Processing of (personal) data by the entity in charge of the online application process
1. General
This privacy notice was last modified onAugust 06, 2021.
TIGNUM truly values the privacy of your personal information and the content that you provide while applying for a position or sending your spontaneous application. This privacy notice explains what information we collect about you and what we may do with that information and how we handle your data. Please read the privacy notice carefully before applying for an open position announced by TIGNUM or sending us your spontaneous application.
This privacy notice relates to job candidates if not stated otherwise in this document. We have adopted principles to protect your personal data.
Learn more about this privacy notice and our principles
We would like to emphasize that this privacy notice has been prepared based on provisions of articles 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter “GDPR”). Personal data is any information which identifies or is capable of identifying an individual.
In addition, the scope of this notice is exclusively the recruitment carried out by TIGNUM, which means that it does not cover services and products provided by us. Different privacy notices cover the referred services and products (e.g. TIGNUM X).
Your privacy is critically important to us. At TIGNUM, we have a few fundamental principles:
_we only collect and process your data for explicit and specific purposes described in this privacy notice
_in regard to sensitive data, we are only going to process them in accordance with the GDPR and the parameters provided by this privacy notice
_you can request the deletion of your data at any time. In this case, we will delete it without undue delay, unless we are obliged to keep the data to comply with the law
_when the processing of your personal data is based on your consent, you can withdraw it at any time
_we implement technical and organizational measures in order to ensure the security and protection of your data
2. Who are we?
TIGNUM is the data controller, meaning that we have set the purposes and means of processing your personal data.
TIGNUM GmbH
Stresemannstr. 7
70192 Stuttgart
Germany
+49 711 411 60 500
3. Who is our Data Protection Officer?
We have indicated an external Data Protection Officer to monitor compliance with the GDPR.
Lars-Holger Krause (extern TERCENUM AG)
Altenwaldstraße 8
72768 Reutlingen
+49 7121 147 88 – 33
lars-holger.krause@tercenum.de
4. What data are collected from you?
We may collect and process the following personal data from you when you apply for a position announced by us or send your spontaneous application:
_contact details, such as your full name, address, email, telephone number, mobile number
_professional qualifications, such as diplomas, certificates, records of achievement, professional experience, language skills, academic background, references, assignments carried out by you during the recruitment process
_your salary expectations, availability and where are you from
_other data that you have voluntarily decided to include in your application, e.g. photo, social media profile, marital status, city, age, date and city of birth
For more information about what data is collected and for what purposes it is processed, please refer to section 5 of this privacy notice.
4.1 How do we collect your data?
We may collect your data:
_provided directly by you, when you apply for an open position announced by us or perform a spontaneous application
_provided by third parties – in particular head hunters – when you send your personal data to them in order to find a career opportunity for you
Even in the case when your data are provided by third parties, we ensure that they also comply with the GDPR in order to protect your personal data.
5. Why do we process your data?
While applying for a position or doing a spontaneous application, we might collect and process your data for the following purposes and based on the following legal grounds:
_contacting you in the context of recruitment
_analyzing the compatibility between your qualifications and the position´s requirements
_verifying visa requirements and eligibility to work
_concluding the employment-related contract
The collection and processing of your data are based on the following legal grounds:
_pre-contractual/contractual measures in the context of the recruitment process
_when we are required to process data to comply with a legal obligation
More details about data processed, purposes of processing an legal grounds
5.1 Contacting you in the context of recruitment
If you apply for a position or send your spontaneous application to us, we collect and use your information to communicate with you during the recruitment process (e.g. scheduling and performing interviews). These are in particular:
_full name
_email address
_other contact information, such as address, telephone/mobile number, social media profile, VoIP username
_your photo, if it is in your application
_your image and voice (e.g. digital interviews). Your image and voice will not be recorded by us
The processing of these data is necessary for TIGNUM to take steps prior to entering into a contract. The legal basis for this data processing is article 6(1)(b) GDPR and Section 26 of the German Federal Data Protection Act (BDSG), which means that it is required to carry out a pre-contractual measure, which takes place on your request.
5.2 Analyzing the compatibility between your qualifications and the position´s requirements
In order to analyze whether the position you applied for is suitable regarding your background and experience or whether your qualifications may match our intention for future positions, we may process the following personal data:
_application details, such as your CV, cover letter and reference letters
_qualifications, such as your diplomas, certificates, titles, records of achievement, records of participation, language skills, training achievements, professional experience, skills, portfolio, publications, memberships related to non-trade unions associations
_assignments carried out by you during the recruitment process
The legal basis is article 6(1)(b) GDPR and Section 26 of the German Federal Data Protection Act (BDSG), which means that we need to process these data for taking steps before entering into a contract in the context of recruitment.
5.3Verifying visa requirements and eligibility to work
We are required to verify whether a successful applicant is eligible to work in Germany or in the US before starting the employment relationship. In this sense, we may process your personal data, such as:
_identification details, such as data inserted in your passport, ID card (e.g. photo, nationality, city of birth, passport number, date of expiry)
_data contained in your residence title and in your work permit, such as issuance date, document number, date of expiry.
The legal grounds for the data processing are the necessity to take pre-contractual measures and to perform the contract pursuant to article 6(1)(b) GDPR and the necessity to comply with German or American legal obligation – article 6(1)(c) GDPR.
Since your nationality, city of birth (and other information about origin) and photo are sensitive data, we can only process it under specific conditions set by the GDPR. In this case, the processing condition is that the processing is necessary to exercise rights and/or comply with legal obligations derived from labour law, social security and social protection law – article 9(2)(b) GDPR.
5.4 Concluding the contract
After a hiring decision, if you decide to accept our job offer, we may process your personal data in order to conclude the contract with you, including:
_contact details
_role-related information, e.g. role, seniority, salary to be paid in regard to the role, work location, date of start
Since the processing is necessary to take steps prior to entering into a contract with you, the legal basis is article 6(1)(b) GDPR and Section 26 of the German Federal Data Protection Act (BDSG).
6. How and where do we process personal data?
We have technological and operational security functions in place to protect personal data from loss, misuse, alteration, unauthorized access or destruction. Only authorized employees have access to the data you provided and that access is limited by need.
Only authorized employees have access to the data you provided and the access is limited by need and by the purpose of processing. This means that your personal data will be collected only for specified, explicit and legitimate purposes described in this privacy notice and will not be processed outside of the purpose of processing.
The data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated.
Your data may be accessible to certain types of persons in charge, involved with the operation of the recruitment process (HR, hiring manager, team leads or external parties (such as Personio GmbH, Zoom, Microsoft Teams) appointed, if necessary, as data processors by TIGNUM.
In regard to personal data subject to the GDPR, the data is processed at the TIGNUM’s operating offices (Germany) and in any other places where the parties involved in the processing are located. Personio GmbH is our main data processor for recruitment purposes and it stores the candidate’s personal data on AWS server hosted in Frankfurt (EU). The data are encrypted at rest and in-transit.
Candidates can request a data transfer by contacting us at any time. You can request a data transfer by contacting us any time by emailing us at privacy@tignum.com.
7. Who else has access to your personal data?
We do not sell your data to third parties. However, we may transfer your data to third parties in the following cases:
_when service providers are processing personal data on behalf of TIGNUM
_when the transfer is necessary for the implementation of the contract or pre-contractual measures with you
_when we are legally obliged to do so, e.g. to comply with EU or National law or in the context of a court order or another official authority
_when you have given express consent to the transfer in advance
When your data is transferred to external service providers, we ensure that:
_the minimum personal data are transmitted, which means that only the data necessary for the purpose of processing will be transferred
_the data recipients, when acting as data processors, comply with the GDPR, in particular the article 28, which sets obligations for the processor, such as providing sufficient guarantees to implement appropriate technical and organizational measures and ensuring the protections of the rights of individuals.
7.1 Categories of data processors
_email service providers and video communication service providers, to communicate with you
_HR management service providers, to prepare, organize and manage the recruitment process and job applications
_recruitment websites and LinkedIn, to publish the job announcements
8. Do we transfer your data to third countries?
If you are an EU resident, your data may be transferred to outside the EU/EEA, including to countries considered not to be adequate in terms of data protection, such as the USA. We will make sure that the level of protection of your personal data observe the standards set by the GDPR and that we and the data recipients observe and comply with the EU data protection law.
We only transfer your personal data based on:
_adequacy decisions adopted by the European Commission (article 45 GDPR)
_standard contractual clauses adopted or approved by the European Commission
_your explicit and valid consent given specifically to implement the international transfer of your personal data
_other derogations of article 49 GDPR, such as the need to implement the contract or when required by law
9. How long do we keep your data?
Personal data will be processed and stored for as long as required by the purpose for which they have been collected or for compliance with European or national laws. Once the retention period expires, personal data will be anonymized or securely deleted.
_personal data collected for the purposes of TIGNUM’s recruitment process shall be retained as long as needed to fulfill such purposes. Personal data is kept for the duration of the recruitment.After the end of the recruitment process, personal data will be stored for a period of up to 7 months, unless you receive and accept a job offer from us
_personal data collected on the basis of your consent will be retained until the consent is withdrawn or their purpose is fulfilled
_furthermore, we may be required to retain your personal data for a longer period whenever required to do so for compliance with a legal obligation, for the establishment, exercise or defence of legal claims or by order of a public authority
10. What are your rights?
As an individual protected by the GDPR, you have the following rights, to the extent that the legal requirements are met:
_right to revoke/withdraw your consent
_right to information
_right to access your personal data
_right to have your personal data rectified and completed
_right to have your personal data erased
_other rights
In order to assert your rights, you can contact us at any time at privacy@tignum.com or send a message to the address stated under the section “who are we?”.
10.1 Your rights
_right to revoke/withdraw your consent by contacting us at privacy@tignum.com, when your personal data is processed based on your consent. In other words, you have the right to withdraw/cancel your consent at any time. By doing this, we are going to stop the processing your personal data based on your consent. However, if you withdraw your consent, this will not affect the legality of the processing made before this decision
_you can request information from TIGNUM at any time as to whether personal data and which categories of personal data about you are processed, for what purposes they are processed, which are the legal grounds for processing, who are the recipients or categories of recipients they may be disclosed to and if international transfer of data is intended and under which legal grounds. Additionally, we will provide you with the following information: the data storage period or the criteria used to determine this period; the existence of the rectification, erasure right, right to restrict the processing or the right to lodge a complaint with the data protection authority; information about the source when the data are not collected directly from you; the existence of automated decision-making. The copy related to your personal data processed will be provided to you free of charge. In case of any additional copies requested by you, we may charge a fee based on administrative cost
_you also have a right to correct or complement your personal data, which means that we must rectify your inaccurate data or complete your personal data without undue delay
_right to have your personal data deleted without undue delay, unless if the processing is necessary for exercising the right of freedom of expression and information; for compliance with a legal obligation; for reasons of public interest in the area of public health; archiving purposes in the public interest; and for the establishment, exercise or defence of legal claims
_right to restriction of the processing of your personal data in the following cases: when you contest the accuracy of your personal data; when the processing is unlawful; we no longer need your personal data for the purposes of processing but you request them for establish, exercise or defend legal claims; you have objected to the processing
_you also have the right to receive from TIGNUM the personal data concerning you which you have provided to us in a structured, common and machine-readable format; you may also transmit or have transmitted this personal data to other controllers, as long as this is technically feasible (right to data portability)
_you have the right to lodge a complaint with a supervisory authority, in particular in the country of your place of residence, workplace or place of presumed infringement, if you are of the opinion that the processing of your personal data violates the GDPR
_in addition, if the processing is based on legitimate interests, you have the right to object the data processing at any time. This also applies for profiling. This means that your personal data will no longer be processed by us, unless we have a compelling reason to continue processing your data
11. Additional information about data collection and processing
11.1. Legal action
Your personal data may be used for legal purposes by TIGNUM in court or in the stages leading to possible legal action arising from improper use of the recruitment procedure and system.
11.2. Additional information about candidate´s personal data
In addition to the information contained in this privacy notice, TIGNUM may provide the candidate with additional and contextual information concerning particular services or the collection and processing of personal data upon request.
11.3. Changes to this privacy notice
TIGNUM reserves the right to make changes to this privacy notice at any time by informing candidates on this page and/or - as far as technically and legally feasible - sending a notice to candidates via any contact information available to TIGNUM. It is strongly recommended to check this page often, referring to the date of the last modification listed at the top.
Should the changes affect processing activities performed on the basis of your consent, we will collect new consent from you, where required.