Privacy notice for recruitment using Teamtailor
The service for handling recruitments and simplifying the hiring process (the “Service”) is powered by Teamtailor on behalf of Platform24 (“Controller” “we” “us” etc.). It is important that the persons using the Service (“Users”) feel safe with, and are informed about, how we handle User’s personal data in the recruitment process. We strive to maintain the highest possible standard regarding the protection of personal data. We process, manage, use, and protect User’s Personal Data in accordance with this Privacy Notice (“Privacy Notice”).
1. General
We are the controller in accordance with current privacy / data protection legislations. The Users’ personal data is processed with the purpose of managing and facilitating recruitment of employees to our business.
2. Collection of personal data
We are responsible for the processing of the personal data that the Users contributes to the Service, or for the personal data that we in other ways collect with regards to the Service.
When and how we collect personal data
We collect personal data about Users from Users when Users:
- make an application through the Service or otherwise, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn; and
- use the Service to connect with our staff, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn.
- provides identifiable data in the chat (provided through the website that uses the Service) and such data is of relevance to the application procedure.
We collect data from third parties, such as Facebook, LinkedIn and through other public sources. This is referred to as “Sourcing” and be manually performed by our employees or automatically in the Service.
We may also use other sources to collect applications, such as recruitment agencies with which we collaborate.
In some cases, existing employees can make recommendations about potential applicants. Such employees will add personal data about such potential applicants. In the cases where this is made, the potential applicant is considered a User in the context of this Privacy Notice and will be informed about the processing.
If you are selected for the next stage of the recruitment process, you will be invited to interviews/tests with us. In this case, we will process personal data that you will disclose during the discussions. Such interviews will be completed by drafting interview minutes which we need to document the discussions in order to make the selection.
The types of personal data collected and processed
The categories of personal data that can be collected through the Service can be used to identify natural persons from names, e-mails, phone number, residence address, pictures and videos, information from Facebook and LinkedIn-accounts, answers to questions asked through the recruiting, titles, education, previous employers, professional experience, professional qualifications, references, certifications, known foreign languages, hobbies and other information that the User or others (such as recruitment agencies) have provided through the Service. Only data that is relevant for the recruitment process is collected and processed.
Purpose and lawfulness of processing
The purpose of the collecting and processing of personal data is to manage recruiting.
The lawfulness of the processing of personal data is (i) our legitimate interest to simplify and facilitate recruitment as well as (ii) taking steps at your request to conclude a contract (individual employment contract).
Personal data that is processed with the purpose of aggregated analysis or market research is always made unidentifiable. Such personal data cannot be used to identify a certain User. Thus, such data is not considered personal data.
Personal data resulted from background checks
Sometimes in the recruitment process, for certain positions that imply accessing and working with sensitive and highly confidential data (i.e. health data concerning the users of Platform24’s healthcare app) we (Platform24, or collaborating contractors that provide background checks services) perform background checks aimed at getting to know the candidate and his/her compatibility with the specific duties of the open position. If background checks are carried out by contractors that provide background checks services, the results of these checks are communicated to us together with other relevant information about you, if you are on the short list of candidates for the vacancy in our organisation.
Components of background checks may vary based on the country of employment and the position/role, in line with country internal legislation, and may include the following:
- News-media;
- CV-analysis;
- Education;
- Professional Experience 5 years;
- Internet Exposure;
- Social media;
- ID-verification;
- Address verification;
- Criminal records check (except for positions where the country of employment is Romania).
We process this personal data on the basis of our legitimate interest in assessing your compatibility with the specific duties of the position for which you are applying and in ensuring a high level of security of the health data concerning the users of Platform24’s healthcare app. Please note that this information may be kept after the recruitment procedure has been completed in order to keep you in our records for future opportunities (see section “How long the personal data will be processed” below).
The consent of the data subject
The User consents to the processing of its personal data with the purpose of Controller’s handling recruiting. The User consents that personal data is collected through the Service, when Users:
- make an application through the Service, adding personal data about themselves either personally or by using a third-party source as Facebook or LinkedIn, and that Controller may use external sourcing-tools to add additional information; and
- when they use the Service to connect to the Controller’s recruitment department, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn.
The User also consents to the Controller collecting publicly available information about the User and compiles them for use in recruitment purposes.
The User consents to the personal data being collected in accordance with the above a) and b) will be processed according to the below sections Storage and transfer and How long the personal data will be processed.
The User has the right to withdraw his or her consent at any time, by contacting the Controller using the contact details listed under 9. Using this right may however, mean that the User can not apply for a specific job or otherwise use the Service.
Storage and transfers
The personal data collected through the Service is stored and processed inside the EU/EEA, or such third country that is considered by the European Commission to have an adequate level of protection, or processed by such suppliers that have entered into such binding agreements that fully complies with the lawfulness of third country transfers or to other supplies where adequate safeguards are in place to protect the rights of the data subjects whose data is transferred. To obtain documentation regarding such adequate safeguards, contact us using the Contact details listed in 9.
How long the personal data will be processed
We will keep your personal data for the duration of the entire recruitment process and, if you as a User have not received a job offer, for a maximum of 24 months from the date of receipt of your consent in Team Tailor, bearing in mind that the recruitment process may extend over a long period. Subsequent storage of your CV and information as a User is carried out by us on the basis of our legitimate interest to ensure the efficiency of the recruitment process and to identify the most suitable candidates for open positions within the organisation. Thus, we may invite you to go through the steps of a specific subsequent recruitment in cases where job opportunities arise for the same or another position in the company. If you as a User do not want your CV and information to be stored by Platform24 for future recruitment, please exercise your right to object by submitting a request to this effect using the contact details in paragraph 9.
Also, to the extent that personal data is relevant to the resolution of a dispute, we will retain that data until the final resolution of that dispute (including any related legal proceedings).
Personal data of candidates who become employees are subject to a separate retention policy.
3. Users’ rights
a) Right to information: Users have the right to receive information on the personal data processing operations carried out by us. Our compliance with this right is achieved through this Privacy Notice;
b) Right of access: Users have the right to request information about the personal data that is processed by us, by notifying in writing, us using the contact details below under paragraph 9 below. Users have the right to a copy of the processed personal data which belongs to them without any charge. Where requests from Users are manifestly unfounded or excessive, in particular because of their repetitive character, Controller has a right to charge a reasonable fee on the basis of the administrative costs for such demand.
c) Right to rectification: Users have the right to, if necessary, rectification of inaccurate personal data concerning that User, via a written request, using the contact details in paragraph 9 below.
d) Right to erasure: Users have the right to request that we erase the personal data we process about them. We must comply with this request if:
- the personal data is no longer necessary for the purposes for which it was collected;
- you object to the processing for reasons relating to your particular situation;
- personal data have been unlawfully processed;
- personal data must be deleted in order to comply with a legal obligation incumbent on us,
unless the data is necessary: to exercise the right to freedom of expression and information; to comply with a legal obligation incumbent on us; for archiving purposes in the public or scientific interest or for historical studies or statistical purposes; or for establishing, exercising or defending a right in a court of law.
e) Right to restriction of processing: Users have the right to obtain from us the restriction of processing of personal data in situations expressly provided for in Article 18 of the GDPR.
f) Right to object: Right to object: where the processing is based on our legitimate interests or those of a third party, Users may object at any time to the processing of their personal data on grounds relating to their particular situation. Where the User objects to such processing, Platform24 shall no longer process the personal data, unless Platform24 demonstrates that it has reasons justifying the processing which override the interests, rights and freedoms of the User.
g) Right to data portability: The User has under certain circumstances a right to data portability, which means a right to get the personal data and transfer these to another controller as long as this does not negatively affect the rights and freedoms of others.
To exercise the above rights, the User may send a written request using the contact details in paragraph 9.
Upon receipt of the request, Platform24 will reply without undue delay, and no later than 1 month after receipt of the request. This period may be extended, in cases justified by the complexity of the request, by an additional period of up to 2 months.
h) Right to lodge a complaint: If you have a complaint about the way we process your personal data, we would prefer that you contact us directly so that we can address your concern. Nevertheless, you have the right to contact the National Supervisory Authority for Personal Data Processing using the form available on the Authority's website: Sweden:https://www.imy.se; Romania: www.dataprotection.ro.
4. Security
We prioritize the personal integrity and therefore works actively so that the personal data of the Users are processed with utmost care. We take the measures that can be reasonably expected to the make sure that the personal data of Users and others are processed safely and in accordance to this Privacy Notice and the GDPR-regulation.
However, transfers of information over the internet and mobile networks can never occur without any risk, so all transfers are made on the own risk of the person transferring the data. It is important that Users also take responsibility to ensure that their data is protected. It is the responsibility of the User that their login information is kept secret.
5. Transfer of personal data to third party
We will not sell or otherwise transfer Users’ personal data to third parties.
We may transfer Users’ Personal Data to:
- our contractors and sub-contractors, acting as our Processors and Sub-Processors in accordance with our instructions, for the provision of the Service;
- authorities or legal advisors in case criminal or improper behaviour is suspected; and
- authorities, legal advisors or other actors, if required by us according to law or authority’s injunction.
We will only transfer Users’ personal data to third parties that we have confidence in. We carefully choose partners to ensure that the User’s personal data is processed in accordance to current privacy legislations. We cooperate with the following categories of processors of personal data: Teamtailor, who supplies the Service, server and hosting companies, e-mail reference companies, video processing companies, information-sourcing companies, analytical service companies and other companies with regards to suppling the Service. We also collaborate with recruitment agencies and companies providing background check services.
6. Aggregated data (non-identifiable personal data)
We may share aggregated data to third parties. The aggregated data has in such instances been compiled from information that has been collected through the Service and can, for example, consist of statistics of internet traffic or the geological location for the use of the Service. The aggregated data does not contain any information that can be used to identify individual persons and is thus not personal data.
7. Cookies
When Users use the Service, information about the usage may be stored as cookies. Cookies are passive text files that are stored in the internet browser on the User’s device, such as computer, mobile phone or tablet, when using the Service. We use cookies to improve the User’s usage of the Service and to gather information about, for example, statistics about the usage of the Service. This is done to secure, maintain and improve the Service. The information that is collected through the cookies can in some instances be personal data and is, in such instances, regulated by our Cookie Policy.
Users can at any time disable the use of cookies by changing the local settings in their devices. Disabling of cookies can affect the experience of the Service, for example disabling some functions in the Service.
8. Changes
We have the right to, at any time, make changes or additions to the Privacy Notice. The latest version of the Privacy Notice will always be available through the Service. A new version is considered communicated to the Users when the User has either received an email informing the User of the new version (using the e-mail stated by the User in connection to the use of the Service) or when the User is otherwise informed of the new Privacy Notice.
9. Contact
For exercising your rights, for questions, further information about our handling of personal data or for contact with us in other matters, please use the below stated contact details:
- Platform24 dpo@platform24.se
- Correspondence address from Västra Järnvägsgatan 7, 116 64 Stockholm, Sweden