Candidate Privacy Policy

Monica + Andy (“Company”, “we”, or “us”) values the trust you place in us when you give us access to your personal data. We respect the privacy rights of individuals and are committed to handling personal information responsibly and in accordance with applicable laws.

The Company is a “data controller” of your personal data (for the purpose of the General Data Protection Regulation (“GDPR”) and is responsible for the lawfulness of what we do with your personal data. These Privacy Policy provisions will apply to our processing of your personal information where you apply to a job opening posted directly by us. Where you apply to a job opening for our Company through the application process of another source, such as a job board, that source may collect and retain your personal information as part of the application process. Any use of your personal information by another source shall be in accordance with that source’s own Privacy Policy.

We use Applicant Tracking Software, branded as HiringThing, an online applicant tracking tool, as a “data processor” to process personal information on our behalf. Applicant Tracking Software is only entitled to process your personal data in accordance with our instructions.

Data Protection Principles

Your data will be:

Security Technology and Practices

We always transmit and store personal information securely. This prevents potential hackers from “tapping” a data conversation. The data security standards we have in place include auditing, logging, backups, and safe-guarding data. Our servers are housed in datacenters that are ISO27001 certified, the highest and most current standard for managing systems and data securely. All datacenter facilities are protected by professional security staff utilizing video surveillance, intrusion detection systems and other electronic means. Authorized staff must pass two-factor authentication a minimum of two times to access data center floors. We are SOC 2 compliant and audited annually by a third party CPA firm.

No method of transmission over the Internet, or method of electronic storage, is 100% secure, however. Therefore, we cannot guarantee its absolute security. If you have any questions about security on our website, you can contact us at

Data Retention

Your personal data will be deleted upon receipt of a written request by you to us.

What information do we collect as part of the application process?

We may collect and process some or all of the following types of information from you when you apply for one of our positions:

Sensitive Personal Information

Information we may collect from other sources (in each case where permissible and in accordance with applicable law):

If you fail to provide personal data when requested, which is necessary for us to consider your application (such as evidence of qualifications or work history), we may not be able to process your application further. For example, if we require references for this role and you fail to provide us with relevant details, we will not be able to take your application further.

What other information do we collect?

Social Media Widgets

Purposes for processing personal information

Application Information

Automated Decision Making

We may use Applicant Tracking Software’s technology in order to automatically sort, select, rate, or filter candidates using criteria specified by us. However, any decision made with respect to hiring a candidate for one of our positions will be made by our staff.

Disclosures of your personal information and transfers abroad

We take care to allow access to personal information only to those who require such access to perform their tasks and duties, and to third parties who have a legitimate purpose for accessing it. Whenever we permit a third party to access personal information, we will implement appropriate measures to ensure the information is used in a manner consistent with this Notice and that the security and confidentiality of the information is maintained.

Transfers Within Our Company

Transfers to Third Party Service Providers

Transfers Abroad

Legal basis for processing your personal information (EEA applicants only)

Under European data protection law, our legal basis for collecting and processing your personal information will depend on the information concerned and the context in which we collect it. However, we will normally collect personal information from you only where: (a) the processing is in our legitimate interests (as summarized above) (and not overridden by your data protection interests or fundamental rights and freedoms); (b) we need the information to comply with applicable immigration and/or employment laws and regulations; (c) we need the information to take steps prior to entering an employment contract with you, where you are considered for employment; (d) you have made the data public; (e) we have your consent to do so; and (f) we need to protect the rights and interests of our Company, our employees, applicants and others, as required and permitted by applicable law.

Where we rely on your consent to collect and process your personal information, you have the right to withdraw or decline your consent at any time. Please note that withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.

Your rights in connection with personal data

Under certain circumstances, by law you have the right to:

If you would like to exercise any of those rights, please contact us using our Contact information below, allow us to collect enough information to identify you, and provide us with the information to which your request relates.

Links to 3rd party sites

Our site includes links to other websites whose privacy practices may differ from those of our Company. If you submit personal information to any of those sites, your information is governed by their privacy policies. We encourage you to carefully read the privacy policy of any website you visit.

Who to contact

Please address any questions or requests relating to this Notice to

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues.