Privacy Policy
How Distributed collects, uses and protects your personal data.
Introduction
Distributed is the data controller of your personal data. Our legal name is DSTBTD Limited (trading as “Distributed”) and we are a company registered in England and Wales (company number 10552489).
This privacy policy applies to personal data we process under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 (DUAA).
It explains how we look after your personal data when you visit our website at www.distributed.com (the Site) or contact us in any other way. The Site is not intended for children and we do not knowingly collect data relating to children.
Contact details
If you have any questions about this privacy policy or how we handle your personal data, please contact us at privacy@distributed.com. Our Head of Operations is responsible for data protection at Distributed.
How to make a complaint
Under the Data Protection Act 2018 (as amended by the DUAA), you can make a complaint directly to us if you believe we have handled your personal data in a way that breaches the UK GDPR.
You can make a complaint by emailing us at privacy@distributed.com. Our Head of Operations handles complaints. If you are not satisfied with our response, you can ask for it to be reviewed by our Chief Executive Officer.
If you make a complaint, we will acknowledge it within 30 days, investigate it without undue delay, keep you informed, and tell you the outcome. We may ask you to confirm your identity, and where someone complains on your behalf we may ask for evidence of their authority to act.
Making a complaint to us does not affect your right to complain to the Information Commissioner’s Office (ICO) at www.ico.org.uk at any time. We would appreciate the chance to resolve your concerns first.
Changes to this policy
We keep this privacy policy under review. This version was last updated on 23 September 2026. We will keep a record of previous versions.
It is important that the personal data we hold about you is accurate. Please let us know if it changes.
The data we collect about you
Personal data means any information from which you can be identified. We collect:
Contact data: your name, email address, company, and the details you send us through our contact form or by email.
Specialist and applicant data: if you apply to join our community or are matched to work, the skills, experience and background you share with us, and professional information that is publicly available, such as your LinkedIn profile. If you are engaged to work with us, we may also collect your identity documents, date of birth, nationality, contact and company details, payment details and an emergency contact.
Technical data: your IP address, browser and device information, and how you use the Site.
Marketing data: your marketing and communication preferences.
If a client engages you through us, we carry out a background check through our screening provider, which includes a right to work check and a basic criminal record (DBS) check. We only run it once a client has committed to engage you, we keep the result secure, and we keep it only as long as we need it.
We do not otherwise collect special category data (such as data about your health, ethnicity or religion), unless you choose to share it with us, for example to ask for an adjustment to an interview.
Where we get your data
Most of the data we hold comes from you. We may also find you through professional networks such as LinkedIn. When we first contact you, we can tell you how we got your details, and you can ask us to stop using them at any time.
How we use your personal data
We only use your personal data where the law allows. In practice we rely on: performing a contract with you, or taking steps to enter into one; our legitimate interests, such as responding to your enquiry, managing our client and specialist relationships, and keeping the Site secure, where these do not override your rights; and complying with our legal obligations.
We use your personal data to respond to your enquiries, assess applications from specialists who want to join our community, propose specialists to our clients, check identity and right to work, carry out the background checks our clients require, pay specialists for their work, manage our relationships with clients, specialists and suppliers, and operate and secure the Site. Where we send you marketing, we do so in accordance with your preferences and applicable law, and you can ask us to stop at any time.
We process criminal record data only where the law allows, to meet our clients' security requirements, and we have a policy that explains how we protect it.
Sharing your personal data
We do not sell your personal data. We share it only with: clients, when we propose you for a role or you work on their engagement; service providers who process it on our behalf, such as our IT, hosting, screening and payment providers; other companies in our group where needed to run our business; our professional advisers; any successor to our business; and where the law requires. Anyone processing personal data for us must keep it secure and use it only on our instructions.
Automated decision-making
We do not make decisions that have a legal or similarly significant effect on you based solely on automated processing. If this changes, we will update this policy and put in place the safeguards required by the UK GDPR.
International transfers
Where we transfer personal data outside the UK, we only do so where the transfer is permitted under UK data protection law, for example where the destination country has UK adequacy status, or we have put appropriate safeguards in place such as the UK International Data Transfer Agreement. Please contact us if you would like more information about the safeguards we use.
Data security
We have appropriate security measures in place to protect your personal data, and we limit access to those who need it. We have procedures to deal with any suspected data breach, and will notify you and the ICO where we are legally required to do so.
Data retention
We keep your personal data only for as long as we need it for the purposes described above, including to meet legal, accounting or reporting requirements. When we no longer need it, we delete or anonymise it.
Your rights
Under UK data protection law you have rights over your personal data: to access it, to have it corrected or erased, to restrict or object to how we use it, and to ask us to transfer it to another provider. These rights apply in certain circumstances and some have conditions or exceptions.
To exercise any of these rights, or to withdraw any consent you have given, contact us at privacy@distributed.com. We may ask you to confirm your identity, and if we need more information to deal with your request the one-month response period may pause until we receive it. We will respond within one month, and will let you know if a complex request needs longer.
You can also complain to us, or to the ICO, at any time (see How to make a complaint above).
Cookies
Cookies are small files placed on your device when you visit a website. We use cookies that are strictly necessary for the Site to work, and, where you agree, analytics cookies that help us understand how the Site is used.
When you first visit the Site, our cookie banner lets you accept or reject non-essential cookies. We only set non-essential cookies after you have given consent. You can see and change your choices at any time using the cookie settings link on the Site, or through your browser settings.