Privacy Policy

GRAFTON PRIVACY NOTICE

1. Introduction

This is a description of how your personal data is processed in our services.

The controller of your personal data is usually employer/potential employer as legal entity that uses Grafton services, which means that also the privacy policy of specific controller may apply. Please contact to employer/potential employer regarding this.

In above mentioned situations, Grafton Latvia is usually data processor regarding your personal data and thus follows also controller’s instructions when processing personal data.

To some activities and related personal data processing, the data controller is SIA Grafton Latvia, address K. Valdemara 33-35, Riga. Such activities include the collection and storing of candidates and potential candidates interest to a specific job type or vacancy.

We also use service provider Teamdash in order to manage our recruitment services and provide this web portal. Please read more information on this in Section 5 of this Privacy Notice.

 

 

2. How we get the personal information?

Grafton collects personal data from publicly available sources and other service providers (for example LinkedIn), also from you as a candidate in case you provide us personal information during the process on this portal.

In addition to this, Grafton processes your personal data to keep and rise the Grafton service quality. For this purpose and under the legal ground of Grafton legitimate interest, we store your interest regarding specific job type. Generally, we do not store detailed candidate information and we collect necessary data every time the Grafton service is used, from the above mentioned sources.

 

 

3. What kind of data is processed and why?

Processing activity

Data categories

Purpose

Legal basis

Account registration and data subject identification

Name, date of birth,  education, phone number, work experience and any other data that is requested or you choose to provide as provided in the web portal forms.

Candidate/potential candidate identification and account registration

Legal  obligation/ Contract

Potential candidate headhunting

Publicly available information (cv.lv; cvmarket.lv; LinkedIn, companys’ homepages, etc.)

Finding the suitable candidate for Grafton clients’s vacancy

Contract

Directing the candidate to personal tests if requested by the Grafton client

Data processing is dependant on testing service provider

Finding the suitable candidate for Grafton client’s vacancy

Contract

Communication with the candidate during the application period

Name, e-mail, phone number, content of the communication

Finding the suitable candidate for Grafton client’s vacancy

Contract/Legitimate interest

Storing the interest to vacancies of candidates/potential candidates

Name, job type

Maintaining and rising the level of Grafton service quality

Legitimate interest

Storing the information of successful employment

Name, employer

Fulfilling the contract between Grafton and its client

Contract

Storing the application information after application proceedings

Data collected and created during the application process

Storing the application data for potential legal dispute of discrimination

Legal obligation

Newsletters and marketing

Name, e-mail

The provision of data for the marketing purposes is optional. Any refusal to provide data or consent will have no consequence on your account registration and will not prevent the provision of our services

Marketing

Consent

 

 

4. Special categories of data

Should you respond to an advertisement or apply voluntarily, you will be given the opportunity to declare whether you belong to a protected category in the data collection forms on the web portal or during a telephone interview or at one of the branches. This information is likely to reveal your state of health and falls within the special categories of data according to GDPR and will be processed in accordance with the relevant regulations in force.

The legal basis applicable to the processing of special categories of personal data concerning you is your explicit consent.

Should you fail to give your consent, it will not be possible to process data concerning your membership of a protected category.

Regardless, please do not indicate any special categories of data in your curriculum vitae (personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data intended to uniquely identify a natural person, data concerning a person's health or sex life or sexual orientation).

 

 

5. Sharing your personal data

We share your personal data only to a specific employer/potential employer and if necessary, to service provider that conducts personal candidate tests. Our employees have the access to your personal data only on need to know basis, which means that they process only the personal data that is related to their specific tasks.

We use third party service providers to help provide our services. Those service providers have access to your information as reasonably necessary to perform these tasks on our behalf and are obligated not to disclose or use it for other purposes. Such service providers may act as personal data processors or, in some activities also as personal data controllers, thus also their privacy notices apply as indicated below.

Why and with whom we share your personal data?

Categories of Recipients

Reason for sharing

Technical service providers

We work with service providers that work on our behalf which may need access to certain personal data to provide their services to us. These companies include those we have hired to operate the technical infrastructure that we need to provide service and assist in protecting and securing our systems and services.

Teamdash (Recruitment Software OÜ)

Teamdash provides the web platform for candidate registration, documentation collection, communication, consent handling, etc. Teamdash acts as data processor or, for certain activities as data controller. Please read the details of personal data processing, by Teamdash in its Privacy Notice  

Testing

We use third party service providers as our partners to carry out individual candidate testing. Grafton does not receive testing results, those results are sent directly to the employer/potential employer.

Advertising partners

We work with advertising partners to enable us to customize the advertising content you may receive. This may also include social media platforms like LinkedIn, Meta etc.

 

International transfers

Some of our processing is cloud based so your personal information might be sent outside the European Economic Area. In such instances we will ensure that the transfer of your personal data is carried out in accordance with applicable privacy laws and, in particular, that appropriate contractual, technical, and organisational measures are in place.

Should you have any additional questions regarding the specific companies we use as service providers and the purposes and legal basis for such processing, please contact us as provided below.

 

 

6. Ensuring the security of personal data

We have taken necessary technical and organizational security measures to protect your personal data against accidental or unlawful destruction, loss or alteration and against the unauthorized disclosure, abuse or other processing in violation of applicable law.

This includes: identity and access management; preventing unauthorized viewing of personal data; deliberately set password requirements; structurally safe network design and other relevant continuously updated security measures.

 

 

7. Retention and deletion of personal data

The storage period of personal data depends on whether we have legal obligations to store data (i.e accounting regulations), contractual obligations, legitimate interest to provide best services or your explicit consent.  

Data Type

Purpose

Retention Time

Data for identification of the candidate/potential candidate

Identification

End of application process+fulfilling the purpose under the legitimate interest or deletion request from data subject

Name, e-mail, phone number, content of the communication

Communication with the candidate during the apply process

End of application process

Fact of successful application that ended with hiring

Fulfilling the contract between Grafton and its client

End of storing period derived from contract between Grafton and client

Data and documentation collected during the application proceedings

Storing the application data for potential legal dispute of discrimination

1 year after the end of application process

Web browser data, IP address, analytical cookies

Website visitor analytics to maintain and rise the high level of user experience

Withdrawal of consent

Name, e-mail

Newsletters and marketing

Withdrawal of consent

Grafton web portal account and related personal data by Teamdash

Providing the Grafton services

30 months

 

 

8. Your rights and preferences

Under data protection law, you have certain rights. In some instances, you need to contact with data controller that may not be Grafton:

  1. Right to be informed and to access. You may get information regarding your personal data processed by us.

  2. Right to data portability. You have the right to receive your personal data from us in a structured, commonly used and machine-readable format and to independently transmit those data to a third party.

  3. Right to erasure. You have the right to have personal data we process about you erased from our systems if the personal data are no longer necessary for the related purposes.

  4. Right to object and restrict. You have the right to object to the processing of your personal data and restrict it in certain cases.

  5. Right to rectification. You have the right to make corrections to your personal data.

  6. Right to withdraw consent. When you have given us consent to process your personal data, you may withdraw said consent at any time.

To exercise any of the abovementioned rights or you have any other data protection related question or concern, please contact us latvia@grafton.com.

 

9. Other important information

Newsletter and direct marketing campaigns

With your explicit consent, we may send you our newsletter. You may opt out of these messages. Please note that email marketing messages include an opt-out mechanism within the message itself (e.g. an unsubscribe link in the emails we send to you). Clicking on the link in an email will opt you out of further messages. You can also write to us by e-mail to request the opt-out from messages. We may also use social media tools to market our products and services. As social media and web analytics providers act as joint processors, there might be consent or opt-out requirements also on their side.

Dispute resolution

If you have questions or concerns about our use of your personal information, please feel free to contact us at latvia@grafton.com.