Privacy at a Glance
- ✓ We collect only data necessary for staffing services
- ✓ Your data is encrypted and stored securely in UK/EU
- ✓ We never sell your personal data to third parties
- ✓ You have rights under UK GDPR (access, rectification, erasure in certain circumstances, portability where applicable)
- ✓ AI assistants help but don't make critical decisions
- ✓ Compliant with UK GDPR & Data Protection Act 2018
Contents
- Who We Are
- Data We Collect
- How We Use Your Data
- AI Platform Assistant
- Who We Share Data With
- International Transfers
- Data Retention
- Your Rights
- Security Measures
- Cookies
- Children's Privacy
- Policy Changes
- Contact & Complaints
1. Who We Are
Data Controller: Opus Platforms Limited (trading as "Opus")
| Field | Value |
|---|---|
| Company Number | 16856935 |
| Registered Office | Unit 314b, 566 Cable Street, London, E1W 3HB, United Kingdom |
| [email protected] | |
| Data Protection Contact | [email protected] |
| Data Protection Lead | Data Protection Lead — [email protected][^dpl] |
| Employer PAYE Reference | 120/BF05099 |
| HMRC Accounts Office Reference | 120PP03666762 |
| ICO Registration | ZC090582 (verify at ico.org.uk) |
Opus engages and supplies temporary workers to hirers through our web platform and WhatsApp. This policy explains how we collect, use, and protect your personal data in compliance with UK GDPR and the Data Protection Act 2018.
[^dpl]: No statutory Data Protection Officer is currently appointed under UK GDPR Article 37. Opus operates at sole-founder stage; the founder acts as Data Protection Lead in the interim. External legal advice is being commissioned on whether Opus's processing of special category data (DBS, biometric RTW) and the projected scale of worker monitoring trigger the Art. 37 statutory DPO requirement. Status will be updated when that opinion is received.
[^dbs-basis]: LDA-04 (OPS-5415, 2026-07-15): a prior version of this row also stated "explicit consent is also obtained before initiating any check." That statement has been removed — consent is not read, persisted, or gated on before Opus initiates a DBS check (the check is admin-triggered as a condition of engagement), so representing it as a basis Opus relies on was inaccurate, and in any event the ICO's position is that consent is generally not a valid Article 6 basis for an employment DBS check given the imbalance of power between Opus and the worker. The final lawful-basis characterisation for DBS processing (including whether Schedule 1 Part 1 Para 1 or a Part 3 criminal-offence-data condition is the correct DPA 2018 condition, and whether an Appropriate Policy Document needs to be authored/updated) is a pending first-time legal review of the underlying consent/background-check documentation — this row will be updated once that review completes.
2. Data We Collect
2.1 Worker Registration
| Data | Purpose | Legal Basis |
|---|---|---|
| Full name | Identity, contracts, payroll | Contract |
| Email address | Account access, notifications | Contract |
| Phone number (E.164) | SMS verification, WhatsApp shifts | Contract |
| Home postcode | Shift matching by location | Contract |
| Password (hashed) | Account security | Contract |
| Role preferences | Job recommendations | Legitimate interest |
| Language preference | Communicating in your preferred language | Consent |
2.2 Identity Verification (Right to Work)
| Data | Purpose | Legal Basis |
|---|---|---|
| Passport / ID documents | UK Right to Work verification | Legal obligation (Immigration Act 2016) |
| Biometric data (facial scan) | RTW biometric matching via Home Office-certified IDSP; raw biometric data processed by IDSP only — not retained by Opus | Where biometric verification is used, Opus processes biometric data only where it has identified an appropriate Article 6 lawful basis and a valid Article 9 condition (including Article 9(2)(g) UK GDPR and DPA 2018, Schedule 1, Part 2, Para 6). A compliant alternative verification route is available where required. Raw biometric data is processed by the IDSP only and is not retained by Opus. |
| National Insurance number | PAYE payroll, tax reporting | Legal obligation (HMRC) |
| Visa type & restrictions | Student hour limits, work eligibility | Legal obligation |
| Share code (non-UK citizens) | Home Office RTW verification | Legal obligation |
Immigration Permission & Work Restrictions: If you hold immigration permission subject to work restrictions, Opus will apply the work conditions shown by the Home Office right to work check and your immigration permission, including any restrictions on hours or type of work.
2.3 DBS Background Checks
| Data | Purpose | Legal Basis |
|---|---|---|
| Personal details for DBS | Criminal record disclosure check | Article 6(1)(b)/(c)/(f) UK GDPR as applicable; Article 10 UK GDPR; Schedule 1 DPA 2018.[^dbs-basis] |
| DBS certificate number | Compliance verification for roles | Legitimate interest |
| DBS Update Service status | Ongoing monitoring (with consent) | Consent |
2.4 Employment & Attendance
| Data | Purpose | Legal Basis |
|---|---|---|
| GPS coordinates (clock-in/out) | Verify attendance at work site | Legitimate interest (monitoring assessed as necessary and proportionate for payroll accuracy and fraud prevention; transparently disclosed to workers) |
| QR attendance records (QR scan event, timestamp, assignment identifier, site identifier, attendance event type such as clock-in or clock-out, and related verification metadata) | Verify attendance at the work site, generate timesheets, support payroll accuracy, prevent fraud, investigate attendance discrepancies, maintain audit records | Legitimate interest (attendance verification, payroll accuracy, fraud prevention, and operational security); and Contract where used to generate timesheets and calculate pay |
| Shift times & attendance | Calculate pay, generate timesheets | Contract |
| Performance ratings | Quality assurance, employer feedback | Legitimate interest |
| Training & professional certifications (e.g., SIA, CSCS, driving licences) | Compliance, skill verification, role eligibility | Contract |
2.5 Financial Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Bank account details | Salary payments via Faster Payments (disbursed through Modulr, our payroll engine's payment sub-processor) | Contract |
| Tax codes | PAYE deductions | Legal obligation |
| Pension enrolment | Auto-enrolment compliance | Legal obligation |
| Payment history | Payslips, P60s, earnings records | Contract + Legal obligation |
2.6 Employer Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Company name & registration | Account setup, invoicing | Contract |
| Business contact details | Service delivery, support | Contract |
| Site addresses & geofences | Worker attendance verification | Contract |
| Billing & payment info | Invoice processing | Contract |
2.7 Automatically Collected
| Data | Purpose | Legal Basis |
|---|---|---|
| Login/session data | Security, fraud prevention | Legitimate interest |
| Device/browser info | Technical support, compatibility | Legitimate interest |
| Usage analytics (if consented) | Platform improvement | Consent |
| AI interaction logs | Audit trail, service improvement | Legitimate interest |
| AI tool execution audit logs | Governance, compliance, safety auditing | Legitimate interest |
| AI approval records | Human oversight of AI-proposed high-impact actions | Legitimate interest |
2.8 CV Analytics & Candidate Scoring (Workers Only)
CV parsing data minimisation (updated 31 July 2026): We use Affinda's EU endpoint to parse an uploaded CV for base staffing under the Article 6 basis described in our records of processing; there is no separate parsing-consent flag. We retain only skills, job titles, dates/durations, education qualification/level/field/completion year, work and education counts, total experience, seniority, sector keywords, inferred certification IDs and sanitised parse-status metadata. We do not retain parser response text, raw or masked CV text, names or contact details parsed from the CV, organisations, institutions, grades or free-text responsibilities. Masking is not anonymisation. Every request uses deleteAfterParse=true, we attempt explicit deletion, and we investigate a deletion failure. Separate headhunting consent is required before creating a candidate profile or disclosing identity to an employer; withdrawal deletes that profile and prevents it being recreated unless consent is granted again.
| Data | Purpose | Legal Basis |
|---|---|---|
| CV text (uploaded document) | Extract structured work history, skills, and education for compliance and matching | Contract |
| Parsed skills list | Build searchable skills profile (worker_skills table) |
Contract |
| Parsed work experience (job titles, durations, sectors) | Assess seniority band, career trajectory | Contract |
| Parsed education records (institution, qualification, level) | Verify qualification-based role eligibility | Contract |
Derived seniority band (entry, mid, senior) |
Segment workforce for shift matching | Contract + Legitimate interest |
reliability_score (0–100, deterministic formula) |
Quality indicator based on attendance, completion rate, no-shows | Legitimate interest |
placement_score (0–100, deterministic formula) |
Aggregate suitability score combining reliability, compliance, experience, skills | Legitimate interest |
headhunting_consent flag + timestamp |
Record your consent to being contacted for permanent/contract roles with third-party employers | Consent (UK GDPR Art. 6(1)(a)) |
CV parsing vendor: Affinda (EU endpoint, deleteAfterParse=true — Affinda does not retain your CV after parsing). Raw CV text is not stored by Opus; only structured extracted fields are retained. Affinda is a third-party machine-learning CV parser. The CV file buffer is sent to Affinda's EU endpoint solely to extract structured fields (work history, education, skills); Affinda is contracted not to retain the document. See §6 for the transfer mechanism and §8 for the full three-layer disclosure of how CV data flows through to recruiter-facing actions.
Scoring: All scores are calculated by deterministic rules — no AI or machine learning is involved on the Opus side. See the formula in §8 (Automated Decision-Making).
2.9 Local On-Device Storage of Pending Writes (PWA / Offline Mode)
If you use Opus from a browser or installed PWA while offline (or with poor connectivity), the service worker queues certain writes locally on your device until connectivity returns. The queue is stored in your browser's IndexedDB under the database opus-sync-queue, object store pending. Queued writes currently cover three flows:
| Flow | Endpoint(s) queued | Data held locally |
|---|---|---|
| Shift acceptance | POST /shifts/{id}/accept, POST /shifts/{id}/apply, POST /assignments |
Shift ID, assignment context |
| Clock-in / clock-out | POST /attendance/clock-in, POST /attendance/clock-out |
GPS coordinates (latitude, longitude), timestamp, shift ID |
| Timesheet correction | POST /timesheets/{id}/correction, PATCH /timesheets/{id}/correction |
Timesheet ID, requested correction values |
Entries are replayed automatically when your device regains connectivity (Background Sync API) and removed from IndexedDB after successful replay. Clearing your browser data deletes any pending entries. See §9 for the security framing.
3. How We Use Your Data
We process your data for these purposes:
| Purpose | Legal Basis | Details |
|---|---|---|
| Provide staffing services | Contract | Match workers to shifts, process assignments |
| Verify identity & RTW | Legal obligation | Immigration Act compliance |
| Process payroll & taxes | Contract + Legal | PAYE, NI, pension contributions |
| Send shift notifications | Contract | WhatsApp/SMS/email alerts |
| Verify attendance | Legitimate interest | GPS clock-in within geofence and/or QR code scan at work site |
| Generate timesheets | Contract | Calculate hours for payment |
| Comply with AWR | Legal obligation | Track 12-week threshold |
| Platform Assistant queries | Consent + Contract | AI-powered shift/compliance help |
| Fraud prevention | Legitimate interest | Detect timesheet manipulation |
| AI governance & oversight | Legitimate interest | Internal review and human approval of AI-proposed high-impact actions via Ops Approval Workbench |
| AI model improvement | Legitimate interest | De-identified data used to train intent routing and safety classification models (opt-out available — see §4.6) |
| Improve services | Legitimate interest | Analytics, feature development |
| CV parsing & candidate scoring | Contract + Legitimate interest | Extract structured skills/experience/education from uploaded CVs; calculate deterministic reliability and placement scores |
| Talent pool and shift visibility | Legitimate interests (UK GDPR Art. 6(1)(f)) | Opus uses objective eligibility, employer relationship/audience, and invitation/offer facts to show usable shifts and prevent unauthorized or unusable applications. You may opt out of talent-pool participation via Account Settings → Privacy at any time. |
| Headhunting (permanent/contract roles) | Consent (UK GDPR Art. 6(1)(a)) | Where you opt in, Opus headhunts on your behalf — your anonymized profile is assessed by Opus staff and proposed directly to employers for permanent or contract roles. Employers do not search the candidate pool themselves. Identity is revealed only after you confirm interest in a specific opportunity. |
4. AI Platform Assistant
How AI Works on Opus: Opus provides AI-powered assistants via web chat and WhatsApp to help you find shifts, check compliance status, and manage your work. Here's what you need to know.
4.1 What AI Can Do
- Workers: Browse shifts, check earnings, view compliance status, manage availability via available AI assistant capabilities
- Employers: View shift fill rates, check worker compliance, assist with timesheet review (human approval required for final approval) via available AI assistant capabilities
- All users: Get instant answers to platform questions 24/7
An AI also parses what you type or say to determine which tool to invoke. This routing AI does not itself make decisions about you; downstream tools that can act on your behalf have their own controls (see §8).
4.2 What AI Cannot Do
Critical Decisions Are Always Human/Rule-Based:
- AI does NOT calculate your pay (deterministic payroll system)
- AI does NOT determine your compliance status (rule-based RAG system)
- AI does NOT approve shift assignments (first-valid-wins or employer approval)
- AI does NOT make hiring/firing decisions
4.3 Data Processing
- Queries processed by: Third-party LLM providers (Anthropic Claude) under data processing agreements
- Data shared: Your query text, user role, relevant context (shift data, compliance status)
- Data NOT shared: Passwords, full bank details, biometric data
- Translation: If you set a language preference, platform communications (e.g., WhatsApp notifications) are translated using AI processing by our LLM providers
- Retention: Full AI conversation turn content is retained for your 20 most recent conversation sessions (older turns are hard-deleted nightly); a summary of each session is retained for 2 years for audit/improvement purposes
4.4 Conversational Memory
To make the AI assistant more useful across sessions, Opus operates a memory service (MemoryExtractionService) that, after a conversation completes, extracts durable facts and preferences from the transcript and persists them in your AI profile (ai_user_profiles table; cached in Redis for low-latency injection). These remembered facts are injected into the system context of your future AI sessions so the assistant can personalise responses (for example, recalling your preferred shift type or commute radius).
Conversational memory does not change your compliance status, your assignments, your pay, or any other deterministic platform decision. It only personalises the AI assistant's responses.
Your controls:
- Opt out: set
training_opt_outin Account Settings → Privacy. This stops new memories being persisted from your conversations. - Delete existing memory: use the in-app memory clear control, or submit a DSAR via §8.
- Global killswitch: Opus operates an admin-level killswitch (
MEMORY_ENABLED=false) that disables the memory feature platform-wide if needed for incident response.
For the full risk analysis see the DPIA §2.1 entry for ai_user_profiles, ai_conversation_sessions, and ai_conversation_turns.
4.5 AI Governance & Human Oversight
Opus operates a tiered governance framework for AI actions on the platform:
| Tier | Risk Level | Examples | Safeguard |
|---|---|---|---|
| Tier 0 | Read-only | Browse shifts, view earnings | Full audit logging |
| Tier 1 | Low-write | Update availability, create support tickets | User confirmation + audit |
| Tier 2 | High-impact write | Bulk shift cancellations, timesheet approvals, compliance overrides, user suspensions | Human ops approval required before execution |
| Tier 3 | Prohibited | Pay calculation, compliance determination, assignment allocation | AI cannot perform — deterministic systems only |
All AI tool executions are performed under a dedicated controlled system identity and recorded in a permanent audit log (retained for 6 years — see §7). High-impact (Tier 2) actions generate approval requests that are reviewed by authorised Opus staff through an internal approval workflow before taking effect. Tier 3 actions are never performed by AI — they are handled exclusively by deterministic, rule-based systems.
For the detailed principles governing transparency, accountability, human oversight, and prohibited control-path use, see RESPONSIBLE-AI-PRINCIPLES.md.
No AI action on the platform bypasses human oversight for high-impact decisions.
4.6 Model Training & Improvement
We may use de-identified and anonymised interaction data (e.g., query patterns, tool usage statistics) to train and improve AI models that power the platform, including:
- Intent routing models (understanding what you're asking)
- Safety classification models (detecting misuse)
- Tool parameter extraction models (improving accuracy)
Safeguards:
- All training data is stripped of personally identifiable information before use
- Training datasets require Data Protection Officer approval
- A Data Protection Impact Assessment (DPIA) is maintained for AI model training
- No biometric data, financial details, or identity documents are used in training
- Models are not trained by third-party LLM providers (Anthropic) on your data — this is contractually prohibited
Opt-out: You may opt out of your de-identified data being used for model training by contacting [email protected] or via Account Settings → Privacy → AI Data Preferences. Opting out does not affect your access to AI features.
4.7 Your Controls
You can opt out of AI features by contacting support. Core platform functionality remains available without AI assistance.
5. Who We Share Data With
5.1 Service Providers (Data Processors)
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| AWS (Amazon Web Services) | Cloud hosting, database, file storage | UK/EU | GDPR DPA, ISO 27001 |
| Yoti / TrustID | Right to Work identity verification | UK | IDSP certified, UK GDPR |
| uCheck | DBS background checks | UK | DBS registered body |
| eSignatures.io | Electronic contract signatures | UK/EU | SCCs, GDPR DPA |
| Stripe | Payment processing | EU/US | PCI-DSS, SCCs |
| Staffology by IRIS | PAYE payroll processing (statutory PAYE/NI/tax, bank details, payslips) | UK | SOC 2, GDPR DPA |
| Modulr | Faster Payments disbursement of worker salary (sub-processor to Staffology by IRIS) | UK | FCA-authorised EMI, GDPR DPA |
| Xero | Accounting & general-ledger sync only (not payroll) | UK | SOC 2, GDPR DPA |
| Meta (WhatsApp Business) | Shift notifications, messaging | US | SCCs, DPA |
| Twilio | SMS notifications, OTP | US | SCCs, GDPR DPA |
| AWS SES | Transactional emails | EU | GDPR DPA, ISO 27001 |
| HubSpot | CRM, employer communications | US | SCCs, ISO 27001 |
| Freshdesk | Support ticket management | US | SCCs, SOC 2 |
| n8n | Workflow automation | EU | GDPR-compliant |
| Affinda | ML-powered CV parsing (deleteAfterParse=true, no CV retention) |
EU | GDPR DPA, EEA adequacy |
| AWS Bedrock (Anthropic Claude Haiku 4.5 + Sonnet 4.6, Amazon Titan v2 embeddings, AWS Bedrock Guardrails) | AI assistant inference, embeddings, safety guardrails | US | AWS DPA; sub-processors Anthropic and Amazon; no model training on customer data |
| Google Analytics 4 | Anonymous platform usage analytics (consent-gated; anonymize_ip: true) |
US | Google DPF / SCCs |
| Apollo.io | Visitor tracking for marketing (consent-gated) | US | SCCs |
| New Relic | Observability and monitoring | EU | GDPR DPA, SOC 2 |
| PagerDuty | Incident management | US | SCCs, SOC 2 |
| Slack | Internal communications | US | SCCs, SOC 2 |
| CharlieHR | HRIS employee record sync | UK | GDPR DPA |
| Postcodes.io | UK postcode geocoding | UK | Open data |
5.2 Employers
When you accept a shift, we share with that employer:
- Your name, phone number, and email
- Compliance status (RTW verified, training completed)
- Attendance records (clock times, GPS coordinates if enabled, QR attendance records if enabled)
- Performance ratings from previous shifts
Data Controller Relationship: Opus and hirers generally act as independent controllers for the personal data each processes for its own purposes. Where Opus and a hirer jointly determine the purposes and means of a specific processing activity, an arrangement under Article 26 UK GDPR will be put in place. Where relevant to an accepted assignment, Opus may share QR attendance confirmations and GPS coordinates with the hirer for attendance verification, dispute resolution, and operational management. Contact the hirer directly for their privacy practices.
5.3 Legal & Regulatory Authorities
- HMRC: Tax and National Insurance reporting (legal obligation)
- Home Office: Right to Work compliance verification
- ICO: Data protection investigations if required
- Law enforcement: If required by court order or statutory duty
- The Pensions Regulator: Auto-enrolment compliance
5.4 User-Initiated MCP Client Integrations
Opus exposes a Model Context Protocol (MCP) endpoint that lets you connect authenticated third-party MCP clients — for example, OpenAI ChatGPT or Anthropic Claude Desktop — to read or act on the data your role permits inside Opus. These integrations are user-initiated: nothing flows to a third-party MCP client unless you authenticate and authorise that client yourself.
- What data the third-party client can see: whatever the MCP tools your role grants would return (the same scope your normal Opus session has).
- Who controls the data once it leaves Opus: the third-party MCP client you chose, under your contract with that provider. Opus does not act as the controller of the onward use.
- What Opus retains: an MCP audit log of which tools were invoked, by which client, with what correlation ID (retained for 6 years for payroll/employment audit reasons). The audit log does not include the third-party client's downstream processing.
- Revocation: you can disconnect a connected MCP client at any time from Account Settings → Integrations.
OpenAI and Anthropic are not Opus processors in this flow — they are recipients you have chosen as the user. See the ROPA entry "User-initiated MCP client integrations" for the full framing.
6. International Transfers
Your data is primarily stored in UK/EU AWS regions. Some services involve transfers outside the UK:
| Service | Destination | Safeguard |
|---|---|---|
| WhatsApp (Meta) | USA | SCCs / UK IDTA (operative mechanism per Meta's/WhatsApp's own published UK privacy policy — WhatsApp does not invoke the UK Extension to the EU-US DPF for UK transfers, even though Meta Platforms, Inc. holds active EU-US and Swiss-US DPF certification) |
| Stripe | USA | UK Extension to EU-US DPF (active — confirmed against dataprivacyframework.gov and Stripe's own DPF policy page, 2026-08-08); SCCs or UK IDTA as fallback |
| AWS Bedrock | USA (us-east-1 inference profiles) | UK Extension to EU-US DPF (active — Amazon.com, Inc., confirmed against dataprivacyframework.gov, 2026-08-08); SCCs / UK IDTA as fallback |
| Affinda | EU | UK adequacy (EEA); SCCs as fallback |
| Google Analytics 4 (Google LLC) | USA | Google DPF / SCCs; IP anonymization (anonymize_ip: true) |
| Apollo.io (Apollo Data Inc.) | USA | SCCs; consent-gated marketing tracking |
| HubSpot | USA | UK Extension to EU-US DPF (active — confirmed against dataprivacyframework.gov participant record, 2026-08-08); SCCs or UK IDTA as fallback |
| Twilio | USA | UK Extension to EU-US DPF (active — confirmed against dataprivacyframework.gov participant record, 2026-08-08); SCCs or UK IDTA as fallback |
| Staffology by IRIS | UK | UK adequacy (no transfer outside UK/EEA) |
| Modulr | UK | UK adequacy (no transfer outside UK/EEA) |
| Xero | UK | UK adequacy — accounting/GL only, no payroll data |
| Freshdesk | USA | UK Extension to EU-US DPF (active — Freshworks, Inc., confirmed against dataprivacyframework.gov, 2026-08-08); SCCs or UK IDTA as fallback |
| eSignatures.io | UK/EU | UK adequacy (EEA); SCCs as fallback |
| PagerDuty | USA | UK Extension to EU-US DPF (active — confirmed against dataprivacyframework.gov, 2026-08-08); SCCs or UK IDTA as fallback |
| Slack | USA | UK Extension to EU-US DPF (active — Slack Technologies, LLC, participates via Salesforce's certification, confirmed against dataprivacyframework.gov, 2026-08-08); SCCs or UK IDTA as fallback |
SCCs = Standard Contractual Clauses approved by the UK ICO. Request copies at [email protected]
Note on UK Extension to the EU-US Data Privacy Framework (DPF): Every recipient above is backed by a live DPA naming SCCs/UK IDTA as a standing fallback regardless of DPF certification status, so a documented safeguard is always in force. As of the 2026-08-08 verification below, seven of the eight US recipients (Stripe, AWS Bedrock, HubSpot, Twilio, Freshdesk, PagerDuty, and Slack) hold active UK Extension to the EU-US DPF certification; WhatsApp (Meta) does not invoke the UK Extension for UK transfers and instead relies on SCCs/UK IDTA as its primary (not fallback) mechanism, per Meta's/WhatsApp's own published UK privacy policy.
Verification commitment (OPS-1630): Per-recipient DPF certification status is checked against the US Department of Commerce's public register (
dataprivacyframework.gov/list) at least quarterly and before any new sub-processor is added. Last verified: 2026-08-08 (resolves the prior "(if certified)" hedge — see OPS-1630 comment history for the per-vendor evidence trail). Framework-level legal risk (flagged 2026-07-03): following the June 2026 U.S. Supreme Court ruling in Trump v. Slaughter (removing the FTC's for-cause removal protections), the privacy advocacy group NOYB has publicly stated an intention to challenge the EU-US DPF's legal validity, on the basis that FTC independence — a condition of the European Commission's adequacy decision — is now in question. Opus is monitoring this development. If the European Commission suspends or the CJEU annuls the DPF adequacy decision, every "UK Extension to EU-US DPF" row above falls back to its stated SCC/UK IDTA safeguard automatically (already contractually in place today, not a future action to be taken), and this policy will be updated to reflect the change in the operative primary mechanism.This static document is a point-in-time summary, not a substitute for the live DPF register — contact [email protected] for the current certification status of a specific recipient.
7. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data | Duration of account + 6 years | Legal claims, tax records |
| Right to Work documents (incl. the share-code identity photograph, where a Home Office share-code check is used) | 2 years after employment ends | UK Immigration Act requirement |
| Payroll & tax records | 7 years | HMRC statutory requirement |
| Attendance records | 6 years | Employment law, payroll disputes |
| Contracts (signed) | 6 years after termination | Limitation Act 1980 |
| DBS certificates | 6 months after verification | DBS Code of Practice |
| DBS outcome record (date, level, result, certificate number) | Duration of employment + 6 months | Legitimate interest / employment obligation |
| DBS Update Service check log | Duration of employment + 6 months | Consent |
| Biometric matching selfie (live selfie used for automated facial matching against your document — distinct from the share-code identity photograph retained as Right to Work evidence above) | Not retained by Opus — deleted by IDSP after verification | — |
| AI interaction logs (full turn content) | Your 20 most recent conversation sessions (older turns hard-deleted nightly) | Audit, service improvement |
| AI interaction logs (session summary) | 2 years | Audit, service improvement |
| AI tool execution audit logs | 6 years | Employment law, governance compliance, ICO accountability |
| AI approval records | 6 years | Governance compliance, employment law audit obligations |
| GPS location data | 2 years | Legitimate interest (attendance verification) |
| QR attendance records | 2 years | Legitimate interest (attendance verification, payroll audit); extended where required for a specific dispute, investigation, or legal obligation |
| Marketing consent | Until withdrawn | Ongoing consent |
| Support tickets | 3 years after resolution | Service continuity |
After retention periods expire, data is securely deleted or anonymized.
8. Your Rights Under UK GDPR
Access (Art. 15)
Request a copy of all data we hold about you. Free of charge, response within 1 month.
Rectification (Art. 16)
Request correction of inaccurate data. Update in account settings or contact us.
Erasure (Art. 17)
Request deletion when data is no longer needed. Some data retained for legal obligations.
Restriction (Art. 18)
Limit processing while disputes are investigated.
Portability (Art. 20)
Receive your data in machine-readable format (JSON) for transfer.
Object (Art. 21)
Object to processing based on legitimate interests or direct marketing.
How to Exercise Your Rights
- Online: Account Settings → Privacy → Data Rights
- Email: [email protected]
- Response time: Within 1 month (may extend to 3 months for complex requests)
- Verification: We may request ID to prevent unauthorized access
Automated Decision-Making
Compliance RAG gating (UK GDPR Article 22). Opus operates a Red/Amber/Green (RAG) compliance system that determines whether a worker is eligible to be assigned to shifts. RAG gating is a solely automated decision within the meaning of UK GDPR Article 22: it is performed by deterministic rules (not AI or machine-learning profiling), it does not involve a human in the loop at the moment of decision, and it has a significant effect on you because a non-green status blocks access to shifts and therefore to earnings. The rules check current Right-to-Work validity, contract status, site-specific DBS where required, and structured mandatory credentials. Optional or unrelated credentials and generic pre-placement training do not make your RAG status non-green.
Your Article 22 safeguards:
- Right to human review on request — email [email protected] and a human operator will re-examine your status.
- Right to contest — submit a contest through Profile → Challenge an AI Decision in the app (select "Compliance Status (RAG)"), or by email as above. In-app appeals are logged, tracked with a reference ID, and reviewed by a human within 5 business days.
- Right to an explanation of the logic — see our published RAG rules summary for the deterministic criteria applied.
Shift eligibility gates (student-visa weekly-hours cap, AWR equal-treatment pay parity, geofence/attendance eligibility). Before you accept a shift, Opus runs deterministic, rule-based eligibility checks — a student-visa weekly-hours cap (Right to Work condition compliance), an AWR equal-treatment pay-parity check after 12 weeks on an assignment, and geofence/attendance eligibility checks. These are solely automated decisions within the meaning of UK GDPR Article 22 with a significant effect (blocking you from a specific shift). Your Article 22 safeguards for these decisions:
- Right to human review on request — email [email protected] with the shift ID or date and a human operator will re-examine the eligibility check.
- Right to contest — submit a contest through Profile → Challenge an AI Decision in the app (select "Shift Eligibility"), mentioning the shift ID or date. In-app appeals are logged, tracked with a reference ID, and reviewed by a human within 5 business days.
- Right to an explanation of the logic — the rules are: student-visa weekly-hours cap (ADR-013), AWR equal-treatment pay parity after the 12-week qualifying period (ADR-009), and geofence-based attendance eligibility.
Shift visibility and employer-selected audience (OPS-8548)
Opus uses deterministic rules to decide which shifts you may discover or act on. The lawful basis is legitimate interests (UK GDPR Art. 6(1)(f)): matching workers to usable opportunities, respecting an employer's selected audience, reducing failed applications, and protecting confidential shift and employer information.
Hard rules include current legal/compliance status, Right-to-Work at shift start, site-specific DBS where required, structured mandatory certifications, shift status/capacity/application cutoff, overlapping work/rest and statutory-hours controls, booking freeze, and the employer's saved audience (all, worked before, or a named talent pool). A current invitation or offer may give you a time-limited relationship to that specific shift. Match score, job/distance/availability preference, optional certifications, generic training, notification preferences, quiet hours, daily caps, and fairness rotation do not hide a shift. No generative AI or LLM makes this decision.
Because hiding a shift can materially affect access to work, Opus applies Article 22 safeguards on a precautionary basis. You may ask for a plain-language explanation of the categories used, correct a wrong input, contest the outcome, and request independent human review through Profile → Challenge an AI Decision (art_22_review) or [email protected]. Compliance/Data Protection Lead review targets 14 calendar days; faster Right-to-Work and DBS correction routes remain available. To protect other people and employers, an explanation will not confirm an unknown or unauthorized shift or disclose another worker's data.
Employers see privacy-preserving reach information: zero may be exact; 1-4 is suppressed; larger groups are shown only as 5-9, 10-24, 25-49, or 50+. Employer small-cell results do not include worker names, rows, or contact details.
Shift allocation is not within Article 22. The FIRST_VALID_WINS allocation model resolves a race condition between workers who have each chosen to accept the same shift; it is a worker-initiated contract acceptance, not a platform decision about you. The EMPLOYER_APPROVAL allocation model is reviewed by a human (the employer) and is therefore also outside Article 22.
Candidate Scoring: The reliability_score and placement_score values in your candidate profile are calculated by a published deterministic formula — not AI or machine learning. The formula considers: completed shifts, no-shows, late cancellations, compliance RAG status, months of experience, and skill count. These scores inform how your profile is ranked in internal search results but do not produce any legal effect and are always subject to human review. The full formula is documented in our internal governance document available on request.
Timesheet Deemed-Approval & Worker Reliability Monitoring (OPS-4561)
Opus operates two rules-based (non-AI, non-machine-learning) monitoring mechanisms that can affect your pay or how your profile is ranked:
- 48-hour deemed-approval on timesheets. Under your assignment confirmation (Clause 4.3), if an employer does not approve or dispute your finalised timesheet within 48 hours of your shift ending, Opus may approve it on your behalf using objective platform evidence (GPS clock-in/out records). This only ever happens for a timesheet that is finalised, has no unresolved anomaly flags or open corrections, and passes the same automated pay-safety checks (including the National Minimum Wage check) applied to every approval — never for a timesheet under dispute or with an unresolved issue, which is instead routed to a human reviewer so you are still paid the objectively-evidenced amount by the next pay day.
- Reliability/no-show scoring. The
reliability_scoredescribed under "Candidate Scoring" above also reflects deemed-approval evidence (i.e., whether your attendance history required employer intervention) as one of its published inputs.
Because deemed-approval can affect when and how you are paid, and reliability scoring can affect how your profile is ranked, we treat both as falling within our UK GDPR Article 22 transparency obligations even though neither is a solely-automated decision with a significant, unreviewable effect: a support ticket is automatically raised for human review whenever a timesheet is NOT safe for deemed-approval, and reliability scoring never triggers suspension or account action by itself. Your safeguards:
- Right to human review — email [email protected] with the timesheet ID, or use Profile → Challenge an AI Decision (select "Timesheet Approval") to have a human recheck a deemed approval.
- Right to contest — a deemed approval based on evidence that you dispute (e.g., a clock-in/out discrepancy) can be corrected via the standard timesheet correction process; a resulting pay adjustment is applied retroactively.
- Right to an explanation of the logic — the deemed-approval criteria are: 48 hours elapsed, timesheet finalised and payable, no unresolved anomaly or open correction, and a pass of the same guard battery (including NMW) every manual approval uses.
- Records retained — every deemed approval is recorded with a system-actor attribution and an audit event, consistent with our data retention schedule (§7).
A Data Protection Impact Assessment for this processing is maintained at documents/COMPLIANCE/DPIA-worker-performance-monitoring.md (internal; available on request via [email protected]).
CV Analytics and Headhunting
CV-driven candidate matching operates in three distinct layers, each with different processing characteristics and safeguards:
- Affinda — ML CV parser (third-party processor). Your uploaded CV is sent to Affinda's EU endpoint solely to extract structured fields (job titles, durations, skills, education). Affinda is contracted to delete the source document after parsing (
deleteAfterParse=true). - Opus deterministic scoring. From the extracted fields, Opus calculates
reliability_scoreandplacement_scoreusing a published, rules-based formula. No AI or machine learning is used at this layer. - Recruiter-approved approach (ADR-038 dryRun/confirm gate). A human Opus recruiter reviews the shortlisted profiles before any outbound approach is made; an automated approach without recruiter confirmation is not possible by design.
Under the EU AI Act, CV analytics used in employment matching are classified as high-risk per Annex III §4 (employment, workers' management, and access to self-employment). Safeguards in place:
- A human recruiter is in the loop on every outbound approach (Article 22 safeguard).
- You have the right to an explanation of the scoring formula on request.
- You have the right to contest your score and request human review of any decision that affected your profile's visibility to employers, via Profile → Challenge an AI Decision in the app or by email (reviewed within 5 business days).
- You may withdraw headhunting consent at any time (see "Right to Withdraw Consent" below).
Fraud / Duplicate-Profile Detection
Opus runs a deterministic, rule-based fraud-detection layer that flags potential duplicate registrations and impersonation attempts. The detector uses:
- National Insurance (NI) number matches across accounts
- Fuzzy name and date-of-birth matches
- Bank-account-fragment matches across accounts
When a multi-signal flag fires, an alert is surfaced to admin operators. A flagged account can lead to admin-confirmed suspension via the HIGH-risk suspend_user MCP tool (which requires an explicit ADR-038 dryRun/confirm gate — see §4.5 Tier 2 governance). Because suspension has a significant effect on you, this falls within UK GDPR Article 22 and you have:
- Right to human review — admin confirmation is already mandatory before any suspension takes effect.
- Right to contest — you can challenge the suspension; the admin team will re-examine the multi-signal evidence.
- Right to an explanation of the logic — the rules above are the full set of signals; we will tell you which signals fired.
Coverage Assurance Agent (Shift-Offer Routing)
Opus operates an autonomous Coverage Assurance Agent that monitors published shifts for fill risk (for example, a shift close to its start time with unfilled slots) and identifies eligible workers who could be invited or offered the opportunity. The agent only ever considers workers who already meet the deterministic compliance and eligibility gates described above (RAG status, Right to Work, student-visa hours cap, etc.) — it does not itself decide who is eligible.
This is not a solely automated decision under UK GDPR Article 22. Before any shift offer or invitation actually reaches you, a human Opus operator must review and approve the agent's proposal (human-on-the-loop) — the agent cannot broadcast a shift or send you a direct invitation on its own. Nonetheless, because an AI system is involved in identifying which workers are surfaced as candidates, we disclose this under our Article 13/14 transparency obligations:
- Right to human review — a human operator already approves every offer/invitation action before it is sent to you; you may additionally request review of a specific instance by emailing [email protected] with the shift ID or date.
- Right to contest — submit a contest through Profile → Challenge an AI Decision in the app (select "Shift Offer Routing"), or by email as above. In-app appeals are logged, tracked with a reference ID, and reviewed by a human within 5 business days.
- Right to an explanation of the logic — the agent surfaces candidates using the same deterministic eligibility criteria described elsewhere in this section (RAG, Right to Work, hours caps); it does not use profiling beyond those documented rules.
- Records retained — the agent's run history and proposed actions are logged internally for audit and safety-review purposes, consistent with our data retention schedule (§7).
AI-Assisted Actions: Where AI proposes actions that may affect your employment (e.g., shift recommendations, compliance suggestions), high-impact proposals are routed to human operators for approval before execution (see §4.5). A Data Protection Impact Assessment (DPIA) is maintained for our AI processing activities in accordance with UK GDPR Article 35 and ICO guidance on AI and data protection.
Your right to human review: You may request human review of any decision in which AI was involved, including any scoring that affects how your profile is presented to employers, by contacting [email protected].
Right to Withdraw Consent
Where we process your data based on consent (e.g., biometric verification, analytics cookies, headhunting matching), you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Withdraw via Account Settings → Privacy, or email [email protected].
Talent pool (shift matching) participation is processed on the basis of legitimate interests — not consent. You may object/opt out at any time via Account Settings → Privacy. Opting out immediately removes you from active talent-pool digests and revokes talent-pool-derived live invitation/offer entitlement; retained history becomes non-actionable. It does not hide all or worked before shifts and does not affect an existing assignment or pending pay.
Headhunting consent is separate from talent pool participation. Withdrawing headhunting consent removes your profile from all active Opus headhunting mandates immediately and does not affect your ability to find and book shifts through Opus.
9. Security Measures
| Measure | Details |
|---|---|
| ✓ Encryption | TLS 1.3 in transit, AES-256 at rest (AWS KMS) |
| ✓ Access Controls | Role-based access, MFA for staff, least privilege |
| ✓ Authentication | bcrypt password hashing (12 rounds), JWT tokens |
| ✓ Monitoring | AWS CloudWatch, intrusion detection, audit logs |
| ✓ Incident Response | Reportable personal data breaches notified to the ICO as soon as possible and, where feasible, within 72 hours; affected individuals notified without undue delay where required by law |
| ✓ Vendor Security | All processors vetted for SOC 2 / ISO 27001 |
| ✓ Offline write queue | Queued offline writes (shift acceptance, clock-in/out including GPS, timesheet corrections) are stored in your browser's IndexedDB (opus-sync-queue); security therefore depends on your device security. Clearing browser data deletes any pending queue, and entries are removed after successful replay. |
10. Cookies
We use three categories of cookies and similar storage technologies. Your consent is required for analytics and marketing cookies; you can grant, refuse, or change consent at any time from Account Settings → Privacy or via the in-app cookie banner. See our full Cookie Policy for the full list with names, durations, and providers.
- Essential cookies / storage — authentication, CSRF protection, and consent state. These do not require consent (PECR reg 6 essential exemption) and the platform does not function without them.
- Analytics (consent-gated) — Google Analytics 4 loads only after you grant
analyticsconsent. We send anonymous usage events (anonymize_ip: true); cookies set include_gaand_ga_<container>with Google's default 2-year retention. Data is processed in the US under the Google DPF / SCCs (see §6). - Marketing (consent-gated) — Apollo.io visitor tracking loads only after you grant
marketingconsent and is used for outbound marketing measurement. Data is processed in the US under SCCs.
Manage preferences anytime in Account Settings → Privacy.
11. Children's Privacy
Our services are for individuals 18+ (UK minimum working age for most roles). We do not knowingly collect data from children. If discovered, it will be deleted immediately.
12. Policy Changes
We may update this policy to reflect legal or service changes. For material changes:
- We update the version number and date
- We notify you via email for significant changes
- We request renewed consent if legally required
Continued use after changes constitutes acceptance. Check back periodically for updates.
13. Contact & Complaints
Contact Opus
- Email: [email protected]
- Address: Unit 314b, 566 Cable Street, London, E1W 3HB
Complain to ICO
Information Commissioner's Office
- Wycliffe House, Water Lane, Wilmslow, SK9 5AF
- Phone: 0303 123 1113
- ico.org.uk/make-a-complaint
We encourage you to contact us first so we can resolve your concern directly.
Version History
| Version | Date | Changes |
|---|---|---|
| v3.5.0 | Aug 6, 2026 | OPS-8548: documented deterministic worker shift visibility and persisted employer audience under Art. 6(1)(f) legitimate interests; distinguished hard authorization inputs from soft ranking/delivery signals; applied precautionary Article 22 explanation, correction, contest, and independent-review safeguards; recorded privacy-preserving reach bands and immediate talent-pool-derived entitlement revocation on opt-out. |
| v3.4.0 | Jul 7, 2026 | OPS-1517 (INF-13-R3-002): added §8 disclosure for the Coverage Assurance Agent (ais-008) — shift-offer routing. The agent was promoted to autonomy stage S1 (human-on-the-loop) and enabled live this date; Tier-2 offer/invitation actions require human operator approval before reaching workers, so this is disclosed as an Article 13/14 transparency matter rather than a solely-automated Article 22 decision. Added the same right-to-human-review / right-to-contest / right-to-explanation structure used elsewhere in §8, with a new "Shift Offer Routing" in-app appeal category. |
| v3.3.0 | Jul 3, 2026 | AIA-04-R3-001 (AI Posture Audit, session AIA-04, run 3): §8 Article 22 — the RAG compliance-gating right-to-contest is now backed by a tracked, worker-initiated in-app route (Profile → Challenge an AI Decision, compliance_gating appeal type) reviewed within 5 business days, not only an unstructured support email; previously the accessible contest route existed only in the backend API (AIA-04-014) and was not reachable from the worker-facing UI. Added a new Article 22 disclosure block for shift-fit eligibility gates (student-visa weekly-hours cap — ADR-013, AWR equal-treatment pay parity — ADR-009, geofence/attendance eligibility), which previously had no documented worker-initiated contest route at all — these now use the same in-app appeal route (eligibility_decision appeal type). CV analytics contest text (§8) also now names the in-app route. |
| v3.2.0 | Jul 2, 2026 | OPS-2899: clarified that talent pool (shift matching) default-on/opt-out participation (§3, established v2.9.0) is enforced automatically from registration, not merely described policy. No change to lawful basis or headhunting's separate consent requirement. |
| v3.1.0 | May 17, 2026 | Compliance/Governance/Legal audit remediation 2026-05-17 — Batches 1-3 closure. §1: named Data Protection Lead (sole founder, acting) with Art. 37 footnote pending external legal advice (R6.5). §2.8: explicit Affinda ML CV-parser disclosure (R1.2); §2.9 (new): offline write queue (PWA/service worker) named including GPS, IndexedDB store opus-sync-queue (R2.4). §4.1: added AI routing sentence (ais-006) (R3.1). §4.4 (new): Conversational memory (ais-003) — MemoryExtractionService, ai_user_profiles, opt-out via training_opt_out, killswitch (R3.1). §5.1: added Affinda (R2.1); replaced Anthropic (Claude) row with AWS Bedrock processor row covering Anthropic Claude Haiku 4.5, Sonnet 4.6, Amazon Titan v2, Bedrock Guardrails (R2.2); added Google Analytics 4 + Apollo.io (R2.5). §5.4 (new): user-initiated MCP client integrations (OpenAI ChatGPT, Anthropic Claude Desktop) — recipient framing, not processor (R2.3). §6: added Bedrock, Affinda, Google, Apollo transfer rows; removed Anthropic-as-processor row (R2.1, R2.2, R2.5). §8: split Article 22 position — RAG compliance gating is solely-automated decision-making with significant effect (right to human review / contest / explanation) (R1.1); added CV analytics three-layer block (Affinda ML → Opus deterministic → recruiter-approved) with EU AI Act Annex III §4 high-risk classification (R1.2); added fraud / duplicate-profile detection block under Art. 22 with NI/name/DOB/bank-account signal disclosure (ais-007) (R3.1). §9: added offline write queue security note (R2.4). §10: expanded to three-category summary naming Google Analytics 4 and Apollo.io with consent-gating (R2.5). |
| v2.9.0 | May 6, 2026 | Corrected lawful bases for talent pool and headhunting processing (§3, §8): talent pool (shift matching) reclassified from consent to contract performance (Art. 6(1)(b)) — workers are included by default as part of the Opus employment contract with an opt-out available; headhunting matching remains consent (Art. 6(1)(a)). Removed "talent pool participation" from consent-withdrawal list (§8) and added clarifying note on contract basis with opt-out. Updated headhunting withdrawal text to reflect that Opus operates headhunting on workers' behalf (employers do not search the pool directly). ADR-048 lawful basis alignment. |
| v2.8.0 | Apr 23, 2026 | Added QR attendance records as a disclosed data category (§2.4), updated attendance verification row in §3, updated employer sharing disclosure (§5.2) to include QR confirmations, added QR attendance records to retention table (§7) |
| v2.7.0 | Apr 10, 2026 | Lawyer review: corrected employment model wording (§1), softened biometric basis (§2.2), updated DBS basis to include Article 10 UK GDPR (§2.3), updated GPS lawful basis from consent to legitimate interest (§2.4), updated student visa wording (§2.2), corrected joint/independent controller framing (§5.2), tightened international transfer DPF conditions (§6), qualified "full control" rights language (§8), corrected breach notification wording (§9), resolved AI timesheet inconsistency (§4.1) |
| v2.6.0 | Mar 25, 2026 | Corrected biometric data lawful basis (§2.2: Explicit consent alone → belt-and-braces: Article 9(2)(g) UK GDPR + DPA 2018 Schedule 1 Part 2 Para 6 as primary basis + explicit consent also collected via Document 6; Article 6(1)(c) legal obligation applies to RTW check itself), expanded DBS lawful basis (§2.3: added Article 9(2)(b) + DPA 2018 Schedule 1 Para 1), added 3 missing retention rows (§7: DBS outcome record, DBS Update Service check log, biometric data not retained) |
| v2.5.0 | Mar 16, 2026 | Aligned AI governance tier table with ToS §5.3 (§4.5: tiered bullet list → formal Tier 0-3 four-tier table per agent-governance.md), fixed eSignatures.io domain name across all documents |
| v2.4.0 | Mar 16, 2026 | Added language preference to data collected (§2.1), expanded training certificates to include professional certifications (§2.4: SIA, CSCS, driving licences per ADR-031), added AI translation disclosure (§4.3), added registration approval gate (ToS §3.2 per ADR-030) |
| v2.3.0 | Mar 16, 2026 | Corrected Xero international transfer safeguard (§6: "UK adequacy decision" → SCCs + GDPR DPA — Australia does not have UK adequacy) |
| v2.2.1 | Mar 16, 2026 (second release) | Removed SendGrid from AWS SES entry (not yet production — §5.1), added CharlieHR as HRIS processor (§5.1), added Twilio/Xero/Freshdesk to international transfers table (§6) |
| v2.2.0 | Mar 16, 2026 (first release) | Updated e-signature processor to eSignatures.io (§5.1), removed Atlantic Data from DBS processors (§5.1), added New Relic/PagerDuty/Slack as processors (§5.1), updated international transfers table (§6), aligned DBS retention with DBS Code of Practice (§7: 3 years → 6 months), aligned AI log retention with DPIA (§7: 90 days → 2 years), added GPS data retention (§7: 2 years), updated MCP tool counts (§4.1) |
| v2.1.0 | Mar 1, 2026 | Added AI governance framework disclosure (§4.5), model training transparency (§4.6), MCP audit & approval data collection (§2.7), 6-year retention for governance logs (§7), DPIA & ICO AI guidance reference (§8) |
| v2.0.0 | Feb 5, 2026 | Added AI Platform Assistant disclosure, complete third-party integrations, table of contents |
| v1.1.0 | Jan 10, 2026 | Added student visa compliance, GPS tracking details |
| v1.0.0 | Nov 1, 2025 | Initial GDPR-compliant privacy policy |
UK GDPR Compliant — This policy fulfills Articles 12, 13, and 14 transparency requirements.
Last reviewed: May 17, 2026 | Next review: November 17, 2026