GDPR Compliance Statement

Last Updated: April 2026

At ResumeStreams, we recognize that staffing agencies handle sensitive Personally Identifiable Information (PII) daily. We are fully committed to complying with the General Data Protection Regulation (GDPR) and the UK Data Protection Act to ensure your candidates' data remains secure and private.

1. Our Role as a Data Processor

Under GDPR definitions, your staffing agency acts as the Data Controller (the entity that collects and determines the purpose of the data), and ResumeStreams acts as the Data Processor (the entity processing data on behalf of the controller). We only process candidate data strictly according to your documented instructions—specifically, to format their resumes into your corporate template.

2. Lawful Basis for Processing

We process data based on the contractual obligations we hold with your agency. We do not use candidate data for our own legitimate interests, marketing, or secondary database building.

3. Data Subject Rights

GDPR grants individuals specific rights regarding their personal data (e.g., the Right to Erasure / "Right to be Forgotten", the Right to Access). Because we operate on a strict 14-day data deletion cycle, candidate data is naturally expunged from our active systems quickly. However, if a candidate requests data deletion through your agency before our 14-day cycle concludes, we will assist you in locating and permanently deleting their files from our network within 72 hours of your written request.

4. Data Security & Transfer

To protect candidate PII from unauthorized access, we implement the following technical and organizational measures:

5. Automated Data Deletion

We practice data minimization. We do not retain raw or formatted resumes indefinitely. All candidate files are permanently purged from our active processing servers 14 days after the completed, formatted resumes have been delivered back to your agency.

6. Data Processing Agreements (DPA)

We are happy to sign a standard Data Processing Agreement (DPA) with our enterprise and high-volume agency clients to formalize these commitments. Please contact your account manager to initiate this process.

For any privacy or compliance-related inquiries, please contact us at hello@resumestreams.com.