Skip to main content

Privacy Notice for European Recruits, Applicants, and Employees

Last updated: September 17th, 2026

This Privacy Notice explains how Client-Side Development, Inc. (“cside”, “we”, “us”, or “our”) collects, uses, and protects personal data relating to individuals located in the European Economic Area (“EEA”), the United Kingdom, and Switzerland who apply for, are recruited by, or are employed or engaged by us.

This notice covers recruitment and employment. Our website Privacy Policy has a separate scope and does not cover the processing described here.

1. Data Controller

Client-Side Development, Inc. is the data controller for the personal data described in this notice. Contact: privacy@cside.com

Representatives. We have appointed a representative under Article 27 of the GDPR and Article 27 of the UK GDPR. Our representative in the EEA is Instant EU GDPR Representative Ltd (contact: Adam Brogden), Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland, and can be reached at contact@gdprlocal.com. Our representative in the UK is GDPRLocal Ltd. (contact: Adam Brogden), 1st Floor Front Suite, 27-29 North Street, Brighton, England BN1 1EB, and can be reached at contact@gdprlocal.com. You may contact either representative on all issues relating to our processing of your personal data and to exercise your data protection rights.

These appointments cover the EEA and the UK. They do not appoint a representative in Switzerland or a Data Protection Officer. Individuals in Switzerland may contact us at privacy@cside.com about the processing described in this notice and their rights under applicable Swiss law.

2. Personal Data We Collect

Depending on your relationship with us, we may collect:

  • Identification and contact details (e.g., name, address, email, phone)
  • Recruitment information (e.g., CV, work history, education, references)
  • Employment information (e.g., job title, compensation, benefits, performance)
  • Payroll and tax information
  • IT and security data (e.g., system access logs)
  • Compliance data (e.g., right-to-work documentation)
  • Applicant verification data (e.g., the email address you enter to confirm an application, applicant and application identifiers, submission time, IP address, browser and device information, country and network information, and the device and network risk indicators derived from them)

Applicant verification. When you confirm an application, our verification tools generate device and network risk indicators and may record them against your application in our recruitment system. A risk indicator is not proof of your identity and is not a finding of wrongdoing, and confirming an email address does not by itself verify that you control that account. If a result affects you, you may contact us at privacy@cside.com to question it, to correct inaccurate information, and to exercise any applicable rights in relation to decisions based solely on automated processing, including obtaining human intervention and contesting the decision.

We process personal data for the following purposes:

  • Recruitment and hiring (GDPR Art. 6(1)(b), (f))
  • Employment administration and workforce management (Art. 6(1)(b))
  • Payroll, benefits, and tax compliance (Art. 6(1)(c))
  • Security, IT, and fraud prevention (Art. 6(1)(f))
  • Legal and regulatory compliance (Art. 6(1)(c))

Where required, we rely on your explicit consent (Art. 6(1)(a)), which may be withdrawn at any time.

4. Data Sharing

We may share personal data with:

  • Service providers (e.g., payroll, benefits, IT, and recruitment platforms, including Ashby, which hosts our recruitment records)
  • Professional advisors and authorities where legally required

All recipients are subject to appropriate confidentiality and data protection obligations.

5. International Transfers

If personal data is transferred outside the EEA/UK/Switzerland, we provide appropriate safeguards through EU Standard Contractual Clauses.

6. Data Retention

We retain personal data only for as long as necessary for the purposes described above, including to meet legal, accounting, or reporting requirements.

7. Your Rights

Subject to applicable law, you have the right to:

  • Access, rectify, or erase your personal data
  • Restrict or object to processing
  • Data portability
  • Withdraw consent (where processing is based on consent)
  • Lodge a complaint with a supervisory authority

Requests may be submitted to privacy@cside.com or to the relevant EEA or UK representative named above. You do not have to use a particular form. You may also lodge a complaint with your local supervisory authority, including the UK Information Commissioner or, in Switzerland, the Federal Data Protection and Information Commissioner.

8. Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse.

9. Updates to This Notice

We may update this document from time to time. The latest version will always be available on our website.

Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

Book a personalized demo to see:

How to achieve PCI DSS requirement 6.4.3 & 11.6.1 compliance in 1 day
Why third-party scripts are a security risk for you and your visitors
Monitoring privacy and consent leakage (GDPR, CCPA) across every third party
Stopping signup abuse, account sharing, and chargeback fraud with device intelligence
Detecting and controlling AI agents and bots hitting your site in real time

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead