Processing of (personal) data by the entity in charge of the online application process
PRIVACY POLICY
1. Data controller
Anders Innovations Oy
Aurakatu 12 B, 20100 Turku, Finland
+358 45 843 6699
2. Contact person for register-related matters
Jaana Anglé
Head of HR & Communications
jaana.angle@anders.com
3. Name of register
Recruitment
4. Purpose of personal data processing
Personal data is used in the recruitment process and contacting job applicants. Personal data is being deleted after 12 months.
5. Data content of the register
The register may contain the following information on the users:
6. Regular sources of information
Job application form from Anders.com websites.
7. Statutory disclosure of information
Data transmitted as part of applications will be transferred using TLS encryption and stored in a database. This database is operated by Personio GmbH, which offers a human resource and applicant management software solution (https://www.personio.com/legal-notice/). In this context, Personio is our processor under article 28 of the GDPR. In this case, the processing is based on an agreement for the processing of orders between us as the controller and Personio.
8. Transfer of data outside of the EU or EEA
Personal data is not transferred outside of the European Union and privacy protection has been ensured in compliance with the Personal Data Act. Access to recruitment register is granted to employees only when needed.
9. Principles of register security
The personal data is kept confidential. Anders Innovations Oy’s data network is protected by a firewall and other technical measures that ensure the level of security. Persons processing register information are obligated to keep the contents of the register confidential. The data subject has the right to check what personal data on them the register contains. If they so wish, the subject may request to review their personal information in the register, and this access will be granted after the customer has been identified. The data controller is obligated, upon the data subject’s request, to correct or delete the information concerning the data subject from the register.
1. Data controller
Anders Innovations Oy
Aurakatu 12 B, 20100 Turku, Finland
+358 45 843 6699
2. Contact person for register-related matters
Jaana Anglé
Head of HR & Communications
jaana.angle@anders.com
3. Name of register
Recruitment
4. Purpose of personal data processing
Personal data is used in the recruitment process and contacting job applicants. Personal data is being deleted after 12 months.
5. Data content of the register
The register may contain the following information on the users:
- Name
- Contact details
- Job application, CV and other information job applicant provides
6. Regular sources of information
Job application form from Anders.com websites.
7. Statutory disclosure of information
Data transmitted as part of applications will be transferred using TLS encryption and stored in a database. This database is operated by Personio GmbH, which offers a human resource and applicant management software solution (https://www.personio.com/legal-notice/). In this context, Personio is our processor under article 28 of the GDPR. In this case, the processing is based on an agreement for the processing of orders between us as the controller and Personio.
8. Transfer of data outside of the EU or EEA
Personal data is not transferred outside of the European Union and privacy protection has been ensured in compliance with the Personal Data Act. Access to recruitment register is granted to employees only when needed.
9. Principles of register security
The personal data is kept confidential. Anders Innovations Oy’s data network is protected by a firewall and other technical measures that ensure the level of security. Persons processing register information are obligated to keep the contents of the register confidential. The data subject has the right to check what personal data on them the register contains. If they so wish, the subject may request to review their personal information in the register, and this access will be granted after the customer has been identified. The data controller is obligated, upon the data subject’s request, to correct or delete the information concerning the data subject from the register.