Privacy Policy for Recruitment

1. Data Controller

ESiOR Ltd, VAT number: FI20675718
Tulliportinkatu 2 LT4, 70100, Kuopio

2. Register name

Recruitment register

3. Contact person for register and data privacy issues

ESiOR Ltd / Data Protection Officer
Tulliportinkatu 2 LT4
70100 Kuopio
tietosuojavastaava@esior.fi

4. Purposes and legal basis for processing of personal data

ESiOR Ltd fully complies with the requirements on data protection described in Regulation (EU) 2016/679, also known as the GDPR.

The purpose of processing personal data is to enable the recruitment of new personnel. Personal data will be used in communication between the data controller and the data subject. The data will also be used to assess the skills and suitability of the applicants for work at ESiOR Ltd. The legal basis of data processing is the applicant’s consent or legitimate interest.

5. Data Contents

We may collect, process, and store the following data:

  1. Name
  2. E-mail address
  3. Phone number
  4. Postal address
  5. Curriculum Vitae (e.g., education, employment history)
  6. Cover letter, application or equivalent
  7. The applied position
  8. Names and contact information of references

6. Data Sources

The register contains data that are submitted in the application by the data subject, or that are received from the references named by the data subject or from other people involved in the recruitment process.

7. Data recipients and data transfers

Register data or right of access to the data will not be granted to third parties without the consent of the data subject unless required by applicable legislation.

8. Data transfers to a third country (outside the European Economic Area) or an international organisation

ESiOR Ltd will not transfer the data outside the European Economic Area or to an international organisation.

9. Data Retention Period

Personal data will be stored as long as necessary for carrying out the intended purposes of the processing. If the applicant wishes to give their consent, the data can be stored longer and be used for other recruitments.

Personal data that is processed based on the data subject’s consent will be stored for the duration specified in the consent or until the subject withdraws the consent.

10. Data Protection

The electronic register is stored in a database that is protected by firewalls, passwords, and other technical safety measures. Access rights to the registry are only held by persons appointed by ESiOR, who have signed a non-disclosure agreement and whose job description necessitates the processing of such data. Every user has a personal username and password. Any non-electronic material will be stored in locked filing cabinets with restricted access.

11. Data subject rights

Data subjects have the following rights:

a) right of access – you have the right to access all personal data that we have on you,

b) right of rectification – you have the right to correct data that is incorrect or incomplete

c) right to be forgotten – you have the right to request erasure of any personal data that is stored on you,

d) right to restrict processing – you have the right to request that we limit the way we use your personal data,

e) right to object – you have the right to object certain types of processing, such as direct marketing and automated decision-making including profiling,

f) right to withdraw consent at any time (the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal),

g) right to lodge a complaint – you have the right to lodge a complaint with a supervisory authority if you consider that your rights under the general data protection regulation have been infringed. Contact information and guidance by the Finnish supervisory authority can be found at: www.tietosuoja.fi

Written requests to exercise data subject rights should be signed and sent by post or e-mail to the contact person for register and data privacy issues as detailed in section 3 above.

12. Approval

The data privacy statement for recruitment has been approved on 23/8/2023.

Terms of data processing

The data are stored and processed according to the classification below.

Personal data

Classification

Name

Email address

Phone number

Postal address

Content created by the subject (e.g. CV, application texts)

Applied position

Names and contact information of the referees

Confidential

Confidential

Confidential

Confidential

Confidential

Confidential

Confidential