Recruitment Privacy Notice
This privacy policy is issued on behalf of the Cero Generation group of companies, so when we mention “Cero Generation”, "we", "us" or "our" in this privacy policy, we are referring to the relevant company in the Cero Generation group responsible for processing your data.
Cero Generation is a "controller" in relation to personal data. This means that we are responsible for deciding how we hold and use personal information about you. You have been provided with a copy of this privacy notice because you are applying for work with us (whether as an employee, worker or contractor). It makes you aware of how and why your personal data will be used, namely for the purposes of the recruitment exercise, and how long it will usually be retained for. It provides you with certain information that must be provided under the UK General Data Protection Regulation (UK GDPR).
Data protection principles
We will comply with data protection law and principles, which means that your data will be:
- Used lawfully, fairly and in a transparent way.
- Collected only for valid purposes that we have clearly explained to you and not used in any way that is incompatible with those purposes.
- Relevant to the purposes we have told you about and limited only to those purposes.
- Accurate and kept up to date.
- Kept only as long as necessary for the purposes we have told you about.
- Kept securely.
- The Personal Data that we collect about you
1.1 The Personal Data that we collect about you
In this section we have set out the general categories of Personal Data that we process and, in the case of Personal Data that we did not obtain directly from you, information about the source and specific categories of that data.
We have also set out the purposes for which we may process your Personal Data and the legal bases of processing.
Category of Personal Data: Contact data and general personal details
Types of Personal Data:
Name, title, addresses, telephone numbers and personal email addresses.
Date of birth.
Gender.
Source of Personal Data:
You
Recruitment agencies
Purpose of processing:
Communicating with you about the recruitment process.
Keeping records related to our hiring processes.
Complying with legal or regulatory requirements
Legal basis for processing
To comply with our legal obligations.
Our legitimate interests, namely to administer and manage our business.
Category of Personal Data: Employment Details
Types of Personal Data:
Information provided within your CV and covering letter or application.
Information you provide to us during the interview process.
Copies of right to work documentation and references
Source of Personal Data:
You
Former employers
Recruitment agencies
Referees
Purpose of processing:
Making a decision about your recruitment or appointment.
Complying with legal or regulatory requirements, including checking you are legally entitled to work in the UK
Legal basis for processing:
To comply with our legal obligations.
Our legitimate interests, namely to ensure that we appoint appropriately qualified and experienced personnel.
Category of Personal Data: Special category and criminal convictions data
Types of Personal Data:
Information about your race or ethnicity, religious beliefs, sexual orientation, and political opinions.
Information about your health, including any medical condition, health and sickness records.
Information about criminal convictions and offences.
Source of Personal Data:
You
Recruitment agencies
Background check provider
Purpose of processing:
In general, we will not process particularly sensitive personal information about you unless it is necessary for performing or exercising obligations or rights in connection with employment. We will only collect information about criminal convictions if it is appropriate given the nature of the role and where we are legally able to do so. We have in place an appropriate policy and safeguards which we are required by law to maintain when processing such data.
We process special category Personal Data and/or criminal convictions data for the following purposes:
- To ensure meaningful equal opportunity monitoring and reporting.
- To determine your suitability for a role with us.
- To provide appropriate adjustments during the recruitment process.
If we reasonably believe that you or another person are at risk of harm and the processing is necessary to protect you or them from physical, mental or emotional harm or to protect physical, mental or emotional well-being.
On rare occasions, there may be other reasons for processing, such as it is in the public interest to do so.
Legal basis for processing:
Our legitimate interests, namely the protection of you, our services and business, and the protection of others.
To comply with our legal obligations.
In relation to special category data: processing is necessary to carry out our obligations and exercise our rights in employment and to safeguard of your fundamental rights in the field of employment and social security and social protection law.
In relation to criminal convictions data: processing is necessary for the purposes of performing or exercising obligations or rights which are imposed or conferred by law on us in connection with employment, social security or social protection.
If you fail to provide personal information
If you fail to provide information when requested, which is necessary for us to consider your application (such as evidence of qualifications or work history), we will not be able to process your application successfully. For example, if we require references for the role you apply for and you fail to provide us with relevant details, we will not be able to take your application further.
Change of purpose
We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Automated decision making
Our recruitment decisions are not based solely on automated decision-making.
1.2 Providing your Personal Data to others (including international data transfers)
We may disclose your Personal Data to any member of our group of companies (this means our subsidiaries, our ultimate holding company and all its subsidiaries) insofar as reasonably necessary for the purposes, and on the legal bases, set out in this policy. We and our other group companies have offices and facilities in France, Germany, Greece, Italy, Poland, Spain and the United Kingdom and we may transfer the personal information we hold about you to such offices and facilities. The competent data protection authorities have made an adequacy determination with respect to the data protection laws of each of these countries.
The following third-party service providers process personal information about you for purposes set out in the table below. This table also sets out where such third-party services providers are located and (if they are located somewhere where the competent data protection authorities have not made an adequacy determination with respect to the data protection laws of that jurisdiction) the appropriate safeguards that are in place for the transfers of your Personal Data to such third party service providers.
Supplier/sub-contractor: Microsoft
Purpose:Document management and storage
Location of supplier/sub-contractor: Various countries around the globe
(if relevant) appropriate safeguard: Standard Contractual Clauses
Supplier/sub-contractor: Wight Computers
Purpose: IT support
Location of supplier/sub-contractor: UK
(if relevant) appropriate safeguard: n/a
Supplier/sub-contractor: Teamtailor
Purpose: Recruitment Platform
Location of supplier/sub-contractor: Sweden
(if relevant) appropriate safeguard: n/a
Supplier/sub-contractor: Hobo
Purpose: HR Platform
Location of supplier/sub-contractor: Various countries around the globe
(if relevant) appropriate safeguard: Standard Contractual Clauses
In addition to the specific disclosures of Personal Data set out in the table above, we may disclose your Personal Data where such disclosure is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person. We may also disclose your Personal Data where such disclosure is necessary for the establishment, exercise, or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure.
We may share your personal information with other third parties, for example in the context of the possible sale or restructuring of the business. In this situation we will, so far as possible, share anonymised data with the other parties before the transaction completes. Once the transaction is completed, we will share your Personal Data with the other parties if and to the extent required under the terms of the transaction.
We may disclose your Personal Data to our insurers and/or professional advisers insofar as reasonably necessary for the purposes of obtaining or maintaining insurance coverage, managing risks, obtaining professional advice.
We may also need to share your personal information with a regulator or to otherwise comply with the law.
1.3 Data security
We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We will store your Personal Data on secure servers, personal computers and mobile devices, and in secure manual record-keeping systems. Additionally, we limit access to your personal information to those employees and other third parties who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
In relation to your log in details to Team Tailor, you should ensure that your password is not susceptible to being guessed, whether by a person or a computer program. You are responsible for keeping the password you use for accessing Team Tailor confidential and we will not ask you for your password (except when you log in to Team Tailor).
1.4 Data retention
We will only retain your personal information for as long as necessary to fulfil the purposes for which we collected it.
If your application for employment is unsuccessful, we will hold your personal data on file for 2 years after the end of the relevant recruitment process. At the end of that period your personal data is deleted or destroyed. We retain your personal information for this period so that we can consider you for future positions at Cero. If your application for employment is successful, personal data gathered during the recruitment process will be transferred to your personnel file and retained during your employment, in which case, retention periods will be covered by a separate privacy notice.
Notwithstanding the other provisions of this section on data retention, we may retain your Personal Data where such retention is necessary for compliance with a legal obligation to which we are subject, or in order to protect your vital interests or the vital interests of another natural person.
Updating information
Please let us know if the personal information that we hold about you needs to be corrected or updated.
1.5 Your rights
In this Section we have listed the rights that you have under Data Protection Law.
Your principal rights under Data Protection Law are:
- the right to access - you can ask for copies of your Personal Data;
- the right to rectification - you can ask us to rectify inaccurate Personal Data and to complete incomplete Personal Data;
- the right to erasure - you can ask us to erase your Personal Data;
- the right to restrict processing - you can ask us to restrict the processing of your Personal Data;
- the right to object to processing - you can object to the processing of your Personal Data;
- the right to data portability - you can ask that we transfer your Personal Data to another organisation or to you;
- the right to complain to a supervisory authority - you can complain about our processing of your Personal Data; and
- the right to withdraw consent - to the extent that the legal basis of our processing of your Personal Data is consent, you can withdraw that consent.
These rights are subject to certain limitations and exceptions. You can learn more about the rights of data subjects by visiting https://edpb.europa.eu/our-work-tools/general-guidance/gdpr-guidelines-recommendations-best-practice... and https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-r....
You may exercise any of your rights in relation to your Personal Data by emailing careers@cerogeneration.com.
If you have any questions about this privacy notice, please email careers@cerogeneration.com.