Skip to main content

Processing of (personal) data by the entity in charge of the online application process

Data Protection Notice of the Controller for Data Processing in the Online Application Process


General Information


This data protection notice refers exclusively to the data collected in the context of the online application process.

Controller

The controller within the meaning of data protection law is:
Risk.Ident GmbH
Am Sandtorkai 50, 20457 Hamburg
Tel.: +49 40 228681 054

Contact Details of the Data Protection Officer

You can contact the company’s Data Protection Officer at:
Mr. Dr. Nils Christian Haag / Data Protection Team
Intersoft consulting services AG
Beim Strohhause 17
20097 Hamburg
E-mail: datenschutz@riskident.com

Which of your personal data do we process?


By submitting an application via our recruiting page, you express your interest in taking up employment with us. We process your personal data insofar as this is necessary for carrying out the application process. This includes the following categories of data:

Standard information:
Name (first and last name)
Email address
Telephone number

Other information:
Publicly accessible, job-related data (e.g., a profile on professional social media networks such as LinkedIn)
The channel through which you became aware of us
Qualification data from uploaded documents (cover letter, CV, application photo, certificates, etc.)

As a rule, we only process the personal data that we receive from you in the context of the application process.

For what purposes and on what legal basis do we process your data?

We process your personal data in particular in compliance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and all other relevant laws.

Data processing for the purposes of the application process (Art. 6 (1) sentence 1 lit. b GDPR)

Personal data of applicants may be processed for the purposes of the application process if this is required for making a decision on establishing an employment relationship with us.

The necessity and scope of data collection depend, among other things, on the position to be filled. If the position you are applying for involves particularly confidential duties or increased personnel and/or financial responsibility, more extensive data collection may be required. For example, we ask our applicants to provide a police clearance certificate. To ensure data protection, such data processing takes place only after the conclusion of the applicant selection process, immediately before your hiring, or only after employment has begun.

Data processing based on consent (Art. 6 (1) sentence 1 lit. a GDPR)

If you have voluntarily given us your consent to collect, process, or transfer certain personal data, this consent forms the legal basis for processing such data.

We process your personal data based on your consent in the following cases:

  • Inclusion in the applicant pool, i.e. we store your application documents beyond the current application process for consideration in future job openings.

Based on the legitimate interest of the controller (Art. 6 (1) sentence 1 lit. f GDPR)

In certain cases, we process your data to safeguard our legitimate interests or those of third parties:

To defend legal claims in proceedings under the General Equal Treatment Act (AGG). In the event of a legal dispute, we have a legitimate interest in processing data for evidentiary purposes.

Data matching against EU anti-terror lists pursuant to Regulations (EC) No. 2580/2001 and 881/2002. As a company, we are obligated under EU law to contribute to combating terrorism. Persons and organizations listed on terrorist lists must not receive funds (“prohibition of provision”). For this reason, we are obligated to perform name checks against these lists.

To whom is your data transferred?


Use of Personio software

To conduct the online application process via our career page, we use the service provider Personio. The provider is Personio SE & Co. KG, Seidlstraße 3, 80335 Munich. The data transmitted as part of your application is transferred encrypted via TLS and stored in Personio’s database. Personio acts as our processor pursuant to Art. 28 GDPR. The legal basis for processing is a data processing agreement between us as the controller and Personio.

Other recipients

Only authorized employees from the HR department or employees involved in the application process have access to your data. In some cases, other internal and external parties are involved in processing your data.

Internal departments, depending on the job posting:
  • HR department
  • Hiring manager

External service providers:
  • IT service providers (e.g. maintenance providers, hosting providers)
  • Service providers for file and data destruction

Are your data transferred to countries outside the European Union (so-called third countries)?

We place great importance on processing your data within the EU/EEA. However, it may occur that we use service providers that process data outside the EU/EEA. In such cases, we ensure that an adequate level of data protection—comparable to EU standards—is established before transferring your personal data. This may be achieved, for example, through EU standard contractual clauses, binding corporate rules, or special frameworks to which the company has committed.

How long will your data be stored?

Personal data is generally stored solely for the purpose of filling the position for which you applied.

If an employment relationship does not come about, your data will be stored for 183 days after the conclusion of the application process. This is usually done to comply with legal obligations or to defend against potential claims under statutory provisions.
If you receive and accept an employment offer from us, we will store the personal data collected during the application process for at least the duration of the employment relationship.

Rights of data subjects

Every data subject has the right of access under Art. 15 GDPR, the right to rectification under Art. 16 GDPR, the right to erasure under Art. 17 GDPR, the right to restriction of processing under Art. 18 GDPR, the right to object under Art. 21 GDPR, and the right to data portability under Art. 20 GDPR. The restrictions under Sections 34 and 35 BDSG apply to the right of access and the right to erasure.

We are happy to provide you with information as to whether personal data concerning you is being processed. If this is the case, you have a right of access to this personal data and to the information listed in detail in Art. 15 GDPR. In addition, you have—subject to the respective legal requirements—the right to rectification (Art. 16 GDPR), the right to restriction of processing (Art. 18 GDPR), the right to erasure (Art. 17 GDPR), and the right to data portability (Art. 20 GDPR).

What rights do you have in the event of data processing based on legitimate or public interest?

Under Art. 21 (1) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data that occurs on the basis of Art. 6 (1) sentence 1 lit. e GDPR (processing in the public interest) or Art. 6 (1) sentence 1 lit. f GDPR (legitimate interests).

In the event of your objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.

You may withdraw your consent to the processing of personal data at any time. Please note that the withdrawal only applies to future processing.

Irrespective of these rights and the option of pursuing other administrative or judicial remedies, you have the right to lodge a complaint with a supervisory authority at any time, in particular in the Member State of your residence, your workplace, or the location of the alleged infringement, if you believe that the processing of your personal data violates data protection regulations (Art. 77 GDPR).

To exercise your data subject rights relating to the data processed in this online application process, please contact our Data Protection Officer (see above).

Is there an obligation to provide your personal data?

The provision of personal data is neither legally nor contractually required, and you are not obligated to provide personal data. However, providing personal data is necessary for carrying out the application process. This means that if you do not provide personal data in an application, we will not be able to conduct the application process.

Final provisions

We reserve the right to amend this privacy notice at any time to ensure that it always complies with current legal requirements or to reflect changes in the application process or similar. The new privacy notice applies to any future visit to this recruiting page or future application.

In addition to this privacy notice, you can access our general privacy policy at
https://riskident.com/de/impressum/.

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.