Skip to main content

Processing of (personal) data by the entity in charge of the online application process

Processing of personal data by the person responsible for the online application procedure
Version 1.1, Status June 2021

General
We provide you with this privacy statement, which relates to the data collected as part of the online application process to inform you about how we handle your personal data collected in the application process.

Controller
The responsible party for data processing in terms of data protection law is:

New Flag GmbH
Leopoldstrasse 154, 80804 Munich, Germany
Phone: +49 89 4111 938 85 
E-Mail:
info@new-flag.com

Data protection officer
We have designated a data protection officer. For the attention of the data protection officer you can contact him through our postal address or by e-mail at
datenschutz@new-flag.com.  

Personal data we need
When you apply, we process data about you that we obtain through your application documents as well as through interviews with you. This can be contact data, all data related to the application (CV, certificates, qualifications, photo, etc.) and, if applicable, data on bank details (for reimbursement of travel expenses). In addition, your data will be processed when conducting our interviews.

Basis and purposes of data processing
We process your data to carry out the application process and to check whether we can offer you the position for which you have applied and employ you with us. The legal basis for this results from Art. 6 (1) 1 lit. b) DSGVO in conjunction with Art. 26 (1) 1 BDSG. If the data is in special categories of personal data (such as data about your health), which you yourself provide to us (for example, information about a severe disability), the processing is based on the legal basis of Art. 9 (2) b) DSGVO in conjunction with § 26 (3) BDSG. 
Only authorized HR employees and managers involved in the application process have access to your data.

Erasion of your data
Your data will be stored for a period of 6 months after completion of the application process. This is done to fulfill legal obligations or to defend against possible claims arising from legal regulations. Afterwards, your data will be deleted or anonymized on the basis of our legitimate interests in analyzing the applicant profiles. In this case, the data is only available to us as so-called metadata without direct personal reference for statistical evaluations (for example, the proportion of women or men in applications, number of applications per period, etc.). 

If your profile is of interest to us and you give us your consent, we will include your data in our "Talent Pool". After 24 months, your data will be permanently deleted. This also applies to applications for apprenticeships or internships.

Transfer of data to third countries
Your data transmitted during the application process will be transferred to us via TLS encryption. Personio GmbH provides us with our applicant management system. This company processes your data within the scope of an order processing contract. In this context, it is our order processor according to Art. 28 DSGVO. 

In addition, we use other service providers who support us in the areas of website hosting, video conferencing, maintenance and support of IT systems, and archiving and destruction of documents, and with whom we have also concluded separate contracts for order processing.

Data subject rights
As a data subject, you have the right to information about the personal data concerning you (Art. 15 DSGVO), to correction of incorrect data (Art. 16 DSGVO) and to deletion, provided that one of the reasons stated in Art. 17 DSGVO applies, e.g. if the data is no longer required for the purposes pursued. There is also the right to restriction of processing if the conditions of Art. 18 DSGVO are met and in the cases of Art. 20 DSGVO the right to data portability. If the processing of personal data is based on your consent, you may revoke it in accordance with Art. 7 (3) DS-GVO.
Please contact our data protection officer at
datenschutz@new-flag.com to assert your rights.

Right to lodge a complaint
In addition, as a data subject, you have the right to lodge a complaint with the data protection supervisory authority if you believe that the processing of your data violates data protection regulations. The data protection supervisory authority responsible for us is “Bayerisches Landesamt für Datenschutzaufsicht”, Postfach 1349, 91504 Ansbach, e-mail:
poststelle@lda.bayern.de.

Final provisions
We reserve the right to adapt this data protection statement at any time to ensure that it always complies with current legal requirements or in the event of changes in the application process.
In addition to this privacy policy, you can find our privacy policy for the use of the website
here.

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.