Contact Agreement
GRS GLOBAL RECRUITMENT SOLUTIONS PRIVACY NOTICE INTRODUCTION
This Privacy Notice explains what we do with your personal data, whether we are in the process of helping you find a job, continuing our relationship with you once we have found you a role, providing you with a service, receiving a service from you, using your data to ask for your assistance in relation to one of our Candidates, or you are visiting our website. It describes how we collect, use and process your personal data, and how, in doing so, we comply with our legal obligations to you. Your privacy is important to us, and we are committed to protecting and safeguarding your data privacy rights. This Privacy Notice applies to the personal data of our Website Users, Candidates, Clients, Suppliers, and other people whom we may contact in order to find out more about our Candidates or whom they indicate is an emergency contact. It also applies to the emergency contacts of our Staff. To be clear, if you are a member of GRS Global Recruitment Solutions’ Staff, you should refer to the GRS Global Recruitment Solutions’ Staff Privacy Notice. For the purpose of applicable data protection legislation (including but not limited to the General Data Protection Regulation (Regulation (EU) 2016/679) (the “GDPR”), the company responsible for your personal data is legal entity GRS Professional Recruitment Services Ltd HE155035 trading as “GRS Global Recruitment Solutions”. It is important to point out that we may amend this Privacy Notice from time to time. Please visit this page if you want to stay up to date, as we will post any changes here. If you are dissatisfied with any aspect of our Privacy Notice, you may have legal rights and, where relevant, we have described these as well. This Privacy Notice applies to Cyprus and Malta where we have operations.
SHORT FORM “AT A GLANCE” SECTION
What is our Legal Basis for Processing your data?
What kind of personal data do we collect?
CANDIDATE DATA:
In order to provide the best possible employment opportunities that are tailored to you, we need to process certain information about you. We only ask for details that will genuinely help us to help you, such as your name, contact details, education details, employment history, emergency contacts, immigration status, financial information (where we need to carry out financial background
checks), and social security number (and of course you may choose to share other relevant information with us). Where appropriate and in accordance with local laws and requirements, we may also collect information related to your health, diversity information or details of any criminal convictions. If you would like a more detailed description of the personal data that we collect about you, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664. To the extent that you access our website we will also collect certain data from you. If you would like more information about this, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
CLIENT DATA:
If you are a GRS Global Recruitment Solutions customer, we need to collect and use information about you, or individuals at your organisation, in the course of providing you services such as: finding Candidates who are the right fit for you or your organization or providing you with Outplacement Services and/or notifying you of content published by GRS Global Recruitment Solutions which is likely to be relevant and useful to you for example Salary Surveys. If you would like a more detailed description of the personal data that we collect in this way, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664. To the extent that you access our website we will also collect certain data from you. If you would like more information about this, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
SUPPLIER DATA:
We need a small amount of information from our Suppliers to ensure that things run smoothly. We need contact details of relevant individuals at your organisation so that we can communicate with you. We also need other information such as your bank details so that we can pay for the services you provide (if this is part of the contractual arrangements between us). If you would like a more detailed description of the personal data that we collect about you, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664. To the extent that you access our website we will also collect certain data from you. If you would like more information about this, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
PEOPLE WHOSE DATA WE RECEIVE FROM CANDIDATES AND STAFF, SUCH AS REFEREES AND EMERGENCY CONTACTS:
In order to provide Candidates with suitable employment opportunities safely and securely and to provide for every eventuality for them and our Staff, we need some basic background information. We only ask for very basic contact details, so that we can get in touch with you either for a reference or because you’ve been listed as an emergency contact for one of our Candidates or Staff members.
If you would like a more detailed description of the personal data that we collect about you, contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
WEBSITE USERS:
We collect a limited amount of data from our Website Users which we use to help us to improve your experience when using our website and to help us manage the services we provide. This includes information such as how you use our website, the frequency with which you access our website, and the times that our website is most popular. If you would like to find out more information about what data we collect about you when you visit our website, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664. A number of elements of the personal data we collect from you are required to enable us to fulfil our contractual duties to you or to others. Where appropriate, some, for example Candidates’ Social Insurance number are required by law. Other items may simply be needed to ensure that our relationship can run smoothly. Depending on the type of personal data in question and the grounds on which we may be processing it, should you decline to provide us with such data, we may not be able to fulfil our contractual requirements or, in extreme cases, may not be able to continue with our relationship. For details of the legal bases that we rely on to be able to use and process your personal data, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
What is our Legal Basis for Processing your data?
When you provide your data, we will do our utmost to protect your information and support you in your job search. GDPR states that we are required to let you know under which legal basis your data is processed. We are using Legitimate Interest as our legal basis for processing the following data: Legitimate Interest – Article 6(1)(f) says: “processing is necessary for the purpose of the legitimate interest pursued by the controller or by the third party except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data”
For Candidates: When you provide us with your CV, apply to one of our adverts or upload your CV onto a job board, it is reasonable to expect that you will be contacted by us about your job search and any potential suitable vacancies. You may not be successful in your initial application, however, by using the information you have provided, we can let you know about any future vacancies that may be suitable for you. We will always have an initial telephone conversation with you, so we can fully understand your career experience to date and what you are looking for, so we can
provide you with a tailored service. We also inform you what you can expect from us and how your data will be used. We will arrange face to face meetings but if this is not possible, these may be completed by Skype, Facetime or other video conference
platforms.
For Clients: We want to ensure that we provide you with the best possible service and so we hold data on your business and the contacts within your business that we may need to have conversations with. We log details of conversations, emails sent and received, meetings, vacancies and placements. For Suppliers: In order to ensure prompt payment for services you have provided, we need to hold certain information on you and your business so that payments can be made.
For Others: We may hold your information if it has been provided to us as a reference for a new employee or a candidate for whom we have secured a placement. The data noted above is necessary for our legitimate interest as a recruitment consultancy to provide a comprehensive recruitment service to our candidates, clients and new employees. If you are a member of staff of GRS Recruitment or are working for us on a temporary contract with one of our clients, there is certain data that we require in order to process payroll – for this information we are using Legal Obligation as the legal basis for processing.
Legal Obligation – Article (6)(1) (c) says: “processing is necessary for compliance with a legal obligation to which the controller is subject.”
How do we collect your personal data?
CANDIDATE DATA:
There are two main ways in which we collect your personal data: 1. Directly from you; and 2.
From third parties. If you want to know more about how we collect your personal data, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664. To the extent that you access our website or read or click on an email from us, we may also collect certain data automatically or through you providing it to us. For more information please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
CLIENT DATA:
There are two main ways in which we collect your personal data:
1 Directly from you; and 2 From third parties (e.g. our Candidates) and other limited sources (e.g. online and offline media). If you would like to know more about how we collect your personal data, contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664. To the extent that you access our website or read or click on an email from us, we may also collect certain data automatically or through you providing it to us. For more information please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
SUPPLIER DATA:
We collect your personal data during the course of our work with you. To the extent that you access our website or read or click on an email from us, we may also collect certain data automatically or through you providing it to us. For more information please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
PEOPLE WHOSE DATA WE RECEIVE FROM CANDIDATES AND STAFF, SUCH AS REFEREES AND EMERGENCY CONTACTS: We collect your contact details only where a Candidate or a member of our Staff puts you down as their emergency contact or where a Candidate gives them to us in order for you to serve as a referee.
WEBSITE USERS:
We collect your data automatically via cookies when you visit our website, in line with cookie settings in your browser. If you would like to find out more about cookies, including how we use them and what choices are available to you, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
How Do We Use Your Personal Data?
CANDIDATE DATA:
The main reason for using your personal details is to help you find employment that might be suitable for you. The more information we have about you, your skillset and your ambitions, the more bespoke we can make our service. Where appropriate and in accordance with the laws of Cyprus & Malta , we may also use your personal data for things like marketing, profiling and diversity monitoring. Where appropriate, we will seek your consent to undertake some of these activities. For more details on how we use your personal data, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
CLIENT DATA:
The main reason for using information about Clients is to ensure that the contractual arrangements between us can properly be implemented so that the relationship can run smoothly. This may involve identifying Candidates who we think will be the right fit for you or your organization or assisting your former employees find work through our Outplacement Services. The more information we have, the more bespoke we can make our service.
For more details on how we use your personal data, contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
SUPPLIER DATA:
The main reasons for using your personal data are to ensure that the contractual arrangements between us can properly be implemented so that the relationship can run smoothly, and to comply with legal requirements. For more details on how we use your personal data, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
PEOPLE WHOSE DATA WE RECEIVE FROM CANDIDATES AND STAFF, SUCH AS REFEREES AND EMERGENCY CONTACTS: We use referees’ personal data to help our Candidates to find employment which is suited to them. If we are able to verify their details and qualifications, we can make sure that they are well matched with prospective employers. We may also use referees’ personal data to contact them in relation to recruitment activities that may be of interest to them. We use the personal details of a Candidates or Staff member’s emergency contacts in the case of an accident or emergency affecting that Candidates or member of Staff. For more detail on how we use your personal data, contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
WEBSITE USERS:
We use your data to help us to improve your experience of using our website. If you are also a Candidate or Client of GRS Global Recruitment Solutions, we may use data from your use of our websites to enhance other aspects of our communications with, or service to, you. If you would like to find out more about cookies, including how we use them and what choices are available to you, please contact us at dpo@grsrecruitment.com Please note that communications to and from GRS Global Recruitment Solutions’ Staff including emails may be reviewed as part of internal or external investigations or litigation.
Who do we share your personal data with?
CANDIDATE DATA:
We may share your personal data with various parties, in various ways and for various reasons. Primarily we will share your information with prospective employers to increase your chances of securing the job you want.
CLIENT DATA:
We will share your data: primarily to ensure that we provide you with a suitable pool of Candidates you require
SUPPLIER DATA:
Unless you specify otherwise, we may share your information with any of our group companies.
PEOPLE WHOSE DATA WE RECEIVE FROM CANDIDATES AND STAFF, SUCH AS REFEREES AND EMERGENCY CONTACTS: Unless you specify otherwise, we may share your information with any of our group companies.
WEBSITE USERS:
Primarily we will share your information with prospective employers to increase your chances of securing the job you want. How do we safeguard your personal data? We care about protecting your information. That’s why we put in place appropriate measures that are designed to prevent unauthorized access to, and misuse of, your personal data. For more information on the procedures we put in place, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
How long do we keep your personal data for?
As a candidate if we have not had meaningful contact with you for a period of forty eight (48) months, we will delete your personal data from our systems unless we believe in good faith that the law or other regulation requires us to preserve it (for example, because of our obligations to the Social Insurance and Tax Authorities or in connection with any anticipated litigation). As a client or prospect client if we have not had meaningful contact with you for a period of forty eight (48) months, we will delete your personal data from our systems unless we believe in good faith that the law or other regulation requires us to preserve it (for example, because of our obligations to the Social Insurance and Tax Authorities or in connection with any anticipated litigation). As a supplier if we have not had meaningful contact with you for a period of eighty four (84) months, we will delete your personal data from our systems unless we believe in good faith that the law or other regulation requires us to preserve it (for example, because of our obligations to the Social Insurance and Tax Authorities or in connection with any anticipated litigation). For more information on our policy for the retention of personal data, please contact our DPO dpo@grsrecruitment.com or call +357 25342720 or +356 27780664.
How can you access, amend or take back the personal data that you have given to us? Even if we already hold your personal data, you still have various rights in relation to it. To get in touch about this please contact our DPO at dpo@grsrecruitment.com We will seek to deal with your request without undue delay, and in any event in accordance with the requirements of any applicable laws. Please note that we may keep a record of your communications to help us resolve any issues which you raise. Right to object: If we are using your data because we deem it necessary for our legitimate interests to do so, and you do not agree, you have the right to object. We will respond to your request within 30 days (although we may be allowed to extend this period in certain cases). Generally, we will only disagree with you if certain limited conditions apply.
Right to withdraw consent: Where we have obtained your consent to process your personal data for certain activities (for example, for profiling your suitability for certain roles), or consent to market to you, you may withdraw your consent at any time. Data Subject Access Requests (DSAR): Just so it’s clear, you have the right to ask us to confirm what information we hold about you at any time, and you may ask us to modify, update or Delete such information. At this point we may comply with your request or, additionally do one of the following: – we may ask you to verify your identity, or ask for more information about your request; and – where we are legally permitted to do so, we may decline your request, but we will explain why if we do so. Right to erasure: In certain situations, (for example, where we have processed your data unlawfully), you have the right to request us to “erase” your personal data. We will respond to your request within 30 days (although we may be allowed to extend this period in certain cases) and will only disagree with you if certain limited conditions apply. If we do agree to your request, we will Delete your data completely. Right of data portability: If you wish, you have the right to transfer your data from us to another data controller. We will help with this – either by directly transferring your data for you, or by providing you with a copy of the data. Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with The Cyprus Supervisory Authority. If your interests or requirements change, you can unsubscribe from our marketing content (for example job role emails or GRS Global Recruitment Solutions newsletters) by contacting us at dpo@grsrecruitment.com Who is responsible for processing your personal data on the GRS Global Recruitment Solutions website? GRS Global Recruitment Solutions controls the processing of personal data on its website. If you’ve got any further questions, please contact us at dpo@grsrecruitment.com
What are Cookies?
A “cookie” is a bite-sized piece of data that is stored on your computer’s hard drive. They are used by nearly all websites and do not harm your system. How to reject cookies If you don’t want to receive cookies that are not strictly necessary to perform basic features of our site, you may choose to opt-out by changing your browser settings. Most web browsers will accept cookies but if you would rather we didn’t collect data
in this way you can choose to accept all or some, or reject cookies in your browser’s privacy settings. However, rejecting all cookies means that you may not be able to take full advantage of all our website’s features. Each browser is different, so check the “Help” menu of your browser to learn how to change your cookie preferences. For more information, generally on cookies, including how to disable them, please refer to www.aboutcookies.org You will also find details on how to delete cookies from your computer.
LONG FORM DETAILED SECTIONS WHAT KIND OF PERSONAL INFORMATION DO WE COLLECT?
So you’re looking for a bit more insight into what data we collect about you? Here’s a more detailed look at the information we may collect. The information described below is, of course, in addition to any personal data we are required by law to process in any given situation.
CANDIDATE DATA:
We may collect some or all of the information listed below to enable us to offer you employment opportunities which are tailored to your circumstances and your interests: – Name; – Contact details; – Education details; – Employment history; – Emergency contacts and details of any dependents; – Referee details; – Immigration status (whether you need a work permit); – A copy of your driving license and/or passport/identity card; – Financial information (Payroll or financial background checks); – Social Insurance number, ARC number and any other tax-related information; – Details of any criminal convictions if this is required for a role that you are interested in applying for; – Details about your current remuneration, pensions and benefits arrangements; – Information on your interests and needs regarding future employment, both collected directly and inferred, for example from jobs viewed or articles read on our website;
– Extra information that you choose to tell us; – Extra information that your referees choose to tell us about you; – Extra information that our Clients may tell us about you, or that we find from other third party sources such as job sites; – IP address; and – The dates, times and frequency with which you access our services; Please note that the above list of categories of personal data we may collect is not exhaustive.
CLIENT DATA:
The data we collect about Clients is actually very limited. We generally only need to have your contact details or the details of individual contacts at your organisation (such as their names, telephone numbers and email addresses) to enable us to ensure that our relationship runs smoothly. We also hold information relating to your engagement with Candidate profiles and other material published by GRS Global Recruitment Solutions, which we use to ensure that our marketing communications to you are relevant and timely. We may also hold extra information that someone in your organisation has chosen to tell us. In certain circumstances, such as when you engage with our Finance and Credit Control personnel, and calls with you may be documented. If we need any additional personal data for any reason, we will let you know.
SUPPLIER DATA:
We don’t collect much data about Suppliers – we simply need to make sure that our relationship runs smoothly. We’ll collect the details for our contacts within your organisation, such as names, telephone numbers and email addresses. We’ll also collect bank details, so that we can pay you. We may also hold extra information that someone in your organisation has chosen to tell us. In certain circumstances, such as when you engage with our Finance and Credit Control personnel, our calls with you may be documented.
PEOPLE WHOSE DATA WE RECEIVE FROM CANDIDATES AND STAFF, SUCH AS REFEREES AND EMERGENCY CONTACTS:
All we need from referees is confirmation of what you already know about our Candidate or prospective member of Staff, so that they can secure that job they really want. Emergency contact details give us somebody to call on in an emergency. To ask for a reference, we’ll obviously need the referee’s contact details (such as name, email address and telephone number). We’ll also need these details if our Candidate or a member of our Staff has put you down as their emergency contact so that we can contact you in the event of an accident or an emergency.
WEBSITE USERS:
We collect a limited amount of data from our Website Users which we use to help us to improve your experience when using our website and to help us manage the services we provide.
HOW DO WE COLLECT YOUR PERSONAL DATA?
CANDIDATE DATA:
We collect Candidate personal data in three primary ways: 1. Personal data that you, the Candidate, gives to us; 2. Personal data that we receive from other sources; and 3. Personal data that we collect automatically. Personal data you give to us GRS Global Recruitment Solutions needs to know certain information about you in order to provide a tailored service. This will enable us to provide you with the best opportunities, and should save you time in not having to trawl through information about jobs and services that are not relevant to you. There are numerous ways you can share your information with us. It all depends on what suits you. These may include – Entering your details on the GRS Global Recruitment Solutions website as part of the registration process; – Leaving a hard copy CV at a GRS Global Recruitment Solutions recruitment event, job fair or office; – Emailing your CV to a GRS Global Recruitment Solutions Consultant or being interviewed by them; – Applying for jobs through a job aggregator, which then redirects you to the GRS Global Recruitment Solutions website; Personal data we receive from other sources We also receive personal data about Candidates from other sources. Depending on the relevant circumstances these may include personal data received in the following situations: – Your referees may disclose personal information about you; – Our Clients may share personal information about you with us; – We may obtain information about you from searching for potential Candidates from third party sources, such as LinkedIn and other job sites; – If you ‘like’ our page on Facebook or LinkedIn or ‘follow’ us on Twitter or Instagram we will receive your personal information from those sites.
Personal data we collect automatically To the extent that you access our website or read or click on an email from us, we may also collect your data automatically or through you providing it to us.
CLIENT DATA:
We collect Client personal data in three ways: 1. Personal data that we receive directly from you; 2. Personal data that we receive from other sources; and 3. Personal data that we collect automatically. Personal data that we receive directly from you We both share the same goal – to make sure that you have the best staff for your organisation. We will receive data directly from you in two ways: – Where you contact us proactively, usually by phone or email; and/or – Where we contact you, either by phone or email, or through our Consultants’ business development activities more generally. Personal data we receive from other sources Where appropriate we may seek more information about you or your colleagues from other sources generally by way of due diligence or other market intelligence including: – From third party market research and by analyzing online and offline media (which we may do ourselves, or employ other organizations to do for us); – From delegate lists at relevant events; and – From other limited sources and third parties (for example from our Candidates to the extent that they provide us with your details to act as a referee for them). Personal data we collect via our website To the extent that you access our website or read or click on an email from us, where appropriate we may also collect your data automatically or through you providing it to us.
WEBSITE USERS:
When you visit our website there is certain information that we may automatically collect, whether or not you decide to use our services and this is essentially your IP address. We collect your data automatically via cookies, in line with cookie settings in your browser.
HOW DO WE USE YOUR PERSONAL DATA?
Having obtained data about you, we then use it in a number of ways.
CANDIDATE DATA: We generally use Candidate data in four ways: – Recruitment Activities; – Marketing Activities; – Equal Opportunities Monitoring for Government departments. – To help us to establish, exercise or defend legal claims. Here are some more details about each: Recruitment Activities Obviously, our main area of work is recruitment – connecting the right Candidates with the right jobs. We’ve listed below various ways in which we may use and process your personal data for this purpose, where appropriate and in accordance with any local laws and requirements. Please note that this list is not exhaustive. – Collecting your data from you and other sources, such as LinkedIn; – Storing your details (and updating them when necessary) on our database, so that we can contact you in relation to recruitment; – Providing you with our recruitment services and to facilitate the recruitment process; – Assessing data about you against vacancies which we think may be suitable for you; – Sending your information to Clients, in order to apply for jobs or to assess your eligibility for jobs; – Enabling you to submit your CV, apply online for jobs or to receive alerts about jobs we think may be of interest to you; – Carrying out our obligations arising from any contracts entered into between us for example as a Temporary Worker; – Carrying out our obligations arising from any contracts entered into between GRS Global Recruitment Solutions and third parties in relation to your recruitment; – Facilitating our payroll and invoicing processes; – Carrying out customer satisfaction surveys;
– Verifying details you have provided, using third party resources (such as psychometric evaluations or skills tests), or to request information (such as references, qualifications and potentially any criminal convictions, to the extent that this is appropriate and in accordance with the laws of Cyprus and Malta); – Complying with our legal obligations in connection with the detection of crime or the collection of taxes or duties; – Processing your data to enable us to send you targeted, relevant marketing materials or other communications which we think are likely to be of interest to you. We may use your personal data for the above purposes if we deem it necessary to do so for our legitimate interests. If you want to know more about what this means, please contact dpo@grsrecruitment.com If you are not happy about this, in certain circumstances you have the right to object and can find out more about how and when to do this by emailing us dpo@grsrecruitment.com Marketing Activities We may periodically send you information that we think you may find interesting, or to ask for your help with connecting other Candidates with jobs. In particular, we may wish to use your data for the purposes listed below, where appropriate and in accordance with laws and requirements. Please note that this list is not exhaustive. To: -enable us to develop and market other products and services; – market our full range of recruitment services (permanent, temporary, contract, outplacement, MSP programs and RPO services) to you; – send you details of reports, promotions, offers, networking and client events, and general information about the industry sectors which we think might be of interest to you; and – display promotional excerpts from your details on GRS Global Recruitment Solutions’ website(s) as a success story (only where we have obtained your express consent to do so). We may need your consent for some aspects of these activities which are not covered by our legitimate interests and, depending on the situation, we’ll ask for this via an opt-in or soft-opt-in (which we explain further below). Soft opt-in consent is a specific type of consent which applies where you have previously engaged with us (for example by submitting a job application or CV, or registering a vacancy to be filled), and we are marketing other recruitment-related services. Under ‘soft opt-in’ consent, we will take your consent as given unless or until you opt out. For most people, this is beneficial as it allows us to suggest other
jobs to you alongside the specific one you applied for, significantly increasing the likelihood of us finding you a new position. For other types of e-marketing, we are required to obtain your explicit consent. If you want to know more about how we obtain consent, please contact us at dpo@grsrecruitment.com. If you are not happy about our approach to marketing, you have the right to withdraw your consent at any time and can find out more about how to do so please contact us at dpo@grsrecruitment.com. Nobody’s perfect, even though we try to be. We want to let you know that even if you have opted out from our marketing communications, it is possible that your details may be recaptured through public sources in an unconnected marketing campaign. We will try to make sure this doesn’t happen, but if it does, we’re sorry. We’d just ask that in those circumstances you opt out again. All our marketing is based on what we think will serve our Clients and Candidates best, but we know we won’t always get it right for everyone. Equal opportunities monitoring and other sensitive personal data We are committed to ensuring that our recruitment processes are aligned with our approach to equal opportunities. Some of the data we may in appropriate circumstances collect about you comes under the umbrella of “diversity information”. This could be information about your ethnic background, gender, disability, age, sexual orientation, religion or other similar beliefs, and/or social-economic background. Where appropriate and in accordance with the laws of Cyprus & Malta, we’ll use this information on an anonymized basis to monitor our compliance with equal opportunities. We may also disclose this (suitably anonymized where relevant) data to Clients where this is contractually required or the Client specifically requests such information to enable them to comply with their own employment processes. This information is what is called ‘sensitive’ personal information and slightly stricter data protection rules apply to it. We therefore need to obtain your explicit consent before we can use it. We’ll ask for your consent by offering you an opt-in. This means that you have to explicitly and clearly tell us that you agree to us collecting and using this information. If you are not happy about this, you have the right to withdraw your consent at any time and you can find out how to do so by contacting dpo@grsrecruitment.com In more unusual circumstances, we may use your personal data to help us to establish, exercise or defend legal claims.
CLIENT DATA:
We use Client information for: – Recruitment Activities; – Marketing Activities; and – To help us to establish, exercise or defend legal claims.
Here are some more details about each: Recruitment Activities Obviously, our main area of work is recruitment, through providing you with Candidates. We’ve listed below the various ways in which we use your data in order to facilitate this. – Storing your details (and updating them when necessary) on our database, so that we can contact you in relation to recruitment activities; – Keeping records of our conversations and meetings, so that we can provide targeted services to you; – Undertaking customer satisfaction surveys; and – Processing your data for the purpose of targeting appropriate marketing campaigns. We may use your personal data for these purposes if we deem this to be necessary for our legitimate interests. If you would like to know more about what this means, please contact us dpo@grsrecruitment.com. If you are not happy about this, in certain circumstances you have the right to object and can find out more about how and when to do this contact us at dpo@grsrecruitment.com. Marketing Activities Subject to any applicable laws in Cyprus & Malta and requirements, we will not, as a matter of course, seek your consent when sending marketing materials such as our Salary Survey to a corporate postal or email address. If you are not happy about this, you have the right to opt out of receiving marketing materials from us and can find out more about how to do so contact us at dpo@grsrecruitment.com In more unusual circumstances, we may use your personal data to help us to establish, exercise or defend legal claims.
SUPPLIER DATA:
We realize that you’re probably busy, and don’t want us to be contacting you about all sorts of things. To find the right balance, we will only use your information: – To store (and update when necessary) your details on our database, so that we can contact you in relation to our agreements; – To offer services to you or to obtain support and services from you;
– To perform certain legal obligations; – To help us to target appropriate marketing campaigns; and – In more unusual circumstances, to help us to establish, exercise or defend legal claims. We may use your personal data for these purposes if we deem this to be necessary for our legitimate interests. If you want to know more about what this means, please contact us at dpo@grsrecruitment.com We will not, as a matter of course, seek your consent when sending marketing messages to a corporate postal or email address. If you are not happy about this, in certain circumstances you have the right to object and can inform us by contacting us at dpo@grsrecruitment.com
PEOPLE WHOSE DATA WE RECEIVE FROM CANDIDATES AND STAFF, SUCH AS REFEREES AND EMERGENCY CONTACTS: We will only use the information that our Candidate gives us about you for the following purposes: – If our Candidates or Staff members put you down on our form as an emergency contact, we’ll contact you in the case of an accident or emergency affecting them; – If you were put down by our Candidate or a prospective member of Staff as a referee, we will contact you in order to take up a reference. This is an important part of our Candidate quality assurance process, and could be the difference between the individual getting a job or not; or – If you were put down by our Candidate or a prospective member of Staff as a referee, we may sometimes use your details to contact you in relation to recruitment activities that we think may be of interest to you, in which case we will use your data for the same purposes for which we use the data of Clients. If you would like to find out more about what this means, please contact us at dpo@grsrecruitment.com We may use your personal data for these purposes if we deem this to be necessary for our legitimate interests. If you would like to find out more about what this means, please contact us at dpo@grsrecruitment.com If you are not happy about this, you have the right to object and can inform us by emailing dpo@grsrecruitment.com
WHO DO WE SHARE YOUR PERSONAL DATA WITH?
Where appropriate we may share your personal data, in various ways and for various reasons, with the following categories of people:
– Any of our group companies; – Individuals and organizations who hold information related to your reference or application to work with us, such as current, past or prospective employers, educators and examining bodies and employment and recruitment agencies; – Tax, audit, or other authorities, when we believe in good faith that the law or other regulation requires us to share this data (for example, because of a request by a tax authority or in connection with any anticipated litigation); – Third party service providers who perform functions on our behalf (including external consultants, business associates and professional advisers such as lawyers, auditors and accountants, technical support functions and IT consultants carrying out testing and development work on our business technology systems); – Third party outsourced IT and document storage providers where we have an appropriate processing agreement (or similar protections) in place; – Marketing technology platforms and suppliers; – In the case of Candidates: potential employers and other recruitment agencies/organisations to increase your chances of finding employment; – In the case of Candidates: third party partners, job boards and job aggregators where we consider this will improve the chances of finding you the right job; – In the case of Candidates and our Candidates’ and prospective members of Staff’s referees: third parties who we have retained to provide services such as reference, qualification and criminal convictions checks, to the extent that these checks are appropriate and in accordance with local laws; – If GRS Global Recruitment Solutions merges with or is acquired by another business or company in the future, (or is in meaningful discussions about such a possibility) we may share your personal data with the (prospective) new owners of the business or company.
HOW DO WE SAFEGUARD YOUR PERSONAL DATA?
We are committed to taking all reasonable and appropriate steps to protect the personal information that we hold from misuse, loss, or unauthorized access. We do this by having in place a range of appropriate technical and organizational measures. These include measures to deal with any suspected data breach. If you suspect any misuse or loss of or unauthorized access to your personal information, please let us know immediately by contacting us at dpo@grsrecruitment.com
HOW LONG DO WE KEEP YOUR PERSONAL DATA FOR?
CANDIDATES:
We will Delete your personal data from our systems if we have not had any meaningful contact with you for four years (48 months), or for such longer period as we believe in good faith that the law or relevant regulators require us to preserve your data. After this period, it is likely your data will no longer be relevant for the purposes for which it was collected. For those Candidates whose services are provided via a third party company or other entity, “meaningful contact” with you means meaningful contact with the company or entity which supplies your services. Where we are notified by such company or entity that it no longer has that relationship with you, we will retain your data for no longer than two years from that point or, if later, for the period of two years from the point we subsequently have meaningful contact directly with you. When we refer to “meaningful contact”, we mean, for example, communication between us (either verbal or written), or where you are actively engaging with our online services. If you are a Candidate, we will consider there to be meaningful contact with you if you submit your updated CV to us. We will also consider it meaningful contact if you communicate with us about potential roles, either by verbal or written communication or respond to any of our marketing communications. Your receipt, opening or reading of an email or other digital message from us will not count as meaningful contact.
CLIENTS:
We will Delete your personal data from our systems if we have not had any meaningful contact with you for fourty eight (48 months), or for such longer period as we believe in good faith that the law or relevant regulators require us to preserve your data. After this period, it is likely your data will no longer be relevant for the purposes for which it was collected. When we refer to “meaningful contact”, we mean, for example, communication between us (either verbal or written), or where you are actively engaging with our online services. If you are a Client or prospective client of GRS , we will consider there to be meaningful contact with you have registered a vacancy, made an enquiry about our services, provided a reference or been in contact with a GRS employee either verbal or written either directly or through a third party platform such as Linked in. We will also consider it meaningful contact if you communicate with us about other services, either by verbal or written communication or respond to any of our marketing communications. Your receipt, opening or reading of an email or other digital message from us will not count as meaningful contact.
SUPPLIERS:
We will Delete your personal data from our systems if we have not had any meaningful contact with you for eighty four months (84 months), or for such longer period as we believe in good faith that the law or relevant regulators require us to preserve your data. After this period, it is likely your data will no longer be relevant for the purposes for which it was collected. When we refer to “meaningful contact”, we mean, for example, communication between us (either verbal or
written), or where we are actively engaging with your service/product by making and receiving orders.
HOW CAN YOU ACCESS, AMEND OR TAKE BACK THE PERSONAL DATA THAT YOU HAVE GIVEN TO US?
One of the GDPR’s main objectives is to protect and clarify the rights of EU citizens and individuals in the EU with regards to data privacy. This means that you retain various rights in respect of your data, even once you have given it to us. These are described in more detail below. To get in touch about these rights, please contact us at dpo@grsrecruitment.com. We will seek to deal with your request without undue delay, and in any event within one month (subject to any extensions to which we are lawfully entitled). Please note that we may keep a record of your communications to help us resolve any issues which you raise. Right to object: this right enables you to object to us processing your personal data where we do so for one of the following four reasons: (i) our legitimate interests; (ii) to enable us to perform a task in the public interest or exercise official authority; (iii) to send you direct marketing materials; and (iv) for scientific, historical, research, or statistical purposes. The “legitimate interests” and “direct marketing” categories above are the ones most likely to apply to our Website Users, Candidates, Clients and Suppliers. If your objection relates to us processing your personal data because we deem it necessary for your legitimate interests, we must act on your objection by ceasing the activity in question unless: – we can show that we have compelling legitimate grounds for processing which overrides your interests; or – we are processing your data for the establishment, exercise or defence of a legal claim. If your objection relates to direct marketing, we must act on your objection by ceasing this activity. Right to withdraw consent: Where we have obtained your consent to process your personal data for certain activities (for example, to find a job), you may withdraw this consent at any time and we will cease to carry out the particular activity that you previously consented to unless we consider that there is an alternative reason to justify our continued processing of your data for this purpose in which case we will inform you of this condition. Data Subject Access Requests (DSAR): You may ask us to confirm what information we hold about you at any time, and request us to modify, update or
Delete such information. We may ask you to verify your identity and for more information about your request. If we provide you with access to the information we hold about you, we will not charge you for this unless your request is “manifestly unfounded or excessive”. If you request further copies of this information from us, we may charge you a reasonable administrative cost where legally permissible. Where we are legally permitted to do so, we may refuse your request. If we refuse your request, we will always tell you the reasons for doing so. Right to erasure: You have the right to request that we erase your personal data in certain circumstances. Normally, the information must meet one of the following criteria: – the data are no longer necessary for the purpose for which we originally collected and/or processed them; – where previously given, you have withdrawn your consent to us processing your data, and there is no other valid reason for us to continue processing; – the data has been processed unlawfully (i.e. in a manner which does not comply with the GDPR); – it is necessary for the data to be erased in order for us to comply with our legal obligations as a data controller; or – if we process the data because we believe it necessary to do so for our legitimate interests, you object to the processing and we are unable to demonstrate overriding legitimate grounds for our continued processing. We would only be entitled to refuse to comply with your request for one of the following reasons: – to exercise the right of freedom of expression and information; – to comply with legal obligations or for the performance of a public interest task or exercise of official authority; – for public health reasons in the public interest; – for archival, research or statistical purposes; or – to exercise or defend a legal claim. When complying with a valid request for the erasure of data we will take all reasonably practicable steps to Delete the relevant data. Right to restrict processing: You have the right to request that we restrict our processing of your personal data in certain circumstances. This means that we can only continue to store your data and will not be able to carry out any further processing activities with it until either:
(i) one of the circumstances listed below is resolved; (ii) you consent; or (iii) further processing is necessary for either the establishment, exercise or defence of legal claims, the protection of the rights of another individual, or reasons of important EU or Member State public interest. The circumstances in which you are entitled to request that we restrict the processing of your personal data are: – where you dispute the accuracy of the personal data that we are processing about you. In this case, our processing of your personal data will be restricted for the period during which the accuracy of the data is verified; – where you object to our processing of your personal data for our legitimate interests. Here, you can request that the data be restricted while we verify our grounds for processing your personal data; – where our processing of your data is unlawful, but you would prefer us to restrict our processing of it rather than erasing it; and – where we have no further need to process your personal data but you require the data to establish, exercise, or defend legal claims. If we have shared your personal data with third parties, we will notify them about the restricted processing unless this is impossible or involves disproportionate effort. We will, of course, notify you before lifting any restriction on processing your personal data. Right to rectification: You also have the right to request that we rectify any inaccurate or incomplete personal data that we hold about you. If we have shared this personal data with third parties, we will notify them about the rectification unless this is impossible or involves disproportionate effort. Where appropriate, we will also tell you which third parties we have disclosed the inaccurate or incomplete personal data to. Where we think that it is reasonable for us not to comply with your request, we will explain our reasons for this decision. Right of data portability: If you wish, you have the right to transfer your personal data between data controllers. In effect, this means that you are able to transfer your GRS Global Recruitment Solutions account details to another online platform. To allow you to do so, we will provide you with your data in electronic format that is password-protected so that you can transfer the data to another online platform. Alternatively, we may directly transfer the data for you. This right of data portability applies to: (i) personal data that we process automatically (i.e. without any human intervention); (ii) personal data provided by you; and (iii) personal data that we process based on your consent or in order to fulfil a contract.
Right to lodge a complaint with a supervisory authority: You also have the right to lodge a complaint with the Local Supervisory Authority of Cyprus or Malta. If you would like to exercise any of these rights, or withdraw your consent to the processing of your personal data (where consent is our legal basis for processing your personal data), contact us at dpo@grsrecruitment.com. Please note that we may keep a record of your communications to help us resolve any issues which you raise. You may ask to unsubscribe from job e-shots at any time by contacting us dpo@grsrecruitment.com It is important that the personal information we hold about you is accurate and current. Please keep us informed if your personal information changes during the period for which we hold your data.
WHO IS RESPONSIBLE FOR PROCESSING YOUR PERSONAL DATA ON THE GRS GLOBAL RECRUITMENT SOLUTIONS WEBSITE?
GRS Global Recruitment Solutions Ltd (legal name GRS Professional Recruitment Services Ltd) is solely responsible for processing all your data. Please contact our Limassol office Agathengeou Business Centre, 101 Gladstonos Street, Limassol, Cyprus or email us at dpo@grsrecruitment.com for further information. If you have any comments or suggestions concerning this Privacy Notice, please email dpo@grsrecruitment.com We take privacy seriously so we’ll get back to you as soon as possible.
COOKIES POLICY
What’s a cookie? A “cookie” is a piece of information that is stored on your computer’s hard drive and which records your navigation of a website so that, when you revisit that website, it can present tailored options based on the information stored about your last visit. Cookies can also be used to analyse traffic and for advertising and marketing purposes. Cookies are used by nearly all websites and do not harm your system. If you want to check or change what types of cookies you accept, this can usually be altered within your browser settings. We do not use your cookies for any purpose whatsoever.
OUR LEGAL BASES FOR PROCESSING YOUR DATA LEGITIMATE INTERESTS
Article 6(1)(f) of the GDPR is the one that is relevant here – it says that we can process your data where it “is necessary for the purposes of the legitimate interests pursued by [us] or by a third party, except where such interests are overridden by the interests or fundamental rights or freedoms of [you] which require protection of personal data.” We don’t think that any of the following activities prejudice individuals in any way – in fact, they help us to offer you a more tailored, efficient service. However, you do have the right to object to us processing your personal data on this basis. If you would like to know more about how to do so, please contact us at dpo@grsrecruitment.com
CANDIDATE DATA:
We think it’s reasonable to expect that if you are looking for employment or have posted your professional CV information on a job board or professional networking site, you are happy for us to collect and otherwise use your personal data to offer or provide our recruitment services to you, share that information with prospective employers and assess your skills against our bank of vacancies. Once it’s looking like you may get the job, your prospective employer may also want to double check any information you’ve given us (such as the results from psychometric evaluations or skills tests) or to confirm your references, qualifications and Police Criminal Record Check, to the extent that this is appropriate and in accordance with local laws. We need to do these things so that we can function as a profit-making business, and to help you and other Candidates get the jobs you deserve. We want to provide you with tailored job recommendations and relevant articles to read to help you on your job hunt. We therefore think it’s reasonable for us to process your data to make sure that we send you the most appropriate content. We have to make sure our business runs smoothly, so that we can carry on providing services to Candidates like you. We therefore also need to use your data for our internal administrative activities, like payroll and invoicing where relevant. We have our own obligations under the law, which it is a legitimate interest of ours to insist on meeting! If we believe in good faith that it is necessary, we may therefore share your data in connection with crime detection, tax collection or actual or anticipated litigation.
CLIENT DATA:
To ensure that we provide you with the best service possible, we store your personal data and/or the personal data of individual contacts at your organisation as well as keeping records of our conversations, meetings, registered jobs and placements. From time to time, we may also ask you to undertake a customer satisfaction survey. We think this is reasonable – we deem these uses of your data to be necessary for our legitimate interests as an organisation providing various recruitment services to you.
SUPPLIER DATA:
We use and store the personal data of individuals within your organisation in order to facilitate the receipt of services from you as one of our Suppliers. We also hold your
financial details, so that we can pay you for your services. We deem all such activities to be necessary within the range of our legitimate interests as a recipient of your services.
PEOPLE WHOSE DATA WE RECEIVE FROM CANDIDATES AND STAFF, SUCH AS REFEREES AND EMERGENCY CONTACTS:
If you have been put down by a Candidate or a prospective member of Staff as one of their referees, we use your personal data in order to contact you for a reference. This is a part of our quality assurance procedure and so we deem this to be necessary for our legitimate interests as an organisation offering recruitment services and employing people ourselves. If a Candidate or Staff member has given us your details as an emergency contact, we will use these details to contact you in the case of an accident or emergency. We are sure you will agree that this is a vital element of our people-orientated organisation, and so is necessary for our legitimate interests. CONSENT In certain circumstances, we are required to obtain your consent to the processing of your personal data in relation to certain activities. Depending on exactly what we are doing with your information, this consent will be opt-in consent or soft opt-in consent. Article 4(11) of the GDPR states that (opt-in) consent is “any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.” In plain language, this means that: – you have to give us your consent freely, without us putting you under any type of pressure; – you have to know what you are consenting to – so we’ll make sure we give you enough information; – you should have control over which processing activities you consent to and which you don’t. To update us on your consent and preferences please contact us at dpo@grsrecruitment.com – you need to take positive and affirmative action in giving us your consent and to ensure that this requirement is met in a clear and unambiguous fashion please contact us in writing at dpo@grsrecruitment.com We will keep records of the consents that you have given in this way.
We have already mentioned that, in some cases, we will be able to rely on soft opt-in consent. We are allowed to market products or services to you which are related to the recruitment services we provide as long as you do not actively opt-out from these communications. As we have mentioned, you have the right to withdraw your consent to these activities. You can do so at any time, and to do so please contact dpo@grsrecruitment.com
ESTABLISHING, EXERCISING OR DEFENDING LEGAL CLAIMS Sometimes it may be necessary for us to process personal data and, where appropriate and in accordance with local laws and requirements, sensitive personal data in connection with exercising or defending legal claims. Article 9(2)(f) of the GDPR allows this where the processing “is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity”. This may arise for example where we need to take legal advice in relation to legal proceedings or are required by law to preserve or disclose certain information as part of the legal process.
ANNEX 1 – HOW TO CONTACT US
You can write to us at the following address:
Agathangelou Business Centre 101
Gladstonos Street
3032, Limassol
Alternatively, you can send an email to: dpo@grsrecruitment.com -To access, amend or take back the personal data that you have given to us; -If you suspect any misuse or loss of or unauthorised access to your personal information; To withdraw your consent to the processing of your personal data (where consent is the legal basis on which we process your personal data); With any comments or suggestions concerning this Privacy Notice You can get in touch with us to update your marketing preferences by contacting us at: dpo@grsrecruitment.com
ANNEX 2 – HOW TO CONTACT THE SUPERVISORY AUTHORITY GRS Global Recruitment Solutions with services Cyprus as our Lead Supervisory Authority is Cyprus.
Details of our local supervisory authority and how you can contact them: Office of the Commissioner of Personal Data Protection For Personal Data Protection 1, Iasonos Street, 1082 Nicosia Tel: 22-818456, Fax: 22-304565 Email: commissioner@dataprotection.gov.cy www.dataprotection.gov.cy
GLOSSARY
Candidates – includes applicants for all roles advertised or promoted by GRS Global Recruitment Solutions, including permanent, part-time and temporary positions and freelance roles with GRS Global Recruitment Solutions’ Clients; as well as people who have supplied a speculative CV to GRS Global Recruitment Solutions not in relation to a specific job. Individual contractors, freelance workers and employees of suppliers or other third parties put forward for roles with GRS Global Recruitment Solutions, or otherwise will be treated as candidates for the purposes of this Privacy Notice.
Clients – this category covers our customers, clients, and others to whom GRS Global Recruitment Solutions provides services in the course of its business.
Delete – while we will endeavor to permanently erase your personal data once it reaches the end of its retention period or where we receive a valid request from you to do so, some of your data may still exist within our systems, for example if it is waiting to be overwritten. For our purposes, this data has been put beyond use, meaning that, while it still exists on an archive system, this cannot be readily accessed by any of our operational systems, processes or Staff.
General Data Protection Regulation (GDPR) – a European Union statutory instrument which aims to harmonize European data protection laws. It has an effective date of 25 May 2018, and any references to it should be construed accordingly to include any national legislation implementing it.
Other people whom GRS Global Recruitment Solutions may contact – these may include Candidates’ and GRS Global Recruitment Solutions’ Staff emergency contacts and referees. We will only contact them in appropriate circumstances. Staff – includes employees and interns engaged directly in the business of GRS Global Recruitment Solutions (or who have accepted an offer to be engaged) as well as certain other workers engaged in the business of providing services to GRS Global Recruitment Solutions (even though they are not classed as employees). For these purposes we also include employees of GRS Global Recruitment Solutions
who are engaged to work on Clients’ premises under the terms of RPO or MSP agreements. To be clear, ‘Staff’ does not include individuals hired by GRS Global Recruitment Solutions for the purpose of being placed with Clients outside of an RPO/MSP arrangement. These individuals are treated in the same way as GRS Global Recruitment Solutions’ Candidates and are covered by this Privacy Notice. Likewise, independent contractors and consultants performing services for GRS Global Recruitment Solutions fall within the definition of a ‘Supplier’ for the purposes of this Privacy Notice.
Suppliers – refers to partnerships and companies (including sole traders), and atypical workers such as independent contractors and freelance workers, who provide services to GRS Global Recruitment Solutions. In certain circumstances GRS Global Recruitment Solutions will sub-contract the services it provides to Clients to third party suppliers who perform services on GRS Global Recruitment Solutions’ behalf. In this context, suppliers that are individual contractors, freelance workers, or employees of suppliers will be treated as Candidates for data protection purposes. Please note that in this context, GRS Global Recruitment Solutions requires Suppliers to communicate the relevant parts of this Privacy Notice (namely the sections directed at Candidates) to their employees.
Website Users – any individual who access the GRS Global Recruitment Solutions website.