1. Who this notice is from
This notice is given by Sen Works LLC, formed in the United States [state of formation and registered agent: TBC], with delivery through our company in Vietnam [name and enterprise registration number: TBC].
2. What this notice covers, and what it does not
This notice covers personal data we decide the use of ourselves: enquiries from this website, business contacts at clients and prospects, people who apply to work with us, and contacts at our suppliers.
It does not cover the data we handle when working for a client. In that work we act on the client's instructions and the client remains responsible for it. Where that data is protected health information under HIPAA, we act as a business associate. Those arrangements are governed by the services agreement, the data processing agreement and the business associate agreement signed with that client, and not by this notice. If you are a patient or a client's employee and want to know how your data is handled, the organisation that holds your record is the right place to ask.
3. What we collect
- Enquiries. Your name, employer, email address and anything you choose to put in your message.
- Candidates. Your application, CV, interview notes, right-to-work and, where a role requires it, the results of background and exclusion screening. See the separate candidate privacy notice [to be written].
- Business contacts. Name, role, work contact details and our record of dealings with you.
- Technical data. When you load this page, our hosting provider receives your IP address and browser details in the ordinary course of serving it. We do not use analytics or advertising tools. See the cookie notice.
4. Why we use it, and on what basis
- Responding to you
- To answer an enquiry and take a conversation forward. Legitimate interests, or steps taken at your request before a contract.
- Recruitment
- To assess an application and meet our checking obligations. Legitimate interests, and legal obligation where screening is required by a client contract or by law.
- Running the business
- Contract administration, invoicing, insurance and professional advice. Contract and legitimate interests.
- Legal and regulatory
- Tax, accounting, sanctions and anti-bribery obligations in the United States and Vietnam. Legal obligation.
5. Who we share it with
Our cloud, email and document providers; our accountants, insurers and legal advisers; and any authority we are legally required to tell. We do not sell personal data, and we do not share it for anyone else's marketing.
6. Sending data across borders
Our people are in the United States and Vietnam, and some of our directors are in the United Kingdom, so ordinary business contact data moves between those places. For personal data leaving the UK or the European Economic Area we rely on the UK International Data Transfer Agreement or Addendum, or the European Commission's standard contractual clauses, supported by a transfer risk assessment.
7. How long we keep it
Enquiries that do not become business, two years. Unsuccessful applications, twelve months, unless you ask us to keep you on file. Contract and financial records, six years after the relationship ends, or longer where tax law in a relevant country requires it. A full retention schedule sits in our internal document set.
8. Your rights
If UK or EU data protection law applies to you, you can ask for a copy of your data, ask us to correct or delete it, object to or restrict our use of it, and ask for it in portable form. Where we rely on legitimate interests you can object, and we will stop unless we can show compelling grounds. Write to [privacy@senworks.com: mailbox not yet created]. We will answer within one month.
You can complain to the Information Commissioner's Office in the United Kingdom, or to your local supervisory authority in the European Economic Area. We would rather you came to us first.
9. Security
How we protect client data is described in the security section of this site. Sen Works does not hold its own security certifications or attestations today. Each resource is contracted to work within the client's information security management system, in addition to Sen Works' own baseline controls and training, so our people meet the third-party requirements of our clients' HITRUST r2, SOC 2, ISO 27001 and other compliance programmes.
10. Changes and contact
We will post any change here with a new revision date. Questions to [privacy@senworks.com], or by post to [registered office: TBC].