Privacy policy for the Natilik employer branding and recruitment
Date of publication: 10-09-2026
Last updated: June 2026 | Data Controller: Natilik Limited, 9a Devonshire Square, London, EC2M 4YN
This Privacy Notice explains how Natilik Limited (“Natilik”, "we", "us", "our") collects, uses, shares, stores, and protects personal data (“personal data”, “data”. This Privacy Notice applies to individuals interacting with us in different capacities, including job applicants, clients, and visitors to our website ("you", "your").
Natilik is a specialist IT and communications provider (company no. 5954905). Our registered address is 9a Devonshire Square, London, EC2M 4YN. The Natilik Group comprises Natilik UK and its trading subsidiaries in the USA and Australia.
For the purposes of UK data protection law, Natilik is the Data Controller of the personal data described in this notice. This means we determine the purposes and means of processing your personal data.
If you have any questions about this notice or how we handle your personal data, please contact us:
Post: Data Protection, Natilik, 9a Devonshire Square, London, EC2M 4YN
2. What personal data we collect and why
We collect and use personal data for the following purposes, each with its own lawful basis under UK General Data Protection Regulation “UK GDPR”:
2.1 Website visitors and enquiries
When you visit our website or contact us, we may collect your name, email address, telephone number, company name, IP address, and information about how you use our website (pages visited, time spent, browser type).
Lawful basis: Legitimate interests (Article 6(1)(f) UK GDPR). We have a legitimate interest in responding to enquiries, improving our website, and understanding how our content is used. We have assessed that this interest is not overridden by your rights and freedoms.
2.2 Marketing communications
If you have provided your contact details and are an existing client, or have expressed interest in our services, we may send you information about our products, services, events, and news.
Lawful basis: Legitimate interests (Article 6(1)(f) UK GDPR). As a B2B provider, we rely on legitimate interests to conduct direct marketing to business contacts. You have the right to opt out at any time — see Section 7.
Where we are required by law to obtain your consent before sending marketing (for example, to individual consumers or sole traders), we will do so.
If you apply for a role at Natilik, we collect information including your name, contact details, CV, employment history, qualifications, and any other information you provide during the recruitment process.
Lawful basis: Legitimate interests (Article 6(1)(f) UK GDPR) and, where necessary, steps taken prior to entering a contract (Article 6(1)(b)). We process your data to assess your suitability for the role and to manage the recruitment process.
We may retain unsuccessful candidate data for up to 24 months in case a suitable role arises, unless you ask us to delete it sooner or opt in to keep yourself on the database for up to 4 years (inactive).
If you are successfully employed, your data will be retained for the duration of your employment and for any specified period set out in Natilik’s data retention policy. After the expiry of the retention period, your data will be securely deleted or anonymised.
2.4 Clients and contractual relationships
Where you enter into a contract with us, or are a contact at a client organisation, we process your personal data to fulfil our contractual obligations, manage the relationship, and provide our services. This comprises; contact information; name, business address, telephone number, email; financial data: payment records, invoicing, bank details; service details: communications related to service delivery or your engagement with us.
Lawful basis: Performance of a contract (Article 6(1)(b)) and legitimate interests (Article 6(1)(f)).
3. How long we keep your data
We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law. As a general rule, we shall retain your data for a period of 6 years having regard to any applicable limitation periods for bringing or defending complaints or claims.
Where different categories of data are processed for different purposes, different retention periods may apply. The criteria used to determine the applicable retention period for each category shall include:
Our standard retention periods are:
4. Who we share your data with
We do not sell or rent your personal data to third parties, and we do not share it with third parties for their own marketing purposes.
We may share your data with:
Third-party service providers who process data on our behalf (such as IT systems providers, payment processors, CRM platforms, and email marketing tools). These providers are contractually required to keep your data secure and to process it only on our instructions.
All third-party processors are subject to data processing agreements that comply with UK GDPR requirements.
5. International transfers
The Natilik Group operates in the UK, USA, and Australia and therefore personal data may be transferred outside the UK or the European Economic Area . Where we transfer your personal data outside the UK, we ensure that appropriate safeguards are in place in accordance with UK GDPR. This may include:
If you would like further information about the specific safeguards we use for international transfers, please contact us at dpo@natilik.com.
6. Profiling and automated decision-making
We may analyse information about you to build a profile of your interests and preferences, in order to send you more relevant communications and improve the services we offer. This profiling is based on information you have provided to us and your interactions with our website and communications.
We do not make solely automated decisions about you that produce legal or similarly significant effects without human involvement. If this changes, we will update this notice and inform you of your rights in that regard.
You have the right to object to profiling used for direct marketing purposes at any time. See Section 7 for how to do this.
Under UK GDPR, you have the following rights in relation to your personal data:
Right to data portability: Where we process your data by automated means on the basis of consent or contract, you can ask us to provide it in a structured, commonly used, machine-readable format.
To exercise any of these rights, please contact us at dpo@natilik.com. We will respond within one month of receiving your request. In complex cases, we may extend this by a further two months, in which case we will notify you.
We will not charge a fee for handling your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse the request.
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection:
Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would, however, appreciate the opportunity to address your concerns before you contact the ICO. Please contact us first at dpo@natilik.com.
Like many other websites, the Natilik website uses cookies. ‘Cookies’ are small pieces of information sent by an organisation to your computer and stored on your hard drive to allow that website to recognise you when you visit. They collect statistical data about your browsing actions and patterns and do not identify you as an individual. For example, we use cookies to store your country preference. This helps us to improve our website and deliver a better more personalised service.
We use the following cookies:
Strictly necessary cookies. These are cookies that are required for the operation of our Site. They include, for example, cookies that enable you to log into secure areas of our Site.
Analytical/performance cookies. They allow us to recognise and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our Site works, for example, by ensuring that users are finding what they are looking for easily.
Functionality cookies. These are used to recognise you when you return to our Site. This enables us to personalise our content for you and remember your preferences (for example, your choice of language or region).
It is possible to switch off cookies by setting your browser preferences. Turning cookies off may result in a loss of functionality when using our website.
10. Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. Sensitive data transmitted via our website is encrypted using SSL/TLS. We regularly review our security practices to ensure they remain appropriate.
Where we share data with third-party processors, we ensure they have appropriate security measures in place through contractual obligations.
11. Links to other websites
Our website may contain links to third-party websites. This privacy notice applies only to our website. We are not responsible for the privacy practices of other sites and encourage you to read their privacy notices.
12. Changes to this notice
We may update this privacy notice from time to time to reflect changes in our practices or legal requirements. The “Last updated” date at the top of this notice will reflect when changes were last made. We encourage you to review this notice periodically.
Continued use of our website after changes are made constitutes acceptance of the updated notice.