JOB CANDIDATE PRIVACY NOTICE

Hoist Finance AB (together referred to as “Hoist”, “us” or “we”) respect your privacy and are committed to protecting your personal data. Hoist is a personal data controller for the data we obtain through direct application from you. This means that we are responsible for deciding how we hold and use personal data about you. This notice is aimed at informing you of how and why your personal data will be used, namely for the purposes of the recruitment exercise, and how long it will be retained for. It provides you with certain information that must be provided under the General Data Protection Regulation ((EU) 2016/679) (GDPR) and the Swedish data protection law.

DATA PROTECTION PRINCIPLES 

We will comply with data protection law and principles, which means that your data will be:

-Used lawfully, fairly and in a transparent way.

-Collected only for valid purposes that we have clearly explained to you and not used in any way that is incompatible with those purposes.

-Relevant to the purposes we have told you about and limited only to those purposes.

-Accurate and kept up to date.

-Maintained only for as long as necessary for the purposes we have told you about, i.e. in relation to the recruitment exercise.

-Kept securely and protected against unauthorized or unlawful processing and against loss or destruction using appropriate technical and organizational measures.

DATA WE HOLD ABOUT YOU 

In connection with your application, we will collect, use and store the following categories of personal data about you:

-The data you have provided to us in your curriculum vitae (CV) and the personal data contained in your covering letter directly or through recruitment agencies.

-The data you have provided through application form such as name, title, home address, telephone number, personal email address, date of birth, gender, employment history, qualifications, nationality, social media accounts, profession, professional memberships, educational achievements, diplomas, transcripts, languages, computer skills, identification number and any data you provide us during interviews at our premises.

- Data provided to us from background checks provided by our third party provider such as: CV-verification, Information from the national registrar, tax information and internet searches. If you are applying for a position in the management body or as a key function holder we will also collect credit information, information from the Enforcement Authority, information on corporate commitments and property possessions as well as information on civil proceedings and tax surcharges. As a part of our background check we will also require you to provide us with a extract from the Swedish Criminal Register. We will only make a note that a satisfactory extract has been presented. The extract itself will be destroyed immediately and will not be processed automatically or manually as part of a filing system. 

-Any personal data provided to us about you by your referees (if applicable).

HOW IS YOUR PERSONAL DATA COLLECTED? 

We collect personal data about candidates from the following sources:

-You, the candidate.

-Your named referees, from whom we collect the following categories of data: full name, periods of previous employment, performance during previous employment.

-From publicly accessible sources, such as LinkedIn etc., where we collect your full name, email, work history, and other data included on your profile.

-From third parties (such as recruitment agencies) that have introduced you to us or you may have directly applied for a vacancy at our company on their website. Those third parties are data controllers for the data which they collect and process for their own purpose. More information about how they process your personal data can be found in their respective privacy notices on their websites.

-From third parties (such as pre-employment screening companies) that will perform checks on candidates in last stage of the recruitment process.

HOW WE WILL USE DATA ABOUT YOU 

We will use the personal data we collect about you to:

-Assess your skills, qualifications, and suitability for the role.

-Carry out pre-employment screening and reference checks, where applicable.

-Communicate with you about the recruitment process.

-Keep records related to our hiring processes.

-Comply with legal or regulatory requirements.

OUR LEGAL BASIS FOR PROCESSING

We as a financial institution who seek to hire only reliable and trustworthy employees rely on different legal obligations to process your personal data in accordance with regulation from EU and Swedish regulators.

It is also in our legitimate interests to decide whether to appoint you to the role since it would be beneficial to our business to appoint a suitable candidate to that role.

We a need to process your personal data also to decide whether to enter into a contract with you.

Having received your CV and covering letter and the results from any tests you took, we will then process that data to decide whether you meet the basic requirements to be shortlisted for the role. If you do, we will decide whether your application is suitable to invite you for an interview. If we decide to call you for an interview, we will use the data you provide to us at the interview to decide whether to offer you the role. If we decide to offer you the role, we may then take up references and/or any other checks before confirming your appointment. 

IF YOU FAIL TO PROVIDE RELEVANT INFORMATION

If you fail to provide personal data when requested, which is necessary for us to consider your application (such as evidence of qualifications or work history), we may not be able to process your application further. For example, if we require references for this role and you fail to provide us with relevant details, we will not be able to take your application further

HOW WE USE PARTICULARLY SENSITIVE PERSONAL DATA 

-We will use your sensitive personal data only in so far as we are permitted by law to do so:

-We will use data about your disability status to consider whether we need to provide appropriate adjustments during the recruitment process, for example whether adjustments need to be made during a test or interview.

-We will use data about your nationality or ethnicity, to assess whether a work permit and a visa will be necessary for the role.

AUTOMATED DECISION-MAKING 

You will not be subject to decisions that will have a significant impact on you based solely on automated decision-making.

DATA SHARING 

We will only share your personal data within Hoist group of companies including subsidiaries and branches.

All our third-party service providers and other entities in the group are required to take appropriate security measures to protect your personal data in line with data protection law and data processing is limited to EU/EEA area. Contractually, if transfers outside the EU/EEA or to countries without an adequacy decision by the European Commission occur in the future they will be based on standard data protection clauses adopted by the European Commission. 

DATA SECURITY 

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need-to-know. They will only process your personal data on our specific instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable authority of a suspected breach where we are legally required to do so.

DATA RETENTION 

We will retain your personal data from recruitment process 5 years after last date of your employment with us if you are successful with your application. If you are unsuccessful we shall retain your personal data for 1 year upon your explicit consent given. We retain your personal data for that period so that we can show, in the event of a legal claim, that we have not discriminated against candidates on prohibited grounds and that we have conducted the recruitment exercise in a fair and transparent way. We further retain such personal data in case a similar role becomes vacant for which you will be a fitting candidate. After this period, we will securely destroy your personal data in accordance with our data retention governance documents. Note that results of pre-employment screening will be held for the duration of your recruitment process with us and deleted after process is finished, unless you are applying for a key management position such as CEO, EMT member, Board member etc. where information about CV-verification and corporate commitments will be retained for 5 years after end of employment.

 YOUR RIGHTS OF ACCESS, CORRECTION, ERASURE, AND RESTRICTION 

Under certain circumstances, by law you have the right to:

-Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.

-Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data corrected.

-Request erasure of data we hold on you where it is no longer necessary for the purpose for which it was collected, where you withdraw any consent you provided for its processing, where you object to our processing of it (see below), or where our processing is unlawful.

-Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal data for direct marketing purposes.

-Request the restriction of processing of your personal data. This enables you to ask us to suspend the processing of personal data about you, for example if you want us to establish its accuracy or the reason for processing it.

-Request the transfer of your personal data to another party.

If you want to request erasure, review, verify, object to processing or correct your personal data, please send an email to career@hoistfinance.com.

DATA PROTECTION QUERIES 

We have appointed a Data Protection Officer to oversee compliance with this privacy notice. If you have any questions about this privacy notice or how we handle your personal data, please contact the DPO at  dpo@hoistfinance.com.  You have the right to make a complaint at any time to the Datainspektionen – Swedish Data Protection Authority at datainspektionen@datainspektionen.se.

CHANGES TO THIS PRIVACY NOTICE

We regularly review this privacy notice. We will notify you of any substantial updates and any updates that affect you in advance. Minor changes to the notice, such as making it clearer, will be implemented without directly notifying you. This notice was last time updated: May 2020.