Privacy Notice

In Heads (hereinafter referred to as the “Company” or “we”) we consider Data Protection an integral part of our operational business principles and are committed in respecting your privacy and complying with all applicable laws on data protection, including the General Data Protection Regulation (GDPR), ensuring that personal data is:

  • a)     processed lawfully, fairly and in a transparent manner in relation to data subjects (GDPR “lawfulness, fairness and transparency” principle of processing personal data);
  • b)    collected for specified, explicit and legitimate purposes and not further processed in any manner that is incompatible with those purposes (GDPR “purpose limitation” principle of processing personal data);
  • c)     adequate, relevant and limited to what is absolutely necessary for the purposes for which they are processed (GDPR “data minimization” principle of processing personal data);
  • d)    accurate and, where necessary, kept up to date; every reasonable step is taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (GDPR “accuracy” principle of processing personal data);
  • e)     kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, subject to implementation of the appropriate technical and organizational measures required by applicable data protection legislation in order to safeguard the rights and freedoms of data subjects (GDPR “storage limitation” principle of processing personal data);
  • f)      processed in a manner that ensures appropriate security of the personal data (including when applicable, anonymization or pseudonymization), including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage using appropriate technical and organizational measures (GDPR “integrity and confidentiality” principle of processing personal data);
  • g)     transferred to a third country, outside the European Economic Area, or international organization, only when adequate level of protection is ensured to safeguard the rights and freedoms of data subjects.

 

In the context of protecting the privacy of our website visitors, we are sharing this privacy notice with you to explain how we collect, process, and use the personal data we receive via our website and the email or phone numbers mentioned within it, and inform you of the rights you have in relation to these data. This notice is subject to modifications at any point in time; hence we advise you to periodically check this page to remain informed and updated on any amendments.

 

What personal data do we process?

We collect information that you voluntarily submit to us though the “Submit an RFP” page for requesting a proposal from our end, or the information you provide to us when you contact us by email or other means or when you decide to submit your Curriculum Vitae (CV) and apply for a job. We collect and process your personal data exclusively for communicating with you, fulfilling your request and improving our services.

 

How do we process your personal data, for what purposes and with which legal basis?

When you “Submit an RFP” to us, we collect your name, surname, the Company you work for, your position, your contact number, your email address, your country and your preferences/proposals in relation to the study. The legal basis for the processing of your personal data is our legitimate interest to evaluate your proposal and make informed decisions on new studies and, in case we choose to proceed, to take the necessary steps prior to entering into a contract.

Our website also gives you the possibility to contact us by sending us an email or traditional post and by phone. If you contact us through any of these means, we will collect and process the information you provide us with, as well as information that will enable us to contact you back and handle your request appropriately. Personal data that we process in this context include your name, surname, contact details and any other information you provide us with in your communication. We process your personal data exclusively for handling your communication and therefore exercising our legitimate business interest to properly address communications.

 

When you send us your CV, whether in relation to a specific job opening or not, the personal data we collect, and process include your identifying information, name and e-mail, information on your educational and professional experience and other information in connection with your job application (e.g., assessments you complete during the application process, information necessary to confirm your ability to work for the Company such as immigration and work permit information, as well as compensations history etc.). We process your personal data solely for the purpose of assessing your qualifications and suitability for a given opening and determining the possibility of employment. The legal basis for the processing of your personal data is our legitimate interest to evaluate job applications and make informed decisions on new recruitments and, in case of eligible candidates, to take the necessary steps prior to entering into an employment contract with them. For further information on processing of information in the context of CVs submitted to us, please refer to the Privacy Notice to Candidates.

 

Information we collect through cookies & other similar tracking technologies

Our website uses cookies and similar tracking technologies which may collect additional information to the personal data described above. For example, when you visit our website, your device provides information to us, such as your IP address, other device identifier, the type of device you use, etc.

Such information may also include usage information and statistics about your interaction with our website, the URLs of our web pages that you visited, URLs of referring and exiting pages, page views, time spent on a page, number of clicks, platform type, location data (if you have enabled access to your location on your mobile device), and other information about how you used the website.

 

Any collection of the above-mentioned information collected by non-strictly necessary cookies and other similar technologies will be based on your prior informed consent. To find out more details on cookies we use, please refer to our Cookies Policy.

 

Recipients of your data

We only share and disclose your personal data with business partners who act on our behalf for the above purposes of processing or that offer us information technology services, e.g., for the registration and storage of data and/or for the operation of our website.

 

Transfers of personal data

Any transfer of your personal data outside the EU/EEA for the purpose of achieving the above processing purposes, due to sharing of personal data with them, will be based on an adequacy decision issued by the European Commission or subject to suitable and appropriate safeguards and conditions to ensure an adequate level of data protection, e.g., data transfer agreements based on standard contractual clauses approved by the European Commission. For further information on how Heads protects personal data when transferred outside the EU/EEA or in order to obtain a copy of the safeguards we implement to protect personal data when transferred outside the EU/EEA, please contact us at dpo@heads-research.com.

 

 

Duration of processing

Retention periods vary significantly based on the type of information and how it is used. Our retention periods are based on criteria that include legally mandated retention periods, pending or potential litigation, our intellectual property or ownership rights, contract requirements, operational directives or needs, and historical archiving. For the duration of processing of information related to CVs, please refer to our Privacy Notice to Candidates. For the duration of the processing of information collected through cookies and similar tracking technologies, please refer to our Cookies Policy.

 

What are your rights?

Right to be informed

You have the right to be informed about the collection and use of your personal data.

Right of Access

You have the right to view, request a copy or access your personal data being processed in a concise, easily understood, transparent and easily accessible form.

Right to Rectification

You have the right to request inaccurate, incomplete, or outdated personal information be updated or corrected.

Right to be Forgotten / Right to Erasure

You have the right to request your personal data be deleted, without any delay, subject to exemptions set by certain laws.

Right to Restriction

You have the right to request the restriction or suppression of processing of your personal data, subject to exemptions set by certain laws.

Right to Withdraw Consent

You may withdraw your consent at any time, where the processing of your personal data is based on your consent.

Right to Portability

You have the right to ask for your personal data to be transferred to another Controller or be provided to them, in a structured, commonly used, machine-readable electronic format.

Right to Obtain Human Intervention

You have the right to object to decisions being made with your data solely based on automated processing, decision making or profiling and hence have the right to obtain human intervention on the part of the Company, to express your point of view and to contest the decision.

 

Heads will satisfy any request you may have based on the conditions set out in the law. Exercising your rights as granted by law does not necessarily imply that it will be fully satisfied, especially when other compelling legal provisions exist. In case we cannot fulfil a request of yours, we will inform you, accordingly, providing you with a relevant justification.

 

How can you exercise your rights?

If you have any question or concern regarding this Privacy Notice and your personal data processing by Heads or if you wish to exercise your rights, you may contact us at dpo@heads-research.com.

 

We will respond to your request within thirty (30) days of receipt; if an extension to this timeline is necessary for us to investigate and/or respond to your request, we will inform you, accordingly, providing you with a relevant justification for the extension required.

 

In any case, if you believe that your data protection rights have been violated, you have the right to lodge a complaint with the corresponding statutory regulator in your jurisdiction.

 

A list of contact details for the Data Protection Authorities in the EEA can be found here.

For the Swiss authority here, for the UK authority here, for the Australian authority here and for the Office of the Privacy Commissioner of Canada here.

 

Last updated: 25-Oct-2023

Get in touch with us or find an office closest to you.