HIREBRIDGE EU-US PRIVACY SHIELD and SWISS-US PRIVACY SHIELD POLICY
Last update: February 6, 2019
PERSONAL INFORMATION RECEIVED FROM THE EEA AND SWITZERLAND
As a data processor, we process and host EEA and Swiss Personal Information obtained from candidates applying to and inquiring about employment opportunities with our customers ("Customer Data") in providing our software applications ("Services"). We only process Personal Information on behalf and instructions of our customers, which in this instance are considered data controllers. This data consists of candidate resume data, and may include contact information, education history, and employment history, however this depends upon the needs of our customer, the data controllers, who decide what is needed through their use of the Services. The data is collected in order for our customers to facilitate their recruitment and hiring process.
Hirebridge is committed to protecting the privacy of your Personal Information (as defined below). We respect individual privacy and value the trust of our customers and candidates, and others who provide their Personal Information to us. This EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield Policy (the "Policy") sets forth the privacy principles that Hirebridge follows with respect to transfers of personal information from the EEA and SWITZERLAND to the United States, and is intended to give you confidence in the privacy and security of your Personal Information when accessing the available pages on any of the following Hirebridge powered customer websites (collectively, the "Services").
COMPLIANCE WITH PRIVACY SHIELD PRINCIPLES
The United States Department of Commerce and the European Commission have agreed on a set of data protection principles and frequently asked questions (the "EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield Framework") to enable U.S. companies to satisfy the requirement under European Union law that adequate protection be given to personal information transferred from either the EU or SWITZERLAND to the U.S.
We recognize that the European Community has established a data protection regime which applies to the European Economic Area ("EEA") and Switzerland, and restricts companies in the EEA and Switzerland in transferring personal data about individuals in the EEA and Switzerland to the U.S., unless there is "adequate protection" for such personal data when it is received in the U.S. To create such "adequate protection," Hirebridge adheres to the EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield Framework published by US Department of Commerce ("EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield Principles") with respect to personal data about individuals in the EEA that we process for our customers and other business partners. Hirebridge's EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield Certification also extends to data that we receive directly through Hirebridge's publicly accessible Site via secure form submission.
HOW LONG WILL WE HOLD YOUR PERSONAL DATA
We will hold you data for as long as we have a contractual obligation to the Customer to provide the Services, and thereafter until such time as we delete the Customer's account in accordance with our Customer Terms and Conditions.
YOUR PERSONAL INFORMATION WILL BE DELETED UPON ONE OF THE FOLLOWING OCCURRENCES
- Deletion of your personal information by you through the relevant Services pages
- Deletion of your personal information by the Customer who subscribes to our service
- Deletion of your personal information by Hirebridge upon written request by you, or by an authorized representative of our Customer
- Deletion of your personal information by Hirebridge upon termination of use of the Service by
ADHERENCE TO SEVEN PRIVACY SHIELD PRINCIPLES
The privacy principles in this Policy have been developed based on the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework Principles.
NOTICE: Where Hirebridge processes Personal Information from individuals in the EEA and Switzerland, we will inform them about the purposes for which we collect and use personal information about them. Notice will be provided in clear and conspicuous language when individuals are first asked to provide personal information to Hirebridge, or as soon as practicable thereafter.
CHOICE: You may elect not to have your Personal Information either (a) disclosed to an unrelated third party, or (b) used for a purpose other than the purpose for which it was originally collected or subsequently authorized by you. In the event you wish to restrict your Personal Information from any such disclosure or use, please contact us at email@example.com to review your request.
ACCOUNTABILITY FOR ONWARD TRANSFERS TO THIRD PARTIES: Where Hirebridge transfers personal information to a third party that is acting as an agent or service provider, prior to the transfer Hirebridge will enter into a written agreement with the third party requiring that the third party provide at least the same level of privacy protection as is required by the EU-US Privacy Shield and Swiss-US Privacy Shield Principles.
- Hirebridge only transfers data to third party vendors or providers on behalf of and at the instruction of our customers, which are the data controllers, pursuant to our contractually obligation to our customers. The type of data is limited in scope and may include, based on our cusotmer (Data Controller) requirements, contact information, education and employment history, depending on the contracted services that our customer has chosen.
- These third party vendors or providers are independantly contracted by our customer to provide requested services, such as background checks, assessments, onboarding or other recruitment related services.
- Hirebridge will also provide that the third party may not use the information for any purpose other than the delivery of services to Hirebridge on behalf of our Customer.
- Pursuant to the Privacy Shield Frameworks we are obliged to inform EU and Swiss individuals that we may be required to disclose an individual's personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.
- In cases of onward transfer to third parties of data of EU and Swiss individuals received pursuant to the EU-US Privacy Shield and Swiss-U.S. Privacy Shield, Hirebridge is potentially liable.
- Where Hirebridge has knowledge that a third party business partner is using or disclosing personal information in a manner contrary to the company policy, Hirebridge will take reasonable steps to prevent or stop the use or disclosure.
SECURITY: Hirebridge will take reasonable precautions to protect Personal Information in its possession from loss, misuse and unauthorized access, disclosure, alteration and destruction by security safeguards appropriate to the sensitivity of the information.
- Hirebridge shall protect personal information against such risks as loss or theft, unauthorized access, disclosure, copying, use, modification or destruction, through appropriate security measures. Hirebridge shall protect the information regardless of the format in which it is held. Hirebridge shall protect personal information disclosed to third parties by contractual agreements stipulating the confidentiality of the information and the purposes for which it is to be used.
- All Hirebridge employees with access to personal information shall be required to respect the confidentiality of that information.
DATA INTEGRITY: Hirebridge will use Personal Information only in ways that are compatible with the purposes for which it was collected or subsequently authorized by the individual. We will take reasonable steps to ensure that Personal Information is relevant to its intended use, accurate, complete, and current.
ACCESS AND CORRECTION: Individuals must have access to personal information about them that an organization holds and be able to correct, amend, or delete that information where it is inaccurate, or has been processed in violation of the Principles, except where the burden or expense of providing access would be disproportionate to the risks to the individual's privacy in the case in question, or where the rights of persons other than the individual would be violated.
If your personal details change you may update them in Hirebridge by accessing the relevant page of the Service, logging in to your account, and making the changes. These changes will be updated in real-time. Upon written request by you or by our Customer or Customers representative, Hirebridge may assist you in updating your information.
VERIFICATION: Hirebridge will use a self-assessment verification approach and conduct compliance audits of its applicable privacy practices to verify adherence to this Policy.
DISPUTE RESOLUTION AND ENFORCEMENT: In compliance with the EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield principles, Hirebridge commits to resolve complaints about your privacy and our collection or use of your Personal Information. Individuals with inquiries or complaints regarding this Policy should first contact Hirebridge by sending the inquiry or complaint to the address listed below or to: firstname.lastname@example.org.
- Hirebridge will respond within 45 days of receiving any complaints. Any complaints or concerns that cannot be resolved internally will be referred to JAMS Privacy Shield Program, an alternative dispute resolution provider located in the United States.
- If you do not receive timely acknowledgement of your complaint from us, or if we have not addressed your complaint to your satisfaction, please contact or visit jamsadr.com/eu-us-privacy-shield for more information or to file a complaint. The services of JAMS Privacy Shield Program are provided at no cost to you.
- Under certain circumstances, an individual may choose to invoke binding arbitration to resolve any disputes that have not been resolved by other means.
- Hirebridge complies with the EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield Principles and is subject to the investigatory and enforcement powers of the United States Federal Trade Commission ("FTC").
- Any employee that Hirebridge determines is in violation of this policy will be subject to disciplinary action up to and including termination of employment.
LIMITATION ON APPLICATION OF PRINCIPLES: Adherence by Hirebridge to these EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield principles may be limited (a) to the extent required to respond to a legal or ethical obligation; (b) to the extent necessary to meet legal, governmental or national security obligations, including requirements to cooperate with law enforcement; and (c) to the extent expressly permitted by an applicable law, rule or regulation.
CONTACT INFORMATION: Questions or comments regarding this Policy should be submitted to Hirebridge's Privacy Office by mail to:
Attn: Privacy Officer
3200 N. University Dr. Suite 214
Coral Springs, FL 33065
or by e-mail to Hirebridge's Privacy Office: email@example.com