The General Data Protection Regulation (GDPR) is an EU regulation that aims to protect personal data and provide a level of online privacy to EU citizens. Whistling Duck LLC, the company behind CVSelection, considers this piece of legislation to be incredibly important and supports the provisions set forth in the GDPR. This document outlines how personal data is handled on CVSelection, and how compliance with the GDPR is made possible.
How we treat personal data We are not in the business of selling our clients' or their candidates' data, so your data will not be sold to or shared with third parties. We do not share or link your data with any AI software. CVSelection does not use cookies or other technologies to track candidates. Each client can set their own data retention policy. Our servers are located in the Netherlands and compliant with GDPR legislation.
CVSelection is built around a number of general principles that aim to balance flexibility with privacy concerns. We have built our system to use as few external services as possible. We sell a recruitment tool that is built around principles of being as transparent and objective as we can make it, and as honest as we can be in providing this service._
We only collect data that are necessary When job application forms are published, CVSelection has to collect certain personal information. After all, personal data are at the core of a job application. However, unlike other platforms that may gather a lot of data behind the scenes, CVSelection only gathers personal data that the candidate actively supplies. CVSelection does not use cookies or other technologies to track candidates.
We allow companies to define their own data expiration policies CVSelection has customers throughout the world and data retention policies across the world. For this reason, CVSelection does not force a specific data retention policy. Instead, each client can set their own data retention policy. This means that every customer can define how long CVs and candidate profiles should be stored for.
Privacy by Design As explained above, CVSelection was made with privacy concerns taken into consideration from the start. Rather than a "collect all that we can" approach, we opted to only collect data that is required. CVSelection was developed a number of years before the GDPR came into force, and there are a number of structural changes that the team had made to make certain parts of managing personal data easier.
Data transparency Through this policy, published on our website, CVSelection makes it clear how it handles personal information. When CVSelection collects data, this is clearly asked from the user and there is no additional personal information collected other than what is being asked. The information collected from a candidate may include the following
Note that within CVSelection, companies have the option to define additional questions, and some companies may request contact information including Whatsapp numbers or other contact details. CVSelection allows each company to define what information they would like to request. But all of this information is asked directly from the candidate and not collected by CVSelection in any other way.
For security purposes, CVSelection stores the following information when a candidate records an application: - Time and date of the application - IP address - Browser
This information is recorded for security purposes, and part of recommended security practices.
Right of access As defined in the GDPR, EU users have a right to access their personal information and receive details about how this information is being used. CVSelection facilitates this process. Our company does not process candidate information directly. Our company stores candidate information and makes it available to our clients (the companies that publish an application form). Therefore, to understand how information of an individual is being used, EU users can submit their request directly to the company they are applying to. All information that CVSelection collects is the same information that is available to the company running the recruitment process. CVSelection does not store any additional information on candidates.
Rectification and erasure EU users have a right that their data be erased within 30 days. CVSelection facilitates this process. Within our website, companies can delete individual candidates from their recruitment process. This will automatically flag the profile for deletion and permanently remove this from our servers within 7 days (we do not permanently delete data instantly due to the risk of accidentally losing critical information). From a data integrity point of view, information about the fact that a candidate applied and moved through the recruitment process can not be erased. In order to erase the personal data, the name of the candidate in activity logs is replaced by a generic name, after the profile itself is removed.
It is important to note that backups are made of our databases - and it is not possible to retroactively change these backups. That means that personal information is still stored within these databases. However, backups are updated on a rolling basis, with only 30 days being retained.
Security of personal data Data uploaded to CVSelection is protected as best we can, taking into account recommended security practices and measures to limit and control server and data access. Measures include the following:
Information on the server itself is furthermore protected by: - One-way encryption of any access credentials (access keys, passwords, etc.) - Software on the server is kept up-to-date and firewalls and other protective measures have been put in place. - Access to the server and database is restricted and monitored. - Daily backups are made and stored remotely.
Our servers are located in the Netherlands
Safety of uploaded files Depending on the vacancy settings, candidates might be able to upload files (such as a CV or motivation letter). For our clients, we provide an initial layer of virus and malware detection on uploaded files, but this is done as a courtesy. Clients are recommended to always scan files that they download from untrusted sources (such as candidates applying for jobs). If a client wishes to eliminate the risks associated with file downloads, we recommend asking all relevant questions within the application form and disabling file uploads as part of recruitment practices.
If we become aware of any breach, we will notify the supervisory authority without undue delay unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.
Database storage consent CVSelection provides options for a dedicated "Candidate Database" that allows organizations to store information on candidates for a longer period of time. This feature can be used by companies as we made an easy system to request permission from candidates for this longer-term storage option. Long-term candidate data storage only happens if this feature was enabled in the vacancy and the candidate opts-in during the application process.
Tracking of individual viewing access We log details of CVs being downloaded and other actions by users who have access to the candidates. These logs are available to each client (but within the team only to those with General administrator or Vacancy administrator privileges). In addition to logging changes and downloads, we also register when candidate profiles are being viewed and by whom. This allows users at the General administrator or Vacancy administrator level to review data access and downloads in detail.
Login functionality for candidates Under the default settings, candidates apply once-off for a vacancy by filling out an application form. We do not create a user profile or store cookies. That means that they have to fill out the same information if they apply to another job at the same company. For those candidates stored in a long-term database that reapply to the same company, we provide an option for candidates to create an account and apply to different positions without having to enter the same information. We have implemented additional features for them to also ensure GDPR compliance (and, for instance, allow them to remove their own profile).