1. Controller and contact information

Controller is the Finnish company Paulig Ltd (business registration number: 0112563-0) or one of the companies belonging to the Paulig group. All together and each separately, they are hereinafter referred to as the "Paulig". The controller is the Paulig group company with which you have applied for an open position. A list of the companies belonging to the Paulig group from time to time is available here

Our contact details in HR-related Privacy Policy matters are:  

Paulig Ltd / job applicant privacy matters
Satamakaari 20
FIN – 00980 Helsinki
FINLAND

employee-privacy@paulig.com
Tel: +358 9 319 81

Please do not hesitate to contact us if you have any questions, concerns, or ideas related to our personal data procedures. 

2. What are our principles for securing your personal data?  

Paulig has established  technical and administrative safeguards designed to make the data collected secure.  

Only appointed personnel of Paulig and of organizations operating by Paulig’s assignment or on behalf of Paulig are entitled to take part in the processing of personal data. All persons taking part in the processing have a personal right of use granted by Paulig or its co-operation partner. Different levels of access have been created based on the data a person needs according to their job description. Paulig’s data systems are protected with firewalls and other appropriate technical measures which protect data in them from contacts outside of Paulig.  

All personnel of Paulig and its subcontractors are obliged to keep the personal data which they obtain in their work confidential. Manually processed documents containing personal data are protected against unauthorized access. 

3. For what purposes do we process your personal data and based on which grounds?

Paulig may process your personal data directly necessary for your recruitment process and possible employment relationship (either with Paulig or with a private employment agency) which is connected with managing the rights and obligations of the parties to the relationship, or with the benefits possibly provided by Paulig to you, or which arises from the special nature of the work concerned.

The processing of your personal data is based on the following grounds of the EU’s General Data Protection Regulation (one or more grounds may apply simultaneously to the same personal data):

  • Processing is necessary in order to take steps at your request prior to entering into a contract.
  • Processing is necessary for compliance with a legal obligation to which we are subject, in particular in the areas of labour and employment legislation, social security legislation, data protection legislation, tax legislation, cybersecurity legislation, and corporate compliance law.
  • Processing is necessary for the purposes of the legitimate interests pursued by Paulig.
  • You have given consent to the processing of your personal data.
     

The legitimate interests of Paulig or third party referred above may include amongst others the following matters:

  • maintaining candidate pool for possible new recruitment needs
  • prevention of misuse of our data systems, including by maintaining log files of who has processed the personal data
  • business development
     

In addition to the above, Paulig uses your data if we think it is necessary for security purposes or to investigate possible fraud or other violations of our agreements or this Privacy Policy.

AI tools are developing and some of your personal data may be processed by AI tools used by Paulig (such as Copilot in the M365 environment) to assist our knowledge work.

Regarding sensitive personal data, the processing is based on the necessity of processing to comply with the special rights and obligations of the controller or the data subject in the field of employment and social security and social protection law or your explicit consent.  

4. What types of personal data we may process about you and for what purposes?

In connection with your recruitment, we may process the types of data and changes made to these data types listed below. Below, we also list the purpose of processing for each data category or, as applicable, for each data type.  

Basic information, processed for the purposes of initiating and carrying out the recruitment process, and for managing the rights and obligations of the parties to the process. This data category includes data types such as:  

  • First names, last name, previous last name
  • Home address
  • E-mail address
  • Phone number(s)
  • Date of birth
  • National identification code
  • Gender
  • Nationality
  • Photo and video clips
  • Languages
     

Information related to your suitability to the open position, for purposes of assessing your suitability for the open position or, as applicable, and to the extent permitted by applicable legislation, to establish your performance and working capacity or your reliability. This data category includes data types such as:  

  • Work history
  • Education
  • Trainings and certificates you have completed
  • Knowledge, skills and expertise (e.g. language and IT skills)
  • Cover letter and CV
  • Salary and benefit requests
  • Personality and aptitude assessment results (as applicable) (e.g. via recruitment consultants)
  • Examples of previous work or presentations (e.g. portfolio of creative works)  
  • Social media content (with consent)
  • Other information during recruitment interviews and reference checking you have provided us with or which we have collected based on your consent
  • Work permit (where applicable)
  • Background check information, such as extract from criminal records (where applicable) to the extent permitted by applicable laws
  • Personal credit information (where applicable) to the extent permitted by applicable laws
  • Medical and drug test data (where applicable) to the extent permitted by applicable laws 

5. What sources do we use to gather your personal data?

Paulig gathers personal data directly from you, for example, from:  

  • website forms  
  • physical forms
  • telephone conversations during which you provide personal data to Paulig
  • e-mail correspondence in which you provide personal data to Paulig
  • personal discussions
  • job application videos
     

Paulig may gather personal data from third parties based on your consent, for example, from:

  • persons you have indicated as a reference
  • companies offering recruitment consultancy and personality and aptitude assessment tests to Paulig
     

Paulig may gather personal data from third parties without your consent when one of the following applies, but only to the extent permitted by applicable laws:

  • an authority discloses information to the employer to enable the latter to fulfil a statutory duty, or  
  • when the employer acquires personal credit data or information from the criminal record in order to establish the employee's reliability.
     

Paulig may obtain and update the personal data in its filing system from authorities and companies offering personal data-related or other services to Paulig. 

6. To whom may we transfer and assign your personal data?

The companies belonging to Paulig have a legitimate interest in transmitting personal data within the group for internal administrative purposes.  

Paulig does not sell, lease, or otherwise disclose your personal data to third parties outside of Paulig unless otherwise stated below.

Paulig may share your personal data with authorized third parties that perform services for Paulig for the purposes described in this Privacy Policy, within the limits of the applicable legislation. The services provided by the third parties may include services such as software services, managing and analyzing personal data, and conducting research. The third parties may include, for example, companies that provide Paulig with recruitment consultancy and personality and aptitude assessment tests.  

Because Paulig takes the responsibility to safeguard your personal data seriously, Paulig does not allow those companies to use your personal data for any purpose other than to perform those services, and Paulig requires them to protect your personal data in a way consistent with this Privacy Policy.  

We may also transfer or disclose your personal data to third parties in the limited situations when requested by you. For example, if you wish us to save your personal data for future recruitment purposes for other Paulig companies also, we will share your personal data with other Paulig companies.  

We may also disclose personal data of job applicants to competent authorities when required to do so under applicable laws or other statutes, to prepare for legal proceedings, or to defend a claim within the limits permitted or required by applicable legislation from time to time.  

Paulig may share your personal data as part of any merger, acquisition, sale of company assets or transition of service to another provider. This also applies in the unlikely event of an insolvency, bankruptcy or receivership in which your personal data would be transferred to another entity as a result of such a proceeding. 

7. Is your data transferred to countries outside the EU?

Paulig’s services may be provided using resources and servers located in various countries around the world. Therefore, Paulig may transfer your personal data outside the country where you are located or where Paulig is established, including to countries outside the EU and EEA that do not have laws providing specific protection for personal data or that have different legal rules on data protection.  

In such cases, Paulig ensures that a legal basis for such a transfer exists and that adequate protection for your personal data is provided as required by applicable law, for example, by using standard agreements approved by relevant authorities, in particular the EU Commission’s standard contractual clauses (where necessary), and by requiring the use of other appropriate technical and organizational information security measures. The standard contractual clauses are available here.  

 

8. How long do we process your data?  

Paulig may process your data in its job applicant system for until the end of the 2nd calendar year following your application year (e.g. application 21 October 2024 à 31 December 2026), except in the case we have a legitimate interest (such as related to an ongoing court proceeding) to store the personal data for a longer period.  

Personal data related to chosen job candidates will be retained in accordance with the retention periods defined in our internal Privacy Policy for employees.  

Based on your consent, for example if you wish us to keep you in mind for future career opportunities, Paulig may process your personal data for as long as you withdraw your consent.  

Paulig may process your personal data based on legal requirements for as long as the applicable legislation allows.  

9. How can you exercise the different types of rights you have?  

All rights can be exercised by contacting Paulig’s privacy team by using the contact details provided in section 1 above. The team will then give further instructions on how to exercise a specific right. Where Paulig has reasonable doubts concerning the identity of the person making the request, Paulig may request the provision of additional information necessary to confirm your identity.

Paulig will provide information on action taken on a request to you within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests.

  • Right of access to your personal data: You have the right to obtain from Paulig confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, receive information about your personal data.
  • Right to rectification: You have the right to obtain from Paulig without undue delay the rectification of inaccurate personal data concerning you.
  • Right to erasure ('right to be forgotten'): You have the right to obtain from Paulig the erasure of personal data concerning you without undue delay where one of the following grounds applies:  
    • your personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed
    • you withdraw consent on which the processing is based and where there is no other legal ground for the processing
    • you object to the processing and there are no overriding legitimate grounds for the processing
    • your personal data have been unlawfully processed
    • your personal data have to be erased for compliance with a legal obligation in Union or member state law to which Paulig is subject, or
    • the personal data have been collected in relation to the offer of information society services.

      However, you do not have the right or erasure if the processing is necessary:
    • exercising the right of freedom of expression and information,
    • for compliance with a legal obligation which requires processing by Union or member state law to which Paulig is subject, or
    • for the establishment, exercise or defense of legal claims.
  • Right to restriction of processing: You have the right to obtain from Paulig restriction of processing where one of the following applies:  
    • the accuracy of the personal data is contested by you, for a period enabling Paulig to verify the accuracy of the personal data
    • the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead
    • Paulig no longer needs the personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defense of legal claims, or
    • you have objected to processing pending the verification whether the legitimate grounds of Paulig override those of you.
  • Right to object: You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on legitimate interests pursued by Paulig, including profiling. Paulig shall no longer process the personal data unless Paulig demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms for the establishment, exercise or defense of legal claims.  

    Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. 

    Please be aware that you cannot opt out of receiving service messages from Paulig, including but not limited to security and legal notices.
     
  • Right to data portability: You have the right to receive the personal data concerning you, which you have provided to Paulig, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller where:  
    • the processing is based on consent or on a contract, and
    • the processing is carried out by automated means. 

10. Is it mandatory for you to disclose your personal data to us?

Where processing of your personal data is necessary for Paulig in order to take steps at your request prior to entering into a contract, it is mandatory for you to disclose the personal data needed for a recruitment process.  

11. How can you withdraw a consent given by you?

You may withdraw possible consent by contacting Paulig’s privacy team (contact information in section 1) or by using possible electronic means provided by Paulig.

12. Do we make decisions affecting you based on automated means?  

Paulig does not make decisions based solely on automated processing which produces legal effects concerning you or similarly significantly affect you. 

13. Do we process your personal data in order to profile you?  

Paulig does not carry out job applicant profiling in a way meant in the EU’s General Data Protection Regulation. 

14. How can you exercise your right to lodge a complaint to the supervisory authority?  

In case you suspect a breach of data protection legislation, please contact Paulig’s privacy team first (contact information in section 1).  

In case the matter is not solved amicably between you and Paulig, you may contact the supervisory authority in the EU member state of your habitual residence, your place of work, or the place of the alleged infringement, or of the country where the Paulig entity in question operates. Contact information of the competent authority of each Paulig’s operation country can be found here.  

15. Which law do we apply for processing personal data?  

The processing of personal data in Paulig’s filing system is governed by the EU’s applicable data protection legislation, as well as national laws of countries where Paulig is established. 

16. How can we update this Privacy Policy?

Paulig may modify this Privacy Policy from time to time as needed. Unless otherwise provided by mandatory applicable legislation, we may not notify changes to the data subjects in person. We therefore encourage you to check this privacy policy from time to time for possible changes.