Sourced candidates privacy policy

29.04.2021

Background

This Sourced Candidates Privacy Policy (referred to as "Privacy Policy") informs why and how we process personal data about potential job candidates, whose data we have collected from publicly available sources (referred to as "Candidate", "you" and jointly "Candidates").

Aiven Ltd, business ID: 2795743-5, is the data controller (referred to as "Aiven", "we" or "us") in relation to the processing of your personal data. As a data controller, Aiven is responsible for ensuring that personal data is processed in compliance with data protection laws. We take your data protection rights seriously and your personal data will be treated in a secure and confidential manner as set out in this Privacy Policy and as required by data protection laws.

If you have any questions regarding this Privacy Policy, please contact us at privacy@aiven.io.

Where do we collect your personal data and what personal data are processed?

We collect your personal data from publicly available sources by using a service provider AmazingHiring. AmazingHiring collects your data from the following publicly available services (referred to as "Public Services"): 

  • Angel.co

  • Behance

  • Bitbucket.org

  • Coderwall.com 

  • Dribble

  • Facebook 

  • GitHub

  • Gravatar.com

  • Habrahabr.ru 

  • Kaggle.com 

  • Keybase.io 

  • Linkedin 

  • Medium.com

  • Meetup.com 

  • Moikrug.com

  • Npmjs.com

  • Plus.google.com

  • Quora.com

  • twitter.com 

  • vk.com 

Personal data available in the Public Service(s)

When you create your public profile in any of the Public Services you can choose what information you set to be public and to what extent search engines like AmazingHiring can access your personal data. You can restrict search engines from accessing your public profile by changing certain profile settings available or by changing or removing the personal data available in the Public Services. 

We collect the following categories of personal data from the Public Services:

  • Identity and contact information of the Candidates (e.g. full name, email address, address, telephone number)

  • Employment and education data, (e.g. previous title, previous employer office location and department, references, licenses, certificates, educational information)

What is the purpose and lawful basis for processing your data?

We have identified the purposes for processing your personal data as provided in the table below. These purposes each relate to a lawful basis for processing, as required by data protection laws. 

Purpose for processing
Lawful basis
Evaluate potential Candidates in order to offer open positions. The processing in this regard includes categorizing and evaluating Candidates’ suitability for open positions by using certain criteria with respect to professional attributes and skills when performing searches from Public Services.
The processing is necessary to achieve the legitimate interests pursued by Aiven. Aiven considers that it has a legitimate interest in attracting and appointing high caliber talents to secure competitiveness and business continuity.
Informing and offering new open positions. The processing in this regard includes contacting suitable Candidates about new open position via email.
The processing is necessary to achieve the legitimate interests pursued by Aiven. Aiven considers that it has a legitimate interest in imparting information and establishing a dialogue with suitable Candidates to ensure effective communication of open positions.

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. Please note that if you submit a job application to us, we will process your personal data for the purposes defined under our Job Applicant Privacy Policy, available here: https://aiven.io/job-candidate-privacy-policy

How do we perform the searches?  

For each of our open position for which we are looking for Candidates, we always have certain predefined criteria to which against we perform the searches. The predefined criteria consists of the following information regarding the Candidate (the combination used in each search may vary):

  • Location 

  • Work Experience

  • Key technologies (e.g. key programming languages)

  • Other similar professional attributes

In other words, we use pre-determined criteria and automated means to process personal data and create profiles of Candidates. Although the processing may amount to profiling, as defined in data protection laws, we do not carry out any automated decision making that would have legal effects or similarly significant effects on the Candidates. 

After performing the search, our recruiters will always review the results and decide which Candidates to contact. In addition, before communicating, our recruiters may also manually check the potential Candidate’s profile in Public Services in order to determine whether the Candidate has the necessary skills and attributes to succeed in our open position. 

To whom we share your data?

We may have to share your personal data with the parties set out below for the purposes described in this Privacy Policy. These parties include:  

  • Service providers who provide IT and system administration services, including our email service provider

  • The Candidate search service provider AmazingHiring

All of our subsidiaries and third party service providers are required to take appropriate security measures to protect your data and they may only process personal data for the purposes mentioned in this Privacy Policy and in accordance with our instructions. 

Do we transfer personal data outside the EU/EEA? 

We store personal data on servers located in the European Union ("EU"). However, some of our service providers or subsidiaries may be based outside the European Economic Area ("EEA"), including the United States of America, so their processing of your personal data will involve a transfer of personal data outside the EEA. 

Whenever we transfer personal data out of the EEA, and unless a specific derogation applies, we seek to ensure that a similar degree of protection is afforded than that provided in the EEA by ensuring at least one of the following safeguards is implemented:

  • Where possible, we will transfer personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission

  • Where we use a service provider residing in a country outside the EEA that is not deemed to provide an adequate level of protection for personal data, we use specific contractual clauses approved by the European Commission (i.e. the Standard Contractual Clauses approved by the European Commission) which aim to provide personal data the same protection as it has in the EEA

Please email us at privacy@aiven.io if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA or to obtain a copy of any contractual clauses in place, although some details may be redacted for confidentiality reasons. 

How long will we retain personal data? 

We will only retain personal data for as long as necessary to fulfill the purposes defined in this Privacy Policy. In general, we comply with the following criteria with respect to retaining and erasing personal data:  

  • Personal data are retained during the search and evaluation period. Following this, personal data will be erased after we have contacted you to inform and offer open position at Aiven 

Please note, that in case you wish to submit a job application to us, we will process that data under our Job Applicant Privacy Policy, which can be found here: https://aiven.io/job-candidate-privacy-policy

What rights do you have? 

Subject to certain exemptions and limitations, you have certain rights in relation to the processing of your personal data. You have the right to:

  • Access your personal data

  • Update incorrect or incomplete personal data 

  • Object to the processing of personal data

  • Erase your personal data

  • Restrict the use of your personal data

  • The right to object processing, that is based on legitimate interest

  • If we would process personal data on the basis of your consent, you will have the right to withdraw your consent at any time 

Should you wish to exercise your above mentioned rights, please send a request to us at privacy@aiven.io.

In case you exercise your rights, we may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

Updates to this privacy policy 

We may update this Privacy Policy from time to time. If we make any updates to this Privacy Policy, we will always publish the updated version on this page. 

Contact

If you have any questions regarding the processing of your personal data, please do not hesitate to contact us. See below for contact details: 

Aiven Oy

Antinkatu 1, 00100 Helsinki, Finland

privacy@aiven.io

You have the right to make a complaint at any time to the supervisory authority in your country of residence. A list of the EEA supervisory authorities can be found here: https://edpb.europa.eu/about-edpb/about-edpb/members_en. In Finland, the relevant supervisory authority is the Office of the Data Protection Ombudsman: https://tietosuoja.fi/en/home. We would, however, appreciate the chance to deal with your concerns before you approach any supervisory authority so please contact us in the first instance. 

Start your free 30 day trial

Test the whole platform for 30 days with no ifs, ands, or buts.

Aiven logo

Let‘s connect

Apache Kafka, Apache Kafka Connect, Apache Kafka MirrorMaker 2, M3, M3 Aggregator, Apache Cassandra, Elasticsearch, PostgreSQL, MySQL, Redis, InfluxDB, Grafana are trademarks and property of their respective owners. All product and service names used in this website are for identification purposes only and do not imply endorsement.