Skip to main content

Processing of (personal) data by the entity in charge of the online application process

Candidate Privacy Notice
 
CALM is aware of its obligations under the General Data Protection Regulation (the “UK GDPR”) and the Data Protection Act 2018 (collectively, “the Data Protection Legislation”) and is committed to processing your data securely and transparently. This privacy notice sets out, in line with the Data Protection Legislation, the types of data that we collect and hold on you as a candidate. It also sets out how we use that information, how long we keep it for and other relevant information about your data.

Data controller details
CALM is a data controller, meaning that it determines the processes to be used when using your personal data. 

Data protection principles
In relation to your personal data, we will:

  • process it fairly, lawfully and in a clear, transparent way
  • collect your data only for reasons that we find proper for the course of your employment in ways that have been explained to you
  • only use it in the way that we have told you about
  • ensure it is correct and up to date
  • keep your data for only as long as we need it 
  • process it in a way that ensures it will not be used for anything that you are not aware of or have consented to (as appropriate), lost or destroyed

Types of data we process
We hold many types of data about you, including:

  • your personal details including your name, address, date of birth, email address, phone numbers.
  • information included on your cover letter and CV including references, education history and employment history.
  • documentation relating to your right to work in the UK.
  • Salary expectations, reasons for leaving previous role.
  • Shortlisting notes and interview notes.
  • Unsuccessful candidate offboarding. 
How we collect your data
We collect data about you in a variety of ways including the information you would normally include in a CV or a job application cover letter, or notes made by our staff during a recruitment interview. Further information will be collected directly from you when you complete forms at the start of your employment, for example, your bank and next of kin details. Other details may be collected directly from you in the form of official documentation such as your driving licence, passport or other right to work evidence. 

In some cases, we will collect data about you from third parties, such as recruitment agencies, former employers when gathering references or credit reference agencies.

Personal data is kept in secure online HR files or within our Cloud-Based HR system.

Why we process your data
The law on data protection allows us to process your data for certain reasons only:

  • in order to perform the employment contract that we are party to
  • in order to carry out legally required duties
  • in order for us to carry out our legitimate interests

All of the processing carried out by us falls into one of the permitted reasons. Generally, we will rely on the first three reasons set out above to process your data. 

We need to collect your data to ensure we are complying with legal requirements such as:
  • carrying out checks in relation to your right to work in the UK and
  • making reasonable adjustments for disabled employees.

We also collect data so that we can carry out activities which are in the legitimate interests of CALM. We have set these out below:

  • making decisions about who to offer employment to
  • making decisions about salary and other benefits
  • dealing with legal claims made against us

If you are unsuccessful in obtaining employment, we will seek your consent to retaining your data in case other suitable job vacancies arise within CALM for which we think you may wish to apply. You are free to withhold your consent to this and there will be no consequences for withholding consent.

If you do not provide your data to us
One of the reasons for processing your data is to allow us to carry out an effective recruitment process. Whilst you are under no obligation to provide us with your data, we may not be able to process, or continue with (as appropriate), your application. 

Sharing your data
Your data will be shared with colleagues within CALM where it is necessary for them to undertake their duties with regard to recruitment. 

In some cases, we will collect data about you from third parties, such as recruitment agencies.

Protecting your data
We are aware of the requirement to ensure your data is protected against accidental loss or disclosure, destruction and abuse. We have implemented processes to guard against such. 

Where we share your data with third parties, we provide written instructions to them to ensure that your data are held securely and in line with the Data Protection Legislation requirements. Third parties must implement appropriate technical and organisational measures to ensure the security of your data.

How long we keep your data for
In line with data protection principles, we only keep your data for as long as we need it for and this will depend on whether or not you are successful in obtaining employment with us.

If your application is not successful and we have not sought consent or you have not provided consent upon our request to keep your data for the purpose of future suitable job vacancies, we will keep your data for 6 months once the recruitment exercise ends.

If we have sought your consent to keep your data on file for future job vacancies, and you have provided consent, we will keep your data for 1 year once the recruitment exercise ends. At the end of this period, we will delete or destroy your data, unless you have already withdrawn your consent to our processing of your data in which case it will be deleted or destroyed upon your withdrawal of consent.

If your application is successful, your data will be kept and transferred to the systems we administer for employees. We have a separate privacy notice for employees, which will be provided to you.

Your rights in relation to your data
The law on data protection gives you certain rights in relation to the data we hold on you. These are:

  • the right to be informed. This means that we must tell you how we use your data, and this is the purpose of this privacy notice
  • the right of access. You have the right to access the data that we hold on you. To do so, you should make a subject access request
  • the right for any inaccuracies to be corrected. If any data that we hold about you is incomplete or inaccurate, you are able to require us to correct it 
  • the right to have information deleted. If you would like us to stop processing your data, you have the right to ask us to delete it from our systems where you believe there is no reason for us to continue processing it
  • the right to restrict the processing of the data. For example, if you believe the data we hold is incorrect, we will stop processing the data (whilst still holding it) until we have ensured that the data is correct 
  • the right to portability. You may transfer the data that we hold on you for your own purposes
  • the right to object to the inclusion of any information. You have the right to object to the way we use your data where we are using it for our legitimate interests
  • the right to regulate any automated decision-making and profiling of personal data. You have a right not to be subject to automated decision making in a way that adversely affects your legal rights.

Where you have provided consent to our use of your data, you also have the unrestricted right to withdraw that consent at any time. Withdrawing your consent means that we will stop processing the data that you had previously given us consent to use. 

There will be no consequences for withdrawing your consent. However, in some cases, we may continue to use the data where so permitted by having a legitimate reason for doing so.

If you wish to exercise any of the rights explained above, please contact the Data Protection Lead, see contact details below.

Making a complaint
The supervisory authority in the UK for data protection matters is the Information Commissioner (ICO). If you think your data protection rights have been breached in any way by us, you are able to make a complaint to the ICO.

Data Protection Lead
The Company’s Data Protection Lead is Linda Buddy. She can be contacted by email at lindabuddy@thecalmzone.net 


Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.