Humetry
Legal · Privacy

Privacy Notice

What this site collects when you visit and when you write to us, what happens to a client's data inside an engagement and to a practitioner's records, and how you ask for any of it to be corrected or deleted. Written to be true of the site as built: no trackers, no analytics, no cookie until you sign in.

01

Who this notice is for

This notice covers visitors to the Humetry public website and the records our own forms create. If you sign in to the console, your organisation's agreement and the security and privacy policy govern what happens inside it. If you are a practitioner, your engagement terms apply alongside the practitioner section below. This page is about visiting, and about what you hand us when you write.

02

What we collect, and why

Forms. The conversation request asks for your name, work email, company, role, where the work runs today, the function of most interest, the systems in the path and what you choose to tell us. The practitioner application asks for your name, email, the desk you ran, your years and where, and the systems you have worked in. The careers application asks for your name, email, phone, where you live, a link if you give one, whether you are authorised to work where the seat is based and whether you need sponsorship, your years of relevant experience, the systems you have worked in, your earliest start, the compensation you have in mind and how you heard of us if you choose to say, your words, and a resume. The partner application asks for your firm, its website, country and size, the kind of partnership, the platforms you work in and how many certified consultants you have on them, the regions and clients you serve, your words, and your name, title, email, phone and how you heard of us if you choose to say. A message to us carries your name, email and the message. We use all of this to reply to you and to consider what you asked, and for nothing else; it is not sold, not shared for advertising, and not added to any list you did not ask for.

Resumes. A resume is stored for the hiring conversation, visible to our staff only, with every access logged, and deleted on your request.

Server logs. Like every website, our servers record request logs (IP address, user agent, pages requested, time) used for security and operations and kept only as long as those purposes need. Sign-ins and failed sign-ins are recorded with the address they came from.

03

Client data inside an engagement

When a client's workers run, Humetry processes records from the client's systems to do the work: invoices, receipts, orders, master data, the correspondence a case needs. For that data Humetry is the processor and the client is the controller; the agreement and its service description say what is processed, where, for how long, and under which identity. Every client has its own environment and nothing is pooled between clients. The case record and its evidence are the client's, exportable, and leave with the client if the engagement ends.

04

Practitioner records

For the people we engage by assignment, Humetry is the controller of the records the engagement creates: the application, the qualification, assignments and their hours, the ledger, standing and its changes with their reasons, and any grievance and its answer. A practitioner reads their own records in the panel; staff reads are logged. The practitioner standard says how the ledger, the standing and the grievance channel are kept, and the plate and the quality record are the practitioner's to show.

05

Cookies

Public pages set no cookies. One signed, HTTP-only session cookie is set when you sign in to the console or the panel, and removed when you sign out. Two review cookies exist for our own reviewers, to read draft pages or retired pages, and are set only when a reviewer presents a key; a visitor never receives them. There are no advertising or analytics cookies.

06

No trackers

The site runs no analytics and no trackers. The one third-party request a public page makes is to Google Fonts for typefaces, which discloses your IP address to Google as any font request would; Google's privacy policy governs that request. The instruments that move as you type or as time passes, the key on the sign-in page, the clocks on the contact page, the sheet on the conversation page, are computed in your browser and send nothing until you press send. If we ever add measurement, it will appear in this notice first, as a new version.

07

Your rights

You may ask what we hold about you, ask for correction, or ask for deletion. A console user deletes their own account from their account page; a practitioner asks for deletion from the account page of the panel and a member of our staff carries it out; a form submission (a conversation request, an application, a resume, a message) is deleted on a request to the address on the contact page. Deletion removes the person: name, contact details, credentials, password, photo. Work already paid for, the terms signed and the audit record stay under a number, not a name. Applicable data protection law, including the GDPR and the UK GDPR where they apply and the state privacy laws of the United States where they apply, gives you these rights; we honour them without requiring you to name the statute.

08

Changes

This notice is versioned. A change is a new version with a new effective date on this page.

Counsel reviews each version before it is deployed publicly. A question about any clause goes to the address on the contact page.