Questions? A person will answer.
Email us
Evaluating us as a supplier?·Jump to the procurement answers →
Security · data protection

Your data, and
who can see it.

Running someone’s job search means holding a lot about their working life — and, when an employer funds it, keeping the two apart. Here is exactly how we do that.

Encrypted credential vault
Employers see aggregate only
UK GDPR, DPA either way
who can see what
Your named specialistEverything needed to run your search
FULL
Operators on your accountThe minimum required to prepare and submit
SCOPED
Our quality reviewerApplications before they are sent
SCOPED
Your employer, if they payAggregate cohort figures only — never your applications
AGGREGATE
Anyone elseNothing at all
NONE
Credentials live in an encrypted vault. Never a spreadsheet, never email, never chat.
What we hold

Only what the search actually needs

  • Your CV and work history
  • Your search preferences — targets, locations, salary floor, deal-breakers
  • The answers employers commonly ask for, so we don’t keep asking you
  • A record of every application we sent on your behalf
  • Portal credentials, only where you choose to give them, only in an encrypted vault
  • Nothing else. We don’t buy data, enrich profiles, or sell anything
What we will never ask for

Your online banking, your personal email password, your government identity logins, or your bank details and National Insurance number before you have a written offer in hand. If anyone contacts you claiming to be from Second Wind and asks for those, it is not us — forward it to hello@secondwind.careers.

Controls

The measures behind that

  • Least-privilege access — operators reach only the accounts they work on
  • Encrypted credential vault, never a tracker or a spreadsheet
  • Two-factor authentication on our own systems
  • Written confidentiality and data protection agreements with everyone who touches client data
  • A documented operations manual every operator works to
  • Breach process — ICO within 72 hours where required, you told without undue delay where the risk is high
  • Data minimisation and a retention schedule, both in our privacy notice
  • UK IDTA and a transfer risk assessment for any operator outside the UK
Your search email

We set up a dedicated secure address for your search, so your personal inbox stays yours and nothing gets lost among everything else. It is deleted when your search ends.

For procurement

What your supplier questionnaire will ask

ItemPosition
ICO registrationRegistered with the ICO — number on request
Cyber EssentialsIn progress — ask us for the current position
Professional indemnity & public liabilityIn place — certificate on request
Data processing agreementWe will sign yours or provide ours
Role under UK GDPRWhere you fund the programme we act as processor on your instructions, with our operators as sub-processors
Sub-processorsFull list provided with our DPA
Data locationUK and EU, with a UK IDTA for any transfer outside
RetentionSet out in the privacy notice — see the privacy notice
Supplier security questionnaireWe will complete yours
DPIAAvailable on request
Being straight about where we are

Some rows above are still being completed. We would rather show you the table with gaps in it than imply certifications we do not yet hold. Ask where any of them stand and you will get a date, not a deflection.

Anything your team needs

Send us your questionnaire, your DPA, or just the question that is holding things up. A person will answer it, usually the same day.