Skip to main content

Processing of (personal) data by the entity in charge of the online application process

1. General

This privacy notice was last modified onAugust 06, 2021.

TIGNUM truly values the privacy of your personal information and the content that you provide while applying for a position or sending your spontaneous application. This privacy notice explains what information we collect about you and what we may do with that information and how we handle your data. Please read the privacy notice carefully before applying for an open position announced by TIGNUM or sending us your spontaneous application.

This privacy notice relates to job candidates if not stated otherwise in this document. We have adopted principles to protect your personal data.

Learn more about this privacy notice and our principles

We would like to emphasize that this privacy notice has been prepared based on provisions of articles 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter “GDPR”). Personal data is any information which identifies or is capable of identifying an individual.

In addition, the scope of this notice is exclusively the recruitment carried out by TIGNUM, which means that it does not cover services and products provided by us. Different privacy notices cover the referred services and products (e.g. TIGNUM X).

Your privacy is critically important to us. At TIGNUM, we have a few fundamental principles:

_we only collect and process your data for explicit and specific purposes described in this privacy notice

_in regard to sensitive data, we are only going to process them in accordance with the GDPR and the parameters provided by this privacy notice

_you can request the deletion of your data at any time. In this case, we will delete it without undue delay, unless we are obliged to keep the data to comply with the law

_when the processing of your personal data is based on your consent, you can withdraw it at any time

_we implement technical and organizational measures in order to ensure the security and protection of your data

2. Who are we?

TIGNUM is the data controller, meaning that we have set the purposes and means of processing your personal data.

TIGNUM GmbH

Stresemannstr. 7

70192 Stuttgart

Germany

+49 711 411 60 500

privacy@tignum.com

3. Who is our Data Protection Officer?

We have indicated an external Data Protection Officer to monitor compliance with the GDPR.

Lars-Holger Krause (extern TERCENUM AG)

Altenwaldstraße 8                                    

72768 Reutlingen                          

+49 7121 147 88 – 33

lars-holger.krause@tercenum.de

4. What data are collected from you?

We may collect and process the following personal data from you when you apply for a position announced by us or send your spontaneous application:

_contact details, such as your full name, address, email, telephone number, mobile number

_professional qualifications, such as diplomas, certificates, records of achievement, professional experience, language skills, academic background, references, assignments carried out by you during the recruitment process

_your salary expectations, availability and where are you from

_other data that you have voluntarily decided to include in your application, e.g. photo, social media profile, marital status, city, age, date and city of birth

For more information about what data is collected and for what purposes it is processed, please refer to section 5 of this privacy notice.

4.1 How do we collect your data?

We may collect your data:

_provided directly by you, when you apply for an open position announced by us or perform a spontaneous application

_provided by third parties – in particular head hunters – when you send your personal data to them in order to find a career opportunity for you

Even in the case when your data are provided by third parties, we ensure that they also comply with the GDPR in order to protect your personal data.

5. Why do we process your data?

While applying for a position or doing a spontaneous application, we might collect and process your data for the following purposes and based on the following legal grounds:

_contacting you in the context of recruitment

_analyzing the compatibility between your qualifications and the position´s requirements

_verifying visa requirements and eligibility to work

_concluding the employment-related contract

The collection and processing of your data are based on the following legal grounds:

_pre-contractual/contractual measures in the context of the recruitment process

_when we are required to process data to comply with a legal obligation

More details about data processed, purposes of processing an legal grounds

5.1 Contacting you in the context of recruitment

If you apply for a position or send your spontaneous application to us, we collect and use your information to communicate with you during the recruitment process (e.g. scheduling and performing interviews). These are in particular:

_full name

_email address

_other contact information, such as address, telephone/mobile number, social media profile, VoIP username

_your photo, if it is in your application

_your image and voice (e.g. digital interviews). Your image and voice will not be recorded by us

The processing of these data is necessary for TIGNUM to take steps prior to entering into a contract. The legal basis for this data processing is article 6(1)(b) GDPR and Section 26 of the German Federal Data Protection Act (BDSG), which means that it is required to carry out a pre-contractual measure, which takes place on your request.

5.2 Analyzing the compatibility between your qualifications and the position´s requirements

In order to analyze whether the position you applied for is suitable regarding your background and experience or whether your qualifications may match our intention for future positions, we may process the following personal data:

_application details, such as your CV, cover letter and reference letters

_qualifications, such as your diplomas, certificates, titles, records of achievement, records of participation, language skills, training achievements, professional experience, skills, portfolio, publications, memberships related to non-trade unions associations

_assignments carried out by you during the recruitment process

The legal basis is article 6(1)(b) GDPR and Section 26 of the German Federal Data Protection Act (BDSG), which means that we need to process these data for taking steps before entering into a contract in the context of recruitment.

5.3Verifying visa requirements and eligibility to work

We are required to verify whether a successful applicant is eligible to work in Germany or in the US before starting the employment relationship. In this sense, we may process your personal data, such as:

_identification details, such as data inserted in your passport, ID card (e.g. photo, nationality, city of birth, passport number, date of expiry)

_data contained in your residence title and in your work permit, such as issuance date, document number, date of expiry.

The legal grounds for the data processing are the necessity to take pre-contractual measures and to perform the contract pursuant to article 6(1)(b) GDPR and the necessity to comply with German or American legal obligation – article 6(1)(c) GDPR.

Since your nationality, city of birth (and other information about origin) and photo are sensitive data, we can only process it under specific conditions set by the GDPR. In this case, the processing condition is that the processing is necessary to exercise rights and/or comply with legal obligations derived from labour law, social security and social protection law – article 9(2)(b) GDPR.

5.4 Concluding the contract

After a hiring decision, if you decide to accept our job offer, we may process your personal data in order to conclude the contract with you, including:

_contact details

_role-related information, e.g. role, seniority, salary to be paid in regard to the role, work location, date of start

Since the processing is necessary to take steps prior to entering into a contract with you, the legal basis is article 6(1)(b) GDPR and Section 26 of the German Federal Data Protection Act (BDSG).

6. How and where do we process personal data?

We have technological and operational security functions in place to protect personal data from loss, misuse, alteration, unauthorized access or destruction. Only authorized employees have access to the data you provided and that access is limited by need.

Only authorized employees have access to the data you provided and the access is limited by need and by the purpose of processing. This means that your personal data will be collected only for specified, explicit and legitimate purposes described in this privacy notice and will not be processed outside of the purpose of processing.

The data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated.

Your data may be accessible to certain types of persons in charge, involved with the operation of the recruitment process (HR, hiring manager, team leads or external parties (such as Personio GmbH, Zoom, Microsoft Teams) appointed, if necessary, as data processors by TIGNUM.

In regard to personal data subject to the GDPR, the data is processed at the TIGNUM’s operating offices (Germany) and in any other places where the parties involved in the processing are located.
 Personio GmbH is our main data processor for recruitment purposes and it stores the candidate’s personal data on AWS server hosted in Frankfurt (EU). The data are encrypted at rest and in-transit.

Candidates can request a data transfer by contacting us at any time. You can request a data transfer by contacting us any time by emailing us at privacy@tignum.com.

7. Who else has access to your personal data?

We do not sell your data to third parties. However, we may transfer your data to third parties in the following cases:

_when service providers are processing personal data on behalf of TIGNUM

_when the transfer is necessary for the implementation of the contract or pre-contractual measures with you

_when we are legally obliged to do so, e.g. to comply with EU or National law or in the context of a court order or another official authority

_when you have given express consent to the transfer in advance

When your data is transferred to external service providers, we ensure that:

_the minimum personal data are transmitted, which means that only the data necessary for the purpose of processing will be transferred

_the data recipients, when acting as data processors, comply with the GDPR, in particular the article 28, which sets obligations for the processor, such as providing sufficient guarantees to implement appropriate technical and organizational measures and ensuring the protections of the rights of individuals.

7.1 Categories of data processors

_email service providers and video communication service providers, to communicate with you

_HR management service providers, to prepare, organize and manage the recruitment process and job applications

_recruitment websites and LinkedIn, to publish the job announcements

8. Do we transfer your data to third countries?

If you are an EU resident, your data may be transferred to outside the EU/EEA, including to countries considered not to be adequate in terms of data protection, such as the USA. We will make sure that the level of protection of your personal data observe the standards set by the GDPR and that we and the data recipients observe and comply with the EU data protection law.

We only transfer your personal data based on:

_adequacy decisions adopted by the European Commission (article 45 GDPR)

_standard contractual clauses adopted or approved by the European Commission

_your explicit and valid consent given specifically to implement the international transfer of your personal data

_other derogations of article 49 GDPR, such as the need to implement the contract or when required by law

9. How long do we keep your data?

Personal data will be processed and stored for as long as required by the purpose for which they have been collected or for compliance with European or national laws. Once the retention period expires, personal data will be anonymized or securely deleted.

_personal data collected for the purposes of TIGNUM’s recruitment process shall be retained as long as needed to fulfill such purposes. Personal data is kept for the duration of the recruitment.After the end of the recruitment process, personal data will be stored for a period of up to 7 months, unless you receive and accept a job offer from us

_personal data collected on the basis of your consent will be retained until the consent is withdrawn or their purpose is fulfilled

_furthermore, we may be required to retain your personal data for a longer period whenever required to do so for compliance with a legal obligation, for the establishment, exercise or defence of legal claims or by order of a public authority

10.  What are your rights?

As an individual protected by the GDPR, you have the following rights, to the extent that the legal requirements are met:

_right to revoke/withdraw your consent

_right to information

_right to access your personal data

_right to have your personal data rectified and completed

_right to have your personal data erased

_other rights

In order to assert your rights, you can contact us at any time at privacy@tignum.com or send a message to the address stated under the section “who are we?”.

10.1 Your rights

_right to revoke/withdraw your consent by contacting us at privacy@tignum.com, when your personal data is processed based on your consent. In other words, you have the right to withdraw/cancel your consent at any time. By doing this, we are going to stop the processing your personal data based on your consent. However, if you withdraw your consent, this will not affect the legality of the processing made before this decision

_you can request information from TIGNUM at any time as to whether personal data and which categories of personal data about you are processed, for what purposes they are processed, which are the legal grounds for processing, who are the recipients or categories of recipients they may be disclosed to and if international transfer of data is intended and under which legal grounds. Additionally, we will provide you with the following information: the data storage period or the criteria used to determine this period; the existence of the rectification, erasure right, right to restrict the processing or the right to lodge a complaint with the data protection authority; information about the source when the data are not collected directly from you; the existence of automated decision-making. The copy related to your personal data processed will be provided to you free of charge. In case of any additional copies requested by you, we may charge a fee based on administrative cost

_you also have a right to correct or complement your personal data, which means that we must rectify your inaccurate data or complete your personal data without undue delay

_right to have your personal data deleted without undue delay, unless if the processing is necessary for exercising the right of freedom of expression and information; for compliance with a legal obligation; for reasons of public interest in the area of public health; archiving purposes in the public interest; and for the establishment, exercise or defence of legal claims

_right to restriction of the processing of your personal data in the following cases: when you contest the accuracy of your personal data; when the processing is unlawful; we no longer need your personal data for the purposes of processing but you request them for establish, exercise or defend legal claims; you have objected to the processing

_you also have the right to receive from TIGNUM the personal data concerning you which you have provided to us in a structured, common and machine-readable format; you may also transmit or have transmitted this personal data to other controllers, as long as this is technically feasible (right to data portability)

_you have the right to lodge a complaint with a supervisory authority, in particular in the country of your place of residence, workplace or place of presumed infringement, if you are of the opinion that the processing of your personal data violates the GDPR

 

_in addition, if the processing is based on legitimate interests, you have the right to object the data processing at any time. This also applies for profiling. This means that your personal data will no longer be processed by us, unless we have a compelling reason to continue processing your data

11. Additional information about data collection and processing

11.1.  Legal action

Your personal data may be used for legal purposes by TIGNUM in court or in the stages leading to possible legal action arising from improper use of the recruitment procedure and system.

11.2. Additional information about candidate´s personal data

In addition to the information contained in this privacy notice, TIGNUM may provide the candidate with additional and contextual information concerning particular services or the collection and processing of personal data upon request.

11.3. Changes to this privacy notice

TIGNUM reserves the right to make changes to this privacy notice at any time by informing candidates on this page and/or - as far as technically and legally feasible - sending a notice to candidates via any contact information available to TIGNUM. It is strongly recommended to check this page often, referring to the date of the last modification listed at the top.

Should the changes affect processing activities performed on the basis of your consent, we will collect new consent from you, where required.

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.