Data Security

Privacy Policy for Taledo

In the following, we, Taledo GmbH (“Taledo”), would like to inform you about how we process your personal data when visiting www.taledo.com, the recruitment services offered (“the services”) and what rights you are entitled to.

Taledo GmbH, located at Rosa-Luxemburg-Straße 7, 10178 Berlin , is responsible for all data processing. Should you have any questions or suggestions, you may contact us in writing at the aforementioned address, by telephone at +49 (30) 220 6637 0 or by e-mail at [email protected].

This Privacy Policy naturally only applies to our website and services and does not include contents and websites of third parties to which our website and services merely link. This equally applies to the personal data that you provide via such platforms, for instance by contacting us via our profile posted on such platforms. Information regarding the management and protection of your personal data on these platforms can be found in the data protection declaration of the respective platform.

1. DATA COLLECTED WHEN USING THE WEBSITE

1.1 When visiting our website, the web server we use automatically logs information transmitted by your browser. This includes the IP address of the computer or other device you are using, the date and time (including time zone) at which the website was accessed, information regarding which part of our website was visited and the files requested on our website, the transferred data volume, the domain via which the respective request was made (so-called Referrer-URL), the operating system used and the browser used.

The legal basis for data processing enabling the use of the website is Art. 6 para. 1 sentence 1 lit. f) of the Basic Data Protection Ordinance (“GDPR”) or, in the case where you are already registered for the services, the legal basis is Art. 6 para. 1 sentence 1 lit. b) GDPR.

1.2 We also process this information in order to prevent the misuse of our website and services, to analyze and optimize the use of our website and services. The legal basis of this processing can be found under Art. 6 para. 1 sentence 1 lit. f) GDPR, where our legitimate interests are the security and enhancement of our website and services.

2. USE OF COOKIES

Our services use cookies. Cookies are small text files which store settings and data on your device. This data is then subsequently transmitted to us each time you access our services. Cookies enable us to recognize your device and, if possible, to make your pre-settings immediately available.

Cookies allow us to make our services more user-friendly and effective, by storing the settings which you use to display our services during your visit and providing us with statistical information on the use of the website and our services. Cookies are only set with your consent (Article 6 (1) sentence 1 (a) GDPR).

Most cookies we use are so-called “session cookies”. They are automatically erased after visiting our website. Other cookies remain stored on your device for 14 days, unless they are deleted by your earlier.

Usually, you can set your browser so that you are informed about the setting of cookies, or that the setting is excluded for certain cases or in general, or that you allow the setting of cookies in individual cases. You can also delete saved cookies in your browser settings. However, disabling cookies may limit the functionality of this website.

3. USE OF GOOGLE ANALYTICS

We use Google Analytics. This is a web analysis service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”), which uses cookies to analyze your use of our website. The information generated by cookies is transmitted by Google to a Google server in the USA and subsequently stored there. We use the extension “anonymizeIP()”. By activating this extension for our website, your IP address will be shortened before being sent to a Google server in the USA within the member states of the EU or other contracting states of the European Economic Area. Google uses the information on our behalf to evaluate your use of our website, to generate reports regarding the website activity and to provide us with other services relating to website and internet use.

The IP address transmitted by Google Analytics from your browser is not merged with any other data provided by Google.

You can prevent the storage of cookies by selecting the appropriate setting on your browser. You may however, in this case, not be able to use the full functionality of our website. Furthermore, you can prevent the collection of data generated by the cookies, related to your use of our website and services (including your IP address) and the processing of this data by Google by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout . You can also prevent the future use of Google Analytics, especially when accessing our website from browsers on mobile devices, by clicking on the following link: here. By clicking on the link, an opt-out cookie is stored on your device. It is thereforenecessary to save it again by clicking on the link if you delete the cookies on your device.

Further information regarding how Google processes personal data in in relation to Google Analytics can be found on the corresponding Google website ( https://marketingplatform.google.com/about/ ) and in Google’s data protection declaration ( https://policies.google.com/privacy?hl=de&gl=de ).

The EU Commission has issued an adequacy decision (No. 2016/1250) for any transmission to the US, according to which companies that meet certain criteria are guaranteed an adequate level of protection, also known as the “EU-US Privacy Shield”. These companies are listed in the so-called “Privacy Shield List” or “Privacy Shield List”. Google is one of the companies listed there. The transmission to Google in connection with Google Analytics is based on Art. 45 and 28 GDPR.

We use Google Analytics to analyze the use of our website and services and to continuously develop our website and services in terms of user-friendliness. The legal basis for the use of Google Analytics is Art. 6 Par. 1 S. 1 lit. f) GDPR. Our legitimate interest is the optimization and further development of our website and services.

4. USE OF HOTJAR

We use Hotjar in order to better understand our users’ needs and to optimize our service and your experience. Hotjar is a technology service that helps us better understand our users experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our platform with user feedback. Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices (in particular device’s IP address (captured and stored only in anonymized form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), preferred language used to display our website). Hotjar stores this information in a pseudonymized user profile. Neither Hotjar nor we will ever use this information to identify individual users or to match it with further data on an individual user. For further details, please see Hotjar’s privacy policy by clicking on this link.

You can opt-out to the creation of a user profile, Hotjar’s storing of data about your usage of our site and Hotjar’s use of tracking cookies on other websites by following this opt-out link.

5. DATA COLLECTED FROM REGISTERED USERS AND PROCESSING OF SUCH DATA

5.1 Data collected during registration

5.1.1 You must register to use the Services. You have the choice between registering as an employer or an applicant. In both cases, you must enter your name, your e-mail address and a password of your own choice to register.

If you register as an applicant seeking job offers, you must in addition provide the following job-related information, which will be included in your user profile: Your place of residency, work experience, basic information about your preferred job (location, field/industry, position) and your employment status (i.e. whether you are currently actively looking for a new job). You must also send us your CV. The communication of your personal data is not required by law, but is required to conclude the contract regarding the use of our services. You may also voluntarily provide additional information to supplement your user profile, such as your exact professional background, the existence of a work permit and details of your skills and experience.

5.1.2 We will process all of the aforementioned personal data of your user profile solely for the purpose of providing the services on the basis of Art. 6 para. 1 sentence 1 lit. b) GDPR.

5.2 Use of the Services

5.2.1 We process the personal data of your user profile in order to provide the services. If you are registered as an applicant, we may also recommend your profile to an employer with regard to a job application, and in this context transfer your personal information stored in your profile.

In addition, we offer communication services through which you can communicate with an employer or applicant. We can thus, for this purpose, transmit data from your user profile and the message content to your communication partner.

The legal basis for the above mentioned data processing is Art. 6 (1) (b) GDPR.

5.2.2 Please note that employers or applicants registered for our services may also be located outside the EU, such as in the US. By providing the services, we can therefore also transfer your personal data to these countries. Transmission will only take place if an appropriate level of protection is guaranteed or if you expressly consent to it after having been informed about the potential risks of such data transmissions without suitable guarantees. The legal basis for these transmissions is Article 6 (1) (b) GDPR and Art. 45 GDPR (if there is an adequacy decision set by the Commission), Art. 46 GDPR (if the respective recipient provides sufficient guarantees) or Art. 47 GDPR, for all other cases.

5.2.3 We may also process the contents of the message in order to improve, detect and prevent misuse of our services. Such data processing is carried out on the basis of Art. 6 (1) (f) GDPR. Our legitimate interest is the optimization of our services and ensuring the proper use of our services.

5.2.4 If a contract between you and an applicant or employer has been concluded, we collect remuneration data from this contract (employment date, job title, and agreed remuneration including any bonus payments). The disclosure of this information is set in the contract regarding the use of our services, so failure to notify us will result in breach of your contract with us. We will process this data together (if necessary with the payment information provided by you) to calculate and bill our compensation as well as, if necessary, to determine your bonus payments, which we may wish to grant you. The legal basis for this processing is Article 6 (1) sentence 1 lit. b) GDPR.

6. NEWSLETTER

You can register for our newsletter service if you wish to receive regular updates regarding our services.

For the registration and sending of the newsletter we need your valid e-mail address. To make sure that you actually want to receive information from us, we use the so-called double opt-in procedure. Once you have registered, you will receive an e-mail containing a link to activate the newsletter service. Only after you have activated the newsletter service in this way will your registration be effective and the selected newsletter will be sent to you.

Of course, you can unsubscribe from the e-mail newsletter and revoke your consent to receive the newsletter at any time. You can object to the use of your e-mail address at any time without incurring any costs other than the transmission costs according to the basic rates. All you have to do is send an informal e-mail to [email protected] or click on the unsubscribe link contained in each newsletter.

The legal basis for data processing in connection with the newsletter is your consent pursuant to Art. 6 para. 1 sentence 1 lit. a) GDPR.

7. OTHER PROCESSING OF PERSONAL DATA

Further personal data is stored if you voluntarily enter it on our website (e. g. when you contact us via the options offered on the website).

We process this personal data to fulfil the purpose noticeably associated with the transmission, e. g. to process your request. The legal basis for this processing of your personal data is Art. 6 Para. 1 S. 1 lit. b) GDPR, in case you enter your personal data for the purpose of initiating a contract. Otherwise, the legal basis of this processing is Art. 6 para. 1 sentence 1 letter f) GDPR. Our legitimate interest is the processing of your request.

8. TRANSMISSION TO SERVICE PROVIDERS

8.1 Any communication with you via email is accomplished by using the Gmail service offered by Google, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA . Your personal data (e-mail address, message content) can also be sent to Google servers outside the EU such as the USA. The transmission to Google is based on Art. 28 and 45 GDPR. For more details, please see paragraph 3. The processing of your personal data is based on Art. 6 Para. 1 S. 1 lit. b) GDPR as long as they are registered for our services. Otherwise, the transmission is based on Art. 6 Par. 1 S. 1 lit. f) GDPR, whereby our legitimate interest is communication with you for processing your possible request.

8.2 We use so-called CRM tools of Sales-force.com Germany GmbH, Erika-Mann-Str. 31, 80636 Munich (“Salesforce”) for the administration of our customer data. This means that your personal data (email address, message content) may be transferred to Salesforce servers, which may also be located outside the EU such as the United States. Salesforce is on the Privacy Shield List. The transfer to Salesforce is based on Articles 28 and 45 GDPR. The processing of your personal data with the CRM tools is based on Art. 6 Par. 1 S. 1 lit. b) GDPR.

9. COMMUNICATION BETWEEN USERS

When communicating via our services and uploading content within our services, we ask the user to note that this may be visible to other users. We therefore ask the user to handle the information provided by him/her carefully. Uploaded user content is transmitted in order to fulfil the relevant functions of our services on the basis of Art. 6 para. 1 sentence 1 lit. b) GDPR.

10. STORAGE PERIOD AND DELETION OF DATA

We process personal data of the user as long as the user is registered for the use of our services or as long as it is necessary to achieve the processing purposes or is prescribed by a legal obligation to store the data. Subsequent to this period, the data is immediately deleted.

However, we store data for legal reasons for as long as this is required by law (up to ten years). Furthermore, we store data, in case legal disputes arise, for as long as this is legally permissible. This can be up to 30 years.

If necessary, we may ask the user, when submitting content, for permission to process the data beyond this period.

11. DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES

Personal data will only be disclosed to third parties – unless otherwise stipulated in this privacy policy – without the express consent of the user, if this is necessary for the provision of Taledo’s services or for the performance of the contract with the user (in particular for personnel placement).

Apart from that, Taledo will not pass on the User’s personal data to third parties unless the user has expressly consented to the transfer (Art. 6 para. 1 sentence 1 lit. a) GDPR) and Taledo is not entitled or obliged to do so by legal provisions or court orders. In the latter case, the transmission by Taledo is for the fulfilment of a legal obligation pursuant to Art. 6 para. 1 sentence 1 lit. c) GDPR.

12. USER RIGHTS

12.1 Right to information

The User has the right to obtain from Taledo, in writing and free of charge, the personal data related to him/her which is stored at Taledo, the purposes of processing, its origin, which recipients or categories of recipients the transfer of data has been passed on to, the storage period and his/her relevant rights at his disposal.

12.2 Right to correction, deletion and/or limitation of data processing

The user has the right to request at any time the correction of incorrect data, the deletion and/or restriction of the processing of personal data stored about him, unless Taledo is legally obliged to retain such data. Insofar as this includes personal data required for the provision of services to the user, the deletion or restriction of the processing of such data can only take place when the user no longer uses Taledo’s services.

12.3 Right to object

The user has the right, at any time, to object to data processing based on Article 6 (1) sentence 1 (e) or (f) GDPR for reasons arising from his particular situation, unless Taledo can demonstrate compelling justifiable reasons, which outweigh the interests of the user, or the processing serves to assert, exercise or defend legal claims. The user can object to data processing for the purpose of direct advertising at any time without special reasons being required.

12.4 Right to Data Transferability

If the user provides data relating to the himself/herself and Taledo processes such data on the basis of the user’s consent or in order to fulfil the contract, the user may request that the he/she receive such data in a structured, current and machine-readable format from Taledo or that Taledo transmit such data to another person responsible to the extent technically possible (so-called right to data transferability).

12.5 Right to revoke consent

Any consent given by the user regarding the use of personal data can be freely revoked by the user at any time with effect for the future.

12.6 Right of appeal to a supervisory authority

The user may also lodge a complaint with a supervisory authority against data processing which, in his opinion, violates the statutory provisions.

13. CHANGES TO THE PRIVACY POLICY

Taledo reserves the right to change this Privacy Policy at any time, while always complying with the statutory data protection requirements. Therefore, Taledo recommends that users regularly take note of the applicable privacy policy.

You can exercise your rights by contacting us in writing at Taledo GmbH, Rosa-Luxemburg-Straße 7, 10178 Berlin or via e-mail to [email protected]. Furthermore, our data protection officer Steffen Weber is available to you in writing at INTARGIA Management Consulting GmbH, Max-Planck-Straße 20, 63303 Dreieich or via email to [email protected] .