Privacy Policy

Your privacy is important to us. This policy explains how we collect, use, and protect your information when you use OneReference.

Last updated: September 22, 2026

1. Roles and scope

OneReference is controller for accounts, the candidate Vault, platform security, billing, support, direct product communications and community moderation. A verified agency or employer is normally an independent controller for its recruitment, employment, compliance and retained evidence copies. In limited configured workflows OneReference may process data for an organisation under contract; that organisation’s notice also applies.

2. Personal data we collect

Category Examples
Account and contact Name, email, telephone, role, organisation, credentials and communication preferences.
Professional and reference CV/profile, work history, qualifications, referee details, requests, answers, declarations, signatures, attachments, Vault and sharing records.
Recruitment and community Jobs, applications, interview notes supplied to the service, messages, posts, reports, blocks, moderation actions and appeals.
Identity and organisation verification Internally processed government-ID and live-face inputs, biometric face template/measurements and similarity score, human/electronic review, verification result, organisation/domain evidence and fraud signals. For successful checks, raw images, manually supplied documents and derived biometric data are deleted after the decision is recorded and no later than 24 hours after completion.
Technical and security IP address, device/browser, access, session, MFA/OTP attempts, token and audit events, cookies and similar technologies.
Commercial and support Plan, invoices, payment status (payment card data is handled by the payment provider), tickets, complaints and rights requests.

Please do not submit criminal-conviction, allegation or other criminal-offence data. We do not intentionally request or use it. Avoid special-category data unless a clearly identified lawful workflow expressly requires it.

3. Sources

Data comes from you; referees; requesting candidates, agencies or employers; verified organisation administrators; people who report content; payment providers; OneReference’s internal identity-verification process; security and fraud signals; and public professional or company sources used for verification. When data comes from another person, we provide notice as required and expect the supplier to have authority to provide it.

4. Purposes and lawful bases

Purpose UK/EU lawful basis
Create accounts; provide Vault, references, jobs, messaging and paid features Contract; steps at your request before contract.
Deliver organisation recruitment/reference workflows Organisation’s lawful basis; our contract and legitimate interests where we are controller/processor as applicable.
Verify users/organisations; prevent fraud; secure service; maintain audit evidence Legitimate interests for ordinary security data. Biometric data used for unique identification also requires a documented UK GDPR Article 9 condition, an appropriate policy document where required, necessity/minimisation and a DPIA before launch.
Billing, tax, compliance, rights requests and legal claims Contract; legal obligation; legitimate interests in establishing, exercising or defending claims.
Service emails, reference reminders and requested communications Contract or legitimate interests; consent where electronic-marketing law requires it.
Community moderation and safety Legitimate interests in a lawful, safe service; legal obligation where applicable.
Optional non-essential cookies or marketing Consent, withdrawable at any time.

5. AI and automated processing

OneReference’s self-hosted AI-assisted system may flag community or chat content that may be unlawful or breach our rules. Community content is not sent to an external AI provider. Flags support moderation and may be reviewed by people. OneReference does not use AI or solely automated processing to make hiring, job-access, reference or other decisions producing legal or similarly significant effects. If this changes, we will update this notice and provide required safeguards before use.

6. Sharing and international transfers

  • With a candidate’s chosen verified organisation through a time-limited Vault share; with the requesting verified organisation for an organisation-requested reference; and with authorised users within that organisation.
  • With Hostinger for website/database hosting and server file storage; Porkbun for domain registration and DNS; OneReference’s private email server for email delivery; Twilio for SMS; Stripe and PayPal for payments; Google reCAPTCHA for bot protection; and ClamAV, operating on the server, for antivirus scanning of uploads. The public site also uses Google Fonts, Bunny Fonts and Cloudflare-hosted interface libraries. These providers receive only the data needed for their function, subject to contract and applicable safeguards.
  • With advisers, regulators, courts, law enforcement or counterparties where lawfully required; and in a corporate transaction with safeguards.

Where personal data leaves the UK or EEA, we use an adequacy decision or appropriate safeguards such as the UK IDTA/Addendum or EU standard contractual clauses, with transfer risk assessment where required. A current named subprocessor register should be published before launch; server-side providers cannot be reliably identified from the public page alone.

7. Retention

We use the OneReference Standard Default Retention Schedule. Different owners and copies have separate clocks; legal hold suspends deletion. Key defaults are:

Record Default
Candidate Vault reference While active; inactivity review after 24 months with reminders. Candidate may delete/export; lawful organisation evidence copy is separate.
Candidate profile/CV/portfolio Active account; inactivity review after 24 months, then delete or anonymise after closure/grace period subject to exceptions.
Vault share link 90 days by default; selectable 30/60/90/180 days; revocable at any time.
Organisation evidence copy 6 years from last use/placement/dispute/audit close; approved 7-year sector policy only where justified.
Pending request / incomplete form 90 days pending, then expire; delete draft after 30 additional days unless evidence is needed.
Successful identity and biometric evidence Raw live-face images, manually supplied identity documents, biometric templates, facial measurements and similarity scores are deleted after the result is recorded and no later than 24 hours after verification completes.
Abandoned or failed verification Delete temporary identity and biometric inputs within 7 days. If referred for human review or appeal, retain only until that process ends, then delete within 24 hours.
Verification result and audit Retain only the account identifier, result, time, method, reviewer/reason code where applicable, notice version, deletion time and deletion confirmation under the compliance/audit schedule.
Job applications/interview/recruitment records 24 months after recruitment close or decision by default.
Messages/notifications and community moderation 12–24 months for ordinary messages; moderation 2 years, or 6 years for serious abuse/legal/safeguarding.
Support / security / audit Support 2 years (6 for dispute/compliance); security 12–24 months; compliance-critical audit 6 years.
Rights/deletion case and proof Case or minimal proof 6 years; export package 7 days by default, maximum 30 days if renewed.
Backups and caches Rolling backups 30–90 days; search/cache/CDN purge within 24 hours where technically possible, with restore suppression.
Invoices/tax 6 years by default.

8. Your rights

Depending on applicable law, you may ask for access, correction, erasure, restriction, portability, objection, withdrawal of consent, and review of an automated decision. We may verify identity and apply lawful exemptions, including the UK confidential-reference exemption case by case. A request normally receives a response within one month under UK/EU rules. Contact privacy@onereference.com.

You may complain to the UK Information Commissioner at ico.org.uk. If the EU GDPR applies, you may also complain to the supervisory authority in the EU/EEA country where you live, work or believe an infringement occurred. OneReference has paid its ICO data-protection fee; the public register entry and public registration number must be added after the ICO publishes them. Internal payment and order references are not public registration numbers. Details of any required EU representative must be published before EU/EEA launch.

9. Children, security and changes

The service is for people aged 16 or over. We do not knowingly permit under-16 accounts. We apply enhanced safeguards for 16–17-year-olds and do not use community-moderation AI for hiring or similar decisions. We use access controls, encryption in transit, monitoring, verification and tested retention controls, but no service is risk-free. Material policy changes will be notified appropriately.