Gaia Trust Centre

Trust through Transparency

Gaia is built for forward-thinking organisations that expect accountability, integrity, and compliance. This Trust Centre outlines how we protect customer and candidate data, uphold regulatory standards, and ensure the responsible use of AI across our platform.

We are proud to be ISO/IEC 27001:2022 certified, and we operate a security, privacy, and governance programme designed to meet the expectations of enterprise, public sector, and international compliance teams.

Security

Gaia’s infrastructure and operations are protected by robust, independently audited controls.

  • ISO/IEC 27001:2022 certified Information Security Management System (ISMS)
  • Hosting on UK-based AWS (London Region)
  • Encryption in transit and at rest
  • Role-based access control (RBAC) and MFA for all privileged systems
  • Daily backups, disaster recovery plans, and environment separation
  • Penetration tests conducted annually
  • Real-time monitoring and alerting

📩 Request security documentation via trust@iamgaia.com

Compliance

Gaia is compliant with global and regional data protection standards, including:

  • UK GDPR and the Data Protection Act 2018
  • EU GDPR (where applicable)
  • CCPA (for California-based users)
  • UK public sector and local authority procurement standards

We maintain Article 30 records, conduct Data Protection Impact Assessments (DPIAs), and follow least-privilege access models across all services.

📄 View Privacy Policy
📄
View DPA

Responsible AI Use

Gaia uses AI in its advertising bidding, optimising campaign performance, retargeting, targeting, channel suggestions, content creation and engagement with our products. However:

  • We do not use AI to screen or reject candidates
  • All final outputs are human-reviewed before being published
  • No customer or candidate personal data is used to train AI models
  • Bias is proactively monitored and mitigated through platform-level auditing
  • Recommendations can be reviewed, overridden, or disabled by users

📄 View AI Compliance Statement

Subprocessors

We only use subprocessors who meet strict security and compliance standards. All data is hosted within the UK, and no personal data is transferred internationally.

Subprocessors support our infrastructure, platform delivery, and advertising execution. All contracts include:

  • Confidentiality and security obligations
  • Data processing restrictions under UK GDPR and/or SCCs where applicable
  • Ongoing due diligence and regular reviews

📄 View List of Current Subprocessors

Candidate Data

When candidates apply via GaiaPages or GaiaChat:

  • Gaia acts as a Data Processor
  • The employer is the Data Controller
  • Candidate data (e.g. name, CV, contact details) is securely stored in the UK
  • Data is retained for a maximum of 12 months unless otherwise agreed
  • No data is reused, sold, or made accessible to other clients

Candidates are required to accept Gaia’s Privacy Policy and Terms of Service before submitting any application.

📄
Review Terms of Service

Documentation Access

We offer on-request access to the following documentation:

  • ISO 27001 certificate
  • Penetration test summaries
  • Completed security questionnaires
  • Data Protection Impact Assessments
  • Security policies

To request documentation, please contact:
📩
trust@iamgaia.com

Contact

Socially Recruited Ltd (trading as Gaia)
Company Number: 10942594
Registered Address: 2 Eastbourne Terrace, London, W2 6LG
Email:
trust@iamgaia.com