Upstream is committed to protecting and respecting your privacy. This Privacy Notice (together with any other documents referred to herein) sets out the basis on which the personal data collected from you, or that you provide to Us, will be processed by Us in connection with Our recruitment processes. When you apply for a job opening posted by Us, these Privacy Notice provisions will apply to Our processing of your personal information.
For the purpose of the General Data Protection Regulation (“GDPR”) the Data Controller for the recruitment process is Upstream SMSA. We use Workable, an online application provided by Workable Software Limited, to assist with Our recruitment process. We use Workable to process personal information as a data processor on Our behalf and in accordance with Our instructions.
Where you apply for a job opening via the application function on a job site or similar online service provider (“Partner”), you should note that the relevant Partner may retain your personal data and may also collect data from Us in respect of the progress of your application. Any use by the Partner of your data will be in accordance with the Partner’s Privacy Notice.
We collect and process some or all of the following types of information from you:
Workable provides Us with the facility to link the data you provide to Us, with other publicly available information about you that you have published on the Internet – this may include sources such as LinkedIn and other social media profiles.
Workable’s technology allows Us to search various databases – some publicly available and others not, which may include your personal data (include your CV or Resumé), to find possible candidates to fill Our job openings. Where We find you in this way We will obtain your personal data from these sources.
We may receive your personal data from a third party (recruiter or current Upstream employee) who recommends you as a candidate for a specific job opening or for Our business more generally.
We rely on legitimate interest as the lawful basis on which We collect and use your personal data. Our legitimate interests are the recruitment of staff for Our business.
Where you apply for a job opening through the Indeed Apply functionality, We rely on your consent, which is freely given by you during the application process, to disclose your personal data to Indeed on the basis described below.
We use information held about you in the following ways:
We may use Workable’s technology to select appropriate candidates for Us to consider based on criteria expressly identified by us, or typical in relation to the role for which you have applied. The process of finding suitable candidates is automatic, however, any decision as to who We will engage to fill the job opening will be made by Our staff.
As set out above, We pass your information to Our third party service providers, including Workable, who use it only in accordance with Our instructions and as otherwise required by law.
Where you have applied for a job opening through the Indeed Apply functionality, and where you have consented to this disclosure, We will disclose to Indeed certain personal data that We hold, including but not limited to a unique identifier used by Indeed to identify you, and information about your progress through Our hiring process for the applicable job opening, as well as tangible, intangible, visual, electronic, present, or future information that We hold about you, such as your name, contact details and other information involving analysis of data relating to you as an applicant for employment (collectively “Disposition Data”). Indeed’s Privacy Notice in respect of Indeed’s use of the Disposition Data is available on Indeed’s website.
Where you have applied to a job opening through another service provider, We may disclose data similar to the Disposition Data defined above to such service provider. The service provider shall be the data controller of this data and shall therefore be responsible for complying with all applicable law in respect of the use of that data following its transfer by Us.
We take appropriate measures to ensure that all personal data is kept secure including security measures to prevent personal data from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal data to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where We are legally required to do so.
Unfortunately, the transmission of information via the internet is not completely secure. Although We will do Our best to protect your personal data, We cannot guarantee the security of your data transmitted through any online means, therefore any transmission remains at your own risk.
Where We store your personal data in Our own systems, it is stored in Greece.
The data that We collect from you and process using Workable’s Services may be transferred to, and stored at, a destination outside the European Economic Area (“EEA”). In particular, your data may be accessible to i) Workable’s staff in the USA or ii) may be stored by Workable’s hosting service provider on servers in the USA as well as in the EU. The USA does not have the same data protection laws as the United Kingdom and EEA. A Data Processor Agreement has been signed between Workable Software Limited and its overseas group companies, and between Workable Software Limited and each of its data processors. These data processor agreements are designed to help safeguard your privacy rights and give you remedies in the unlikely event of a misuse of your personal data.
We will hold all the data for 18 months.
Your personal information will be deleted earlier on one of the following occurrences:
Under the General Data Protection Regulation you have a number of important rights. In summary, those include rights to:
You can exercise the aforementioned rights and send any relevant query regarding the personal data that We hold about you by sending an email at firstname.lastname@example.org. In this case you will need to:
We hope that We can resolve any query or concern you raise about Our use of your information.
You also have the right to lodge a complaint with the Greek Data Protection Authority, if you consider that the company violates the applicable data protection laws when processing your personal data (www.dpa.gr).
All questions, comments and requests regarding this Privacy Notice should be addressed to email@example.com