Privacy notice for recruiting through Teamtailor (Applicants Privacy Policy)
Date of last update: 24-07-2024
Source Up is committed to respecting your privacy and protecting your personal data. This Candidate privacy notice and the Cookie Policy available on Teamtailor, and any other documents referred to, inform you about how we collect and process your personal data, including through your use of our career website, regardless of where you visit it from. This privacy notice also informs you of your privacy rights and how the law protects you.
1. Data Controller & Data Subjects
The term “Data Protection Laws” used in this policy means the General Data Protection Regulation EU 2016/679 (GDPR) and any corresponding or equivalent national laws or regulations of the European Union (EU) or EU Member States that are applicable to the processing of personal data under this notice. The terms “Data controller”, “Personal data”, “Data subjects” and “processing” used in this notice shall have the same meaning as those prescribed in the Data protection Laws.
The service of processing, recruiting and simplifying the hiring process (the "Service") is offered by Teamtailor on behalf of Source up (the "Company", "we", "us", "our", etc.).
When we use the term “Users”, "Applicants" or “Candidates” in this privacy policy, we are referring to individuals ("data subjects") who:
- make a request through the Service or otherwise and add personal data about themselves personally or through a third-party source, such as Facebook or LinkedIn; and use the Service to connect with our staff, by adding personal data about them either personally or through a third-party source, such as Facebook or LinkedIn; and provides data that is identifiable in our chat (on the website operating the Service) and relevant as part of an application process;
- create an account on our website;
- apply for a position we are searching for;
- subscribe to our service or publications;
- want to receive information or request marketing to be sent to them;
- give us feedback or contact us in the frame of a recruitment process or current/future vacancies;
It is important that individuals using the Service feel safe and are informed about how we process their personal data as part of their recruitment process. We strive to maintain the highest possible level of protection of personal data. We process, manage, use and protect the Users’ personal data in accordance with this Privacy Policy.
We are responsible for the processing in full compliance with the applicable privacy laws. Users' personal data is processed for the purpose of managing and simplifying the recruitment process. We act as the data controller when we process your personal data as described in this Privacy policy.
2. Type of data collected
Only data that is relevant to the recruitment process is collected and processed.
During the Service, the Company collects personal information that may consist of, but is not limited to:
-
Contact details: your name, email address, telephone number and physical address.
-
Information in your application: your CV, cover letter, picture, work samples, references, letters of recommendation, education, language skills, experience, etc.
-
Data from interviews/assessments and other information part of the recruitment process: notes from interviews with you, answers to questions asked during the Service, assessments and tests made, salary requirements, current benefits, eligibility to work in the country, etc.
-
Information in your public profile: the information we collect about you from public sources related to your professional experience, such as LinkedIn or the website of your current employer.
-
Information provided by references: the information we receive from our employees or partners who refer you to us, or by the persons you have listed as your references.
-
Communications data: your communication with us, including the information you provided in the communication. This may include the content of emails, audio/video recordings, the information you add to your account with us, surveys, links to your social media pages, messages on social media etc.
-
Technical/Device data: when you visit our Career Site, we will automatically collect information about your equipment, browsing actions and patterns. We collect this personal information by using cookies and other similar technologies and from the communications we receive from your browser. Please see our Cookie policy for further details about how we use cookies and other similar technologies.
3. How we collect data
The Company collects this information in different ways:
-
From the career site: when you visit our Career Site, we collect technical information about how you use the Career Site, and information from your device.
-
Directly from you: Most of the information we process about you, we receive directly from you, for example when you apply for a position with us or connect with us. You may give us your data by filling in forms or by corresponding with us by post, phone, email, chat, via a dedicated online form on our websites, in person or otherwise. You can always choose not to provide us with certain information. However, some personal data is necessary in order for us to process your application or provide you the information you request to get from us.
-
From public sources: We may collect data from public sources, such as Facebook, LinkedIn, and other public sources. This is called "Sourcing", an activity carried out manually by our employees or automatically by the Service.
-
From our references: We may receive information about you from our employees or partners (such as recruitment service providers), when they believe your profile is of interest for our current or future vacancies. These employees will add personal data about these potential candidates. In cases where this is done, the potential candidate will be considered a User in the context of this Privacy Policy and will be informed of the processing of his or her data.
-
From your references: If you provide us with references, we may collect information about you from them.
-
Data we create ourselves or in cooperation with you: Information about your application and profile is usually created by us, or by us in cooperation with you, during the recruitment process. This may for example include notes from interviews with you, assessments and tests made.
4. For what purposes and how long do we process your personal data?
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
-
Provide our Service and carry on the Recruitment process
- Review profiles and applications sent to us. This also includes communicating with you about your application and profile.
- Collect and evaluate your professional profile on our own initiative. This also includes communicating with you regarding your profile.
- Share your personal data with other recipients, for the purposes mentioned in Section 5 below.
- Keep you informed about the Service and contact you directly about specific/future vacancies with us.
If you apply for a position, we keep your personal data for the whole duration of the recruitment process to decide if you are a suitable candidate for the relevant vacancy(ies) (not longer than 2 years after the last contact with the applicant).
If you do not succeed in the initial recruitment process, we keep your personal data for a duration of 12 months (as per consent given initially). To potentially contact you for relevant future job openings. After these initial 12 months, you will receive an email from us confirming the extension to keep your data for another 12 months, unless you withdraw your consent (link in the email).
If you are hired, your data may be kept by the employer for the duration of the employment contract.
-
Respond to your request or questions or provide information when you contact us or make a request to us (data kept based on initial consent and as long as consent is valid)
-
Provide analysis or valuable information so that we can improve the Service. Personal data that is processed for the purposes of aggregate analysis or market research will be systematically anonymized. This personal data cannot be used to identify a certain User.
-
Collect information about your use of the Career Site, using cookies and other tracking technologies, as described in our Cookie Policy. We keep your personal data to analyze the performance of the Career Site for as long as we keep personal data about you for other purposes.
-
Defend our interests in legal proceedings. If we process your personal data for the purpose of being able to protect and enforce our rights, we will keep your personal data until the relevant legal issue has been fully and finally resolved.
5. On what legal basis do we process your personal data?
We will only use your personal data when legally permitted. The above-described purposes are based on at least one of the following legal bases:
- The legal basis we rely on is normally that the processing is necessary for our legitimate interest in being able to recruit talents and therefore managing and maintaining our business.
- The processing can also be necessary for the performance of a contract (or in the pre-contractual phase) to which the data subject is bound.
- There may be specific circumstances when the processing is only performed if and when you provide your consent to the processing of their personal data for one or more specific purposes. This is for example the case if we propose to record an interview with you. We also ask your consent as one of the first steps when you register via Connect or when you apply for a position, where you need to confirm to us your agreement to process your data to benefit from the Service. Please see Section 9 below for more information about your right to withdraw your consent.
- The processing is necessary for compliance with a legal obligation to which Source Up is subject.
6. Whom do we share your personal data with?
We may have to share your personal data with the parties set out below for the purposes set out in the contract we have with you or in paragraph 4 above.
- We may share with or give access to your personal data to our colleagues at Source Up and our sourcers in the European Economic Area (EEA), in compliance with the obligations applicable to the GDPR. Access to your personal data is limited to a restricted number of employees at Source Up: recruiters, hiring managers, HR departments, supervisors with whom you will be working, employees directly involved in the hiring process.
-
Your employer or future employer or any person we have a contract with and that has requested, with your knowledge, that we perform recruitment services on their behalf. If you are a candidate, we share your personal data with our clients who have vacancies for jobs that interest you.
-
Service providers
- who provide IT, system administration and/or data hosting services.
- who provide recruitment support services such as: Teamtailor
- who provide personality and motivational questionnaires, ability tests, 360° feedback providers such as: Assess First, SHL, Insights Discovery (non-exhaustive list).
-
Authorities, legal advisers, or any other similar entity when we are ordered to do so. We will share your personal data with authorities and other public actors when we have a legal obligation to do so.
-
Parties involved in legal proceedings. If needed to protect or defend our rights, we share your personal data with public authorities or with other parties involved in a potential or existing legal proceeding. This can for example be in case of discrimination claims.
- To the new owners of the business and their advisors in the event of a reorganization, merger, sale, joint venture, assignment or other transfer or disposition of all or a portion of our business.
We only transfer Users' personal data to third parties that we trust. We carefully select our partners to ensure that the User's personal data is processed in accordance with applicable privacy laws. We cooperate with the following categories of personal data processors: Teamtailor, which provides the Service, server and hosting companies, email referencing companies, video processing companies, information supply companies, analytics services companies, and any other companies with respect to offering the Service.
We may share aggregated data with third parties. The aggregated data in these cases has been compiled from information collected through the Service and may, for example, consist of internet traffic or geological location statistics in connection with the use of the Service. Aggregated data does not contain any information that can be used to identify individual individuals and is therefore not personal data.
7. When do we transfer your personal data outside of the EU/EEA?
As our company is based in Luxembourg and not part of a larger group, your personal data is stored and processed within the European Economic Area (EEA).
Certain clients, suppliers and service providers may have personnel or systems located outside of the EEA. In this context, your personal data may be transferred outside the European Economic Area (EEA) for the purposes set forth in this notice, to countries that may not offer a level of protection of personal data equivalent to that offered within the EEA. Where third parties transfer your personal data outside of the EEA, we will take steps to ensure that your personal data receives an adequate level of protection, including by, for example, entering into data transfer agreements or by ensuring that third parties are certified under appropriate data protection schemes and where adequate safeguards are in place.
You have a right to request a copy of any data transfer agreement under which your personal data is transferred, or to otherwise have access to the safeguards used by contacting us.
8. Security
We prioritize personal integrity and therefore actively work to ensure that users' personal data is handled with the utmost care. Therefore, we take steps that can reasonably be expected to ensure that the personal data of Users and other individuals is treated securely and in accordance with this Privacy Policy and the GDPR.
However, data transfers over the Internet and mobile networks can never be done without any risk, therefore, all transfers are made at the personal risk of the person performing them. It is important that Users also take responsibility for ensuring that their data is well protected. It is the User's responsibility to ensure that his/her login data remains secret.
9. What rights do you have?
In this section, you will find information about the rights you have when we process your personal data. As described below, some of the rights only come into play when we process your personal data under a particular legal basis.
You have the right to be informed about how we process your personal data. You also have the right to be informed if we plan to process your personal data for any purpose other than that for which it was originally collected.
We provide you with such information through this privacy policy, through updates on our Career Site (see also Section 11 below), and by answering any questions you may have for us.
- Right to access your personal data
You have the right to know if we process personal data about you, and to receive a copy of the data we process about you. In connection with receiving the copy of your data, you will also receive information about how we process your personal data.
- Right to access and to request a transfer of your personal data to another recipient (“data portability”)
You can request a copy of the personal data relating to you that we process for the performance of a contract with you, or based on your consent, in a structured, commonly used, machine-readable format. This will allow you to use this data somewhere else, for example to transfer it to another recipient. If technically feasible, you also have the right to request that we transfer your data directly to another recipient.
- Right to have your personal data deleted (“right to be forgotten”)
In some cases, you have the right to have us delete personal data about you. This is for example the case if it’s no longer necessary for us to process the data for the purpose for which we collected it; if you withdraw your consent; if you have objected to the processing and there are no legitimate, overriding justifications for the processing. (For the separate right to object, see below.)
- Right to object against our processing of your personal data
You have the right to object to processing of your personal data which is based on our legitimate interest, by referencing your personal circumstances.
- Right to restrict processing
If you believe that the personal data we process about you is inaccurate, that our processing is unlawful, or that we don’t need the information for a specific purpose, you have the right to request that we restrict the processing of such personal data. If you object to our processing, as described just above, you can also request us to restrict processing of that personal data while we make our assessment of your request.
When our processing of your personal data is restricted, we will (with the exception of storage) only process the data with your consent or for the establishment, exercise or defence of legal claims, to protect the rights of another natural or legal person, or for reasons relating to an important public interest.
You have the right to request that we rectify inaccurate information, and that we complete information about you that you consider incomplete.
- Right to withdraw your consent
When we process your personal data based on your consent, you have the right to withdraw that consent at any time. If you do so, we will stop processing your data for the purposes you’ve withdrawn your consent for. However, it doesn’t affect the lawfulness of processing that was based on your consent before it was withdrawn. The use of this right may also imply that the User will not be able to apply for a specific job or otherwise use the Service.
- Right to raise a complaint
If you have complaints about our processing of your personal data, you can raise a complaint with the data protection authority in Luxembourg. You can find their contact details here.
You can also lodge a complaint with your national data protection authority, which you can find listed here if you are based in the EU. If you are based in the UK, you can lodge a complaint with the Information Commissioner’s Office, here.
10. Updates & Contact
We update this privacy policy when necessary - for example, because we start processing your personal data in a new way, because we want to make the information even clearer to you, or if it’s necessary to do so in order to comply with applicable data protection laws.
We encourage you to regularly check this page for any changes. You can always check the top of this page to see when this privacy policy was last updated.
If you want to exercise any of the rights listed here, we suggest that you:
- Visit the Data & Privacy page on our Career Site, where we offer features to let you exercise your rights;
-
Log in to your account with us, where you can use the settings in the account to exercise your rights; or
- Contact us directly at contact@sourceup.lu.