Privacy Policy
Last updated: 26 August 2026
1. Who we are
This platform is operated by CoreTalent Network Specialists Limited ("CoreTalent", "we", "us"), a company registered in Ireland, company number [CRO NUMBER — fill in at admin_partner_companies.php, billing panel], with its registered office at The Crescent, Yeats Way, Park West Business Park, Dublin 12, D12 DD74.
For the personal data described in this policy we act as the data controller under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Irish Data Protection Act 2018.
For questions about this policy or about your data, contact admin@coretalentnetwork.com or our data protection contact, [DATA PROTECTION CONTACT / DPO, IF APPOINTED].
2. Businesses on the platform
CoreTalent is used by partner companies who schedule and supervise workforce. When you work shifts for a partner company, that company can see the data it needs to run those shifts — your name, qualifications, attendance, and the location data described in section 3. Each partner company sees only its own operations; it cannot see your data in relation to any other company.
Where a partner company decides how your data is used for its own purposes, that company acts as a data controller in its own right and its own privacy notice also applies.
3. What we collect and why
| Data | Why we need it | Legal basis |
|---|---|---|
| Name, email, phone, date of birth, profile photo | To create and secure your account and identify you on shift | Performance of a contract |
| PPS number and identity documents | To meet Irish tax, payroll and right-to-work obligations | Legal obligation |
| Bank details (IBAN, BIC) | To pay you for work completed | Performance of a contract |
| Licences, certifications and compliance documents | To confirm you are qualified for the roles you are assigned to | Legal obligation; performance of a contract |
| Location (GPS) when you clock in, clock out and during an active shift | To confirm attendance at the correct site and to keep lone workers safe | Legitimate interests — see section 4 |
| Clock-in and clock-out times, hours worked, pay records | To calculate pay and keep the records the law requires | Legal obligation; performance of a contract |
| Messages you send in shift chats and direct messages | To coordinate work and to investigate incidents | Legitimate interests |
| Device and notification data (browser push tokens, app version) | To send you shift alerts on your device | Consent — you can turn notifications off at any time |
| Google Calendar connection (see section 5) | To put your shifts in your own calendar | Consent — optional, and you can disconnect at any time |
4. Location data — what we do and do not do
Location is one of the most sensitive things we handle, so we are specific about it:
- We record your location when you clock in and clock out, to confirm you were at the site.
- We record periodic location updates only while a shift of yours is active.
- We do not track you outside your shifts, and we do not track you when you are not clocked in.
- If you decline location access, you can still clock in — the record is simply marked as having no location attached.
5. Google Calendar integration
Connecting your Google Calendar is entirely optional. You start it yourself from your profile, and nothing happens until you do.
When you connect it:
- We create one new calendar in your Google account, named "CoreTalent Shifts", and we write your assigned shifts into it as events.
- We update or remove those events when a shift changes or is cancelled, so your calendar matches your actual schedule.
- We request only the permission needed to manage the calendar we created. We cannot see, read or change any other calendar or event in your Google account, including your personal appointments.
- We store an access token that lets us write to that calendar. It is encrypted before it is stored.
Limited use. CoreTalent's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except where you ask us to for support, where it is needed for security, or where the law requires it.
Disconnecting. You can disconnect at any time from your profile. When you do, we revoke our access with Google and delete the events we created. You can also revoke access directly at myaccount.google.com/permissions.
6. Who we share data with
- Partner companies you work shifts for — as described in section 2.
- Payment providers, to make payments to you and to process subscription payments where they apply.
- Google, if — and only if — you connect your calendar (section 5).
- Telegram, if you choose to link your Telegram account for notifications.
- Our hosting and email providers, who process data on our instructions in order to run the service.
- Public authorities, where the law requires us to.
We do not sell your personal data, and we do not use it for advertising.
7. Where your data is held
Our servers are located in the European Union. Some of the providers listed in section 6 may process data outside the European Economic Area. Where that happens, the transfer is covered by an adequacy decision of the European Commission or by Standard Contractual Clauses.
8. How long we keep it
We keep your data for as long as your account is active. After your account closes we keep records for [RETENTION PERIOD — e.g. 7 years for payroll and tax records, as Irish law requires], and delete the rest.
Some records cannot be deleted on request because we are legally required to keep them — pay records and tax documents are the main example.
9. Your rights
Under the GDPR you have the right to:
- ask for a copy of the personal data we hold about you;
- ask us to correct anything that is wrong;
- ask us to delete your data, where we are not legally required to keep it;
- ask us to restrict or object to how we use it, including our use of location data under legitimate interests;
- ask for your data in a portable format;
- withdraw consent at any time, where we rely on consent — for example notifications or the calendar connection.
To exercise any of these, email admin@coretalentnetwork.com. We will respond within one month.
If you are not satisfied with our response, you can complain to the Irish Data Protection Commission (dataprotection.ie).
10. Security
Access to the platform requires a password, and what each person can see is limited to their role and their company. Sensitive credentials — including the calendar tokens described in section 5 — are encrypted before they are stored. Traffic between your device and our servers is encrypted in transit.
No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will notify you and the Data Protection Commission as the GDPR requires.
11. Cookies
We use a session cookie to keep you signed in, and local storage to remember interface preferences such as whether the sidebar is collapsed. These are necessary for the service to work. We do not use advertising or third-party tracking cookies.
12. Children
The platform is not intended for anyone under 16, and accounts are not knowingly created for them. If you believe a minor has an account, contact us and we will remove it.
13. Changes to this policy
If we change this policy we will update the date at the top of this page. Where a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.
14. Contact
CoreTalent Network Specialists Limited
The Crescent, Yeats Way, Park West Business Park, Dublin 12, D12 DD74
admin@coretalentnetwork.com