Privacy policy for recruitment using Teamtailor
The service for handling recruitments and simplifying the hiring process (the "Service") is powered by Teamtailor on behalf of the Conscia Group ("Controller",“we”, “us” etc.). It is important that the persons using the Service ("Users”) feel safe with, and are informed about, how the User's personal data is handled in the recruitment process when applying for vacancies and employment. In the Conscia Group, we strive to maintain the highest possible standard regarding the protection of personal data. In this Privacy Policy, we describe how the User’s Personal Data is processed, managed, used, and protected during the recruitment process..
1. General
We are the controller in accordance with current privacy legislations. The Users’ personal data is processed with the purpose of managing and facilitating recruitment of employees to our business.
The Conscia entity you are submitting your application to is the controller (Controller) in accordance with current privacy legislations. Information on the relevant Conscia entity is available in the job posting, including contact details. Please also see https://conscia.com/about-us/our-locations/ for our contact details and legal information.
The Users’ personal data is processed with the purpose of managing and facilitating recruitment of employees to our business.
2. Collection of personal data
The Controller is responsible for the processing of the personal data that the Users contributes to the Service, or for the personal data that in other ways is collected with regards to the Service.
When and how personal data is collected
Personal data about Users from Users are collected when Users;
- make an application through the Service or otherwise, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn; and
- use the Service to connect with Conscia staff, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn.
- provides identifiable data in the chat (provided through the website that uses the Service) and such data is of relevance to the application procedure;
Personal data is collected from third parties, such as Facebook, LinkedIn and through other public available sources. This is referred to as “Sourcing” and be manually performed by Conscia employees or automatically in the Service.
In some cases, existing employees can make recommendations about potential applicants. Such employees will add personal data about such potential applicants. In the cases where this is made, the potential applicant is considered a User in the context of this Privacy Policy and will be informed about the processing.
The types of personal data collected and processed
The categories of personal data that can be collected through the Service can be used to identify natural persons from names, e-mails, pictures and videos, information from Facebook and LinkedIn-accounts, answers to questions asked through the recruiting, titles, education and other information that the User or others have provided through the Service. Only data that is relevant for the recruitment process is collected and processed.
Purpose and lawfulness of processing
The purpose of the collecting and processing of personal data is to manage recruiting. The lawfulness of the processing of personal data is our legitimate interest to simplify and facilitate recruitment, including to process the information you provide to us when applying for a vacancy in order for us to handling recruiting, cf. GDPR art. 6(1)(f).
Personal data that is processed with the purpose of aggregated analysis or market research is always made unidentifiable. Such personal data cannot be used to identify a certain User. Thus, such data is not considered personal data.
The consent of the data subject
The User consents to the processing of its personal data with the purpose of Controller’s handling recruiting. The User consents that personal data is collected through the Service, when Users;
- make an application through the Service, adding personal data about themselves either personally or by using a third-party source as Facebook or LinkedIn, and that Controller may use external sourcing-tools to add additional information; and
- when they use the Service to connect to Controller’s recruitment department, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn.
The User also consents to the Controller collecting publicly available information about the User for use in recruitment purposes.
The User consents to the personal data being collected in accordance with the above a) and b) will be processed according to the below sections Storage and transfer and How long the personal data will be processed.
The User has the right to withdraw his or her consent at any time, by lgging in to the service and withdraw consent or all data or by contacting Controller using the contact details listed under 8. Using this right may however, mean that the User can not apply for a specific job or otherwise use the Service.
Storage and data transfers to third countries
The personal data collected through the Service is stored and processed inside the EU/EEA, or inside such third country that is considered by the European Commission to have an adequate level of protection, cf. GDPR art. 45(3).
The personal data collected through the Service may also be stores and processed by such suppliers (data processors and sub-data processors) that have entered into such binding agreements that fully complies with the lawfulness of third country transfers (as the Commissions Standard Contractual Clauses) and where the adequate, appropriate and suitable safeguards are secured in order to protect the rights of the data subjects whose data is transferred. To obtain documentation regarding such safeguards, please contact us using the Contact details listed in 8.
How long the personal data will be processed
The personal data will be stored and processed by the Controller as long as it is deemed necessary with regards to the purposes stated above. The following principals for retention is applied:
- Applications for vacancies are deleted not later than six months after finalizing the recruitment process, unless there is a specific reason for processing the application for further periods of time. However, for candidate employed by the Controller, the application will be kept also as part of the personal folder. If an applicant (User) consents to the Controller, the application and supplemental personal data may also be processed for further periods of time for the purpose of future recruitments in accordance with the collected consent. If you as a User wish to have your Personal Data processed for this purpose (future recruitment) please tick the “Yes, Conscia can also contact me about future job opportunities” when submitting your application.
3. Users’ rights
Users have the right to request information about the personal data that is processed by the Controller, by notifying in writing, using the contact details below under paragraph 8. Users have the right to one (1) copy of the processed personal data which belongs to them without any charge. For further demanded copies, Controller has a right to charge a reasonable fee on the basis of the administrative costs for such demand.
Users have the right to, if necessary, rectification of inaccurate personal data concerning that User, via a written request, using the contact details in paragraph 8 below.
The User has the right to demand deletion or restriction of processing, and the right to object to processing based on legitimate interest under certain circumstances.
The User has the right to revoke any consent to processing that has been given by the User to Controller. Using this right may however, mean that the User can not apply for a specific job or otherwise use the Service.
The User has under certain circumstances a right to data portability, which means a right to get the personal data and transfer these to another controller as long as this does not negatively affect the rights and freedoms of others.
User has the right to lodge a complaint to the supervisory authority regarding the processing of personal data relating to him or her, if the User considers that the processing of personal data infringes the legal framework of privacy law.
4. Security
The Conscia Group prioritize the personal integrity and therefore works actively so that the personal data of the Users are processed with utmost care. The Controller thus takes the measures that can be reasonably expected to the make sure that the personal data of Users and others are processed safely and in accordance to this Privacy Policy and the GDPR-regulation.
However, transfers of information over the internet and mobile networks can never occur without any risk, so all transfers are made on the own risk of the person transferring the data. It is important that Users also take responsibility to ensure that their data is protected. It is the responsibility of the User that their login information is kept secret.
5. Transfer of personal data to third party
The Controller will not sell or otherwise transfer Users’ personal data to third parties.
The Users’ personal data may be transferred to;
- contractors and sub-contractors, acting as data processors and Sub-data processors in accordance with written instructions, for the provision of the Service;
- authorities or legal advisors in case criminal or improper behaviour is suspected; and
- authorities, legal advisors or other actors, if required according to law or authority’s injunction.
6. Aggregated data (non-identifiable personal data)
The Controller may share aggregated data to third parties. The aggregated data has in such instances been compiled from information that has been collected through the Service and can, for example, consist of statistics of internet traffic or the geological location for the use of the Service. The aggregated data does not contain any information that can be used to identify individual persons, including any Users and is thus not personal data.
7. Changes
The Controller has the right to, at any time, make changes or additions to the Privacy Policy. The latest version of the Privacy Policy will always be available through the Service. A new version is considered communicated to the Users when the User has either received an email informing the User of the new version (using the e-mail stated by the User in connection to the use of the Service) or when the User is otherwise informed of the new Privacy Policy.
8. Contact
For questions, further information about handling of personal data or for contact with us in other matters, please use the below stated contact details; Conscia dataprotectionteam@conscia.com specifying which Conscia entity your request concerns.