1. Controller of the filing system

Controller of this filing system is the Finnish company Paulig Ltd (business registration number: 0112563-0) and companies at the time belonging to the Paulig, all together hereinafter referred to as ”Paulig”.

Paulig Ltd’s contact details in HR related privacy policy matters are:

Paulig Ltd / job applicant privacy matters
Satamakaari 20
FIN – 00980 Helsinki
FINLAND

employee-privacy@paulig.com
Tel: +358 9 319 81

Please do not hesitate to contact us if you have any questions, concerns or ideas related to Paulig’s personal data procedures.

2. Definitions

In the following the most essential terms used in this privacy policy are explained:

  1. 'Applicant' means any person who has sent a specific or general job application to any of Paulig companies or recruitment companies acting on behalf of Paulig, based on a recruitment notice or as an open application.
  2. 'Personal data' means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly.
  3. 'Consent' of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
  4. 'Profiling' means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

3. What are our principles for securing your personal data?

Paulig has established electronic and administrative safeguards designed to make the information collected secure.

Only appointed personnel of Paulig and of organizations operating by Paulig’s assignment or on behalf of Paulig are entitled to use the personal data filing system. All persons processing the system have a personal right of use granted by Paulig or its co-operation partner. Different levels of access have been created based on the data a person needs according to his/her job description. The system is protected with a fire-wall which protects it from contacts outside of Paulig.

All personnel of Paulig and its subcontractors are obliged to keep the information of the personal data which they obtain in their work confidential.

Manually processed documents containing personal data are protected against unauthorized access.

4. To what purposes we process your data and based on which grounds?

Paulig may process your personal data directly necessary for your recruitment process and possible employment relationship (either with Paulig or with a private employment agency) which is connected with managing the rights and obligations of the parties to the relationship or with the benefits possibly provided by Paulig for you, or which arises from the special nature of the work concerned.

Processing of your personal data is based on the following grounds of the EU’s General Data Protection Regulation (one or more grounds may apply simultaneously):

a) Processing is necessary in order to take steps at your request prior to entering into a contract.
b) Processing is necessary for the purposes of the legitimate interests pursued by Paulig.
c) You have given consent to the processing of your personal data.

The legitimate interests of Paulig or third party referred to in point b) above may include amongst others the following matters:

  • maintaining candidate pool for possible new recruitment needs
  • maintaining log files of who has processed the personal data
  • business development


In addition to the above, Paulig uses your data if we think it’s necessary for security purposes or to investigate possible fraud or other violations of our agreements or this Privacy Policy.

5. What types of information we may collect about you?

Content of Paulig’s filing system may include the following types of data and changes made to these data types:

A. Personal information

  • Last name, all first names, previous last name
  • Home address
  • E-mail address
  • Phone number(s)
  • Date of birth
  • National identification code
  • Gender
  • Nationality
  • Photo and video clips
  • Languages
  • Medical and drug test data (where applicable)
  • Use of your rights related to your personal data (such as right to access your personal data)


B. Employment related information

  • Work history
  • Education
  • Trainings and certificates you have completed
  • Knowledge, skills and expertise (e.g. language and ICT skills)
  • Cover letter and CV
  • Salary and benefit requests
  • Personality and aptitude assessment results (e.g. via recruitment consultants)
  • Examples of previous work or presentations (e.g. portfolio of creative works)
  • Social media content (with consent)
  • Other information during recruitment interviews and reference checking
  • Work permit (where applicable)
  • Credit rating (where applicable)
  • Extract from criminal records (where applicable)

6. Which sources we gather your personal data from?

Paulig gathers personal data directly from you, for example from:

  • website forms
  • physical forms
  • telephone conversations during which you provide personal data to Paulig
  • e-mail correspondence in which you provide personal data to Paulig
  • personal discussions
  • job applications videos 


Paulig may gather personal data from third parties based on your consent, for example from:

  • persons you have indicated as a reference
  • companies offering recruitment consultancy and personality and aptitude assessment tests to Paulig


Paulig may gather personal data from third parties without your consent when:

  • an authority discloses information to the employer to enable the latter to fulfil a statutory duty or
  • when the employer acquires personal credit data or information from the criminal record in order to establish the employee's reliability.


Paulig may obtain and update the personal data in its filing system from officials and companies offering personal data services.

7. To whom we may transfer and assign your personal data?

Paulig companies have a legitimate interest in transmitting personal data within Paulig for internal administrative purposes.

Paulig does not sell, lease or otherwise disclose your personal data to third parties outside of Paulig unless otherwise stated below.

Paulig may share your personal data with authorized third parties that perform services for Paulig for the purposes described in this Privacy Policy within the limits of the applicable legislation. This may include for example providing services such as software services, managing and analyzing personal data and conducting research.

Because Paulig takes the responsibility to safeguard your personal data seriously, Paulig does not allow those companies to use it for any purpose other than to perform those services, and Paulig requires them to protect your personal data in a way consistent with this privacy policy.

Paulig may share your personal data based on a valid order from a court or other official body with sufficient authority.

Paulig may share your personal data as part of any merger, acquisition, sale of company assets or transition of service to another provider. This also applies in the unlikely event of an insolvency, bankruptcy or receivership in which your personal data would be transferred to another entity as a result of such a proceeding.

8. Is your data transferred to countries outside the European Union?

Paulig’s services may be provided using resources and servers located in various countries around the world. Therefore Paulig may transfer your personal data outside the country where you use our services, including to countries outside the EU and EEA that do not have laws providing specific protection for personal data or that have different legal rules on data protection.

In such cases Paulig ensures that a legal basis for such a transfer exists and that adequate protection for your personal data is provided as required by applicable law, for example, by using standard agreements approved by relevant authorities (where necessary) and by requiring the use of other appropriate technical and organizational information security measures.

9. How long do we process your data?

Paulig may process your data in its job applicant system for until the end of the second year following your application year (for example: application 1 August 2018 => 31 December 2020).

Based on your consent Paulig may process your personal data for as long as the consent describes.

Paulig may process your personal data based on legal requirements for as long as the applicable legislation allows.

10. How can you exercise the different types of rights you have?

All rights can be exercised by contacting Paulig’s privacy team by using the contact details issued at section 1 above. The team will then give further instructions on how to exercise a specific right. Where Paulig has reasonable doubts concerning the identity of the person making the request, Paulig may request the provision of additional information necessary to confirm your identity.

Paulig will provide information on action taken on a request to you within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests.

10.1. Right of access to your personal data

You have the right to obtain from Paulig confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, receive information about your personal data.

10.2. Right to rectification

You have the right to obtain from Paulig without undue delay the rectification of inaccurate personal data concerning you.

10.3. Right to erasure ('right to be forgotten')

You have the right to obtain from Paulig the erasure of personal data concerning you without undue delay where one of the following grounds applies:

a) your personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;

b) you withdraw consent on which the processing is based and where there is no other legal ground for the processing;

c) you object to the processing and there are no overriding legitimate grounds for the processing;

d) your personal data have been unlawfully processed;

e) your personal data have to be erased for compliance with a legal obligation in Union or member state law to which Paulig is subject;

f) the personal data have been collected in relation to the offer of information society services.

However, you do not have the right or erasure if the processing is necessary:

a) for exercising the right of freedom of expression and information;

b) for compliance with a legal obligation which requires processing by Union or member state law to which Paulig is subject; or

c) for the establishment, exercise or defence of legal claims.

10.4. Right to restriction of processing

You have the right to obtain from Paulig restriction of processing where one of the following applies:

a) the accuracy of the personal data is contested by you, for a period enabling Paulig to verify the accuracy of the personal data;

b) the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead;

c) Paulig no longer needs the personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defence of legal claims;

d) you have objected to processing pending the verification whether the legitimate grounds of Paulig override those of you.

10.5. Right to object

You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on legitimate interests pursued by Paulig, including profiling. Paulig shall no longer process the personal data unless Paulig demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms for the establishment, exercise or defence of legal claims.

Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.

Please be aware that you cannot opt out of receiving service messages from Paulig, including but not limited to security and legal notices.

10.6. Right to data portability

You have the right to receive the personal data concerning you, which you have provided to Paulig, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller where:

a) the processing is based on consent or on a contract; and

b) the processing is carried out by automated means.

11. Is it mandatory for you to disclose your personal data to us?

Where processing of your personal data is necessary for Paulig in order to take steps at your request prior to entering into a contract, it is mandatory for you to disclose the personal data needed for a recruitment process.

12. How can you withdraw a consent given by you?

You may withdraw possible consent by contacting Paulig’s privacy team (contact information in section 1) or by using possible electronic means provided by Paulig.

13. Do we make decisions affecting you based on automated means?

Paulig does not make decisions based solely on automated processing which produces legal effects concerning you or similarly significantly affect you.

14. Do we process your personal data in order to profile you?

Paulig does not carry out job applicant profiling in a way meant in the GDPR.

15. How can you exercise your right to lodge a complaint to the supervisory authority?

In case you suspect a breach of data protection legislation, please contact Paulig’s privacy team first (contact information in section 1). This Privacy Policy covers Paulig’s operations in all countries.

In case the matter is not solved amicably between you and Paulig, you may contact the Data Protection authority of the country where the Paulig entity in question operates. Contact information of the competent authority of each Paulig’s operation country can be found here.

16. Which law do we apply for processing personal data?

The processing of personal data in Paulig’s filing system is governed by the European Union’s applicable data protection legislation as well as national laws of countries where Paulig is established.

17. How can we update this Privacy Policy?

Paulig may modify this privacy policy, and if we make material changes to it, we will provide notice on our intranet or by other means, to provide you the opportunity to review the changes before they become effective and binding.