This Privacy Notice (together with any other documents referred to herein) sets out the basis on which Workable ( “We”, “Us” or “Workable”) collects and processes your personal data in connection with Our recruitment processes. Please read the following carefully to understand Our views and practices regarding your personal data and how We will treat it.
For the purposes of this Privacy Notice, any references to "personal data"; "legal basis"; "processing"; or "data controller" shall have the meaning established in the General Data Protection Regulation (“GDPR”) and the United Kingdom General Data Protection Regulation (“UK GDPR) and the UK Data Protection Act 2018.
We use Our own platform (Workable), to assist Us with Our recruitment process. We also use the appropriate Workable Affiliate to process personal information as a data processor on Our behalf. Any Workable Affiliate is only entitled to process your personal data in accordance with Our instructions.
Where you apply for a job opening via the application function on a job site or similar online service provider (“Partner”), you should note that the relevant Partner may retain your personal data and may also collect data from Us in respect of the progress of your application. Any use by the Partner of your data will be in accordance with the Partner’s Privacy Notice.
The primary applicable Data Controller will be the Workable entity that is recruiting for the role or intends to enter the employment contract with you.
For candidates located in Greece, the Data Controller is Workable Software Single Member Private Company, having its registered office address at Kifisias 95-97 Ave., Marousi Attiki, 15125, Greece.
For candidates located in the United Kingdom, the Data Controller is Workable Software Limited, registered in England and Wales, with Company Registration Number 08125469 and having its registered office address at 5 Golden Square, 5th Floor, London, W1F 9BS, UK.
For candidates located in the United States of America or the rest of the World, the Data Controller is Workable Inc., with offices located at 33 Arch Street, WeWork 17th Floor, ℅ Workable, Boston, Massachusetts 02110, USA.
We collect and process some or all of the following types of information from you:
Workable provides Us with the facility to link the data you provide to Us, with other publicly available information about you that you have published on the Internet – this may include sources such as LinkedIn and other social media profiles.
Workable’s technology allows Us to search various databases – some publicly available and others not, which may include your personal data (include your CV or Resumé), to find possible candidates to fill Our job openings. Where We find you in this way we will obtain your personal data from these sources.
We may receive your personal data from a third party who recommends you as a candidate for a specific job opening or for our business more generally, through our Referral portal.
Lawful basis for processing
Depending on your jurisdiction, under the GDPR and UK GDPR, Workable needs a lawful basis in order to process your personal data.
We rely on legitimate interest as the lawful basis on which We collect and use your personal data, provided this is not overridden by your data protection interests or fundamental rights and freedoms. Our legitimate interests are the evaluation of candidates and, eventually, the recruitment of staff for Our business.
In limited situations, we might rely on your consent to process your personal data, in which we will ask for your clear consent to process your data.
Purposes of Processing
We use information held about you in the following ways:
Automated Decision Making / Profiling
We will not use your data to make any automated decisions. We may use Workable’s technology to select appropriate candidates for Us to consider based on criteria expressly identified by Us, or typical in relation to the role for which you have applied to search through potential candidates and automatically add them to the recruiters’ pipeline. The process of finding suitable candidates might be automatic, however, any decision concerning who we will interview, who will proceed in the next interview round, and who will eventually fill the job Opening will always be made by Our staff.
As set out above, we may disclose your information to our third party service providers, who use it only in accordance with our instructions and as otherwise required by law.
Where you have applied for a job opening through Indeed, We will disclose to Indeed certain information, including but not limited to a unique identifier used by Indeed to identify you, and information about your progress through our hiring process for the applicable job opening, and other information involving analysis of data relating to you as an applicant for employment (collectively “Disposition Data”). Indeed’s Privacy Notice in respect of Indeed’s use of the Disposition Data is available on Indeed’s website.
Where you have applied to a job opening through another service provider, we may disclose data similar to the Disposition Data defined above to such service provider. The service provider shall be the data controller of this data and shall therefore be responsible for complying with all applicable law in respect of the use of that data following its transfer by Us.
We take appropriate measures to ensure that all personal data is kept secure including security measures to prevent personal data from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal data to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where We are legally required to do so.
Unfortunately, the transmission of information via the internet is not completely secure. Although We will do Our best to protect your personal data, We cannot guarantee the security of your data transmitted through any online means, therefore any transmission remains at your own risk.
Where We store your Personal Data
Your personal data is stored in our own systems, in Greece, the United Kingdom and the United States.
The data that We collect from you and process using Workable’s services may be transferred to, and stored at a destination outside the UK or the European Economic Area ("EEA"). It may also be processed by staff operating outside the UK or the EEA who work for Us or for one of our suppliers. Such staff may be engaged in, among other things, the provision of support services. By submitting your personal data, you agree to this transfer, storing or processing.
In particular, your data may be i) accessible to Workable’s staff in the USA or ii) stored by Workable’s hosting service provider on servers in the USA. The USA does not have the same data protection laws as the UK and EEA. A Data Processing Agreement has been signed between the Workable group of companies, and between the appropriate Workable entity and each of its data processors. These data processing agreements are designed to help safeguard your privacy rights and give you remedies in the unlikely event of a misuse of your personal data.
For transfers of data from the EEA, Switzerland and the UK to the USA, We rely on the European Commission Standard Contractual Clauses ( “EU “SCCs”) and the UK International Data Transfer Addendum (“UK IDTA”) as approved by the Information Commissioner’s Office (“ICO”) (all together the “SCCs”).
If you would like further information please contact Us (see ‘Contact’ below). We will not otherwise transfer your personal data outside of the United Kingdom or EEA or to any organisation (or subordinate bodies) governed by public international law or which is set up under any agreement between two or more countries.
How long we keep your personal data
We have different retention periods for the personal data we receive from you based on privacy or other applicable laws and regulations in each jurisdiction.In any case, your personal information will be deleted upon receipt of a written request by you to us.
Subject to local data protection laws and in particular under the GDPR and the UK GDPR, you have a number of important rights free of charge. In summary, those include rights to:
For further information on each of those rights, including the circumstances in which they apply, see the Guidance from the UK Information Commissioner’s Office on individuals rights under the UK GDPR.
If you would like to exercise any of those rights, please:
For clarity, the above rights apply to EU, UK and Swiss data subjects, as required under applicable law, but also any other candidate, regardless of location, may exercise any of these rights.
We hope that We can resolve any query or concern you raise about Our use of your information.
The General Data Protection Regulation and the UK GDPR also give you right to lodge a complaint with a supervisory authority, in particular (under the GDPR) in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred.
The Supervisory Authority in the UK is the Information Commissioner who may be contacted at https://ico.org.uk/concerns/ or telephone: 0303 123 1113.
In Greece, the Supervisory Authority to which you may address your complaint is the Hellenic Data Protection Authority, situated at Kifissias Avenue (str. No 1-3, PC 11523). You may contact them at Call Centre: +30-210 6475600 or E-mail: [email protected].
If you have any questions about this Privacy Notice or would like to exercise any of your rights, please contact [email protected], attention Workable’s DPO.
All questions, comments, and requests regarding this Privacy Notice or any of your rights should be addressed to Workable’s support team.