Policy

Privacy Policy

Thotara is a business-to-business recruiting platform that stores professional information about clinicians, facility contacts and recruiting staff. This policy explains what personal data is processed, on what basis, who it is shared with, how long it is kept, and how individuals exercise their rights.

Last updated 21 August 2026

1. Scope and roles

This policy applies to personal data processed in the Thotara platform, on our public website and in support interactions. It does not apply to a customer organization's own systems, or to third-party services an organization connects using its own credentials.

Controller and processor

Each staffing organization using Thotara is the controller (or "business") of the records in its workspace: it decides which providers and clients are entered, what is collected and how it is used. Thotara operates as the processor ("service provider") and acts on that organization's documented instructions. Thotara is the controller only for its own account, billing and platform-security data about administrators and staff users.

Requests to access, correct or delete a record should be directed to the organization holding it; where a request reaches us first, we route it to that organization and assist with fulfilment.

2. Data we process

CategoryExamplesNotes
Provider (clinician) dataRecruiting and credentialing fileName, date of birth where required for credentialing, contact details, NPI, DEA, state licences, board certifications, CV and work history, education, references, malpractice and NPDB self-query documentation, immunisation and health attestations, rate expectations, availability, travel preferences.Includes professional-conduct and malpractice history; treated as sensitive.
Payment and tax dataPayment set-up onlyDirect-deposit authorisation, bank routing and account numbers, taxpayer identification number, business-entity details for entity billing.Stored encrypted; displayed to staff only in masked form, with every reveal logged.
Client and facility dataCommercial relationshipFacility profile, contact names, business email and phone, job orders, presented candidates, agreements, timesheets, invoices and payment status.Business-contact data; no consumer profiling.
Staff user dataWorkspace administrationName, work email and phone, role and permission assignments, authentication and two-step verification factors, and recorded work activity such as calls, texts, emails, notes, record edits and productivity metrics.Activity data is visible to that organization's managers and administrators.
Technical and log dataSecurity and reliabilitySign-in events, IP address and user agent captured by the authentication provider, audit-log entries, error diagnostics, webhook and message delivery receipts.Used for security monitoring, not for advertising.

Thotara is not a clinical system. It is not intended to hold patient medical records or protected health information, and customers are contractually prohibited from uploading them. Provider health attestations and immunisation records are credentialing artefacts about the clinician, not about any patient.

3. Sources of data

  • Directly from the individual — intake forms, portal profile edits, uploaded documents, direct-deposit submissions and e-signatures.
  • From the customer organization — records entered by recruiters, bulk imports from a prior CRM, and files received by email.
  • From public and professional sources — the NPI registry, state licensing boards, certification bodies and public professional profiles.
  • From optional connectors an organization enables — sourcing providers, telephony and email systems.
  • Generated by the platform — audit entries, activity metrics, AI suggestions and derived matching scores.

4. Purposes and legal bases

PurposeLegal basis (UK/EU GDPR terms)
Operating the recruiting workflow: sourcing, matching, presenting candidates, placements and schedulingLegitimate interests of the organization and the clinician's own interest in employment; contract performance once engaged
Credentialing and verification of licences, certifications and professional historyLegal obligation and legitimate interests (patient-safety and client contractual requirements); substantial public interest for professional-conduct data
Payment set-up, invoicing and tax reportingContract performance and legal obligation
Platform security, fraud prevention, audit logging and incident investigationLegitimate interests and legal obligation
Service communications, support and portal notificationsContract performance and legitimate interests
Recruiting outreach by SMS or email through a connected providerConsent where required by TCPA/CAN-SPAM or local marketing rules; obtained and evidenced by the organization
Aggregate, de-identified product analytics and reliability metricsLegitimate interests; no re-identification and no cross-customer profiling

We do not sell personal data, do not share it for cross-context behavioural advertising, and do not use customer data to train third-party foundation models.

5. Public-source enrichment and AI

To reduce manual data entry, Thotara looks up publicly available professional information — for example the NPI registry, licence boards and public professional profiles — and proposes field values. AI is also used to extract data from CVs and credentialing documents, to draft letters, agreements and job summaries, and to score candidate-to-job fit.

  • Every AI or enrichment output is a suggestion. It carries its source, is queued for review, and is never written to a record until a person accepts it.
  • No automated decision with legal or similarly significant effect is made about an individual: matching scores rank options for a recruiter, they do not hire, reject or price anyone.
  • Model prompts are limited to the fields needed for the requested task, are not retained by the model provider for training, and are logged with the requesting user for accountability.
  • Individuals may ask the controlling organization to correct any enriched field, and corrections override the suggested value permanently.

6. Who can access data

  • Access is scoped to a single organization at the database layer through row-level security; one customer's workspace is never visible to another.
  • Within an organization, role and permission checks decide which surfaces and fields a user can open; sensitive surfaces such as banking, audit and access review are restricted to administrators or a finance role.
  • Providers signing in to the provider portal see only their own profile, assignments, letters, agreements, travel and timesheets.
  • Facility contacts see only their own client's jobs, presented candidates, timesheets, invoices and agreements.
  • Thotara personnel do not access customer records in the ordinary course. Access for support or incident response is limited to named staff, requires a business justification, and is time-bound and logged.
  • Disclosure to law enforcement or a regulator is made only where legally compelled; where the law permits, we notify the affected organization first.

7. Sub-processors

Sub-processor categoryPurposeProcessing region
Managed cloud database, authentication and object storageHosting of application data, user accounts, sessions and uploaded documentsUnited States
AI gateway (large language and document models)Document extraction, drafting of letters, agreements and job summaries, and field suggestions; prompts carry only the data needed for the task and are not used to train third-party modelsUnited States
Transactional email providerAuthentication emails, notifications and, where the organization configures its own domain, outbound recruiting emailUnited States / organization-selected
Telephony and SMS provider (optional, organization-supplied)Staff calling and texting, call/message metadata and recordings where the organization enables themOrganization-selected
Sourcing and contact-enrichment providers (optional, organization-supplied)Look-up of publicly available professional contact informationOrganization-selected

Each sub-processor is bound by written terms that impose confidentiality, security and data-protection obligations no less protective than this policy. Optional connectors are engaged by the organization under its own agreement with that vendor. We maintain a current sub-processor register and notify organization administrators of a material change or a new sub-processor before it begins processing, giving them an opportunity to object.

8. International transfers

Application data is hosted in the United States. Where personal data is transferred from the UK, EEA or Switzerland, the transfer relies on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, supported by a transfer risk assessment and the technical measures described below — encryption in transit and at rest, tenant isolation and access logging. Copies of the transfer terms are available to customers on request.

9. Retention and deletion

DataRetention period
Active workspace recordsProviders, clients, jobs, placements, documents.Life of subscription
Audit logAccess, role, settings, credentialing and export events.24 months
In-app notificationsRead and unread alerts.12 months
Webhook and message delivery eventsDelivery receipts and payload metadata.6 months
Signed letters and agreementsImmutable executed records.Life of subscription
Deleted records and documentsThen permanently purged.30 days
Closed workspaceExport window, then permanent deletion.30 days

Retention is enforced by a nightly scheduled purge rather than manual clean-up, and each run records what it deleted. Backups roll off on their own schedule within 35 days, so a deleted record may persist in an encrypted backup until that window closes. Where a record is subject to a legal hold, tax obligation or an unresolved dispute, it is retained until that obligation ends.

10. Security measures

Measures include encryption in transit and at rest, organization-scoped row-level security, least-privilege roles, mandatory two-step verification (authenticator app for staff, emailed one-time code for portal users), breached-password screening, a 30-minute idle session timeout, private document storage with short-lived signed links, server-side-only secrets, immutable audit logging and constant-time verification of webhook and scheduled-job credentials. The security page documents the control set in full.

11. Individual rights

  • Access — obtain a copy of the personal data held about you.
  • Rectification — correct inaccurate or incomplete data; portal users can edit much of their own profile directly.
  • Erasure — ask for deletion where there is no overriding legal, contractual or credentialing obligation to retain.
  • Restriction and objection — ask that processing based on legitimate interests be paused or stopped.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — for SMS or marketing outreach, at any time, including by replying STOP or using the unsubscribe link.
  • Complain — to your local supervisory authority; in the UK, the Information Commissioner's Office.

Send requests to privacy@thotara.com. We acknowledge within five business days and respond within 30 days (extendable once by a further 60 days for complex requests, with notice). We verify identity before disclosing data, and requests about a customer's records are routed to that organization as controller. There is no charge unless a request is manifestly excessive or repetitive.

12. US state privacy rights

Residents of California, Colorado, Connecticut, Virginia, Texas and other states with comprehensive privacy laws have rights to know, access, correct, delete, obtain a portable copy, and to opt out of sale, targeted advertising and profiling with legally significant effects. Thotara does not sell personal information, does not process it for targeted advertising, and does not conduct such profiling, so there is nothing to opt out of. We do not discriminate against anyone for exercising a right, and an authorised agent may submit a request with written proof of authority. Where Thotara acts as a service provider, the request is fulfilled by the controlling organization.

13. Children's data

The platform is intended for professional use by adults. We do not knowingly collect personal data from anyone under 16. If such data is uploaded in error, notify us and it will be deleted.

14. Cookies and tracking

Thotara sets only cookies and local-storage entries that are strictly necessary to run the service: session and authentication tokens, two-step verification state, the active organization selection, idle-timeout coordination between tabs and interface preferences. There are no advertising cookies, no third-party trackers and no cross-site profiling, so no consent banner is required. Clearing site data signs you out.

15. Breach notification

Confirmed security incidents affecting personal data are triaged, contained and investigated under a documented incident-response procedure. Affected organization administrators are notified without undue delay and in any event within 72 hours of confirmation, with the nature of the incident, the categories and approximate volume of data involved, the likely consequences and the remedial steps taken. Where an organization is the controller, it is responsible for notifying its own regulator and individuals, and we provide the information it needs to do so.

16. Changes and contact

Material changes to this policy are announced to organization administrators before they take effect, and the "last updated" date above always reflects the current version. Privacy enquiries: privacy@thotara.com. Security matters: security@thotara.com.