Candidate Privacy Policy
Privacy policy for recruitment using Teamtailor
At Mindler, your privacy and safety are of utmost importance to us. We strive to maintain the highest possible standard regarding the protection of personal data and to make our policies clear and understandable.
This Privacy Policy outlines how Mindler ("Controller" “we” “us” etc.) collects, processes and protects personal data when handling recruiting (the "Service"). To provide the Service and simplify the hiring process Mindler utilizes Teamtailor ("Processor", the “Site”) who acts under the instruction of Mindler. It is important that the persons using the Service ("Users”) feel safe and are informed about how we handle Users' personal data in the recruitment process.
1. General
We are the controller in accordance with current privacy legislation. The Users’ personal data is processed for the purpose of handling the recruitment of employees to our business.
2. Collection of personal data
We are responsible for the processing of the personal data that the Users contribute to the Service, or for the personal data that we in other ways collect with regards to the Service.
When and how we collect personal data
We collect personal data about Users from Users when Users;
make an application through the Service or otherwise, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn; and
use the Service to connect with our staff, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn.
provides identifiable data in the chat (provided through the website that uses the Service) and such data is of relevance to the application procedure;
We collect data from third parties, such as Facebook and LinkedIn, when the User provides this information as an attachment to the application or in other forms and use it for the purpose of handling recruiting.
In some cases, existing employees can make recommendations about potential applicants when such employees may share personal data about potential applicants with Mindler. In cases where this is done, the potential applicant is considered a User under this Privacy Policy and will be informed about the processing.
To find potential candidates, we may also collect data from publicly available sources, such as Facebook and LinkedIn (“Sourcing”). Sourcing can be manually performed by our employees or automatically in the Service. In cases where this is done, the potential applicant is also considered a User under this Privacy Policy and will be informed about the processing no later than one month from the first processing of personal information that we didn’t directly collect from the User.
The types of personal data collected and processed
The categories of personal data that can be collected through the Service can be used to identify natural persons from names, e-mails, pictures and videos, information from Facebook and LinkedIn-accounts, answers to questions asked through the recruiting, titles, education and other information that the User or others have provided through the Service. Only data that is relevant to the recruitment process is collected and processed.
Purpose and lawfulness of processing
The purpose of the processing of Users’ personal data stated above is to handle recruiting and the legal basis for that processing is the User’s given consent (GDPR Art. 6.1.a or UK GDPR Art. 6.1.a).
The purpose of the processing of personal data of potential applicants is Sourcing and the legal basis for processing is Mindler’s legitimate interest (GDPR Art. 6.1.f or UK GDPR Art. 6.1.f). Please contact us by using the contact details below should you like more information on how we have conducted our legitimate interest assessment for sourcing.
Personal data that is processed with the purpose of aggregated analysis or market research is always made unidentifiable. Such personal data cannot be used to identify a certain User. Thus, such data is not considered personal data.
The consent of the data subject
The User consents to the processing of its personal data with the purpose of the Controller’s handling recruiting. The User consents that personal data is collected through the Service, when Users;
make an application through the Service, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn, and that Controller may use external sourcing-tools to add additional information; and
when they use the Service to connect to the Controller's recruitment department, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn.
The User consents to the personal data being collected in accordance with the above a) and b) will be processed according to the below sections Storage and transfer and How long the personal data will be processed.
The User also consents to the Controller collecting publicly available information about the User from third-party systems such as Facebook and LinkedIn for the purpose of Sourcing.
The User has the right to withdraw his or her consent at any time, by contacting the Controller using the contact details listed under 9 or by removing the consent in the Site. Using this right may, however, mean that the User can not apply for a specific job or otherwise use the Service.
Storage and transfers
The personal data collected through the Service is stored and processed mainly within the EU/EEA. In some cases, we may transfer your personal data outside the EU/EEA, mainly in cases where we use service providers that process personal data outside the EU/EEA. When transferring personal data to a country outside the EU/EEA, or to a country which is not subject to an adequacy decision by the European Commission or considered adequate as determined by applicable data protection laws, we take appropriate legal, technical and organizational security measures to ensure that the personal data is adequately protected according to the same level of protection as within the EU/EEA. If your personal data is transferred outside the EU/EEA, then this is done on the basis of appropriate and adequate safeguards for data transfers to comply with the requirements set out in GDPR Chapter V. To obtain documentation regarding such adequate safeguards, contact us using the Contact details listed in 9.
How long the personal data will be processed
If a User does not object, in writing or by removing the consent in the Site, to the processing of their personal data, the personal data will be stored and processed by us as long as we deem it necessary or five (5) years from the date of actively consenting us processing their personal data with regards to the purposes stated above. Note that an applicant (User) may be interesting for future recruitment and for this purpose we may store Users’ Personal Data until they are no longer of value as potential recruitments. If you as a User wish not to have your Personal Data processed for this purpose (future recruitment) please contact us using the contact details in paragraph 9 or by removing the consent in the Site.
3. Users’ rights
Users have the right to request information about the personal data that is processed by us, by notifying us in writing, using the contact details below under paragraph 9 below. Users have the right to one (1) copy of the processed personal data which belongs to them without any charge. For further demanded copies, Controller has a right to charge a reasonable fee on the basis of the administrative costs for such demand.
Users have the right to, if necessary, rectification of inaccurate personal data concerning that User, via a written request, using the contact details in paragraph 9 below.
The User has the right to demand deletion or restriction of processing, and the right to object to processing based on legitimate interest under certain circumstances.
The User has the right to revoke any consent to processing that has been given by the User to Controller. Using this right may, however, mean that the User can not apply for a specific job or otherwise use the Service.
The User has under certain circumstances a right to data portability, which means a right to get personal data and transfer these to another controller as long as this does not negatively affect the rights and freedoms of others.
User has the right to lodge a complaint to the supervisory authority regarding the processing of personal data relating to them if the User considers that the processing of personal data infringes the legal framework of privacy laws.
4. Security
We prioritize personal integrity and therefore work actively so that the personal data of the Users are processed with utmost care. We take the measures that can be reasonably expected to make sure that the personal data of Users and others are processed safely and in accordance with this Privacy Policy and privacy legislations such as the GDPR and the UK GDPR.
However, transfers of information over the Internet and mobile networks can never occur without any risk, so all transfers are made at the User’s own risk of transferring their personal data. It is important that Users also take responsibility to ensure that their data is protected. It is the responsibility of the User that their login information is kept secret.
5. Transfer of personal data to third parties
We will not sell or otherwise transfer Users’ personal data to third parties.
We may transfer Users’ Personal Data to;
our contractors and subcontractors, acting as our Processors and Sub-Processors in accordance with our instructions, for the provision of the Service;
authorities or legal advisors in case criminal or improper behavior is suspected; and
authorities, legal advisors or other actors, if required by us according to law or authority’s injunction.
We will only transfer Users’ personal data to third parties that we have confidence in. We carefully choose partners to ensure that the User’s personal data is processed in accordance with current privacy legislation. We cooperate with the following categories of processors of personal data; Teamtailor, which supplies the Service, server and hosting companies, e-mail reference companies, video processing companies, information-sourcing companies, analytical service companies and other companies with regards to supplying the Service.
6. Aggregated data (non-identifiable personal data)
We may share aggregated data with third parties. The aggregated data has in such instances been compiled from information that has been collected through the Service and can, for example, consist of statistics of internet traffic or the geological location for the use of the Service. The aggregated data does not contain any information that can be used to identify individual persons and is thus not personal data.
7. Cookies
When Users use the Service, information about the usage may be stored as cookies. Cookies are passive text files that are stored in the internet browser on the User’s device, such as a computer, mobile phone or tablet, when using the Service. We use cookies to improve the User’s usage of the Service and to gather information about, for example, statistics about the usage of the Service. This is done to secure, maintain and improve the Service. The information that is collected through the cookies can in some instances be personal data and is, in such instances, regulated by our Cookie Policy.
Users can at any time disable the use of cookies by changing the local settings in their devices. Disabling cookies can affect the experience of the Service, for example disabling some functions in the Service.
8. Changes
We reserve the right and may make changes or additions to this Privacy Policy from time to time in response to changing legal, technical, or business developments. The latest version of the Privacy Policy will always be available through the Site. Minor changes to our Privacy Policy will be communicated through our Website. Major changes regarding how your data is processed will be communicated through the Website or email (using the e-mail stated by the User in connection to the use of the Service). We will not make substantial changes to this Privacy Policy or reduce your rights under this Privacy Policy without providing you with a notice.
This policy was last updated on 2024-03-27.
9. Contact
For questions or further information about our handling of personal data please contact us at privacy@mindler.se. In case you want to contact us on other matters, please reach out to adrian.lyng@mindler.se.
Complaints
Mindler has appointed Bird & Bird DPO Services SRL as our Data Protection Officer (DPO). If you have any questions or complaints about our compliance with this Privacy Policy or how we process your personal data, please contact our DPO via email at: dpo@mindler.se.
Our DPO may also be contacted at the following address: Bird & Bird DPO Services SRL, Avenue Louise 235 b 1, 1050 Brussels, Belgium.