Privacy Notice to Candidates
Thank you for your interest in submitting your Curriculum Vitae (CV) to HeaDS (hereinafter referred to as the “Company” or “we”). By submitting your CV, we are given the opportunity to review your qualifications and assess your suitability for either the job applied for or for future job openings. Following assessment of the information you provide; we may contact you to request further information and potentially arrange an interview with you.
In HeaDS we consider Data Protection an integral part of our operational business principles and are committed in respecting your privacy and complying with all applicable laws on data protection, ensuring that personal data is:
- a) processed lawfully, fairly and in a transparent manner in relation to data subjects (General Data Protection Regulation-GDPR- “lawfulness, fairness and transparency” principle of processing personal data);
- b) collected for specified, explicit and legitimate purposes and not further processed in any manner that is incompatible with those purposes (GDPR “purpose limitation” principle of processing personal data);
- c) adequate, relevant and limited to what is absolutely necessary for the purposes for which they are processed (GDPR “data minimization” principle of processing personal data);
- d) accurate and, where necessary, kept up to date; every reasonable step is taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (GDPR “accuracy” principle of processing personal data);
- e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, subject to implementation of the appropriate technical and organizational measures required by applicable data protection legislation in order to safeguard the rights and freedoms of data subjects (GDPR “storage limitation” principle of processing personal data);
- f) processed in a manner that ensures appropriate security of the personal data (including when applicable, anonymization or pseudonymization), including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage using appropriate technical and organizational measures (GDPR “integrity and confidentiality” principle of processing personal data);
- g) transferred to a third country, outside the European Economic Area, or international organization, only when adequate level of protection is ensured to safeguard the rights and freedoms of data subjects.
Personal data we process and disclose
|What Candidate Personal Data Do We Process?||To Whom Do We Disclose Candidate Personal Data for a Business Purpose?|
|Identifying information and contact details (e.g., name, surname, postal address, telephone number, email address)||
Within the Company, to employees involved in the selection and recruitment process based on their role and responsibilities.
Outside the Company to:
|Information on your educational and professional experience (e.g., CV, academic degrees, foreign languages, publications, professional qualifications, certifications, training courses, transcript information, cover letter, work history, performance information and references provided or confirmed by academic institutions or previous employers and assessment information provided potentially by recruiting agencies)|
|Information in connection with your job application to us (e.g., assessments you complete during the application process and information collected through the application process)|
|Information necessary to confirm your ability to work for the Company, to the extent required or permitted to comply with applicable legislation (e.g., immigration information, work permit, proof of vaccination, visa information)|
|Other information, that you may voluntarily choose to provide in connection with you job application (e.g., compensation history, sensitive personal data e.g., medical conditions / disability)|
When your personal data is transferred to a third country, outside the European Economic Area, or an international organization, the Company ensures that an adequate level of protection is in place to safeguard your rights and freedoms. For further information on how the Company protects personal data when transferred outside the European Economic Area or in order to obtain a copy of the safeguards we implement to protect personal data when transferred outside the European Economic Area, please contact our Data Protection Officer at email@example.com.
When providing information of third parties to the Company (e.g., referees etc.) it is important that you inform the people concerned of the notification of their details to HeaDS.
You will not be subject to decisions that will have a significant impact on your application based solely on automated decision-making.
Why do we process your personal data and on what lawful basis?
We collect and process your personal data only to pursue our legitimate interest in assessing your qualifications and suitability for a given opening and hence determining the possibility of employment, taking steps at your request prior to entering into a contract with you and if applicable, to complete preliminary steps of the hiring process in order to enter into a contractual agreement with you (Lawful basis: legitimate interests, legal obligations).
We collect and process your personal data in the context of references provided or confirmed by academic institutions or previous employers, based on your consent.
In the context of above, we may also process your personal data for supporting our Company’s right to establish, exercise and defend legal claims (Lawful basis: legal claims; legal obligations; legitimate interest).
How long do we process your personal data for?
HeaDS maintains digital records of your personal data, taking all appropriate security measures, for six (6) months following the completion of the recruitment process, whether you submit your CV and additional supporting documentation in response to specific, published job opening, or you submit your CV and additional supporting documentation voluntarily on your own initiative.
You may withdraw your consent at any time by sending an e-mail to firstname.lastname@example.org, including in the subject “REVOKE CONSENT”.
|Right to be informed||You have the right to be informed about the collection and use of your personal data.|
|Right of Access||You have the right to view, request a copy or access your personal data being processed in a concise, easily understood, transparent and easily accessible form.|
|Right to Rectification||You have the right to request inaccurate, incomplete, or outdated personal information be updated or corrected.|
|Right to be Forgotten / Right to Erasure||You have the right to request your personal data be deleted, without any delay, subject to exemptions set by certain laws.|
|Right to Restriction||You have the right to request the restriction or suppression of processing of your personal data, subject to exemptions set by certain laws.|
|Right to Withdraw Consent||You may withdraw your consent at any time. Withdrawal of consent will not affect processing activities performed prior to withdrawal.|
|Right to Portability||You have the right to ask for your personal data to be transferred to another Controller or be provided to them, in a structured, commonly used, machine-readable electronic format.|
HeaDS will satisfy your request based on the conditions set out in the law. Exercising your rights as granted by law does not necessarily imply that it will be fully satisfied, especially when other compelling legal provisions exist. In case we cannot fulfil a request of yours, we will inform you, accordingly, providing you with a relevant justification.
How can you exercise your rights?
If you have any question or concern regarding this Privacy Notice and your personal data processing by HeaDS or if you wish to exercise your rights, you may contact us at email@example.com.
We will respond to your request within thirty (30) days of receipt; if an extension to this timeline is necessary for us to investigate and/or respond to your request, we will inform you, accordingly, providing you with a relevant justification for the extension required.
In any case, if you believe that your data protection rights have been violated, you have the right to lodge a complaint with the corresponding statutory regulator in your jurisdiction.
A list of contact details for the Data Protection Authorities in the EEA can be found here.
Last Updated: 15-Nov-2023