Privacy policy for recruitment using Teamtailor
The service for handling recruitments and simplifying the hiring process (the "Service") is powered by Teamtailor on behalf of Spacelift, Inc. with its principal office at 541 Jefferson Ave. Suite 100, Redwood City CA 94063, United States of America ("Controller" “we” “us” etc.). It is important that the persons using the Service ("Users”) feel safe with, and are informed about, how we handle User's personal data in the recruitment process. We strive to maintain the highest possible standard regarding the protection of personal data. We process, manage, use, and protect User's Personal Data in accordance with this Privacy Policy ("Privacy Policy").
1. General
We are the controller in accordance with current privacy legislations. The Users’ personal data is processed with the purpose of managing and facilitating recruitment of employees to our business.
2. Collection of personal data
We are responsible for the processing of the personal data that the Users contribute to the Service, or for the personal data that we in other ways collect with regards to the Service.
When and how we collect personal data
We collect personal data about Users from Users when Users:
- make an application through the Service or otherwise, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn;
- use the Service to connect with our staff, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn; and
- provide identifiable data in the chat (provided through the website that uses the Service) and such data is of relevance to the application procedure;
Please note that submission of data by the candidate is voluntary; however, the consequence of failing to provide the data will be the inability to participate in the recruitment.
We collect data from third parties, such as Facebook, LinkedIn and through other public sources. This is referred to as “Sourcing” and be manually performed by our employees or automatically in the Service.
In some cases, existing employees can make recommendations about potential applicants. Such employees will add personal data about such potential applicants. In the cases where this is made, the potential applicant is considered a User in the context of this Privacy Policy and will be informed about the processing.
The types of personal data collected and processed
The categories of personal data that can be collected through the Service can be used to identify natural persons from names, e-mails, pictures and videos, information from Facebook and LinkedIn-accounts, answers to questions asked through the recruiting, titles, education and other information that the User or others have provided through the Service. Only data that is relevant for the recruitment process is collected and processed.
Purpose, basis and duration of personal data processing
1) Legal basis: article 6(1)(b) GDPR - performance of a contract to which the data subject is a party or actions leading to the conclusion of a contract
Purpose of processing: handling a recruitment application for an open position (obtaining and screening applications, contacting to arrange an interview, conducting
interviews, verifying and assessing the candidate's knowledge and skills)
Retention: for the time necessary to conduct the recruitment, including until its completion
2) Legal basis: article 6(1)(f) GDPR - legitimate interest
Purpose of processing: a) to carry out an assessment of the candidate which is necessary to determine whether the candidate is the right person for the position being recruited; b) to ensure security and c) to establish, assert and defend against claims
Retention: for the time necessary to pursue the Controller’s legitimate interest, but no longer than until you have objected to the processing of your
personal data;
3) Legal basis: article 6(1)(a) of the GDPR - consent
Purpose of processing: future recruitments by the Controller
Retention: until the consent is withdrawn, but no longer than 12 months from the moment of consent
Storage and transfers
The personal data collected through the Service is stored and processed inside the EU/EEA, or such third country that is considered by the European Commission to have an adequate level of protection, or processed by such suppliers that have entered into such binding agreements that fully complies with the lawfulness of third country transfers (as Data Privacy Framework) or to other supplies where adequate safeguards are in place to protect the rights of the data subjects whose data is transferred.
Automated processing
You will not be subject to a decision that is based solely on automated processing, including profiling, and produces legal effects on you or similarly significantly affects you.
3. Users’ rights
Users have the right to:
- access to the data, rectify the data, request for erasure, as well as the right to restrict the processing of the personal data and the right to data portability;
- to the extent that the data are processed on the basis of a separate consent, the right to withdraw it at any time by contacting us according to section 9; the withdrawal of consent shall, however, not affect the lawfulness of the processing that took place before its withdrawal;
- to object to the processing of personal data based on legitimate interest under certain circumstances;
- lodge a complaint to the supervisory authority, if the User considers that the processing of personal data infringes the legal framework of privacy law.
4. Security
We prioritize the personal integrity and therefore work actively so that the personal data of the Users are processed with utmost care. We take the measures that can be reasonably expected to make sure that the personal data of Users and others are processed safely and in accordance to this Privacy Policy and the GDPR-regulation.
However, transfers of information over the internet and mobile networks can never occur without any risk, so all transfers are made on the own risk of the person transferring the data. It is important that Users also take responsibility to ensure that their data is protected. It is the responsibility of the User that their login information is kept secret.
5. Transfer of personal data to third party
We will not sell or otherwise transfer Users’ personal data to third parties.
We may transfer Users’ Personal Data to such recipient as:
- entities supporting the recruitment process,
- entities providing legal services,
- entities providing software and tools used by the Controller,
- entities providing IT and hosting services,
- entities providing electronic mail,
- social media (e.g. LinkedIn).
We will only transfer Users’ personal data to third parties that we have confidence in. We carefully choose partners to ensure that the User’s personal data is processed in accordance to current privacy legislations.
6. Aggregated data (non-identifiable personal data)
We may share aggregated data to third parties. The aggregated data has in such instances been compiled from information that has been collected through the Service and can, for example, consist of statistics of internet traffic or the geological location for the use of the Service. The aggregated data does not contain any information that can be used to identify individual persons and is thus not personal data.
7. Cookies
When Users use the Service, information about the usage may be stored as cookies. Cookies are passive text files that are stored in the internet browser on the User’s device, such as computer, mobile phone or tablet, when using the Service. We use cookies to improve the User’s usage of the Service and to gather information about, for example, statistics about the usage of the Service. This is done to secure, maintain and improve the Service. The information that is collected through the cookies can in some instances be personal data and is, in such instances, regulated by our Cookie Policy.
Users can at any time disable the use of cookies by changing the local settings in their devices. Disabling of cookies can affect the experience of the Service, for example disabling some functions in the Service.
8. Changes
We have the right to, at any time, make changes or additions to the Privacy Policy. The latest version of the Privacy Policy will always be available through the Service. A new version is considered communicated to the Users when the User has either received an email informing the User of the new version (using the e-mail stated by the User in connection to the use of the Service) or when the User is otherwise informed of the new Privacy Policy.
9. Contact
For questions, further information about our handling of personal data or for contact with us in other matters, please contact us:
- by post: 541 Jefferson Ave. Suite 100, Redwood City CA 94063, United States of America or
- by e-mail: privacy@spacelift.io