GRAFTON PRIVACY NOTICE
1. Introduction
This is a description of how your personal data is processed in our services.
The controller of your personal data is usually employer/potential employer as legal entity that uses Grafton services, which means that also the privacy policy of specific controller may apply. Please contact to employer/potential employer regarding this.
In above mentioned situations, Grafton Latvia is usually data processor regarding your personal data and thus follows also controller’s instructions when processing personal data.
To some activities and related personal data processing, the data controller is SIA “Grafton Latvia“, address K. Valdemara 33-35, Riga. Such activities include the collection and storing of candidates and potential candidates interest to a specific job type or vacancy.
We also use service provider Teamdash in order to manage our recruitment services and provide this web portal. Please read more information on this in Section 5 of this Privacy Notice.
2. How we get the personal information?
Grafton collects personal data from publicly available sources and other service providers (for example LinkedIn), also from you as a candidate in case you provide us personal information during the process on this portal.
In addition to this, Grafton processes your personal data to keep and rise the Grafton service quality. For this purpose and under the legal ground of Grafton legitimate interest, we store your interest regarding specific job type. Generally, we do not store detailed candidate information and we collect necessary data every time the Grafton service is used, from the above mentioned sources.
3. What kind of data is processed and why?
Processing activity |
Data categories |
Purpose |
Legal basis |
Account registration and data subject identification |
Name, date of birth, education, phone number, work experience and any other data that is requested or you choose to provide as provided in the web portal forms. |
Candidate/potential candidate identification and account registration |
Legal obligation/ Contract |
Potential candidate headhunting |
Publicly available information (cv.lv; cvmarket.lv; LinkedIn, companys’ homepages, etc.) |
Finding the suitable candidate for Grafton clients’s vacancy |
Contract |
Directing the candidate to personal tests if requested by the Grafton client |
Data processing is dependant on testing service provider |
Finding the suitable candidate for Grafton client’s vacancy |
Contract |
Communication with the candidate during the application period |
Name, e-mail, phone number, content of the communication |
Finding the suitable candidate for Grafton client’s vacancy |
Contract/Legitimate interest |
Storing the interest to vacancies of candidates/potential candidates |
Name, job type |
Maintaining and rising the level of Grafton service quality |
Legitimate interest |
Storing the information of successful employment |
Name, employer |
Fulfilling the contract between Grafton and its client |
Contract |
Storing the application information after application proceedings |
Data collected and created during the application process |
Storing the application data for potential legal dispute of discrimination |
Legal obligation |
Newsletters and marketing |
Name, e-mail The provision of data for the marketing purposes is optional. Any refusal to provide data or consent will have no consequence on your account registration and will not prevent the provision of our services |
Marketing |
Consent |
4. Special categories of data
Should you respond to an advertisement or apply voluntarily, you will be given the opportunity to declare whether you belong to a protected category in the data collection forms on the web portal or during a telephone interview or at one of the branches. This information is likely to reveal your state of health and falls within the special categories of data according to GDPR and will be processed in accordance with the relevant regulations in force.
The legal basis applicable to the processing of special categories of personal data concerning you is your explicit consent.
Should you fail to give your consent, it will not be possible to process data concerning your membership of a protected category.
Regardless, please do not indicate any special categories of data in your curriculum vitae (personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data intended to uniquely identify a natural person, data concerning a person's health or sex life or sexual orientation).
5. Sharing your personal data
We share your personal data only to a specific employer/potential employer and if necessary, to service provider that conducts personal candidate tests. Our employees have the access to your personal data only on need to know basis, which means that they process only the personal data that is related to their specific tasks.
We use third party service providers to help provide our services. Those service providers have access to your information as reasonably necessary to perform these tasks on our behalf and are obligated not to disclose or use it for other purposes. Such service providers may act as personal data processors or, in some activities also as personal data controllers, thus also their privacy notices apply as indicated below.
Why and with whom we share your personal data?
Categories of Recipients |
Reason for sharing |
Technical service providers |
We work with service providers that work on our behalf which may need access to certain personal data to provide their services to us. These companies include those we have hired to operate the technical infrastructure that we need to provide service and assist in protecting and securing our systems and services. |
Teamdash (Recruitment Software OÜ) |
Teamdash provides the web platform for candidate registration, documentation collection, communication, consent handling, etc. Teamdash acts as data processor or, for certain activities as data controller. Please read the details of personal data processing, by Teamdash in its Privacy Notice |
Testing |
We use third party service providers as our partners to carry out individual candidate testing. Grafton does not receive testing results, those results are sent directly to the employer/potential employer. |
Advertising partners |
We work with advertising partners to enable us to customize the advertising content you may receive. This may also include social media platforms like LinkedIn, Meta etc. |
International transfers
Some of our processing is cloud based so your personal information might be sent outside the European Economic Area. In such instances we will ensure that the transfer of your personal data is carried out in accordance with applicable privacy laws and, in particular, that appropriate contractual, technical, and organisational measures are in place.
Should you have any additional questions regarding the specific companies we use as service providers and the purposes and legal basis for such processing, please contact us as provided below.
6. Ensuring the security of personal data
We have taken necessary technical and organizational security measures to protect your personal data against accidental or unlawful destruction, loss or alteration and against the unauthorized disclosure, abuse or other processing in violation of applicable law.
This includes: identity and access management; preventing unauthorized viewing of personal data; deliberately set password requirements; structurally safe network design and other relevant continuously updated security measures.
7. Retention and deletion of personal data
The storage period of personal data depends on whether we have legal obligations to store data (i.e accounting regulations), contractual obligations, legitimate interest to provide best services or your explicit consent.
Data Type |
Purpose |
Retention Time |
Data for identification of the candidate/potential candidate |
Identification |
End of application process+fulfilling the purpose under the legitimate interest or deletion request from data subject |
Name, e-mail, phone number, content of the communication |
Communication with the candidate during the apply process |
End of application process |
Fact of successful application that ended with hiring |
Fulfilling the contract between Grafton and its client |
End of storing period derived from contract between Grafton and client |
Data and documentation collected during the application proceedings |
Storing the application data for potential legal dispute of discrimination |
1 year after the end of application process |
Web browser data, IP address, analytical cookies |
Website visitor analytics to maintain and rise the high level of user experience |
Withdrawal of consent |
Name, e-mail |
Newsletters and marketing |
Withdrawal of consent |
Grafton web portal account and related personal data by Teamdash |
Providing the Grafton services |
30 months |
8. Your rights and preferences
Under data protection law, you have certain rights. In some instances, you need to contact with data controller that may not be Grafton:
- Right to be informed and to access. You may get information regarding your personal data processed by us.
- Right to data portability. You have the right to receive your personal data from us in a structured, commonly used and machine-readable format and to independently transmit those data to a third party.
- Right to erasure. You have the right to have personal data we process about you erased from our systems if the personal data are no longer necessary for the related purposes.
- Right to object and restrict. You have the right to object to the processing of your personal data and restrict it in certain cases.
- Right to rectification. You have the right to make corrections to your personal data.
- Right to withdraw consent. When you have given us consent to process your personal data, you may withdraw said consent at any time.
To exercise any of the abovementioned rights or you have any other data protection related question or concern, please contact us latvia@grafton.com.
9. Other important information
Newsletter and direct marketing campaigns
With your explicit consent, we may send you our newsletter. You may opt out of these messages. Please note that email marketing messages include an opt-out mechanism within the message itself (e.g. an unsubscribe link in the emails we send to you). Clicking on the link in an email will opt you out of further messages. You can also write to us by e-mail to request the opt-out from messages. We may also use social media tools to market our products and services. As social media and web analytics providers act as joint processors, there might be consent or opt-out requirements also on their side.
Dispute resolution
If you have questions or concerns about our use of your personal information, please feel free to contact us at latvia@grafton.com.