment
Legal Executive Search
Legal on-Demand
Hiring for Law Firms
Blog: Hiring Advice
Career Opportunities
Open Permanent Positions
Join On–Demand Network
Blog: Career Advice
About Us
Get in touch!
en
de
open/close navigation

Privacy Policy

This Privacy Policy explains how Deep Blue Recruitment Ltd (“we,” “us,” or “our”) collects, uses, discloses, and protects personal data when you visit or interact with our website (hosted on Webflow), including features such as our contact form and newsletter signup. We comply with the UK Data Protection Act 2018, UK GDPR, and EU GDPR (Regulation (EU) 2016/679).

1. Data Controller

Deep Blue Recruitment Ltd
20‑22 Wenlock Road
London, N1 7GU
United Kingdom
Email: info@deepbluerecruitment.com

‍

2. Data Protection Officer (DPO)

If required under GDPR, our DPO is:
Name: Mr. Peter Clark
Email: info@deepbluerecruitment.com

‍

3. EU Representative (if applicable)

Name: Mr. Peter Clark
Email: info@deepbluerecruitment.com

‍

4. Children’s Data

We do not knowingly collect personal data from children under the age of 16 (or 13 in Member States that set a lower age). If we become aware that a minor has submitted data without parental consent, we will delete it immediately (Art 8 GDPR).

‍

5. Personal Data We Collect

5.1 Contact Form

  • Data fields: First name; Last name; Email address; Phone number
  • Metadata: Timestamp; IP address; browser/user‑agent string

5.2 Newsletter Signup

  • Data fields: Email address (via Sendinblue form at sibforms.com)
  • Metadata: Timestamp; IP address

5.3 Website Analytics (Plausible Analytics)

We use Plausible Analytics, a privacy-friendly web analytics service provided by Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. Plausible does not use cookies, does not store anything on your device (no local storage, no persistent identifiers) and does not track you across websites or devices.

  • Data processed: page address (URL) and referring website; browser, operating system and device type (derived from the user-agent string); approximate location (country, region, city, derived from the IP address); time spent and scroll depth on a page; interactions with our website, such as clicks on buttons, links and job listings, language switches, and whether a form was started or sent successfully. The content you enter into forms is never sent to Plausible.
  • How visitors are counted: your IP address and user-agent string are combined with our website domain and a random value (salt) that is deleted and replaced every 24 hours, and then irreversibly hashed. This daily identifier is used only to count unique visitors and to group page views into visits on that day. Your IP address and the full user-agent string are not stored.
  • Result: we only see aggregated statistics. They do not allow us to identify you, and no user profiles are created.
  • Hosting: all data is processed and stored within the EU. Plausible acts as our processor under a data processing agreement (Art 28 GDPR).
  • Legal basis: legitimate interest (Art 6 (1)(f) GDPR) in understanding how our website is used, so that we can improve its content and measure which pages and enquiry routes work. Plausible stores no information on your device and does not recognise you across days or websites, so no consent is required.
  • Your right to object: you can object to this processing at any time (Art 21 GDPR) by contacting us. You can also prevent analytics entirely by blocking scripts from plausible.io in your browser or with a content blocker.

5.4 Spam Protection for Forms (Cloudflare Turnstile)

Our hosting provider Webflow protects the forms on our website against spam and automated abuse with Cloudflare Turnstile, provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. When you visit our website, Turnstile processes your IP address and technical information about your browser and device to distinguish humans from bots. Cloudflare uses this information to detect and block bots and to improve its bot detection; according to Cloudflare, it is not used to identify, profile or target individuals. Legal basis: legitimate interest in protecting our forms and systems (Art 6 (1)(f) GDPR). Any access to information on your device is strictly necessary for this security function (§ 25 (2) no. 2 German TDDDG).

5.5 Job Listings (JOIN)

On our careers page for permanent positions, our current vacancies are loaded from JOIN, the recruiting platform of JOIN Solutions AG, Eichenstrasse 2, 8808 Pfäffikon SZ, Switzerland. To display the listings, your browser connects to JOIN’s servers, which process your IP address and technical browser data. Legal basis: legitimate interest in presenting our current vacancies (Art 6 (1)(f) GDPR). Switzerland is covered by an adequacy decision of the European Commission and the UK. If you click on a job listing, you are taken to JOIN’s website, where JOIN’s privacy policy applies.

5.6 Cookies and Similar Technologies

We do not use cookies or similar technologies (such as local storage) for analytics, marketing or advertising, and we therefore do not use a cookie banner. Our website only uses technologies that are strictly necessary for its secure operation (see section 5.4).

‍

6. Purposes & Legal Bases for Processing

  • Responding to contact‑form inquiries (Legal basis: Consent (Art 6 (1)(a)))
  • Delivering newsletter communications (Legal basis: Consent (Art 6 (1)(a)))
  • Website analytics with Plausible (Legal basis: Legitimate interest (Art 6 (1)(f)))
  • Protecting our forms against spam and abuse (Legal basis: Legitimate interest (Art 6 (1)(f)))
  • Displaying our current vacancies via JOIN (Legal basis: Legitimate interest (Art 6 (1)(f)))
  • Ensuring website security and integrity (Legal basis: Legitimate interest (Art 6 (1)(f)))
  • Meeting legal obligations (e.g. record‑keeping) (Legal basis: Legal obligation (Art 6 (1)(c)))

‍

Legitimate Interests Assessment (Art 6 (1)(f))

Website security

  • Interest: Protecting our website and data from fraud, hacking, spam and abuse
  • Necessity: Security logging and bot detection (IP, user‑agent) are essential to detect/prevent attacks
  • Balance: Low privacy impact; data used only for security purposes (security logs retained max 12 months)

Website analytics

  • Interest: Understanding which pages and content help clients and candidates, so that we can improve our website
  • Necessity: Cookieless, aggregated statistics are the least intrusive way to measure this
  • Balance: No cookies, no stored IP addresses, no user profiles or cross‑site tracking, processing within the EU; you can object at any time

‍

7. Categories of Recipients (Art 13 (1)(e))

  • Internal: Sales & marketing team; IT & security staff; finance department
  • External processors and service providers:
    • Webflow, Inc. (hosting & form data processing)
    • Webflow hosting services subcontractors (please refer to https://webflow.com/legal/subprocessors for detailed information)
    • Plausible Insights OÜ (privacy‑friendly web analytics, EU, https://plausible.io/privacy)
    • Cloudflare, Inc. (spam protection for forms via Webflow, https://www.cloudflare.com/turnstile-privacy-policy/)
    • JOIN Solutions AG (job listings on our careers page, https://join.com/)
    • Sendinblue / Brevo (newsletter delivery, https://www.brevo.com/)
  • Authorities: UK ICO, EU DPAs, courts or regulators if legally required

‍

8. International Transfers & Safeguards (Art 13 (1)(f))

Plausible processes all analytics data within the EU. JOIN is based in Switzerland, which is covered by an adequacy decision. Some other processors (such as Webflow and Cloudflare) may transfer data outside the UK/EU. We ensure:

  • Standard Contractual Clauses approved by the European Commission (and the UK SCC addendum)
  • EU‑US Data Privacy Framework (and its UK extension) where the recipient is certified
  • Adequacy decisions (e.g. UK → EU; EU → UK; Switzerland)
  • To request a copy of the SCCs or other safeguards, please contact us at info@deepbluerecruitment.com.

‍

9. Data Retention & Criteria (Art 13 (2)(a))

  • Contact‑form submissions. Retention period: Up to 3 years. Criteria: End of client relationship + statute of limitations period
  • Newsletter sign‑up records. Retention period: Until you unsubscribe. Criteria: Consent withdrawn
  • Security logs (IP, user‑agent). Retention period: 12 months. Criteria: To investigate security events only
  • Website analytics. Plausible keeps only aggregated statistics that do not identify you. The random value used to count unique visitors is deleted after 24 hours; IP addresses are not stored.

‍

10. Cookies & Tracking

Our website does not use cookies or similar technologies for analytics, marketing or advertising, and it does not track you across websites. That is why we do not show a cookie banner. Our website analytics work without cookies (see section 5.3); spam protection for our forms is described in section 5.4.

‍

11. Automated Decision‑Making & Profiling (Art 13 (2)(f))

We do not carry out automated decision‑making, including profiling, that produces legal effects or significantly affects you.

‍

12. Your Rights

Under UK GDPR and EU GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate or incomplete data
  • Erase (“be forgotten”) where no overriding legal basis exists
  • Restrict or object to processing
  • Data portability (receive data in a structured, machine‑readable format)
  • Withdraw consent at any time (without affecting lawfulness of prior processing)
  • Lodge a complaint with the ICO (UK) or your local EU Data Protection Authority

‍

13. Exercising Your Rights

To exercise any of the above rights, or to complain about our processing, contact our DPO at info@deepbluerecruitment.com. You may also lodge a complaint with the UK Information Commissioner’s Office (ICO) or, if you reside in the EU, with your local DPA.

‍

14. Security Measures & Breach Notification

We implement appropriate technical and organisational measures (e.g. HTTPS/TLS, access controls, pseudonymisation). In the unlikely event of a personal data breach, we will notify the relevant supervisory authority within 72 hours and inform impacted individuals where required (Art 33, Art 34 GDPR).

‍

15. Changes to This Policy

We may update this policy to reflect legal, technical or organisational changes. Where material changes occur, we will notify you by email (if you have subscribed) or via a prominent notice on our website.

‍

16. Effective Date

This version is effective as of 9 October 2026.

deep blue recruitment
homepage
Recruitment Solutions
Permanent Legal Recruitment
Executive Legal Search
interim & Legal on-Demand
Connect
About Us
Contact
Subscribe
Join our newsletter to stay up to date on open positions and new services
Label
Subscribe
By subscribing you agree to with our Privacy Policy and provide consent to receive updates from our company.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
© 2026 Deep Blue Recruitment Ltd. All rights reserved.
ImprintPrivacy Policy
info@deepbluerecruitment.com
linkedin