Privacy Notice for Recruitment using TeamTailor
The service for handling recruitments and simplifying the hiring process (the "Service") is powered by Teamtailor on behalf of KPMG Global Services Hungary ("Controller" “we” “us” etc.). It is important that the persons using the Service ("Users”) feel safe with, and are informed about, how we handle User's personal data in the recruitment process. We strive to maintain the highest possible standard regarding the protection of personal data. We process, manage, use, and protect User's Personal Data in accordance with this Privacy Notice ("Privacy Notice").
1. General
We are the controller, in accordance with current privacy legislation. The Users’ personal data is processed with the purpose of managing and facilitating recruitment of employees to our business.
2. Collection of personal data
We are responsible for the processing of the personal data that the Users contribute to the Service, or for the personal data that we in other ways collect with regards to the Service.
When and how we collect personal data?
We collect personal data about Users from Users when Users
- make an application through the Service or otherwise, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn; and
- use the Service to connect with our staff, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn.
- provide identifiable data in chat (provided through the website that uses the Service) and where such data is of relevance to the application procedure;
We also collect data from third parties, such as LinkedIn and through other public professional sources (i.e. press, professional associations). This is referred to as “Sourcing” and may be manually performed by our employees in the Service.
In some cases, existing employees can make recommendations about potential applicants. Such employees will add personal data about such potential applicants. In the cases where this is done, the potential applicant is considered a User in the context of this Notice or Procedure and will be informed about the processing.
The types of personal data collected and processed
The categories of personal data that can be collected through the Service and can be used to identify natural persons are names, e-mails, pictures and videos (if shared by the User), information from LinkedIn-accounts, answers to questions asked through recruiting, the titles, education and/or other information that the User or others have provided through the Service. Only data that is relevant for the recruitment process is collected and processed.
Purpose and lawfulness of processing
The purpose of data processing is the enablement of the Recruitment process. The lawful basis is Consent, collected from the User by the Service.
Personal data that is processed with the purpose of aggregated analysis or market research is always made unidentifiable in terms of individuals. Such personal data cannot be used to identify a specific User. Thus, such data is not considered personal data.
The consent of the data subject
The User consents to the processing of their personal data with the purpose of the Controller’s handling of recruiting. The User consents that personal data may be collected through the Service, when Users
a. make an application through the Service, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn; and
b. when they use the Service to connect to the Controller’s recruitment department, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn.
The User also consents to the Controller collecting publicly available professional information about the User and compiling such for use for recruitment purposes.
The User consents to their personal data being collected in accordance with the above a) and b) and that such data will be processed according to the below sections: Storage and Transfer and How long the personal data will be processed.
The User has the right to withdraw his or her consent at any time, by contacting the Controller using the contact details listed under 9. Using this right may however, mean that the User can thereafter not apply for a specific job or otherwise use the Service.
Storage and Transfers
The personal data collected through the Service is stored and processed inside the EU/EEA, any third country that is considered by the European Commission to have an adequate level of protection, or where data is processed by such suppliers that have entered into such binding agreements that fully comply with the lawfulness of third country transfers (as Privacy Shield) - or to other supplies where the adequate safeguards are in place in order to protect the rights of the data subjects whose data is transferred. To obtain documentation regarding such adequate safeguards, contact us using the Contact details listed in 9.
How long the personal data will be processed
If a User does not object, in writing, to the processing of their personal data, the personal data will be stored and processed by the controlling entity for as long as professional practice dictates but no longer than 2 years with regards to the purposes stated above. Please note that an applicant (User) may be interesting for future recruitment and for this purpose we may store Users’ Personal Data until they are no longer of value as potential recruitments. If you as a User wish not to have your Personal Data processed for this purpose (future recruitment) you have the option to delete your data from the platform at any point. In case of inactivity your profile will be automatically deleted after 6 months.
3. Users’ rights
Users have the right to request information about the personal data that is processed by us, by notifying us in writing using the contact details below under paragraph 9 below. Users have the right to one (1) copy of the processed personal data which belongs to them, free of charge. For further demanded copies, the Controller has the right to charge a reasonable fee on the basis of the administrative costs for such a demand.
Users have the right, if necessary, to the rectification of inaccurate personal data concerning that User, via the platform. Each User has access to modify/delete their data, and in cases of any further concern the User can send a written request, using the contact details in paragraph 9 below.
The User has the right to demand deletion or restriction of processing, and the right to object to processing based on legitimate interests under certain circumstances.
The User has the right to revoke any consent to processing that has or had been given by the User to Controller. Using this right may however, mean that the User can not apply for a specific job or otherwise use the Service.
The User has, under certain circumstances, the right to data portability, which means a right to obtain their personal data and transfer such to another controller as long as this does not negatively affect the rights and freedoms of others.
Users have the right to lodge a complaint to the supervisory authority regarding the processing of personal data relating to him or her, if the User considers that the processing of personal data infringes the legal framework of privacy law.
Click here to see the availability of the Hungarian supervisory authority: NAIH
4. Security
We prioritize personal integrity and therefore we work actively so that the personal data of the Users are processed with utmost care. We take the measures that can be reasonably expected to make sure that the personal data of Users and others are processed safely and in accordance with this Notice and standard GDPR-regulations.
However, transfers of information over the internet and mobile networks can never occur with zero risk, so all transfers are made at the own risk of the person transferring the data. It is important that Users also take responsibility to ensure that their data is protected. It is the responsibility of the User that their login information is kept secret.
5. Transfer of personal data to a third party
We will not sell or otherwise transfer Users’ personal data to third parties other than our contracted suppliers/sub-contractors. We may transfer Users’ Personal Data to
- our contractors and sub-contractors, acting as our Processors and Sub-Processors in accordance with our instructions, in line with the provision of the Service;
- authorities or legal advisors, if criminal or improper behaviour is suspected; and
- authorities, legal advisors or other actors, if required of us according to the law or authority’s injunction.
We will only transfer Users’ personal data to third parties that we have confidence in. We carefully choose partners to ensure that the User’s personal data is processed or used in accordance with current privacy legislations. We cooperate with the following processors and categories of processors of personal data:
- TeamTailor, an entity which supplies the Service, also
- server and hosting companies,
- e-mail reference companies, video processing companies, information-sourcing companies, analytical service companies and other companies with regards to suppling the Service.
6. Aggregated Data (non-identifiable personal data)
We may share aggregated data with third parties. Such aggregated data has in such instances been compiled from information that has been collected through the Service and can, for example, consist of statistics of internet traffic or the geographical location(s) for the use of the Service. Such aggregated data does not contain any information that can be used to identify individual persons and is thus not personal data.
7. Cookies
When Users use the Service, information about the usage may be stored as cookies. Cookies are passive text files that are stored in the internet browser on the User’s device, such as computer, mobile phone or tablet, when using the Service. We use cookies to improve the User’s experience of the Service and to gather information about, for example, statistics on the usage of the Service. This is done to secure, maintain and improve the Service. The information that is collected through such cookies can in some instances be related to personal data and is, in such instances, regulated by our Cookie Policy.
Users can at any time disable the use of cookies by changing the local settings in their devices. Disabling of cookies can affect the experience of the Service, for example it may disable some functions in the Service.
8. Changes
We have the right to, at any time, make changes or additions to the Privacy Notice. The latest version of the Privacy Notice will always be available through the Service. A new version is considered communicated to the Users when the User has either received an email informing the User of the new version (using the latest e-mail address given by the User in connection with their use of the Service) or when the User is otherwise informed of the new Privacy Notice.
9. Contact
For questions, further information about our handling of personal data or for contact with us in other matters, please use the following contact details: DataPrivacyKGSH@kpmg.hu.
Please also read KPMG Global Services Hungary's Fair Processing Notice (Privacy Statement)