Privacy policy for recruitment using Teamtailor
The service for handling recruitments and simplifying the hiring process (the "Service") is powered by Teamtailor on behalf of Root Platform, Inc. ("Root") and/or any company forming part of Root's group ("Controller" “we” “us” etc.). It is important that the persons using the Service ("Users”) feel safe with, and are informed about, how we handle such User's personal data in the recruitment process. The Users’ personal data is processed with the purpose of managing and facilitating recruitment of employees to our business.
1. General
We as the Controller strive to maintain the highest possible standard regarding the protection of personal data. We process, manage, use, and protect a User's personal data in accordance with this privacy policy ("Privacy Policy")and all applicable data protection laws, including: South Africa’s Protection of Personal Information Act 2013 ("POPIA").
2. Collection of personal data
We are responsible for the processing of the personal data that the Users contributes to the Service, or for the personal data that we in other ways collects with regards to the Service.
When and how we collect personal data
We collect personal data about Users when Users;
a) make an application through the Service or otherwise, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn; or
b) use the Service to connect with our staff, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn; or
c) provide identifiable data through any other means, and such data is of relevance to the application procedure.
We collect data from third parties, such as Facebook, LinkedIn and through other public sources. This is referred to as “Sourcing” and be manually performed by our employees or automatically in the Service.
In some cases, existing employees can make recommendations about potential applicants. Such employees will add personal data about such potential applicants. In the cases where this is made, the potential applicant is considered a User in the context of this Privacy Policy and will be informed about the processing.
The types of personal data collected and processed
The categories of personal data that can be collected through the Service can be used to identify natural persons from names, e-mails, pictures and videos, information from Facebook and LinkedIn-accounts, answers to questions asked through the recruiting, titles, education and other information that the User or others have provided through the Service. Only data that is relevant for the recruitment process is collected and processed.
Purpose and lawfulness of processing
The purpose of the collecting and processing of personal data is to manage recruiting. The lawfulness of the processing of personal data is our legitimate interest to simplify and facilitate recruitment.
Personal data that is processed with the purpose of aggregated analysis or market research is always made unidentifiable. Such personal data cannot be used to identify a certain User. Thus, such data is not considered personal data.
The consent of the data subject
The User consents to the processing of its personal data with the purpose of Controller’s handling recruiting. The User consents that personal data is collected through the Service, when Users;
a) make an application through the Service, adding personal data about themselves either personally or by using a third-party source as Facebook or LinkedIn, and that Controller may use external sourcing-tools to add additional information; and
b) when they use the Service to connect to Controller’s recruitment department, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn.
The User also consents to the Controller collecting publically available information about the User and compiles them for use in recruitment purposes.
The User consents to the personal data being collected in accordance with the above a) and b) will be processed according to the below sections "Storage" and "How long the personal data will be processed".
The User has the right to withdraw his or her consent at any time, by contacting Controller using the contact details listed under 9. Using this right may however, mean that the User can not apply for a specific job or otherwise use the Service.
Storage
Personal data collected through the Service is stored on the Teamtailor database and on Google Workspaces. We may share data with our subsidiaries and affiliates to conduct data processing on our behalf, however access to this information is limited to staff on a need to know basis.
How long the personal data will be processed
We only retain a User's personal data for as long as necessary for the purposes described above. We may also store a Users’ personal data for potential future recruitment opportunities for a maximum of 18 months from the date on which such data was collected. If you as a User wish not to have your Personal Data processed for this purpose (future recruitment) please contact us using the contact details in paragraph 9.
3. Users’ rights
Users have the right to request information about the personal data that is processed by us, by notifying in writing, us using the contact details below under paragraph 9 below.
Users have the right to one (1) copy of the processed personal data which belongs to them without any charge. For further demanded copies, Controller has a right to charge a reasonable fee on the basis of the administrative costs for such demand.
Users have the right to, if necessary, rectification of inaccurate personal data concerning that User, via a written request, using the contact details in paragraph 9 below.
The User has the right to demand deletion or restriction of processing, and the right to object to processing based on legitimate interest under certain circumstances.
The User has the right to revoke any consent to processing that has been given by the User to Controller. Using this right may however, mean that the User can not apply for a specific job or otherwise use the Service.
The User has under certain circumstances a right to data portability, which means a right to get the personal data and transfer these to another controller as long as this does not negatively affect the rights and freedoms of others.
User has the right to lodge a complaint to the supervisory authority regarding the processing of personal data relating them, if the User considers that the processing of personal data infringes the legal framework of privacy law.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
4. Security
We at Root emphasise privacy and security throughout all system design processes and implement security measures based on the sensitivity of the data we hold. These measures are in place to protect the data from being disclosed, from loss, misuse and unauthorised access and from being altered or destroyed. They include: Encryption to keep your data private while stored and in transit; Multi-factor authentication and strong password requirements on the application; Using trusted, SOC2 certified and ISO27001 compliant AWS data centres for cloud-hosting our platform infrastructure; Strict access control in accordance with the principle of least privilege, meaning that access to personal data is limited to only Root employees and contractors who need that information to process it; and Regularly tested security incident response procedures.
However, transfers of information over the internet and mobile networks can never occur without any risk, so all transfers are made on the own risk of the person transferring the data. It is important that Users also take responsibility to ensure that their data is protected. It is the responsibility of the User that their login information is kept secret.
5. Transfer of personal data to third party
We will not sell Users’ personal data to third parties.
We may transfer Users’ Personal Data to;
a) our contractors and sub-contractors, acting as our Processors and Sub-Processors in accordance with our instructions, for the provision of the Service;
b) authorities or legal advisors in case criminal or improper behaviour is suspected; and
c) authorities, legal advisors or other actors, if required by us according to law or authority’s injunction.
We will only share your personal data with these third party service providers to the extent necessary for them to perform their services for us. We only use service providers we trust, and who have agreed to keep your data secure and confidential and to only use it for the purpose for which we shared it with them. Some of our service providers may be located in other countries. We provide for appropriate safeguards through contracts between our foreign and local service providers and us. Third party service providers are not owned or controlled by Root and third parties that have been granted access to information may have their own policies and practices for its collection, use and sharing.
6. Aggregated data (non-identifiable personal data)
We may share aggregated data to third parties. The aggregated data has in such instances been compiled from information that has been collected through the Service and can, for example, consist of statistics of internet traffic or the geological location for the use of the Service. The aggregated data does not contain any information that can be used to identify individual persons and is thus not personal data.
7. Cookies
When Users use the Service, information about the usage may be stored as cookies. Cookies are passive text files that are stored in the internet browser on the User’s device, such as computer, mobile phone or tablet, when using the Service. We use cookies to improve the User’s usage of the Service and to gather information about, for example, statistics about the usage of the Service. This is done to secure, maintain and improve the Service. The information that is collected through the cookies can in some instances be personal data and is, in such instances, regulated by our Cookie Policy.
Users can at any time disable the use of cookies by changing the local settings in their devices. Disabling of cookies can affect the experience of the Service, for example disabling some functions in the Service.
8. Changes
We have the right to, at any time, make changes or additions to the Privacy Policy. The latest version of the Privacy Policy will always be available through the Service. A new version is considered communicated to the Users when the User has either received an email informing the User of the new version (using the e-mail stated by the User in connection to the use of the Service) or when the User is otherwise informed of the new Privacy Policy.
9. Contact
For questions, further information about our handling of personal data or for contact with us in other matters, please use the below stated contact details; Root Platform meg@root.co.za