Policy
Privacy Policy
Thotara is a business-to-business recruiting platform that stores professional information about clinicians, facility contacts and recruiting staff. This policy explains what personal data is processed, on what basis, who it is shared with, how long it is kept, and how individuals exercise their rights.
Last updated 21 August 2026
1. Scope and roles
This policy applies to personal data processed in the Thotara platform, on our public website and in support interactions. It does not apply to a customer organization's own systems, or to third-party services an organization connects using its own credentials.
Controller and processor
Each staffing organization using Thotara is the controller (or "business") of the records in its workspace: it decides which providers and clients are entered, what is collected and how it is used. Thotara operates as the processor ("service provider") and acts on that organization's documented instructions. Thotara is the controller only for its own account, billing and platform-security data about administrators and staff users.
Requests to access, correct or delete a record should be directed to the organization holding it; where a request reaches us first, we route it to that organization and assist with fulfilment.
2. Data we process
| Category | Examples | Notes |
|---|---|---|
| Provider (clinician) dataRecruiting and credentialing file | Name, date of birth where required for credentialing, contact details, NPI, DEA, state licences, board certifications, CV and work history, education, references, malpractice and NPDB self-query documentation, immunisation and health attestations, rate expectations, availability, travel preferences. | Includes professional-conduct and malpractice history; treated as sensitive. |
| Payment and tax dataPayment set-up only | Direct-deposit authorisation, bank routing and account numbers, taxpayer identification number, business-entity details for entity billing. | Stored encrypted; displayed to staff only in masked form, with every reveal logged. |
| Client and facility dataCommercial relationship | Facility profile, contact names, business email and phone, job orders, presented candidates, agreements, timesheets, invoices and payment status. | Business-contact data; no consumer profiling. |
| Staff user dataWorkspace administration | Name, work email and phone, role and permission assignments, authentication and two-step verification factors, and recorded work activity such as calls, texts, emails, notes, record edits and productivity metrics. | Activity data is visible to that organization's managers and administrators. |
| Technical and log dataSecurity and reliability | Sign-in events, IP address and user agent captured by the authentication provider, audit-log entries, error diagnostics, webhook and message delivery receipts. | Used for security monitoring, not for advertising. |
Thotara is not a clinical system. It is not intended to hold patient medical records or protected health information, and customers are contractually prohibited from uploading them. Provider health attestations and immunisation records are credentialing artefacts about the clinician, not about any patient.
3. Sources of data
- Directly from the individual — intake forms, portal profile edits, uploaded documents, direct-deposit submissions and e-signatures.
- From the customer organization — records entered by recruiters, bulk imports from a prior CRM, and files received by email.
- From public and professional sources — the NPI registry, state licensing boards, certification bodies and public professional profiles.
- From optional connectors an organization enables — sourcing providers, telephony and email systems.
- Generated by the platform — audit entries, activity metrics, AI suggestions and derived matching scores.
4. Purposes and legal bases
| Purpose | Legal basis (UK/EU GDPR terms) |
|---|---|
| Operating the recruiting workflow: sourcing, matching, presenting candidates, placements and scheduling | Legitimate interests of the organization and the clinician's own interest in employment; contract performance once engaged |
| Credentialing and verification of licences, certifications and professional history | Legal obligation and legitimate interests (patient-safety and client contractual requirements); substantial public interest for professional-conduct data |
| Payment set-up, invoicing and tax reporting | Contract performance and legal obligation |
| Platform security, fraud prevention, audit logging and incident investigation | Legitimate interests and legal obligation |
| Service communications, support and portal notifications | Contract performance and legitimate interests |
| Recruiting outreach by SMS or email through a connected provider | Consent where required by TCPA/CAN-SPAM or local marketing rules; obtained and evidenced by the organization |
| Aggregate, de-identified product analytics and reliability metrics | Legitimate interests; no re-identification and no cross-customer profiling |
We do not sell personal data, do not share it for cross-context behavioural advertising, and do not use customer data to train third-party foundation models.
5. Public-source enrichment and AI
To reduce manual data entry, Thotara looks up publicly available professional information — for example the NPI registry, licence boards and public professional profiles — and proposes field values. AI is also used to extract data from CVs and credentialing documents, to draft letters, agreements and job summaries, and to score candidate-to-job fit.
- Every AI or enrichment output is a suggestion. It carries its source, is queued for review, and is never written to a record until a person accepts it.
- No automated decision with legal or similarly significant effect is made about an individual: matching scores rank options for a recruiter, they do not hire, reject or price anyone.
- Model prompts are limited to the fields needed for the requested task, are not retained by the model provider for training, and are logged with the requesting user for accountability.
- Individuals may ask the controlling organization to correct any enriched field, and corrections override the suggested value permanently.
6. Who can access data
- Access is scoped to a single organization at the database layer through row-level security; one customer's workspace is never visible to another.
- Within an organization, role and permission checks decide which surfaces and fields a user can open; sensitive surfaces such as banking, audit and access review are restricted to administrators or a finance role.
- Providers signing in to the provider portal see only their own profile, assignments, letters, agreements, travel and timesheets.
- Facility contacts see only their own client's jobs, presented candidates, timesheets, invoices and agreements.
- Thotara personnel do not access customer records in the ordinary course. Access for support or incident response is limited to named staff, requires a business justification, and is time-bound and logged.
- Disclosure to law enforcement or a regulator is made only where legally compelled; where the law permits, we notify the affected organization first.
7. Sub-processors
| Sub-processor category | Purpose | Processing region |
|---|---|---|
| Managed cloud database, authentication and object storage | Hosting of application data, user accounts, sessions and uploaded documents | United States |
| AI gateway (large language and document models) | Document extraction, drafting of letters, agreements and job summaries, and field suggestions; prompts carry only the data needed for the task and are not used to train third-party models | United States |
| Transactional email provider | Authentication emails, notifications and, where the organization configures its own domain, outbound recruiting email | United States / organization-selected |
| Telephony and SMS provider (optional, organization-supplied) | Staff calling and texting, call/message metadata and recordings where the organization enables them | Organization-selected |
| Sourcing and contact-enrichment providers (optional, organization-supplied) | Look-up of publicly available professional contact information | Organization-selected |
Each sub-processor is bound by written terms that impose confidentiality, security and data-protection obligations no less protective than this policy. Optional connectors are engaged by the organization under its own agreement with that vendor. We maintain a current sub-processor register and notify organization administrators of a material change or a new sub-processor before it begins processing, giving them an opportunity to object.
8. International transfers
Application data is hosted in the United States. Where personal data is transferred from the UK, EEA or Switzerland, the transfer relies on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, supported by a transfer risk assessment and the technical measures described below — encryption in transit and at rest, tenant isolation and access logging. Copies of the transfer terms are available to customers on request.
9. Retention and deletion
| Data | Retention period |
|---|---|
| Active workspace recordsProviders, clients, jobs, placements, documents. | Life of subscription |
| Audit logAccess, role, settings, credentialing and export events. | 24 months |
| In-app notificationsRead and unread alerts. | 12 months |
| Webhook and message delivery eventsDelivery receipts and payload metadata. | 6 months |
| Signed letters and agreementsImmutable executed records. | Life of subscription |
| Deleted records and documentsThen permanently purged. | 30 days |
| Closed workspaceExport window, then permanent deletion. | 30 days |
Retention is enforced by a nightly scheduled purge rather than manual clean-up, and each run records what it deleted. Backups roll off on their own schedule within 35 days, so a deleted record may persist in an encrypted backup until that window closes. Where a record is subject to a legal hold, tax obligation or an unresolved dispute, it is retained until that obligation ends.
10. Security measures
Measures include encryption in transit and at rest, organization-scoped row-level security, least-privilege roles, mandatory two-step verification (authenticator app for staff, emailed one-time code for portal users), breached-password screening, a 30-minute idle session timeout, private document storage with short-lived signed links, server-side-only secrets, immutable audit logging and constant-time verification of webhook and scheduled-job credentials. The security page documents the control set in full.
11. Individual rights
- Access — obtain a copy of the personal data held about you.
- Rectification — correct inaccurate or incomplete data; portal users can edit much of their own profile directly.
- Erasure — ask for deletion where there is no overriding legal, contractual or credentialing obligation to retain.
- Restriction and objection — ask that processing based on legitimate interests be paused or stopped.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — for SMS or marketing outreach, at any time, including by replying STOP or using the unsubscribe link.
- Complain — to your local supervisory authority; in the UK, the Information Commissioner's Office.
Send requests to privacy@thotara.com. We acknowledge within five business days and respond within 30 days (extendable once by a further 60 days for complex requests, with notice). We verify identity before disclosing data, and requests about a customer's records are routed to that organization as controller. There is no charge unless a request is manifestly excessive or repetitive.
12. US state privacy rights
Residents of California, Colorado, Connecticut, Virginia, Texas and other states with comprehensive privacy laws have rights to know, access, correct, delete, obtain a portable copy, and to opt out of sale, targeted advertising and profiling with legally significant effects. Thotara does not sell personal information, does not process it for targeted advertising, and does not conduct such profiling, so there is nothing to opt out of. We do not discriminate against anyone for exercising a right, and an authorised agent may submit a request with written proof of authority. Where Thotara acts as a service provider, the request is fulfilled by the controlling organization.
13. Children's data
The platform is intended for professional use by adults. We do not knowingly collect personal data from anyone under 16. If such data is uploaded in error, notify us and it will be deleted.
15. Breach notification
Confirmed security incidents affecting personal data are triaged, contained and investigated under a documented incident-response procedure. Affected organization administrators are notified without undue delay and in any event within 72 hours of confirmation, with the nature of the incident, the categories and approximate volume of data involved, the likely consequences and the remedial steps taken. Where an organization is the controller, it is responsible for notifying its own regulator and individuals, and we provide the information it needs to do so.
16. Changes and contact
Material changes to this policy are announced to organization administrators before they take effect, and the "last updated" date above always reflects the current version. Privacy enquiries: privacy@thotara.com. Security matters: security@thotara.com.

