PASS

Privacy Policy

Version 2.0 · Effective 1 July 2026

This policy explains what personal data we collect about you, why we collect it, how we use and share it, how long we keep it, and the rights you have. It applies to the PASS mobile apps, the PASS website at pass.kitchen, and the PASS desktop application (together, the Service).

1. Who we are

Oventro Technologies Ltd (trading as PASS) is the data controller for personal data processed through the Service, except where we act as a processor on behalf of a hiring venue (see section 8). You can reach our privacy team at hi@pass.kitchen or by post at the address at the end of this policy.

Where a hiring venue uses PASS to source, assess, contact or retain records about candidates, that venue is an independent controller of the personal data it collects, views or exports through the Service, and its own privacy notice will apply to those activities.

Where we operate

PASS is available worldwide. People sign up from many countries, including the United Kingdom, the European Economic Area (EEA), the United States and elsewhere. Oventro Technologies Ltd is established in the United Kingdom and is the controller of your personal data. In this policy, GDPR means the UK GDPR (the retained EU General Data Protection Regulation as it forms part of the law of England and Wales, together with the Data Protection Act 2018) and, because we offer the Service to people in the EEA, the EU GDPR (Regulation (EU) 2016/679), which applies to that processing under its Article 3(2). Your own country's data-protection law may also apply to you, and nothing in this policy takes away rights you have under the mandatory law of the country where you live.

Our EU representative (Article 27)

Because we offer the Service to people in the EEA but are not established there, we are appointing a representative in the European Union under Article 27 of the EU GDPR. Until that appointment is finalised, you can raise any EU data-protection matter with our privacy team at hi@pass.kitchen, marked for the attention of our EU representative, and we will publish the representative's name and contact details here once appointed. EU representative: to be appointed.

Our privacy contact and Data Protection Officer

We have not appointed a statutory Data Protection Officer (DPO). Responsibility for data protection sits with our privacy team, which is accountable for how PASS handles personal data and is your first point of contact for any privacy question, request or complaint. Reach the privacy team at hi@pass.kitchen. We keep the need for a DPO under review as the Service grows and will appoint one if the law requires it.

2. The data we collect

We collect the following categories of personal data, depending on how you use the Service:

Special category data

Some information you choose to provide — for example, documents that reveal your nationality or ethnic origin as part of a right-to-work check — is special category data under the UK GDPR. We process it only where you have given explicit consent, or where processing is necessary for the purposes of carrying out obligations in the field of employment law, and we apply additional safeguards. You are never required to upload special category data to use the core Service.

3. How we collect it

We collect data directly from you when you create an account, build your profile, or contact us; from other users (for example, a head chef who verifies your role, or a venue that rates a trial); automatically from your device when you use the Service; and from our service providers (for example, fraud-prevention and payment partners).

4. Why we use it, and our lawful bases

Under the UK GDPR we must have a lawful basis for each use of your personal data. Our uses and bases are:

PurposeLawful basis
Creating and running your account, and providing the core ServicePerformance of a contract with you
Verifying identity and work history, and maintaining a trusted networkLegitimate interests (trust, safety and integrity of the network); employment-law obligations where right-to-work data is involved
Matching chefs to hiring venues, including AI-assisted matching and scoringPerformance of a contract; legitimate interests in operating an effective marketplace
Processing payments and managing venue subscriptionsPerformance of a contract; compliance with tax and accounting law
Keeping the Service secure and preventing fraud, abuse and impersonationLegitimate interests; legal obligation
Sending service messages you need to receivePerformance of a contract
Sending marketing and product updatesConsent (which you may withdraw at any time)
Handling right-to-work and special category dataExplicit consent, and/or employment-law obligations under Article 9(2)(b)
Complying with law, responding to lawful requests, and defending legal claimsLegal obligation; legitimate interests

Where we rely on legitimate interests, we have carried out a balancing assessment to ensure our interests do not override your rights. You may ask us for details of that assessment.

5. Automated matching and profiling

PASS uses automated systems, including machine-learning models ("PASS AI"), to generate match scores and to rank chefs against a venue's stated needs based on verified work history, vouches, skills, availability and cook-off performance. This is profiling as defined by the UK GDPR.

These systems assist human decision-making; they do not, by themselves, produce legal or similarly significant effects on you without human involvement. A venue's decision to contact, trial or hire you is always made by a person at that venue. If a decision that significantly affects you were ever made solely by automated means, you would have the right to obtain human intervention, to express your point of view, and to contest the decision. You can ask us how a score was produced by emailing hi@pass.kitchen.

6. Who can see your data on the Service

PASS is a network, so some data is shared by design. You control much of what is visible:

7. Sharing with third parties

We do not sell your personal data. We share it only with:

8. When a venue is the controller

When a hiring venue uses PASS to build a candidate shortlist, record trial outcomes, or export data for its own hiring records, the venue determines how it uses that data and is an independent controller. We act as the venue's processor for those specific activities under a data-processing agreement. Questions about a venue's use of your data should be directed to that venue.

9. International transfers

PASS is available worldwide, and our service providers — including our AI, payment, hosting, error-monitoring and identity partners — are based in several countries, including the United States. Your personal data may therefore be transferred to and processed in countries outside the one you live in, including outside the UK and the EEA. Where we transfer personal data out of the UK, we protect it with a safeguard recognised under the UK GDPR — a UK adequacy regulation (such as the UK Extension to the EU–US Data Privacy Framework, the "UK–US Data Bridge"), the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. Where we transfer personal data out of the EEA, we rely on an EU adequacy decision or the EU Standard Contractual Clauses. In each case the transfer is supported by a transfer risk assessment where required. You may request a copy of the relevant safeguard.

10. How long we keep it

We keep personal data only as long as necessary for the purposes above:

11. Your rights

Subject to conditions in the law, you have the right to:

To exercise any right, email hi@pass.kitchen or use the in-app tools. We will respond within one month. There is normally no charge.

12. Complaints

We would like the chance to resolve any concern first, so please contact us. If you are in the UK, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113. If you are in the EEA, you have the right to lodge a complaint with the data-protection supervisory authority in your country (you can find yours through the European Data Protection Board at edpb.europa.eu), and you may also contact our EU representative (see section 1). If you are in the United States, you may raise a concern with your state Attorney General. Wherever you live, you may be able to complain to your local data-protection regulator.

13. Security

We use technical and organisational measures appropriate to the risk — including encryption in transit, access controls, least-privilege staff access, logging and regular review. No system is perfectly secure, but we take our responsibility for your data seriously and will notify you and the relevant regulator of a personal-data breach where the law requires.

14. Children

PASS is not for anyone under 18. We do not knowingly collect data from children. If you believe a minor has an account, tell us and we will remove it.

15. Changes to this policy

We may update this policy from time to time. If we make a material change we will notify you in the app or by email before it takes effect. The "Effective" date above shows the current version.

16. Our sub-processors

We use a small set of trusted providers to run the Service, each acting on our instructions under a written contract. They include: Railway (application hosting), Cloudflare R2 (media storage), Resend (transactional email), Stripe (venue payments and billing), Sightengine (content moderation), Anthropic and OpenAI (AI matching and assistant features), Google (address and place look-ups, and "Sign in with Google"), Apple ("Sign in with Apple"), CARTO and OpenStreetMap (map tiles), Sentry (crash and error monitoring), and, where enabled, Twilio (SMS verification). None of them use your data for their own purposes, and none are advertising networks. We do not sell your personal data.

17. Your US state privacy rights

If you are a resident of the United States, your state may give you rights over the personal information ("PI") we hold about you. Two points apply to everyone in the US: PASS does not sell your personal information, and PASS does not "share" your personal information for cross-context behavioural (targeted) advertising, as those terms are defined under US state privacy laws. We do not serve targeted advertising and we do not use advertising or cross-site tracking cookies. We also do not discriminate or retaliate against you for exercising any privacy right.

California (CCPA / CPRA)

If you are a California resident, you have the right to: know what personal information we collect and how we use and disclose it; access a copy of it; delete it; correct inaccurate information; opt out of any "sale" or "sharing" (we do neither); and limit the use of sensitive personal information. The categories we collect are described in section 2 above; we collect them for the business purposes in section 4 and disclose them only to the service providers in section 16. Right-to-work, immigration and similar documents can be sensitive personal information under the CPRA — we use these only to provide the Service you ask for and never to infer characteristics about you. To exercise a right, email hi@pass.kitchen; we will verify your identity before responding, and you may use an authorised agent.

Other US states

If you live in another US state with a comprehensive privacy law (for example Virginia, Colorado, Connecticut, Texas, Oregon, Montana or others as they take effect), you have comparable rights to confirm, access, correct, delete and obtain a portable copy of your personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Because we do not sell data, serve targeted advertising, or carry out profiling that produces legal or similarly significant effects without human involvement (see section 5), there is generally nothing to opt out of — but you can still exercise your access, correction and deletion rights at hi@pass.kitchen, and you may appeal a decision by replying to our response.

Do Not Track & Global Privacy Control

Most web browsers offer a "Do Not Track" (DNT) setting. There is no common industry standard for how to respond to DNT, so we do not respond to DNT signals — but our practices already reflect that preference, because we do not track you across sites or sell your data. Where a recognised opt-out preference signal such as the Global Privacy Control (GPC) applies to you, we will treat it as a valid request to opt out of any "sale" or "sharing" of your personal information (again, we do neither).