Privacy
Privacy Policy
1. Who we are
Altor Partners Limited is the data controller for the personal data described in this policy. That means we decide why and how your personal data is used, and we are responsible to you for it.
Company | Altor Partners Limited |
Registered in | Ireland, company number 771825 |
Registered office | 2 The Beeches, Castleknock, Dublin 15, D15 F7K8, Ireland |
Privacy contact | ian.cleary@altorpartners.com |
Website | altorpartners.com |
Ian Cleary is our appointed point of contact for data protection. He is personally accountable for how personal data is handled at Altor Partners and is the person to write to on any question in this policy.
Our lead supervisory authority is the Irish Data Protection Commission.
2. Who this policy is for
This policy covers everyone whose personal data we hold, not only people who use our website.
Website visitors. Anyone who browses altorpartners.com or submits a form on it.
Clients and prospective clients. People at companies who enquire about hiring, or who engage us on a search.
Candidates. People we place, interview, speak to, or identify as a possible fit for a role, whether they contacted us or we found them.
Referees and referrals. People whose details a candidate or client gives us.
Where we act for a client on a search, we and the client each decide separately what to do with candidate data once it reaches them. In GDPR terms we are independent controllers, not their processor. That means the client is responsible to you for what it does with your data after we share it, and we are responsible for what we do with it. We tell you in section 7 before we share anything with a client.
Our website links to other sites, such as client career pages and LinkedIn. This policy does not cover those sites.
3. What personal data we collect
From website visitors
Our site is built and hosted on Framer. When you submit a form on it we collect what you type into that form: your name, email address, company name, phone number, and anything you write in a message field.
Framer records aggregate visit statistics for us, such as page views and referring sites. These statistics are not tied to your name and we cannot use them to identify you.
Our hosting provider processes your IP address and browser details in server logs in order to serve the site and protect it from abuse. We do not use those logs to build a profile of you.
From clients and prospective clients
Name, work email address, phone number, job title and company name. Records of our correspondence, calls and meetings. Contract, billing and payment details.
From candidates
Candidates are not asked to upload anything to our website. Candidate information reaches us by email, by LinkedIn message, by phone, or through a referral. Depending on the conversation, it may include:
Name, email address, phone number and location
Your CV, work history, employers, job titles and dates
Sales performance information such as quota, attainment, deal sizes and markets sold into
Current and expected salary, notice period, and visa or work authorisation status where the role requires it
Our interview notes, scorecards and the assessment we form of your fit for a role
References, where you have given us the referee's details
Feedback from a client about your application
We do not ask for special category data, which means information about health, racial or ethnic origin, religion, political opinions, trade union membership, sex life or sexual orientation, genetic or biometric data. We also do not ask for criminal conviction data. Please do not send it to us. If it arrives unprompted in a CV or an email we delete it unless it is legally required for the role, in which case we will tell you and ask for your explicit consent first.
4. Where we get your data if you did not give it to us
We are a search firm. Most of the best candidates for a role are not looking for one, so we go and find them. If we contacted you out of the blue, this section explains where your details came from.
We source candidate information from:
LinkedIn and other professional networks. Public profile information such as your name, employer, job title, career history and location.
Company websites and public announcements. Team pages, press releases, conference speaker lists and podcast appearances.
Referrals. A colleague, a client or another candidate suggests you and passes on your name and contact details.
Our own records. Previous conversations with you, or a search we ran in the past.
Business contact databases. Third-party tools that compile professional contact details from public sources.
We only collect information that relates to your professional life. We do not collect anything from your personal social media accounts.
When we obtain your data this way, Article 14 of the GDPR requires us to tell you within one month of getting it, or at the point we first contact you, whichever comes first. In practice our first message to you will say where we found you, and will link to this policy. If you would rather we did not hold your details, reply and say so, and we will delete them. We do not need a reason.
If a client or a referee gives us your details, we will tell you who provided them if you ask.
5. Why we use your data, and our legal basis
The GDPR requires us to have a lawful basis for every use of your personal data. Here is ours, use by use.
What we do | Whose data | Lawful basis |
|---|---|---|
Reply to an enquiry sent through our website | Website visitors | Legitimate interests: responding to someone who contacted us. Where the enquiry is about engaging us, steps prior to entering a contract |
Discuss a search, scope a role and agree terms | Clients | Performance of a contract, or steps taken at your request before entering one |
Run a search and deliver it | Clients | Performance of a contract |
Identify and approach candidates for a specific role | Candidates | Legitimate interests: matching professionals to relevant roles, and helping employers fill them. See section 6 |
Assess your suitability, interview you and write up notes | Candidates | Legitimate interests, and steps taken at your request before entering an employment contract with our client |
Share your profile with a named client | Candidates | Consent. We ask you first, for each client, every time |
Keep your details on file for future roles | Candidates | Consent, which you can withdraw at any time |
Take up references | Candidates and referees | Consent |
Send occasional market updates and role alerts | Clients and candidates | Consent, or legitimate interests where you are an existing client contact. Every message has an unsubscribe link |
Invoice, take payment and keep accounts | Clients | Legal obligation under Irish tax and company law, and performance of a contract |
Keep records to defend a legal claim or answer a regulator | Everyone | Legitimate interests, and legal obligation |
Maintain and secure our website | Website visitors | Legitimate interests: keeping the site available and protecting it from abuse |
We do not use your personal data for any purpose that is not on this list. If that changes we will update this policy and, where the law requires it, ask your permission first.
6. When we rely on legitimate interests
Where the table above says legitimate interests, the law requires us to balance our interest against your rights. We have done that, and here is the reasoning in plain words.
Our interest. We run a search business. To do it we have to identify professionals who fit a role and approach them about it.
Why it is reasonable to expect. If you hold a go-to-market role at a software company, you have a public professional profile and you expect to hear from recruiters about relevant positions. Approaching you about a role that matches your career is within the reasonable expectations of your professional life.
How we limit the impact on you. We collect professional information only. We approach you about a specific role we are actually working on, not as part of a bulk mailing. We say where we found you. We never pass your details to a client without asking you first. One reply telling us to stop ends it permanently.
Your right to object. You can object to any use of your data that relies on legitimate interests. Email ian.cleary@altorpartners.com. Unless we have compelling grounds that override your rights, which is rare, we will stop and delete your record. For direct marketing there is no balancing at all: if you object we stop, without exception.
7. Who we share your data with
We do not sell personal data. We have never sold it and we will not.
Client companies
If you are a candidate, we share your profile with a client only after you have agreed to it, for that named client, for that named role. We tell you who the client is before we send anything. If you say no, nothing is sent and it does not affect any other role we discuss with you.
Once a client holds your data it is responsible for it as a separate controller under its own privacy policy. We will tell you which policy applies.
Service providers
We use a small number of suppliers to run the business. They process data on our instructions only, under a written contract that meets Article 28 of the GDPR, and they cannot use your data for their own purposes.
Supplier | What they do | Where |
|---|---|---|
Framer B.V. | Website hosting and form submissions | Netherlands, with global content delivery |
Microsoft Ireland Operations Limited | Microsoft 365: email, calendar, file storage and documents. This is where candidate and client records are held | Ireland and the EU Data Boundary |
Google Ireland Limited | YouTube, for the embedded podcast videos on our site. See section 10 | Ireland, with processing by Google LLC in the United States |
Others
Professional advisers. Our accountant, auditors and solicitors, where they need the information to advise us.
Authorities. Where we are legally required to disclose, for example to Revenue or in response to a court order.
A buyer. If the business is sold or merged, personal data may transfer to the buyer, who would be bound by this policy until they give you notice of their own.
We will keep this supplier list current. If you want to know exactly who holds your data at any point, ask us and we will tell you.
8. Sending data outside the EEA
We work with companies in Ireland, across the EU and in the United States, so personal data sometimes leaves the European Economic Area.
When that happens we rely on one of the following safeguards, as required by Chapter V of the GDPR:
An adequacy decision. The European Commission has decided the destination country protects personal data adequately.
The EU-US Data Privacy Framework. Where a US recipient is certified under it.
Standard Contractual Clauses. The European Commission's approved contract terms, backed by an assessment of whether local law in the destination country undermines them, and additional measures such as encryption where it does.
For candidates this matters most in one situation. If you apply through us to a US-based client, your CV and our notes go to that client in the United States. We will tell you the client is US-based before you agree, so you are deciding with that in mind.
You can ask us for a copy of the safeguard we rely on for any particular transfer. Email ian.cleary@altorpartners.com.
9. How long we keep your data
We do not keep personal data indefinitely. Each category has a retention period and a defined point where the clock starts.
Category | We keep it for | Counting from |
|---|---|---|
Website enquiry that goes nowhere | 12 months | The date of your enquiry |
Candidate we approached who did not reply or declined | 6 months | Our last contact attempt |
Candidate considered for a role but not placed | 24 months | The date the search closed |
Candidate we placed | 6 years | The end of the guarantee period on that placement |
Candidate on file for future roles | 24 months, then we ask if you want to stay | Your last confirmation |
Client contact records | 24 months after our last engagement | The close of the last search |
Contracts, invoices and accounting records | 6 years | The end of the relevant financial year |
Records needed for a live or threatened legal claim | Until the claim is resolved, plus the limitation period | The date the matter is resolved |
The six-year periods are set by Irish law. Section 886 of the Taxes Consolidation Act 1997 requires six years of accounting records, and the Statute of Limitations 1957 gives six years to bring a contract claim, which is how long we may need records to defend ourselves.
When a period ends we delete the data, or anonymise it so it can no longer identify you. Anonymised figures, such as the number of searches we ran in a year, may be kept indefinitely because they are no longer personal data.
If you are on file for future roles, we will email you before the 24 months are up and ask whether you want to stay. If you do not reply, we delete your record. Silence is not consent.
10. Cookies and analytics
We do not use advertising pixels, marketing trackers or session recording on this website. There is no Google Analytics, no Meta pixel and no LinkedIn Insight Tag. Two things on the site do touch your browser, and they are set out below.
Our analytics do not use cookies
Our site runs on Framer, and we use Framer's built-in analytics. It uses no cookies and no persistent identifier. It counts unique visitors by hashing your IP address and browser details with a secret that is regenerated and destroyed every day, so the same visitor cannot be recognised across two days, let alone tracked across the web. We see page views, rough location, device type and referring site as aggregate estimates. We cannot identify you from any of it.
Embedded YouTube videos do use cookies
We embed episodes of our podcast from YouTube. YouTube is operated by Google. When a YouTube player loads on a page, Google can place cookies on your device and receives your IP address and details about your browser, whether or not you press play. Google may use this to build a profile of your interests and to personalise advertising to you elsewhere.
Those cookies are not necessary for our site to work, so we do not load them unless you say yes.
The first time you visit, you will see a notice asking whether to allow embedded video content. Until you accept, the YouTube player does not load and no Google cookies are set. If you decline, you will see a placeholder with a link that opens the episode on YouTube in a new tab, where Google's own terms apply.
What | Who sets it | Purpose | When it is set |
|---|---|---|---|
Framer analytics | Framer B.V. | Aggregate visit statistics. No cookie, no persistent identifier | Always. It stores nothing on your device |
YouTube cookies, including VISITOR_INFO1_LIVE, YSC and CONSENT | Google Ireland Limited | Video playback, playback preferences, and Google's own analytics and advertising | Only after you accept embedded video content |
11. How we protect your data
We keep the amount of data we hold small, and we protect what we hold with measures appropriate to the risk, as Article 32 of the GDPR requires:
Accounts protected by strong, unique passwords and two-factor authentication
Data encrypted in transit and at rest by the providers we use
Access limited to those who need it. In practice, a one-person firm means access is limited to Ian Cleary
Written data processing agreements with every supplier that touches personal data
Devices encrypted, locked and kept up to date
No candidate or client data stored on personal devices belonging to anyone outside the business
12. Automated decisions and the use of AI
No decision about you is made by a machine. Every shortlist, every rejection and every recommendation to a client is made by a person, and that person is Ian Cleary.
We use software, including AI-assisted tools, to help build lists of people who might fit a role, to research companies and markets, and to draft outreach. These tools help us decide who to contact. They do not decide whether you are suitable, they do not score or rank you, and nothing they produce goes to a client without a human reading it first.
This means Article 22 of the GDPR, which covers decisions based solely on automated processing that produce legal or similarly significant effects, does not apply to what we do. You still have the right to ask us how we reached a view on your application, and we will tell you.
We do not upload candidate CVs or interview notes into public AI tools that would use them to train models.
13. Your rights
If you are in the EEA or the UK, the GDPR gives you the following rights over your personal data. They are free to use.
Right | What it means |
|---|---|
Access | Get a copy of the personal data we hold about you, including our interview notes on you |
Rectification | Have anything inaccurate corrected, or anything incomplete completed |
Erasure | Have your data deleted, where we have no overriding reason to keep it |
Restriction | Have us pause all use of your data while a dispute about it is resolved |
Portability | Receive the data you gave us in a machine-readable format, or have us send it to someone else |
Objection | Object to any use based on legitimate interests. For direct marketing, we stop on request, always |
Withdraw consent | Withdraw consent at any time, which does not affect anything done before you withdrew it |
Complain | Lodge a complaint with a supervisory authority. See section 17 |
How to use them
Email ian.cleary@altorpartners.com and say what you want. You do not need to use any particular wording, cite any article, or explain why.
We will respond within one month. If the request is complex we may extend that by two further months, and we will tell you within the first month if we do.
We may ask you to confirm your identity before we release data, so that we do not hand your information to someone else.
One practical note for candidates: a subject access request covers our written assessment of you as well as your CV. If you ask, you get the notes.
14. If you are in the United States
We work with US companies and US candidates. State privacy laws in California, Colorado, Connecticut, Virginia and elsewhere may not apply to a business of our size, because most of them only bite above revenue or data-volume thresholds we do not meet. We are not relying on that.
We extend the same rights to everyone, wherever you are. If you are a US resident you can ask us to:
Tell you what categories of personal information we have collected about you, where we got it, why we have it and who we shared it with
Give you a copy of it
Correct anything that is wrong
Delete it
Stop sending you marketing
Two statements that California law asks us to make plainly:
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We never have.
We do not discriminate against anyone for exercising a privacy right. Asking us to delete your data will not affect how we treat you as a candidate or a client.
The categories of personal information we collect are set out in section 3, the purposes in section 5, and who receives it in section 7. To make a request, email ian.cleary@altorpartners.com. You may use an authorised agent, and we will ask for proof of their authority.
15. Children
Our services are for working professionals. We do not knowingly collect personal data from anyone under 18, and our website is not directed at children. If you believe we hold data about a child, email ian.cleary@altorpartners.com and we will delete it.
16. Changes to this policy
We update this policy when what we do with data changes, or when the law does. The version date is at the top of the page, and we keep the previous version available on request.
If a change materially affects your rights, for example a new category of data, a new purpose, or a new recipient, we will email everyone on our candidate and client records before it takes effect rather than relying on you to re-read the page.
This policy is governed by Irish law.
17. Contact us, or complain
Write to us first. We would rather fix something than have you take it elsewhere, and we answer quickly.
Altor Partners Limited Ian Cleary 2 The Beeches, Castleknock, Dublin 15, D15 F7K8, Ireland ian.cleary@altorpartners.com
If you are not satisfied with our answer, you have the right to complain to a supervisory authority. Ours is:
Data Protection Commission 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland +353 1 765 0100 or 1800 437 737 dataprotection.ie
You can also complain to the supervisory authority in the EU country where you live or work. If you are in the UK, you can complain to the Information Commissioner's Office at ico.org.uk.
Complaining to a regulator does not stop you from also bringing a claim in court.
Last updated: 22.09.2026