Privacy Policy — JustApply Apprenticeship Service Importer

Last updated: 27/07/2026

This policy explains what the JustApply Apprenticeship Service Importer browser extension (“the Extension”) does with data, in plain terms, so you can make an informed decision before installing it and so it can be published to the Chrome Web Store.

This is a first draft based on exactly what the code does today. It has not been reviewed by a solicitor. Please get it checked before publishing it as your live privacy policy — in particular the data protection / GDPR framing, since the Extension handles job applicants’ personal data (including special category data) on behalf of whoever installs it.

1. Who this policy is for

The Extension is installed by a recruiter or employer (“you”, “the user”) to speed up importing candidate applications from the Apprenticeship Service (`recruit.manage-apprenticeships.service.gov.uk`) into your organisation’s own Microsoft Dataverse environment. It also, necessarily, processes personal data about the job applicants (“candidates”) whose applications you import. This policy covers both.

2. What the Extension does

The Extension only runs on two Apprenticeship Service pages you open yourself:

– an individual application review page, and

– the “Manage Advert” page listing applications for a vacancy.

On those pages it reads the visible page content and, only when you click one of its “Process…” / “Import to JustApply” buttons, sends the extracted data to a URL you configure yourself (see §5). It does not run on, or read, any other website.

3. Data collected about candidates

When you import an application, the Extension reads and transmits the following from the application page:

Contact details: candidate name, email address, phone number, home address / personal details, preferred work location(s)

Application identifiers: the Apprenticeship Service Application ID, application and vacancy reference numbers, the source page URL, page title, and the time of import

Qualifications: subjects, grades, and training courses, as listed on the application

Work history: previous employers, job titles, responsibilities, and dates, as listed on the application

Application answers: the candidate’s answers to “What are your skills and strengths?”, “What interests you about this apprenticeship?”, and any other custom questions the employer set on the vacancy

Interview support and Disability Confident responses — please note these two fields can reveal that a candidate has a disability or health condition, which is a special category of personal data under UK GDPR requiring extra care

A full raw-text copy of the application page, kept as a fallback/audit record alongside the structured fields above

The Extension does not collect anything about candidates beyond what already appears on the application page you’re viewing.

4. Data collected about you (the Extension’s user)

The Extension stores the following locally in your own browser (via Chrome’s `storage` permission) — this never leaves your device except as described in §5:

– The Power Automate endpoint URL you enter on the Options page

– Temporary state while a bulk import is running (which applications are queued, how far through the batch it’s got) — this is deleted automatically once the batch finishes

– The advert reference captured from the “Manage Advert” page, used to link an application back to its vacancy

The Extension does not collect analytics, does not use cookies or trackers, and does not communicate with any server operated by the Extension’s developer — there isn’t one.

5. Where the data goes

Each time you import an application, the Extension sends the data described in §3 in a single HTTPS request to the Power Automate URL you configured in §4. That URL is one you or your organisation created and control — it routes into a Microsoft Power Automate flow, which writes the data into your own organisation’s Microsoft Dataverse environment. The Extension’s developer has no server, receives no copy of this data, and cannot access your Dataverse environment.

6. Permissions the Extension requests, and why

| `storage` | To save your Options-page settings and short-lived import progress on your own device |

| `activeTab` | To read the Apprenticeship Service page you’re currently viewing when you use the Extension |

| Access to `recruit.manage-apprenticeships.service.gov.uk` | To read application data from the pages listed in §2 |

| Access to `*.logic.azure.com` | To send data to the Power Automate endpoint you configure — this is Microsoft’s own domain for Power Automate flow triggers |

7. Data retention

The Extension itself does not retain candidate data at all — it reads a page, sends the data, and keeps no local copy once a batch import finishes. Retention of the data in your Dataverse environment is governed by your own organisation’s data retention policy, not by this Extension.

8. Your responsibilities as the Extension’s user

If you install and use the Extension, you (or your organisation) are the data controller for the candidate personal data it imports on your behalf — you decide what data is collected and why, and you are responsible for having a lawful basis to process it, for candidates’ rights requests, and for keeping your Dataverse environment secure. The Extension is a tool that helps you do that; it is not itself a data controller or processor for your organisation’s data.

9. Changes to this policy

If what the Extension collects or where it sends data changes, this page will be updated and the “Last updated” date at the top will change accordingly.

10. Contact

Questions about this policy or how your organisation uses the Extension: support@focusonbusiness.co.uk