Recruitment Privacy Notice
1. What does this privacy notice cover?
This privacy notice (“Privacy Notice”) describes how SEON use the personal data of applicants (“you”) in connection with your application for open positions at SEON. At SEON we are committed to protecting your personal data and to respect your right to privacy.
When SEON processes your personal data on the basis of its legitimate interest (see Section 6 of this Privacy Notice) you have the right to object to that processing (see Section 11.1.5). If you wish to exercise this right, please contact SEON at the email contact details specified in Section 2. When SEON processes your personal data on the basis of your consent, you have the right to withdraw your consent.
SEON complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, as set forth by the U.S. Department of Commerce. SEON has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles the Principles shall govern. To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov/
SEON is responsible for processing personal data it receives under the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, and subsequently transfers to a third party acting as an agent on its behalf. Access complies with the EU-U.S. DPF Principles for all onward transfers of personal data from the EU, including the onward transfer liability provisions. The Federal Trade Commission has jurisdiction over SEON compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. In certain situations, Access may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
SEON Technologies is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC) with regard to our compliance with the EU-U.S. Data Privacy Framework (DPF).
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, SEON commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU and UK individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, should first contact SEON at: [email protected]
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, SEON commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF to an alternative dispute resolution with the panel established by the EU data protection authorities (DPAs) and Information Commissioner’s Office (ICO).
For complaints, regarding EU-U.S. DPF and the UK Extension to the EU-U.S. DPF compliance not resolved by any of the other DPF mechanisms; you have the possibility, under certain conditions, to invoke binding arbitration. Further information can be found on the official DPF website: https://www.dataprivacyframework.gov/s/article/C-Pre-Arbitration-Requirements-dpf.
2. The data controller and DPO
The data controller of your personal data is
SEON Technologies Kft.
Registered seat: H-1072 Budapest, Rákóczi út 42. 7. em
Company registration number: 01-09-292732
(hereinafter referred to as “SEON”, “we”, “us” or “our”)
For any inquiries about this privacy notice, please contact any SEON entity at the following email address: [email protected]
SEON appointed a DPO. For any inquiries about this Privacy Notice, you may contact our DPO at [email protected].
3. What personal data does SEON collect?
SEON collects the following categories of your personal data:
- Personal identification and communication information (e.g. your name, home address, phone number, email address, date of birth, gender, correspondence);
- Application-related information (e.g. curriculum vitae (CV), cover letter, employment history, education history, qualifications and skills, hobbies, publications, assessment scores, position preferences, desired salary, interests and aspirations background information (e.g. public social media profile information), notes made during interviews, conclusions drawn during the hiring process, history of the hiring process).
- Special categories of data (e.g. sensitive personal data, criminal history, personal data revealing racial or ethnic origin, health-related data, data concerning a person’s sexual orientation).
We may collect special categories of personal data (sensitive personal data) about a candidate to the extent permitted to do so by applicable laws (e.g., U.S. equal opportunity laws) to support our efforts to create an inclusive and diverse work environment. We only collect special categories of personal data (sensitive personal data) that a candidate voluntarily discloses during the recruiting process. Please keep in mind that providing these types of information is optional and has no impact on the outcome of your application.
For certain positions, we have the appropriate legal basis and right to process your criminal history. Where we do so, we only do so in accordance with our Privacy Policy, the principles in Article 5 GDPR, and the prevailing legislation in the area of criminal background checks as updated from time to time.
4. The sources of personal data
In general, SEON collects personal data from you directly when you apply for a job and throughout the job application or recruitment process. SEON may also collect personal data from other persons (i.e. recruitment agencies, online testing tools), or from other publicly available sources (i.e. social media providers, etc.) and combine it with the personal data you provide us. For example, we may collect your personal data from:
- Job board websites you may use to apply for a job with us;
- Prior employers that provide us with employment references;
- Professional references that you authorise us to contact;
- Pre-employment screening services, such as background check providers (where permitted by law);
- Employment agencies and recruiters;
- Your educational institutions;
- Your public social media profile or other publicly-available sources;
- Online activity information that we and our service providers collect using server logs, “cookies” and similar technologies on the Careers Site. Please see our Privacy Policy for more information.
5. How long does SEON retain your personal data?
- If your application is successful: We will retain your personal data until the employment agreement is concluded with you. When you become our employee, some of your personal data will become a part of your employee file and will be processed in accordance with our employee privacy notice which will be provided to you in a timely manner.
- If your application is not successful: SEON will retain your personal data for 2 years after the recruitment procedure is finished to create and maintain applicant community and to protect our rights and interest if we are need to, or until you object (whichever is earlier). After 2 years we will ask for your consent to retain your personal data for 2 more additional years.
6. Why does SEON collect and use this personal data?
SEON collects, uses and processes your personal data on the following legal basis and for the purposes set out below:
Purpose | Legal Basis | Categories |
Conducting recruitments, in particular, making informed hiring decisions and assessing your suitability for the role and communicating with you about your application, respond to your inquiries and schedule interviews. | SEON has a legitimate interest in being able to organize the recruitment procedure and finding the appropriate applicant for the position. | Personal identification and communication information; Application-related information |
Verifying the details you have supplied, including the existence of your professional skills. | SEON has a legitimate interest in ascertaining whether the applicants have the necessary professional skills required for the position. | Personal identification and communication information; Application-related information. |
Enhance equality and diversity to the extent permitted by applicable law. | Special categories of personal data or other information that is regarded as sensitive personal data is only processed with your consent. | Special categories of data. |
Create and maintain applicant community as part of the applicant management system. | We will add you to our applicant community if you give your consent. | Personal identification and communication information; Application-related information. |
Recruitment marketing. | On the basis of your consent, SEON will contact you after your unsuccessful application about future career opportunities. | Personal identification and communication information. |
Protecting and exercising our rights and interests. | SEON has a legitimate interest in the protection and exercise of their rights and interest. | Personal identification and communication information. |
7. How does SEON share your personal data?
Personal data will be primarily processed by the employees in SEON’s recruiting department and the relevant hiring managers. This includes sharing your personal data between SEON group entities. Please note that we share your personal data with SEON entities outside of the EEA, in particular, we transfer your personal data to the UK. Data transfers to the UK are currently not restricted. SEON will make sure that it provides an appropriate safeguard to the data transferred if such becomes necessary.
Your personal data will be shared with the following categories of business partners that provide us services to achieve the above listed purposes: cloud providers, applicant tracking system providers, head-hunters, recruitment agencies, social media providers, and (online) testing tools providers. Please note that we share your personal data with some business partners outside of the EEA, in particular, we transfer your personal data to the US. In these cases, we enter into standard contractual clauses adopted by the European Commission with these business partners to ensure the adequate protection of your personal data. A copy of these safeguards can be obtained for your review on request by using the contact details specified in this Privacy Notice.
SEON complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, as set forth by the U.S. Department of Commerce. SEON has certified to the U.S. Department of Commerce that it adheres to the EU U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF.
Your personal data will only be shared by us for the purposes specified in this Privacy Notice.
8. No profiling
SEON does not carry out automated decision-making or profiling based solely on automated processing in relation to your personal data.
9. Recruitment marketing
We will only send you marketing emails or contact you about our future career opportunities if you’ve given your consent to this. We may personalise content based on the information you’ve provided. Should you change your mind after having opted in for marketing activity, you can update your preferences or unsubscribe from any direct marketing email. If you no longer wish to receive recruitment marketing messages, you can unsubscribe using the link provided in the marketing messages, or you can contact us using the contact details provided in this Privacy Notice.
10. Investigatory and Enforcement Powers of the Federal Trade Commission (FTC)
SEON is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC) under the Federal Trade Commission Act. The FTC has the authority to investigate and enforce violations of its privacy and data security rules, as well as unfair or deceptive trade practices. This means that the FTC may: a.) Investigate our data practices: The FTC may investigate our organization’s data collection, use, and disclosure practices to ensure compliance with applicable laws and regulations. This may involve requesting documents, conducting interviews, and inspecting our systems. b.) Take enforcement action: If the FTC finds that our organization has violated its privacy or data security rules, it may take a variety of enforcement actions, including issuing cease and desist orders, imposing civil penalties, or requiring us to take corrective action.
We take our obligations under the FTC Act seriously and strive to maintain robust data privacy
and security practices.
We encourage all employees to familiarize themselves with our privacy notice and to raise any
concerns they may have regarding our data practices.
Additional Information:
? You can learn more about the FTC’s privacy and data security rules on their website:
https://www.ftc.gov/business-guidance/privacy-security
? You can also report concerns about our data practices directly to the FTC:
https://www.ftc.gov/about-ftc/contact
11. Rights and remedies
In compliance with the EU-U.S. Data Privacy Framework (DPF) and the UK Extension to the EU-U.S. DPF, SEON commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) with regard to unresolved complaints concerning our handling of human resources data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF in the context of the employment relationship.
11.1 Rights of data subjects
Pursuant to Articles 15-21 of the GDPR, in relation to your personal data processed by SEON you are entitled to:
- access personal data;
- request rectification of personal data;
- request erasure of personal data;
- request restriction of the processing of personal data;
- object to the processing of personal data;
- receive the personal data and transmit personal data to another controller, if the relevant legal requirements are met (right to data portability, see below in Section 7.1.6);
- withdraw your consent at any time if the processing is based on your consent.
If you wish to exercise any of your rights, please contact us at the email contact information indicated in Section 2 of this Privacy Notice. SEON will provide information on the actions taken on your request without undue delay, and in any event within 30 days of the receipt of the request. If we do not take any action on your request, we will inform you without delay and at the latest within 30 days of the receipt of the request of the reasons for not taking action and on the possibility of lodging a complaint with a data protection supervisory authority and seeking judicial remedy. If you do not agree with the answer or measures applied by SEON, remedies are available as set out in Section 7.2. SEON informs all recipients of all rectification, erasure, or restriction of processing to whom personal data was disclosed except if it is impossible or requires disproportionate effort. On request, SEON provides information on recipients.
You can also exercise some of your rights via the settings available in our applicant tracking system.
11.1.1 Right to access
You have the right to obtain from SEON confirmation as to whether or not their personal data are being processed. If your personal data is processed you have the right to access to the personal data, (or obtain a copy) and to receive information about the circumstances of the data processing. The information requested may include but are not limited to the following: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipient to whom the personal data have been or will be disclosed by SEON; the planned period for which the personal data will be stored; where the personal data are not collected from you, any available information as to their source, etc.
11.1.2 Right to rectification
You have the right to obtain from SEON without undue delay the rectification of inaccurate personal data and to have incomplete personal data completed.
11.1.3 Right to erasure (“right to be forgotten”)
You have the right to request from SEON the erasure of your personal data without undue delay where one of the following applies:
- the personal data are no longer necessary for the purposes for which they were processed;
- the consent on which the processing is based is withdrawn, and where there is no other legal ground for the processing;
- you object to the processing and there are no overriding legitimate grounds for the processing;
- the personal data have been unlawfully processed by SEON;
- the personal data have to be erased for compliance with a legal obligation.
SEON does not erase the personal data where the processing is necessary for any of the following reasons: (i) for exercising the right of freedom of expression and information; (ii) for compliance with a legal obligation which requires processing; (iii) for the establishment, exercise or defence of legal claims.
11.1.4 Right to restriction of processing
You have the right to obtain from SEON a restriction of processing where one of the following applies:
- you contest the accuracy of the personal data. In this case the restriction applies for a period enabling SEON to verify the accuracy of the personal data;
- the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead;
- SEON no longer needs the personal data for the purposes of the processing, but you require them for the establishment, exercise, or defence of legal claims;
- you have objected to the processing. In this case the restriction applies for the period of the verification whether the legitimate grounds of SEON override yours.
Where processing has been restricted, such personal data will, with the exception of storage, only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State. You will be informed by SEON before the restriction of processing is lifted.
11.1.5 Right to object to processing
You have the right to object, on grounds relating to your particular situation, at any time to any processing of your personal data, which is based on the legitimate interests pursued by SEON. In this case, SEON will no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override your interests, rights, and freedoms or that are related to the establishment, exercise, or defence of legal claims.
11.1.6 Right to data portability
If it does not adversely affect the rights and freedoms of others, you have the right to receive your personal data (which you provided to SEON) in a structured, commonly used, and machine-readable format and you also have the right to have the personal data transmitted directly from SEON to another controller, if the following cumulative conditions are fulfilled:
- the processing is based on your consent, or it is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract; and
- the processing is carried out by automated means, i.e. the processing is carried out in an IT system instead of a paper form.
11.1.7. Your Rights- California Residents
If you are a resident of California, under the California Consumer Privacy Act (“CCPA”), we are required to provide additional information to you about how we use and disclose your information, and you may have additional rights with regard to how
we use your information.
Consistent with the “WHY AND HOW ARE WE PROCESSING YOUR PERSONAL DATA“ section above, we collect certain categories and specific pieces of information about individuals that are considered “Personal Information” in California. As detailed above, we may collect this Personal Information from you and other third parties. We collect, share and disclose Personal Information for the business purposes described in the “Why does SEON collect and use this personal data?” section above.
We do not sell Personal Information, as this term is defined under California law.
Subject to certain exceptions, as a California consumer, you have the right to: (i) access your Personal Information; (ii) obtain deletion of your Personal Information; (iii) receive information about the Personal Information about you that we have “sold” (as such term is defined under California law) to third parties within the past 12 months; and (iv) opt-out of the “sale” of your Personal Information, including as detailed above in the “Cookies and Tracking Technologies” section. To the extent permitted by applicable law, we may be required to retain some of your Personal Information, and certain Personal Information is strictly necessary in order for us to fulfill the purposes described in this Privacy Policy
Should you wish to request the exercise of your other rights as detailed above with regard to your Personal Information, we will not discriminate against you by offering you different pricing, products or services, or by providing you with a different level or quality of products or services, based solely upon this request. Please see the “Contact us” section below if you have questions or wish to exercise such rights.
If you are a California consumer and you wish to exercise your rights as outlined in this section, you may need to provide information such as name and e-mail so that we can verify your identity. We will use the information you provide when exercising your rights for no other purpose other than to verify your identity. You also have the option of designating an authorized agent to exercise your rights on your behalf. For authorized agents submitting requests on behalf of California residents, please contact us as described below, with any evidence you have that you have been authorized by a California consumer to submit a request on their behalf.
We do not rent, sell, or share your Personal Information with nonaffiliated companies for their direct marketing purposes, unless we have your permission. You also may have the right to request that we provide you with (1) a list of certain categories of
personal information we have disclosed to third parties for their direct marketing purposes during the immediately preceding calendar year, and (2) the identity of those third parties.
You can exercise any of these rights by contacting us through the methods described
in the Privacy Notice section below.
11.2 Remedies
If you do not agree with the communication or actions taken by SEON, you have the right to lodge a complaint with the data protection supervisory authority in the EU Member State of your habitual residence, place of work or place of alleged infringement, in particular, with the following supervisory authority:
- Hungarian National Authority for Data Protection and Freedom of Information – Address: 1055 Budapest, Falk Miksa utca 9-11; mailing address: 1363 Budapest, Pf. 9.; tel.: +36-1-391-1400; e-mail: [email protected]; website: naih.hu
- Information Commissioners Office (address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, online contact form: https://ico.org.uk/global/contact-us/).
- EU authorities at https://ec.europa.eu/justice/article-29/structure/data-protectionauthorities/index_en.htm
- California residents may contact the California Privacy Protection Agency.
- In other US jurisdictions, please contact the Office of the Attorney General for your
jurisdiction.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, SEON commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) with regard to unresolved complaints concerning our handling of data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF.
You may, subject to its terms, invoke binding arbitration in accordance with Annex I of the DPF Principles: https://www.dataprivacyframework.gov/s/article/ANNEX-I-introduction-dpf
This provides that you may invoke binding arbitration by delivering notice to SEON and following the procedures and subject to conditions set forth in Annex I of the Principles.
12. Updates to this privacy notice
SEON may amend this Privacy Notice. In such a case, SEON publishes the updated version of the Privacy Notice. SEON will always provide you with adequate information on the major changes.