Privacy Policy
I. INTRODUCTION
The following document describes Complywiser's privacy policy. Complywiser's privacy policy, hereinafter: the policy defines the rules, methods of processing and use of data as well as information from candidates, customers and users of all websites belonging to Complywiser, including: www.complywiser.com
Terms used in the Privacy Policy
Personal data - defined as Personal data within the meaning of the GDPR, i.e. all information relating to an identified or identifiable natural person. These data identify directly or indirectly a natural person with regards to the name, e-mail address or telephone number of the natural person and other data that, in connection with the above-mentioned, may identify the User.
GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46 / EC (general Data Protection Regulation), pursuant to which Complywiser and its Subsidiaries process Users Personal Data.
Complywiser - Complywiser Sp. z o.o. with its seat in (01-234) Warsaw, Poland at Kasprzaka 29/ 318, TAX number: 5273095019.
Specialist - a job candidate offered by Complywiser to its customers.
User - job candidate, newsletter subscriber, competition participant, person asking a question, training participant, person recommending a friend to work and visiting websites belonging to Complywiser, as well as a person using the candidate's portal.
Services - services provided by Complywiser electronically, via the website, i.e .: subscribing to the newsletter, sending inquiries via the contact form, sending documents necessary in the recruitment process, application for participation in competitions, application for participation in training, creation of an account on the candidate portal.
Providing Personal Data - By providing personal data on www.complywiser.com and any other website that belongs to Complywiser, the User confirms that he/she has all necessary permissions to disclose personal data that will be later used by Complywiser in a manner described in this Policy.
Data Protection Officer - A Data Protection Officer has been appointed at Complywiser: Tomasz Baliński. In case of any questions regarding regulations concerning personal data processing described in this Policy, contact the Data Protection Officer by sending an email to hello@complywiser.com.
II.PROCESSING OF PERSONAL DATA - PURPOSES, LEGAL BASIS, SCOPE
Complywiser processes Personal Data for various purposes for which it needs a specific scope of Personal Data from the User, and each purpose of processing has its legal basis resulting from the provisions of the GDPR and sectoral regulations that contain regulations regarding the protection of Personal Data:
Purpose of processing personal data | Legal basis for processing personal data | Scope of processed personal data |
---|---|---|
Conducting recruitment for the needs of Complywiser |
|
|
Conducting recruitment for projects carried out for Complywiser customers |
|
|
Sending anwers to Users, to the e-mail addresses or telephone numbers provided by them, to previous inquiries sent via the contact form, as well as to contact the Users and answer their previously sent messages and inquiries. | Art. 6 para. 1 point f GDPR - legitimate interest of Complywiser as the Administrator of personal data |
|
Sending marketing and promotional information about products and services, events and news, including subscription to the newsletter. |
|
|
Providing the User with marketing information by phone or SMS. |
|
|
Pursuing and defending rights in the event of mutual claims. | Art. 6 para. 1 point f GDPR - legitimate interest of Complywiser as the Administrator of personal data |
|
Organizing and conducting trainings for Users and employees of Complywiser customers. | Art. 6 para. 1 point b GDPR - conclusion and performance of the contract between the User and Complywiser |
|
Organization and conducting of competitions. | Art. 6 para. 1 point a GDPR - consent to the processing of personal data |
|
Organization of conferences, seminars, events, webinars. | Art. 6 para. 1 point a GDPR - consent to the processing of personal data |
|
Profiling the data held in order to better match marketing information and job offers to the User's preferences. | Art. 6 para. 1 point f GDPR - legitimate interest of Complywiser as the Administrator of personal data |
|
Contacting customers' and suppliers' representatives to coordinate activities under the contracts. Conducting negotiations, discussions with potential suppliers / customers. | Art. 6 para. 1 point f GDPR - legitimate interest of Complywiser as the Administrator of personal data |
|
The following chapters provide more detailed information on the Personal Data processed:
- As for the processing of Personal Data for the purposes of recruitment - Chapter VI of this Policy
- As for the processing of Personal Data in connection with marketing activities - Chapter VII of this Policy
- As for the processing of Personal Data in connection with organizing and conducting training - Chapter VIII of this Policy
- As for the processing of Personal Data in connection with the organization of events, conferences, seminars, webinars - Chapter IX of this Policy 8 As for the processing of Personal Data in connection with organizing and conducting competitions - Chapter X of this Policy
- As for the processing of Personal Data in connection with the performance of contracts (suppliers, customers) - Chapter XI of this Policy.
Legitimate interest of Complywiser as the Administrator of personal data:
Legitimate interest is one of the legal grounds provided for in Art. 6 para. 1 GDPR, which assumes that there are situations in which the Personal Data Administrator may perform specific processing of Personal Data. Such legitimate interests that we use at Complywiser include:
- Possibility of pursuing claims or defending against them. Promoting Complywiser, sending marketing information
- Implementation of cooperation agreements with customers and suppliers
- Conducting negotiations, discussions with potential customers
- Conducting recruitment for projects carried out for Complywiser's customers
- Handling inquiries sent to Complywiser - providing answers to Users.
In the event of contact with the User in order to provide an answer, the legal basis for the processing of Personal Data is the legitimate interest of Complywiser as the administrator of Personal Data provided on the contact form (Art. 6 para. 1 point f GDPR). The legitimate interest is manifested in the possibility of responding to the inquiry sent, providing the User with a comprehensive answer. Without the processing of Personal Data, in particular contact data, we will not be able to provide an answer, and thus, help in resolving an issue indicated in the inquiry.
III. STORING OF PERSONAL DATA
The processing of personal data generally continues until the purpose for which the Personal Data was obtained and processed and stored, for the purpose of achieving it, ceases to exist. After achieving the goal or its termination, Complywiser removes all personal data obtained from the User. However, there are situations in which Complywiser stores Personal Data even if the purpose of processing has been achieved or will no longer be achieved. This is due to legal requirements or business needs. Importantly, the provisions of the GDPR make it possible to show the exact duration of the storage of Personal Data (days / weeks / months / years) and to indicate the criteria for data storage for a given period of time, e.g. 'for the period of limitation of the User's potential claims against Complywiser', 'until withdrawal consent to the processing of Personal Data '.
Below, information on the storage periods of Personal Data.
Purpose of processing personal data | Personal data storage period | The basis for the storage of personal data | What does the retention period result from? |
---|---|---|---|
Conducting recruitment for the needs of Complywiser. | Until the consent to the processing of Personal Data is withdrawn. | Art. 6 para. 1 point a GDPR - consent to the processing of personal data. | Complywiser's authorization obtained based on the consent of the User - candidate. |
Conducting recruitment for projects carried out for Complywiser customers. | Until the consent to the processing of Personal Data is withdrawn 5 years after the completion of the recruitment process at the customer with a negative result. | Art. 6 para. 1 point a GDPR - consent to the processing of personal data Art. 6 para. 1 point f GDPR - legitimate interest of Complywiser as the Administrator of personal data. | Complywiser's authorization obtained based on the consent of the User - candidate. Data storage for 5 years - requirements set out in contracts with customers regarding the prohibition of Complywiser from offering again a previously rejected candidate. |
Sending answers to Users, to the e- mail addresses or telephone numbers provided by them, to previous inquiries sent via the contact form, as well as to contact the Users and answer their previously sent messages and inquiries. | 2 months | Art. 6 para. 1 point f GDPR - legitimate interest of Complywiser as the Administrator of personal data. | Mechanisms set up in the IT system to remove messages-inquiries after they are handled by a dedicated employee. |
Sending marketing and promotional information about products and services, events and news, including subscription to the newsletter. | Until the consent to the processing of Personal Data is withdrawn. | Art. 6 para. 1 point a GDPR - consent to the processing of personal data. | Complywiser's authorization obtained based on the consent of the User - recipient of marketing materials. |
Providing the User with marketing information by phone or SMS | Until the consent to the processing of Personal Data is withdrawn. | Art. 6 para. 1 point a GDPR - consent to the processing of personal data. | Complywiser's authorization obtained based on the consent of the User - recipient of marketing materials. |
Pursuing and defending rights in the event of mutual claims. | Limitation period for potential claims. | Art. 6 para. 1 point a GDPR - consent to the processing of personal data. | Mechanisms set up in the IT system to remove messages-inquiries after they are handled by a dedicated employee. |
Sending marketing and promotional information about products and services, events and news, including subscription to the newsletter. | Until the consent to the processing of Personal Data is withdrawn. | Art. 6 para. 1 point a GDPR - consent to the processing of personal data. | Complywiser's authorization obtained based on the consent of the User - recipient of marketing materials. |
Providing the User with marketing information by phone or SMS. | Until the consent to the processing of Personal Data is withdrawn. | Art. 6 para. 1 point a GDPR - consent to the processing of personal data. | Complywiser's authorization obtained based on the consent of the User - recipient of marketing materials. |
Pursuing and defending rights in the event of mutual claims. | Limitation period for potential claims. | Art. 6 para. 1 point f GDPR - legitimate interest of Complywiser as the Administrator of personal data. | A right resulting from legal provisions (especially the Civil Code) |
Organizing and conducting trainings for Users and employees of Complywiser customers. | Time to organize and conduct the training. Limitation period for potential claims. | Art. 6 para. 1 point a GDPR - consent to the processing of personal data Art. 6 para. 1 point f GDPR - legitimate interest of Complywiser as the Administrator of personal data. | Implementation of the training contract between the User and Complywiser, the contract concluded by subscribing to the training. A right resulting from legal provisions (especially the Civil Code) |
Organization and conducting of competitions | Time to organize and conduct the competition | Art. 6 para. 1 point a GDPR - consent to the processing of personal data. | Complywiser's authorization obtained based on the consent of the User - competition's participant |
Organization of conferences, seminars, events, webinars | Time of organization and implementation of the event / seminar / conference / webinar | Art. 6 para. 1 point a GDPR - consent to the processing of personal data. | Complywiser's authorization obtained based on the consent of the User - participant of the event / seminar / conference / webinar. |
Profiling the data held in order to better match marketing information and job offers to the User's preferences | Until the User objects to further profiling | Art. 6 para. 1 point f GDPR - legitimate interest of Complywiser as the Administrator of personal data. | Business need to match marketing information / job offers to have information provided by or obtained from the User or available on professional social networks such as LinkedIn. |
Contacting customers' and suppliers' representatives to coordinate activities under the contracts. Conducting negotiations, discussions with potential suppliers / customers. | The time of Complywiser's cooperation with a customer / supplier or the period of negotiations with a potential supplier / customer. | Art. 6 para. 1 point f GDPR - legitimate interest of Complywiser as the Administrator of personal data. | Agreements concluded with suppliers and customers. A right resulting from legal provisions (Civil Code). |
Ensuring the quality of services provided through the Complywiser Contact Center. | The time necessary to answer the question asked by the User or to take the action requested by the Users. The time necessary to evaluate the actions taken by Complywiser as a result of the conversations. The period of limitation of potential claims (5 years). | Art. 6 para. 1 point a GDPR - consent to the processing of personal data. | A right resulting from legal provisions (Civil Code). |
The above mentioned list of store periods for Personal Data is general and does not contain details that are relevant in each case. The mentioned details were recorded:
- In connection with recruitment for Complywiser customers - chapter VI of this Policy
- In connection with cooperation with suppliers, customers - chapter XI of this Policy.
IV. TRANSFER OF PERSONAL DATA
There are situations in which Complywiser transfers the User's Personal Data to other external entities - companies, entrepreneurs or public institutions. The transfer of Personal Data results fromr
Provisions of law requiring the transfer of data to a specific public institution (police, court, prosecutor's office, etc.);
Complywiser's internal needs regarding obtaining a specific service to support the achievement of business goals (entities providing legal advisory services, legalization of foreigners' stay, booking accommodation in hotels, sending mass-mailings, etc.).
The transfer of Personal Data takes place in the form of sharing or entrusting them. Below is an explanation of the differences between the indicated forms.
Sharing Personal Data | Entrusting Personal Data |
---|---|
Enstrusting Personal Data consists of transferring data to another entity based on one of the legal grounds specified in the provisions of the GDPR - specifically: Art. 6 para. 1. i.e.User's consent (point a) Performance of the contract between the User and Complywiser (point b) Provision of law authorizing or obliging Complywiser to provide Personal Data (point c) Complywiser's legitimate interest as the Personal Data Administrator resulting from the provisions of law (point f). Note: other grounds: vital interests (point d) and acting in the public interest (point e) do not apply to Complywiser, as it does not conduct activities for which it obtains and processes Personal Data on their basis. | Entrustment is the transfer of Personal Data based on Art. 28 GDPR - Complywiser, as the Administrator of Personal Data, transfers them to another entity by concluding a special so- called contracts for entrusting the processing of personal data. |
Complywiser provides or entrusts Personal Data to the following entities:
Sharing Personal Data | Entrusting Personal Data |
---|---|
Complywiser customers (in the scope of contact details of representatives) | Entities providing mass marketing e-mail / SMS mailing services |
Complywiser's potential customers (in the scope of contact details of representatives) | Entities providing services that conduct certification exams at the end of courses and training |
Suppliers (in the scope of contact details of representatives) | Training providers |
Public administration bodies authorized under the provisions of law | Entities intermediating in the organization of events (owners of portals for registering for events) |
Complywiser provides Users' Personal Data to its customers in connection with their recruitment for the purpose of employment, then delegation to provide services under the outsourcing of specialists or entire teams. Complywiser has concluded appropriate agreements and contracts specifying the rules for disclosing Personal Data. Each User has the right to access information to which customer Personal data has been made available on the terms set out in Chapter V of this Policy.
V. USER RIGHTS
Each User has the rights related to the processing of his Personal Data by Complywiser, in accordance with Chapter III: Art. 15-22 GDPR:
What law? | What is it? | Situations excluding the implementation of the law |
---|---|---|
The right to access one's Personal Data (Art. 15 GDPR) | The User receives a list of Personal Data obtained from him by Complywiser and processed in documents and IT systems. | None |
The right to rectify the processed data (Art. 16 GDPR) | The User may report the need to update, supplement the Personal Data provided to Complywiser or request correction if Complywiser uses incorrect data. | None |
The right to delete data ("the right to be forgotten") (Art. 17 GDPR) | Complywiser deletes all Personal Data obtained from the User. This right is exercised without undue delay in one of the following circumstances: 1) The Personal Data held are no longer needed by Complywiser to achieve the purpose or the purpose for which the Personal Data is processed has expired. 2) The User has withdrawn consent to the processing of Personal Data, which is the only legal basis for Complywiser (Art. 6 para. 1 point a GDPR). 3) The User objects to the further processing of his Personal Data, based on the legitimate interest of Complywiser as the Personal Data Administrator (Art. 6 para. 1 point f GDPR). 4) Complywiser processed Personal Data contrary to the applicable law. 5) The law requires the deletion of Personal Data. | Legal provisions that require further processing - the storage of Personal Data despite the lack of purpose for their processing. Considerations of public interest in the field of public health. Archival purposes. Establishing, pursuing or defending claims by Complywiser or the User. |
Right to restriction of processing (Art. 18 GDPR) | The User may request the restriction of the processing of his Personal Data, i.e. he may oblige Complywiser, for example, not to disclose them to another entity to be used for the implementation of marketing mailing, to withhold access to them by Complywiser employees. The User may exercise this right in the following situations: 1) He has doubts as to the correctness of Personal Data held by Complywiser and wants to clarify any doubts. 2) Complywiser no longer needs the data to achieve the goal, but the User does not want them to be deleted in order to be able to pursue claims against Complywiser or defend against them. 3) The User has objected to further data processing and wants to receive information from Complywiser whether his legitimate interests as the basis for the processing of Personal Data override the interests and rights of the User. | None |
Right to transfer of Personal Data (Art. 20 GDPR) | The User may submit a request for Complywiser to prepare a report / statement with his Personal Data, and then for Complywiser to provide the report / statement to another entity - the Personal Data Administrator. This right is exercised if: 1) Complywiser processes Personal Data based on the User's consent or the data is necessary for the performance of the contract between Complywiser and the User. 2) Personal data is processed in an automated manner = in IT systems. | None |
Right to transfer of Personal Data (Art. 20 GDPR) | The User may object to Complywiser against further processing of their Personal Data, regardless of the reason. From the moment the objection is raised, Complywiser cannot continue processing Personal Data. | Complywiser will prove to the User that its own legitimate interests for data processing override the User's rights. The data is processed for the purposes of scientific, historical or statistical research. |
The right not to be subject to decisions based solely on automated processing, including profiling (Art. 22 GDPR) | The User has the right to be assessed on the basis of comprehensive actions based on the Personal Data obtained from the User, not only by special algorithms that bring the data together, but also by actions taken by employees. | Making decisions is necessary for the performance of the contract between Complywiser and the User.The law authorizes to make such decisions. The user has consented to such decisions. |
The right to withdraw consent to the processing of Personal Data (Art. 7 sec 3 GDPR) | The User may revoke the previously expressed voluntarily consent to the processing of his Personal Data. Wherever consent is the only legal basis for Complywiser to process Personal Data, this right is strictly enforced. That is, inter alia: 1) conducting recruitment processes; 2) sending newsletters; 3) participation in the competition. | None |
The right to file a complaint against the processing of Personal Data (Art. 13 para. 2 point d GDPR; Art. 14 sec 2 point e GDPR) | The user may notify the GDPR control authority - in Poland it is: The President of the Office for Personal Data Protection, that Complywiser violates the provisions of the GDPR, that, for example, it fails to secure data, has obtained more data than is actually necessary for a specific purpose. Contact details: Polish Data Protection Commissioner (Urząd Ochrony Danych Osobowych) Stawki 2, 00-193 Warsaw, www.uodo.gov.pl, e-mail: kancelaria@uodo.gov.pl, telephone number: 606-950-000 | None |
The implementation of each of the above rights takes place at the User's request sent to hello@complywiser.com. Complywiser examines the submitted application and sends a reply within 1 month from the date of receipt of the application together with an indication of the result of the examination - what specific actions have been taken with the estimated time for the processing of the entire application, if specific activities require a longer processing time. Complywiser reserves the right to respond to a request for the exercise of any right later than the abovementioned date: up to two months (resulting from Art. 12 para. 3 GDPR), due to the number of inquiries or the complex nature of the inquiry sent. By complexity, we understand the need to compile data from many IT systems or the need to consult more than one person from a department or departments in order to obtain information that is the subject of the application. In each case, Complywiser undertakes to inform the User about this fact, providing justification. Complywiser also reserves that it may refuse to exercise any of the rights specified in Art. 15 - 22 of the GDPR in a situation where the User submits applications in a continuous, excessive manner, without any justification. Each time Complywiser will justify the refusal to exercise the right indicated in the application. By persistent and excessive nature, we mean sending subsequent requests with a similar request to the original one, despite the examination and notification of its processing, e.g. The User sends the request for access to information, Complywiser executes it - it sends a summary of the information it has, and the User sends the second and the same request again, without explaining the reason for the repeated request for information.
Under the right to withdraw consent, the User may at any time withdraw consent to further processing of Personal Data for purposes that require consent, provided that the withdrawal of consent does not affect the lawful use of Personal Data in activities based on consent before its withdrawal. The following chapters provide details on how to withdraw consent for a specific purpose (recruitment, marketing, competitions, etc.)
Under the right to access information, the User is entitled to obtain the following information in the form of a report or statement:
- Purpose of processing Personal Data
- Categories of Personal Data - what data we process, e.g. name, surname, telephone number
- Legal bases for data processing
- Information on recipients or categories of recipients of data - to whom (a person, company, institution) this data may be transferred
- Information on the right to request from Complywiser the rectification of data, their deletion or limitation of their processing and to object to specific data processing
- Information on the possibility of lodging a complaint to the President of the Personal Data Protection Office
- Information about the data source, if the data has not been obtained directly from the User - indication of the person or company or institution that provided the Personal Data
- On the use of profiling: on what terms it is undertaken, what may be the consequences of profiling for the User
Complywiser also informs that each subsequent copy of Personal Data is associated with a fee resulting from the costs incurred in connection with the creation of another copy of Personal Data. Complywiser notifies the User about the costs after assessing the scope of the information indicated in the application.
With regards to the right to delete Personal Data, Complywiser deletes not only data obtained from the User himself, but also information obtained as a result of the analyzes, e.g. information about the User's interests in specific categories of information, products, services based on the User's-consumer activities; information about the professional experience of the User-candidate obtained as a result of the interview, the candidate's own assessment based on the course of the interview. Exceptions to the implementation of the law, shown in the table, result from applicable law. Complywiser analyzes each case of an exception individually for each case - the relationship between Complywiser and the User. What is crucial, this right shall always be executed. Legal or internal - business requirements are only factors that extend the full implementation of the request for the removal of Personal Data.
The right to object to the further processing of Personal Data is that the User indicates that he does not want his Personal Data to be used for purposes that are pursued as legitimate interests within the meaning of Art. 6 para. 1 point f GDPR. After receiving the objection, Complywiser analyzes whether the objection may be taken into account or whether there are grounds to reject it, as it is not an absolute right. There may be situations in which the User's right to object to further data processing will make it impossible for Complywiser to achieve the goal. Examples of the purposes of processing Personal Data in a legitimate interest, where the objection may be disregard:
- Intention to pursue claims against the User or defense against potential claims on the part of the User;
- The User is a candidate recruited by a Complywiser customer, recruitment interviews are ongoing, and the User does not want his Personal Data to be still processed.
Each case is analyzed individually. The result of the analysis, together with the decision and justification for not considering the objection, is sent to the User by Complywiser as part of the examination of the submitted application.
If the analysis shows that Complywiser has no prerequisites for further processing of Personal Data, the objection is accepted and Complywiser deletes the Personal Data.
With regards to the right not to be subject to decisions based solely on automated processing, including profiling - it is important that no automated activities are performed at Complywiser. Employees compile Personal Data, as discussed in more detail in Chapter XII of this Policy. Typical automated processing activities are e.g. carrying out a creditworthiness assessment.
VI. PROCESSING OF PERSONAL DATA IN RECRUITMENT PROCESSES
As Complywiser, we recruit for our own needs and for customers, to whom we provide specialist delivery services or specialist teams, so-called body leasing. Therefore, we would like to inform you that the data of the User - candidate (herein from in this chapter: candidate) may also be processed by Complywiser customers, as mentioned in the content of the job advertisement, indicating that we are recruiting for the customer.
The legal basis for the acquisition and processing of Personal Data for recruitment by Complywiser is the candidate's consent (Art. 6 sec 1 point a GDPR). At the same time, we would like to inform you that by agreeing to the recruitment processes, this consent will apply to both recruitment for a specific position included in the job advertisement, and for future recruitment for similar positions tailored to the profile and professional experience. As a candidate, you can withdraw your consent to further processing at any time, in accordance with Chapter VIII of this Policy, which, however, does not affect the lawful use of Personal Data in activities carried out on the basis of consent before its withdrawal.
However, it is important to emphasize that there is a specific scope of Personal Data obtained from the candidate, which results directly from the law - Art. 221 § 1 of the Labor Code, which fills in Art. 6 para. 1 point c GDPR - a legal provision authorizing or obliging to obtain and process Personal Data. These are the following data:
- First name(-es) and surname
- Date of birth
- Contact details provided by the User in the CV / cover letter
- Education
- Vocational qualifications
- The history of previous employment.
Other data, incl. regarding the assessment of the candidate's competences from previous employers, public image, Complywiser acquires on the basis of the candidate's voluntary consent.
As far as the sources of obtaining Personal Data for the purpose of recruitment processes are concerned, these are the following:
- Candidate applications submitted in response to job advertisements posted on portals such as pracuj.pl and on our website Complywiser.com, career table
- Candidate's referral system. In this situation, the recommending person enters his data and the data of the recommended person and places a CV under the form with the User's data.
Complywiser verifies the CV of the recommended person, received from the recommending person, in terms of the consent of the recommended person to the processing of Personal Data that meets the requirements of the GDPR. If the consent has been concluded, Complywiser has the right to use this data for recruitment processes:
- Direct contact with the candidate via social networking sites LinkedIn, Goldenline (so-called headhunting). The Complywiser recruiting employee contacts the candidate directly from LinkedIn /Goldenline level, sends a request for the candidate's interest in the presented job offer and further contact. After receiving information about the interest in the offer, the employee registers the candidate in the CRM system by entering only the first and last name and contact details available on the candidate's profile on LinkedIn / Goldenline, generates a special form to obtain consent for recruitment processes, while the recruitment is continued. Once the candidate accepts this special form, Complywiser is entitled to carry out future recruitments - sending the candidate new job offerse
- CV sent by the candidate on his / her own initiative via the form on Complywiser.pl, tab career.
Recruitment for the needs of customers
As mentioned at the beginning of the chapter, Complywiser recruits for its own needs and for its customers. Recruitment for customers is carried out:
- By posting a job advertisement with information about recruitment for the customer
- Contact with the candidate already registered in our CRM database, in connection with participation in the previous recruitment, with the consent given to Complywiser for the processing of Personal Data for the purpose of carrying out future recruitment processes
- Direct contact with the potential candidate via social networking sites LinkedIn, Goldenline (so-called headhunting).
Generally, Complywiser first recruits, conducts interviews and technical tests (verification of practical skills). The result of the interview is a decision whether the candidate will be offered to the customer or not. If so - the recruiting employee prepares a CV in a special format, consisting of the candidate's data such as: name, date of birth, description of education, work experience, completed courses and training. The CV prepared in this way is forwarded to the customer by an employee representing Complywiser in contacts with the customer. The customer verifies the candidate presented and decides whether they wish to conduct an interview. If so - the customer arranges an interview with the candidate through the Complywiser employee responsible for contact with the customer. After the interview, the customer decides whether or not to hire a candidate.
In the context of Personal Data provided to the customer and processed by him, the following issues are relevant:
- Complywiser is the Administrator of personal data - it acquires data and processes it for the purpose of the recruitment process for work for the customer. The processing of Personal Data is based on the candidate's consent to recruit (Art. 6 sec 1 point a GDPR)e
- Transfer of Personal Data to the customer based on the legitimate interest of Complywiser as the Personal Data Administrator (Art. 6 sec 1 point f GDPR) in the form of their disclosure. The legitimate interest is manifested in ensuring the implementation of the cooperation agreement concluded with the customer for the preparation and delegation of a candidate-specialist or a team of candidates-specialists to perform the work specified in the cooperation agreement. Importantly, at the very beginning of the recruitment process, the candidate receives information that the recruitment is carried out for the customer's needs, to perform work for them. The aforementioned consent applies to situations when Complywiser verifies the submitted application
- The customer becomes a separate administrator of personal data, independently provides the appropriate legal basis for the processing of the received personal data of the candidate. It obtains consent (or provides another legal basis from the GDPR) and sends an information clause to meet the GDPR requirement of Art. 13-14e
- The personal data of the candidate recruited to the customer is stored by Complywiser for a period of 5 years counted from the end of the recruitment. Importantly, this only applies to candidates rejected by the customer - who have not been hired
- It results from the provisions in the contracts with each customer: a clause concerning the prohibition of re-offering the candidate and his professional profile for 5 years, in a situation where the candidate has already participated in the recruitment completed with a negative result
- The candidate always has the right to withdraw consent to the processing of Personal Data, without affecting the actions taken before its withdrawal. As for the withdrawal of consent for Complywiser (i.e. recruitment for Complywiser's internal needs), the procedure is described in Chapter VIII of this Policy. However, when it comes to the customer, the candidate contacts the customer using contact details provided in the information clause
- The candidate may object to the transfer of Personal Data by Complywiser to the customer, the processing of his data by the customer. The objection will be considered by Complywiser, the data will be deleted, however this is equal to the candidate's resignation from participation in the recruitment process. this means the candidate's resignation from participation in the recruitment process.
An important issue in recruiting for customers are additional requirements on the part of some customers to carry out the so-called background check. This process consists of verifying the information provided by the candidate in the CV: information about education, work experience, completed courses, training, language skills (level of proficiency in foreign languages). Verifications are carried out by Complywiser in accordance with the requirements specified in the cooperation agreements. They are followed by, among others
- Certificates and diplomas
- References from previous employers
In addition to the above, the customer may require a background check extended to include information on criminal record, credit history, and financial matters (debt). In Poland, there is a general prohibition of verification of the above-mentioned information, except for the exceptions specified directly in Polish law (banking law, provisions on the rules for obtaining information on a clean criminal record, etc.). Therefore, in contracts with customers, Complywiser agrees that the background check of the information contained in the CV is carried out by Complywiser, and in the field of no criminal record, credit history, and financial matters, the customer conducts the background check on the candidates.
VII. PROCESSING OF PERSONAL DATA FOR MARKETING PURPOSES
By submitting an inquiry or signing up for a training, conferences or other event organized by Complywiser, the User may consent to processing of personal data in order to receive marketing information on products and services offered by Complywiser, including newsletters. The rules for obtaining such consent have been described in the chapter VI points 1-2 of this Policy. The consent may be withdrawn anytime taking into consideration rules defined in the chapter VIII of this Policy.
User's consent for processing personal data (Art. 6 para. 1 point a GDPR) is the legal basis for sending newsletters. It can be granted while providing one's e-mail address in the newsletter subscription form or gated content as well as by checking a box while completing a contact or recruitment form. Providing the e- mail address in the newsletter subscription form is a clear affirmative action of consenting to processing personal data as defined in the Art. 4 para. 11 of GDPR regarding the definition of consent as well as connected 32nd motif of GDPR explaining the clear affirmative action.
According to the above-mentioned motif, a clear affirmative action includes informing Complywiser that User's e-mail address provided in the form may be used for sending newsletter that includes Complywiser's promotional information. It is one of acceptable forms of consenting to using provided e-mail address for the defined purpose (such forms also include checking a box located near the content of the consent).
Consent to sending unsolicited marketing information, according to Art. 10 of rules for electronically supplied services and Art. 172 para. 1 of Telecommunication Act, is provided by the user independently and separately by checking a dedicated box located near the content of the consent.
In order to obtain some materials uploaded to Complywiser's website, it may be necessary to complete a form that requires providing personal data. Such data will be processed according to the consent (Art. 6 para. 1 point a GDPR) expressed by a clear affirmative action. If the User wishes to receive other marketing information, he/she may state so by checking a relevant box. If the User will not state so, it means that he/she is not interested in receiving other information thus Complywiser will not send it.
VIII. PROCESSING OF PERSONAL DATA WHEN ORGANIZING AND CONDUCTING TRAININGS
One of the areas of Complywiser's activity are open and dedicated training for Complywiser's customers and any other interested person. Therefore, Complywiser will process the Personal Data of Users declaring participation in training, to the extent necessary to carry out matters related to the training. Details on the purposes for which the Users' Personal Data - training participants are processed and other information are specified in the dedicated chapter on the protection of Personal Data in the Training Regulations available at the time of enrollment for the training.
IX. PROCESSING OF PERSONAL DATA IN CONNECTION WITH THE ORGANIZATION OF EVENTS
Complywiser processes Users' personal data in connection with organizing and conducting events. By signing up for the event - using a special form or by sending an application to a dedicated e- mail address - the User gives consent to the processing of his Personal Data for the implementation of all activities related to the organized event. Consent stands for the legal basis for data processing (Art. 6 sec 1 point a GDPR) expressed in the form of an explicit affirmative action. The User may at any time withdraw consent under the rights in accordance with Chapter VI, but this means that he / she will not be able to continue participating in the event. Details on the purposes for which the Users' Personal Data - event participants are processed and other information are specified in the dedicated chapter on the protection of Personal Data in the Training Regulations available at the time of enrolment for the event.
X. PROCESSING OF PERSONAL DATA IN CONNECTION WITH THE ORGANIZATION AND CONDUCTING OF COMPETITIONS
Complywiser processes Users' personal data in connection with organizing and conducting events. By signing up for the competition - using a special form or by sending an application to a dedicated e-mail address - the User gives consent to the processing of his Personal Data for the implementation of all activities related to the organized competition. Consent stands for the legal basis for data processing (Art. 6 para. 1 point a GDPR) expressed in the form of an explicit affirmative action. The User may at any time withdraw consent under the rights in accordance with Chapter VI, but this means that he / she will not be able to continue participating in the competition. Details on the purposes for which the Users' Personal Data - competition participants are processed and other information are specified in the dedicated chapter on the protection of Personal Data in the Training Regulations available at the time of enrolment for the competition.
XI. PROCESSING OF PERSONAL DATA IN CONNECTION WITH A CONVERSATION VIA THE CONTACT CENTER
Complywiser records voice conversations of Users calling the Complywiser Contact Center number. Therefore, it processes Personal Data in the form of the voice of the caller and other Personal Data provided by the User during the call. The aim of the data processing is to answer the questions asked by the User during the call, undertake the actions requested by the User, ensure the quality of services offered by Complywiser, and assert possible claims resulting from the conversation. The basis for processing the Personal Data is the consent (Art. 6 sec. 1 point a GDPR) expressed by the User calling Complywiser Contact Center. The User may withdraw consent at any time within the framework of their rights, in accordance with Chapter VI, which, however, does not affect the lawful use of Personal Data in activities performed on the basis of consent prior to its withdrawal. Furthermore, withdrawal of consent may prevent Complywiser from responding to the question asked by the User or from taking actions requested by the User. Call recordings are stored by Complywiser for a period of 5 years, after which they are permanently deleted. Call recordings are not made available to other external entities except for situations concerning state bodies and strictly required by law.
XII. PROCESSING OF PERSONAL DATA OF CUSTOMERS, POTENTIAL CUSTOMERS, SUPPLIERS
Complywiser processes Personal Data of:
- Customers and suppliers - representatives of persons entered in the National Court Register, proxies as well as contact persons and delegated employees for the coordination of cooperationZ 8 Potential customers and suppliers - representatives entered in the National Court Register, proxies and contact persons in connection with the ongoing talks on potential cooperation.
Detailed information is presented below:
Personal Data Controller:
- Complywiser
Source of obtaining Personal Data:
- Public registers of business entities (applies to persons representing a business entity)
- Employees of the customer / potential customer / supplier / potential supplier Purpose of processing Personal Data Coordination of cooperation, providing necessary information related to the contract, settlement of work performed, ensuring the safety of personnel, property and information belonging to Complywiser.
- Legal basis: Art. 6 sec 1 point f GDPR - legitimate interest of Complywiser as the administrator of personal data
- Scope of processed personal data
- Full name
- Work e-mail address
- Work phone number
- Job position
- Entity name
- PESEL number (applies only to persons entered in the National Court Register)
- Personal data storage period The time of Complywiser's cooperation with a customer / supplier or the period of negotiations with a potential supplier / customer. Limitation period for potential claims
- Recipients of Personal Data Public administration bodies authorized under the provisions of law Entities providing cloud solution delivery services Subsidiary companies
- Personal Data protection rights Details are presented in Chapter V of this Policy
XIII. PROCESSING OF PERSONAL DATA AND PROFILING
In Complywiser, profiling is understood as a form of automated processing of personal data that includes using some of User's personal data. Obtained data may include information from social media profiles, location or data provided by Users via Complywiser's website. It allows Complywiser to:
- ensure a more conscious and better suited selection of job 's skills and experience (in case of job candidates)
- tailor marketing and advertising materials to User's interests and needs.
The tools used by Complywiser for profiling link the data provided by the User during the recruitment process or as a result of receiving a newsletter with the data available, e.g., in social networks - which were provided by the User themselves. Data binding allows Complywiser to create User's profile which can be used in:
- providing information on job offers that take into account that person's competences and professional experience
- sending marketing materials that cover that person's preferences and interests
- sending information on planned trainings and events organized by Complywiser that cover competences or interests of that person.
Owing to that, we do not sent irrelevant and unwanted information as well as reduce the risk of creating spam.
An example of such activities may be binding data provided during recruitment process (e.g. CV, covering letter) and contact data (e.g. e-mail, phone number) with information provided on websites such as LinkedIn or Goldenline (e.g. identification and contact data, professional experience description, education, skills or interests). In this case, binding data means connecting information from own IT systems (such as job candidate data kept in CRM) with information provided online.
Using the profiling tool influences the scope of information sent to the User e.g. content of newsletter that may include information on trainings, events, current promotions or discounts. In case of recruitment, the obtained data allows making a decision whether the User should be still processes as a job candidate, have technical tests or be presented to a customer.
All of the above-mentioned aspects of using the tools and its effects are the justified interest of Complywiser as a Data Controller (Art. 6 sec 1 point f GDPR). The reason being that personal data obtained by the tools allows Complywiser to make decisions that enable decreasing the operational cost of recruitment processes, marketing activities that aim at building Complywiser's reputation as a reliable company which focuses on the quality of provided services and worker satisfaction as well as respecting User's needs and requirements in terms of sent information.
Complywiser ensures that information or data gained by the tools are used only for purpose described above and are not shared with other parties that specialize in creating such profiles. The User may object to profiling at any given moment according to chapter VIII, points 6-7 of this Policy. As a result, the User will not receive any marketing or sales information as well as updates with job offers tailored to his/her profile or competences. In addition, it also means that Complywiser will stop using the tool to profile this User's personal data but is still able to process it in case of having a different legal basis e.g. consent.
XIV. SECURITY
Complywiser has implemented appropriate (organisational and technical) security measures to protect personal data from loss, misuse, unauthorised processing or modification. Complywiser is obliged to protect any information disclosed by Users in accordance to security and confidentiality standards.
Complywiser has implemented the Information Security Management System that is certified as compliant with international ISO 27001 security norms which ensure that Complywiser operates according to GDPR regulations in terms of implemented security measures for processing personal data (Art. 32 GDPR). Complywiser has proper procedures for managing accesses to IT systems that disable unauthorised workers from processing data. Complywiser's workers are subjected to regular trainings regarding secure processing of personal data and current threats. In order to guarantee the security of personal data provided by the users, Complywiser uses dedicated SSL certificates that use data encryption keys based on most reliable encryption algorithms such as RSA or SHA (min. 1024 bites) to transfer data provided on Complywisers websites to IT systems.
XV. COOKIES
The websites belonging to Complywiser (including www.complywiser.com) use cookies. By using these websites, the User agrees to the storing of cookies on the device with which they enter the website, as explained below.
Cookies are small text files sent to the User's browser by a site they visit at a given time. Cookies allow it to remember information about the visit. As a result, on subsequent visits, the site is easier to use and better adapted to the User's preferences.
Settings regarding cookies used on the www.complywiser.com and other websites may be modified via our website or via a third-party website. Cookies are used by Complywiser to:
- Customize content of webpages to User's preferences, and to optimize their use (in particular, these files allow identification of User's device and proper display of the webpage tailored to their individual needs)
- Create statistics that help to understand how Users use the websites which leads to improving its structure and contenta "e Deliver marketing content tailored to Users' interests.
Types of cookies used by Complywiser:
“Essential” cookies that enable the use of services available through the site e.g. allowing the use of sessions;
“Functional” cookies that allow the website to “remember” settings chosen by the User and personalize the interface e.g. in terms of selected mobile/desktop version, the last phrases typed by the User, website's appearance etc.;
“Analytical” cookies that allow us to monitor the activity of Users on the website.
“Marketing” cookies that allow us to tailor advertisements and communications to the User's interests and behaviours.
The User may block saving cookies by accessing the preference settings in the cookies window that appears when visiting the website for the first time, accessing the“Cookie Settings” link located in the footer of the website, or changing their browser settings. Disabling cookies may affect the functioning of the website.
XVI. MODIFICATIONS TO THE POLICY
In relation to the development and progress of technology and changing regulations, the principles set out in this Privacy Policy may change. Any changes to these rules will be communicated to Users by publishing the new contents of this document on thewww.complywiser.com/privacy-policy/website.