Privacy policy for recruitment
Our objective with this privacy policy is to inform you, as a prospective job applicant (”User” or ”you”), about how we, Astrea UK Services Limited and the subsidiaries and affiliates presented in the advertised job ("Controller" “we” or “us”), use and take care of your personal data in our recruitment process. It is important that you feel safe with, and are informed about, how we handle your personal data in the recruitment process. We strive to maintain the highest possible standard regarding the protection of personal data. We process, manage, use, and protect User's Personal Data in accordance with this Privacy Policy ("Privacy Policy").
1. General
We are responsible for processing your personal data as the controller. The Users’ personal data is processed with the purpose of managing and facilitating recruitment of employees to our business. To help us we use a service for handling recruitments and simplifying our hiring process (the "Service"), which is powered by Teamtailor. Teamtailor is our processor which means that they may not use your personal data for their own purposes.
2. Collection of personal data
When and how we collect personal data
We collect your personal data when you:
- make an application through the Service, adding personal data about yourself either personally or by using a third-party source, Facebook or LinkedIn,
- use the Service to connect with us, adding personal data about yourself either personally or by using a third-party source, Facebook or LinkedIn, and
Later in the recruitment process, we may collect data from applicant’s references and this can be manually performed by our employees or automatically in the Service.
In some cases, existing employees can make recommendations about potential applicants. Such employees will add personal data about such potential applicants in the Service. In the cases where this is made, the potential applicant is considered a User in the context of this Privacy Policy and will be informed about the processing.
The types of personal data collected and processed
The categories of personal data that are collected through the Service and used within our recruitment process varies. Most commonly we have the following information; name, e-mail, phone number, address, job applications, pitch, CV, pictures and videos, answers to questions asked through the recruiting process, titles, education and other information and documents that the User or others have provided through the Service, for example recommendations.
If you choose to log in with your Facebook and LinkedIn-account, your name and e-mail will be collected as well as your LinkedIn profile URL.
Data that is not relevant for the recruitment process may be provided by the User but will not be considered during the recruitment unless we inform you about it.
Purpose and lawfulness of processing
The purpose of collecting and processing the personal data is to manage recruitment. The lawfulness of the processing of personal data is based on our legitimate interest to find the candidate that best fit our needs and that would be most likely to thrive with us as well as to simplify and facilitate our recruitment process, by collecting information directly from the applicant in the Service and compile them for recruitment purposes as well as to anonymise data for statistical purposes.
Storage and transfers
The personal data collected through the Service is stored and processed inside the EU/EEA, or such third country that is considered by the European Commission to have an adequate level of protection, or where the personal data is transfered to a third country only processed by such suppliers that have entered into binding agreements that fully complies with the lawfulness of third country transfers or to other supplies where adequate safeguards are in place to protect the rights of the data subjects whose data is transferred. To obtain documentation regarding such adequate safeguards, contact us using the Contact details listed in paragraph 9.
How long the personal data will be processed
All personal data of Users will be stored for 1 year. Then you will receive an email notification that asks if you wish your personal data to be saved and considered for future positions. If you so indicate we will continue to store your personal data for 1 year, otherwise we will delete your personal data after 1 month of receiving the email notification from us.
If you are offered a position with us, we will continue to process your personal data. You will receive more information regarding this upon your employment.
3. Users’ rights
Users have the right to request information about what personal data that is processed by us, by notifying us in writing by using the contact details below under paragraph 9 below or through the ”Request my data” function in the Data & Privacy section. If you make a request through the function “Request my data” we want to inform you that you will receive an automatic email informing you of all information processed in the Service, although we might process more information about you – we encourage you to send a request by email to us.
Users have the right to, if necessary, rectification of inaccurate personal data concerning that User, via a written request, using the contact details in paragraph 9 below. You can also update your data via the Candidate log in.
The User has the right to demand deletion or restriction of processing, and the right to object to processing based on legitimate interest under certain circumstances. You can request deletion of your personal data through the ”Remove my data” function in the Data & Privacy section, or send us a request by using the contact details below under paragraph 9 below.
The User has the right to lodge a complaint to the supervisory authority regarding the processing of personal data relating to him or her, if the User considers that the processing of personal data infringes the legal framework of privacy law. You can find contact details to all Supervisory Authorities in EU/EEA here. If you have any comments or questions about our processing, we encourage you to contact us first, so that we have the opportunity to assist you and address your questions.
For US applicant only
CALIFORNIA CONSUMER NOTICE Under California Civil Code Section 1789.3, California users must receive the following specific consumer rights notice: The Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs may be contacted in writing at 1020 N Street, #501, Sacramento, California 95814, or by telephone at 1-916-445-1254.
California and Nevada – Shine the Light Law & Your Privacy Rights
California and Nevada residents may request and obtain from us, once a year, free of charge, a list of third parties, if any, to which we disclosed their Personal Information (as defined in the Shine the Light Law, Cal. Civ. Code § 1798.83 or under Nevada law) for direct marketing purposes during the preceding calendar year and the categories of Personal Information shared with those third parties. If you are a California or Nevada resident and wish to obtain that information, please submit your request by using the contact details below under paragraph 9 below, we will confirm your identity and response in accordance with legal requirements.
4. Security
We prioritize the personal integrity and therefore work actively so that your personal data are processed with utmost care. We take the measures that can be reasonably expected to make sure that your personal data are processed safely and in accordance to this Privacy Policy and the GDPR-regulation.
Transfers of information over the internet and mobile networks always carry some risk. It is essential that Users take measures to ensure their data is protected. Users are responsible for keeping their login information confidential.
5. Transfer of personal data to third party
We may transfer Users’ Personal Data to;
- our contractors and sub-contractors, acting as our Processors and Sub-Processors in accordance with our instructions, for the provision of the Service;
- authorities or legal advisors in case criminal or improper behaviour is suspected; and
- authorities, legal advisors or other actors, if required by us according to law or authority’s injunction.
We carefully choose partners to ensure that the User’s personal data is processed in accordance to current privacy legislations.
We cooperate with the following categories of processors of personal data;
- Teamtailor, who supplies the Service,
- server and hosting companies,
- e-mail reference companies,
- video processing companies,
- information-sourcing companies,
- personality and evaluation testing services
- analytical service companies, and
- other companies with regards to suppling the Service.
6. Aggregated data (non-identifiable data)
We may share anonymised aggregated data to third parties. The aggregated data has in such instances been compiled from information that has been collected through the Service and can, for example, consist of statistics of internet traffic or the geological location for the use of the Service. The aggregated data does not contain any information that can be used to identify individuals and is thus not personal data.
7. Cookies
When you visit and use the Service you will be asked to make a choice, to consent to use of cookies or reject non-necessary cookies. Cookies are small text files that are stored on the User’s device, such as computer, mobile phone or tablet, when using the Service. We use non-necessary cookies to improve the User’s usage of the Service and to gather information about, for example, statistics about the usage of the Service. This is done to secure, maintain and improve the Service. The information that is collected through the cookies is regulated by our Cookie Policy
Users can at any time withdraw their consent to the use of cookies by changing the settings in the function ”Manage cookies” in the footer of the page.
8. Changes
We may make changes or update the Privacy Policy over time. The latest version of the Privacy Policy will always be available through the Service.
9. Contact
For questions, further information about our processing of your personal data or for contact with us in other matters, please contact dataprotection@astrea-bio.com