Privacy Policy

Last updated: March 2026

1. Who we are

Chosen Care Group (“we”, “us”, “our”) is a UK-based healthcare provider. We are the data controller for the personal data we collect through our recruitment platform at careers.chosencaregroup.com.

2. What data we collect

When you apply for a role or create an account, we may collect:

  • Name, email address, phone number, and postal address
  • CV / resume, cover letters, and qualification documents
  • Right to work status and National Insurance number
  • Skills, experience, shift preferences, and availability
  • Interview records, assessment answers, and application history
  • Messages exchanged via the portal, WhatsApp, or email
  • Technical data: IP address, browser type, and session cookies

3. How we use your data

We process your data to:

  • Assess your suitability for roles you apply to
  • Manage the recruitment pipeline (interviews, offers, pre-employment checks)
  • Communicate with you about your application via portal, email, or WhatsApp
  • Provide AI-assisted features (suitability scoring, chat assistant) to improve your experience
  • Generate anonymised analytics to improve our recruitment process
  • Comply with legal obligations (e.g. right to work checks, CQC requirements)

Legal basis: We process your data under legitimate interest (recruitment), your consent (marketing communications), and legal obligation (right to work verification).

4. AI processing

We use AI systems (powered by Anthropic and OpenAI) to assist with resume scoring, suitability assessments, and our recruitment chat assistant. AI-generated outputs are always reviewed by our recruitment team before any hiring decisions are made. You can request a human-only review of any AI-assisted decision.

5. Who we share data with

We may share your data with:

  • Cloud service providers: Neon (database), AWS (document storage), Vercel/Railway (hosting)
  • Communication providers: Meta (WhatsApp Business API), Resend (email delivery)
  • AI providers: Anthropic, OpenAI (for AI-assisted features)
  • Regulatory bodies: CQC, HMRC, or other authorities as required by law

We do not sell your personal data to third parties.

6. Data retention

We retain your data for the duration of the recruitment process plus 12 months after your last interaction. If you are hired, relevant data transfers to your employee record. You can request deletion at any time through your account settings.

7. Your rights

Under UK GDPR, you have the right to:

  • Access your personal data (via the “Export my data” feature in your account settings)
  • Rectify inaccurate data (edit your profile at any time)
  • Erase your data (“right to be forgotten” via account deletion in settings)
  • Restrict or object to processing (update your consent preferences)
  • Data portability (download your data as JSON)
  • Withdraw consent at any time without affecting previous processing

8. Cookies

We use essential cookies for authentication (httpOnly session cookies) and optional analytics cookies. You can manage cookie preferences through your browser settings. We do not use third-party tracking cookies.

9. Security

We protect your data with: encrypted connections (TLS), hashed passwords (bcrypt), role-based access controls, rate limiting, and regular security reviews. Documents are stored in encrypted cloud storage with time-limited access URLs.

10. Contact us

For any data protection queries or to exercise your rights, contact:

Data Protection Officer
Chosen Care Group
Email: privacy@chosencaregroup.com
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).