Workable Candidate Privacy Notice

This Privacy Notice (together with any other documents referred to herein) sets out the basis on which Workable ( “We”, “Us” or “Workable”) collects and processes your personal data in connection with our recruitment processes. Please read the following carefully to understand our views and practices regarding your personal data and how We will treat it.

For the purposes of this Privacy Notice, any references to "personal data"; "legal basis"; "processing"; or "data controller" shall have the meaning established in the General Data Protection Regulation (“GDPR”) and the United Kingdom General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018.

We use our own platform (Workable), to assist Us with our recruitment process. We also use the appropriate Workable Affiliate to process personal information as a data processor on our behalf. Any Workable Affiliate is only entitled to process your personal data in accordance with our instructions.

Where you apply for a job opening posted by Us, these Privacy Notice provisions will apply to our processing of your personal information in addition to our other Privacy Policy which has been provided to you separately or is available on our Website. See Privacy policy | Workable.

Where you apply for a job opening via the application function on a job site or similar online service provider (“Partner”), you should note that the relevant Partner may retain your personal data and may also collect data from Us in respect of the progress of your application. Any use by the Partner of your data will be in accordance with the Partner’s Privacy Notice.

Data controllers

The primary applicable Data Controller will be the Workable entity that is recruiting for the role or intends to enter the employment contract with you.

For candidates located in Greece, the Data Controller is Workable Software Single Member Private Company, having its registered office address at Kifisias 95-97 Ave., Marousi Attiki, 15125, Greece.

For candidates located in the United Kingdom, the Data Controller is Workable Software Limited, registered in England and Wales, with Company Registration Number 08125469 and having its registered office address at 5 Golden Square, 5th Floor, London, W1F 9BS, UK.

For candidates located in the United States of America or the rest of the World, the Data Controller is Workable Inc., with offices located at 83 Morse Street 26th Floor Boston, Workbar Building 6 c/o Workable, Norwood MA 02062, United States.

Your personal information

Information We collect from you

We collect and process some or all of the following types of information from you:

  • Information that you provide when you apply for a role. This includes information provided through an online job site, via email, in person at interviews and/or by any other method.
  • In particular, We process personal details such as name, email address, address, date of birth, qualifications, experience, information relating to your employment history, skills and experience that you provide to Us.
  • If you contact Us, We may keep a record of that correspondence.
  • A record of your progress through any hiring process that we may conduct.
  • Your IP address
  • Your video interview in case your interview was performed through the video interview feature.
Information We collect from other sources

Workable provides Us with the facility to link the data you provide to Us, with other publicly available information about you that you have published on the Internet – this may include sources such as LinkedIn and other social media profiles.

Workable’s technology allows Us to search various databases – some publicly available and others not, which may include your personal data (include your CV or ResumĂ©), to find possible candidates to fill our job openings. Where We find you in this way we will obtain your personal data from these sources.

We may receive your personal data from a third party who recommends you as a candidate for a specific job opening or for our business more generally, through our Referral portal.

Uses made of your information

Lawful basis for processing

Depending on your jurisdiction, under the GDPR and UK GDPR, Workable needs a lawful basis in order to process your personal data.

We rely on legitimate interest as the lawful basis on which We collect and use your personal data, provided this is not overridden by your data protection interests or fundamental rights and freedoms. Our legitimate interests are the evaluation of candidates and, eventually, the recruitment of staff for our business.

In limited situations, we might rely on your consent to process your personal data, in which we will ask for your clear consent to process your data.

Purposes of processing

We use information held about you in the following ways:

  • To consider your application in respect of a role for which you have applied.
  • To consider your application in respect of other similar roles.
  • To communicate with you during the recruitment process.
  • To enhance any information that we receive from you with information obtained from third party data providers.
  • To find appropriate candidates to fill our job openings.
  • To send you a formal employment offer, if we determine you are a suitable candidate.
  • To help our service providers (such as Workable’s processors and data providers) and Partners (such as the job sites through which you may have applied) improve their services.
  • To help improve and develop our own services (including training of our AI models).

Automated decision making / profiling

We will not use your data to make any automated decisions. We may use Workable’s technology to select appropriate candidates for Us to consider based on criteria expressly identified by Us, or typical in relation to the role for which you have applied to search through potential candidates and automatically add them to the recruiters’ pipeline. The process of finding suitable candidates might be automatic, however, any decision concerning who We will interview, who will proceed in the next interview round, and who will eventually fill the job opening will always be made by our staff.

Aggregate data

We may use anonymised and/or aggregate data collected through your use of the Services and the Website for statistical purposes, for improvement and development of the Services (including training of our AI models), to conduct research,or any other lawful purpose. Aggregate Data is not considered personal data.

Disclosure of your information

As set out above, we may disclose your information to our third party service providers, who use it only in accordance with our instructions and as otherwise required by law.

Where you have applied for a job opening through Indeed, We will disclose to Indeed certain information, including but not limited to a unique identifier used by Indeed to identify you, and information about your progress through our hiring process for the applicable job opening, and other information involving analysis of data relating to you as an applicant for employment (collectively “Disposition Data”). Indeed’s Privacy Notice in respect of Indeed’s use of the Disposition Data is available on Indeed’s website.

Where you have applied to a job opening through another service provider, we may disclose data similar to the Disposition Data defined above to such service provider. The service provider shall be the data controller of this data and shall therefore be responsible for complying with all applicable law in respect of the use of that data following its transfer by Us.

How We store your personal data

Security

We take appropriate measures to ensure that all personal data is kept secure including security measures to prevent personal data from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal data to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where We are legally required to do so.

Unfortunately, the transmission of information via the internet is not completely secure. Although We will do our best to protect your personal data, We cannot guarantee the security of your data transmitted through any online means, therefore any transmission remains at your own risk.

Where We store your personal data

Your personal data is stored in our own systems, in Greece, the United Kingdom and the United States.

The data that We collect from you and process using Workable’s services may be transferred to, and stored at a destination outside the UK or the European Economic Area ("EEA"). It may also be processed by staff operating outside the UK or the EEA who work for Us or for one of our suppliers. Such staff may be engaged in, among other things, the provision of support services. By submitting your personal data, you agree to this transfer, storing or processing.

In particular, your data may be i) accessible to Workable’s staff in the USA or ii) stored by Workable’s hosting service provider on servers in the USA. The USA does not have the same data protection laws as the UK and EEA. A Data Processing Agreement has been signed between the Workable group of companies, and between the appropriate Workable entity and each of its data processors. These data processing agreements are designed to help safeguard your privacy rights and give you remedies in the unlikely event of a misuse of your personal data.

For transfers of data from the EEA, Switzerland and the UK to the USA, We rely on the European Commission Standard Contractual Clauses ( “EU “SCCs”) and the UK International Data Transfer Addendum (“UK IDTA”) as approved by the Information Commissioner’s Office (“ICO”) (all together the “SCCs”).

If you would like further information please contact Us (see ‘Contact’ below). We will not otherwise transfer your personal data outside of the United Kingdom or EEA or to any organisation (or subordinate bodies) governed by public international law or which is set up under any agreement between two or more countries.

How long We keep your personal data

We have different retention periods for the personal data we receive from you based on privacy or other applicable laws and regulations in each jurisdiction.In any case, your personal information will be deleted upon receipt of a written request by you to us.

In the event you are offered and you accept a job with Us, your personal data will be kept in accordance with Workable’s Employees Privacy Policy, which is available to all Workable Employees.

Your rights

Subject to local data protection laws and in particular under the GDPR and the UK GDPR, you have a number of important rights free of charge. In summary, those include rights to:

  • access to your personal data and to certain other supplementary information that this Privacy Notice is already designed to address
  • require Us to correct any mistakes in your information which We hold
  • require the erasure of personal data concerning you in certain situations
  • receive the personal data concerning you which you have provided to Us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a third party in certain situations
  • object at any time to processing of personal data concerning you for direct marketing
  • object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you
  • object in certain other situations to our continued processing of your personal data
  • otherwise restrict our processing of your personal data in certain circumstances
  • claim compensation for damages caused by our breach of any data protection laws.

For further information on each of those rights, including the circumstances in which they apply, see the Guidance from the UK Information Commissioner’s Office on individuals rights under the UK GDPR.

If you would like to exercise any of those rights, please:

  • contact us using our Contact details below
  • let Us have enough information to identify you,
  • let Us have proof of your identity and address, and
  • let Us know the information to which your request relates.

For clarity, the above rights apply to EU, UK and Swiss data subjects, as required under applicable law, but also any other candidate, regardless of location, may exercise any of these rights.

How to complain

We hope that We can resolve any query or concern you raise about our use of your information.
The General Data Protection Regulation and the UK GDPR also give you right to lodge a complaint with a supervisory authority, in particular (under the GDPR) in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred.

The Supervisory Authority in the UK is the Information Commissioner who may be contacted at https://ico.org.uk/concerns/ or telephone: 0303 123 1113.

In Greece, the Supervisory Authority to which you may address your complaint is the Hellenic Data Protection Authority, situated at Kifissias Avenue (str. N­­o 1-3, PC 11523). You may contact them at Call Centre: +30-210 6475600 or E-mail: [email protected].

Contact

If you have any questions about this Privacy Notice or would like to exercise any of your rights, please contact [email protected], attention Workable’s DPO.

All questions, comments, and requests regarding this Privacy Notice or any of your rights should be addressed to Workable’s support team.