SBHA Privacy Policy for Recruitment using Teamtailor
The service for handling recruitments and simplifying the hiring process (the "Service") is powered by Teamtailor on behalf of Scottish Borders Housing Association ("Controller" “we” “us” etc.). It is important that the persons using the Service ("Users”) feel safe with, and are informed about, how we handle User's personal data in the recruitment process. We strive to maintain the highest possible standard regarding the protection of personal data. We process, manage, use, and protect User's Personal Data in accordance with this Privacy Policy ("Privacy Policy").
1. General
We are the controller in accordance with current privacy legislations. The Users’ personal data is processed with the purpose of managing and facilitating recruitment of employees to our business.
2. Collection of personal data
We are responsible for the processing of the personal data that the Users contributes to the Service, or for the personal data that we in other ways collects with regards to the Service.
When and how we collect personal data
We collect personal data about Users from Users when Users;
- make an application through the Service or otherwise, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn; and
- use the Service to connect with our staff, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn.
- provides identifiable data in the chat (provided through the website that uses the Service) and such data is of relevance to the application procedure;
We collect data from third parties, such as Facebook, LinkedIn and through other public sources. This is referred to as “Sourcing” and be manually performed by our employees or automatically in the Service.
In some cases, existing employees can make recommendations about potential applicants. Such employees will add personal data about such potential applicants. In the cases where this is made, the potential applicant is considered a User in the context of this Privacy Policy and will be informed about the processing.
The types of personal data collected and processed
The categories of personal data that can be collected through the Service can be used to identify natural persons from names, e-mails, pictures and videos, information from Facebook and LinkedIn-accounts, answers to questions asked through the recruiting, titles, education and other information that the User or others have provided through the Service. Only data that is relevant for the recruitment process is collected and processed.
Purpose and lawfulness of processing
The purpose of the collecting and processing of personal data is to manage recruiting. The lawfulness of the processing of personal data is our legitimate interest to simplify and facilitate recruitment.
Personal data that is processed with the purpose of aggregated analysis or market research is always made unidentifiable. Such personal data cannot be used to identify a certain User. Thus, such data is not considered personal data.
The consent of the data subject
The User consents to the processing of its personal data with the purpose of Controller’s handling recruiting. The User consents that personal data is collected through the Service, when Users;
- make an application through the Service, adding personal data about themselves either personally or by using a third-party source as Facebook or LinkedIn, and that Controller may use external sourcing-tools to add additional information; and
- when they use the Service to connect to Controller’s recruitment department, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn.
The User also consents to the Controller collecting publicly available information about the User and compiles them for use in recruitment purposes.
The User consents to the personal data being collected in accordance with the above a) and b) will be processed according to the below sections Storage and transfer and How long the personal data will be processed.
The User has the right to withdraw his or her consent at any time, by contacting Controller using the contact details listed under 9. Using this right may however, mean that the User can not apply for a specific job or otherwise use the Service.
Storage and transfers
The personal data collected through the Service is stored and processed inside the EU/EEA, or such third country that is considered by the European Commission to have an adequate level of protection, or processed by such suppliers that have entered into such binding agreements that fully complies with the lawfulness of third country transfers or to other supplies where adequate safeguards are in place to protect the rights of the data subjects whose data is transferred. To obtain documentation regarding such adequate safeguards, contact us using the Contact details listed in 9.
How long the personal data will be processed
If a User does not object, in writing, to the processing of their personal data, the personal data will be stored and processed by us as long as we deem it necessary with regards to the purposes stated above. Note that an applicant (User) may be interesting for future recruitment and for this purpose we may store Users’ Personal Data until they are no longer of value as potential recruitments. If you as a User wish not to have your Personal Data processed for this purpose (future recruitment) please contact us using the contact details in paragraph 9.
3. Users’ rights
Users have the right to request information about the personal data that is processed by us, by notifying in writing, us using the contact details below under paragraph 9 below. Users have the right to one (1) copy of the processed personal data which belongs to them without any charge. For further demanded copies, Controller has a right to charge a reasonable fee on the basis of the administrative costs for such demand.
Users have the right to, if necessary, rectification of inaccurate personal data concerning that User, via a written request, using the contact details in paragraph 9 below.
The User has the right to demand deletion or restriction of processing, and the right to object to processing based on legitimate interest under certain circumstances.
The User has the right to revoke any consent to processing that has been given by the User to Controller. Using this right may however, mean that the User can not apply for a specific job or otherwise use the Service.
The User has under certain circumstances a right to data portability, which means a right to get the personal data and transfer these to another controller as long as this does not negatively affect the rights and freedoms of others.
User has the right to lodge a complaint to the supervisory authority regarding the processing of personal data relating to him or her, if the User considers that the processing of personal data infringes the legal framework of privacy law.
4. Security
We prioritise the personal integrity and therefore works actively so that the personal data of the Users are processed with utmost care. We take the measures that can be reasonably expected to the make sure that the personal data of Users and others are processed safely and in accordance to this Privacy Policy and the GDPR-regulation.
However, transfers of information over the internet and mobile networks can never occur without any risk, so all transfers are made on the own risk of the person transferring the data. It is important that Users also take responsibility to ensure that their data is protected. It is the responsibility of the User that their login information is kept secret.
5. Transfer of personal data to third party
We will not sell or otherwise transfer Users’ personal data to third parties.
We may transfer Users’ Personal Data to;
- our contractors and sub-contractors, acting as our Processors and Sub-Processors in accordance with our instructions, for the provision of the Service;
- authorities or legal advisors in case criminal or improper behaviour is suspected; and
- authorities, legal advisors or other actors, if required by us according to law or authority’s injunction.
We will only transfer Users’ personal data to third parties that we have confidence in. We carefully choose partners to ensure that the User’s personal data is processed in accordance to current privacy legislations. We cooperate with the following categories of processors of personal data; Teamtailor, who supplies the Service, server and hosting companies, e-mail reference companies, video processing companies, information-sourcing companies, analytical service companies and other companies with regards to suppling the Service.
6. Aggregated data (non-identifiable personal data)
We may share aggregated data to third parties. The aggregated data has in such instances been compiled from information that has been collected through the Service and can, for example, consist of statistics of internet traffic or the geological location for the use of the Service. The aggregated data does not contain any information that can be used to identify individual persons and is thus not personal data.
7. Cookies
When Users use the Service, information about the usage may be stored as cookies. Cookies are passive text files that are stored in the internet browser on the User’s device, such as computer, mobile phone or tablet, when using the Service. We use cookies to improve the User’s usage of the Service and to gather information about, for example, statistics about the usage of the Service. This is done to secure, maintain and improve the Service. The information that is collected through the cookies can in some instances be personal data and is, in such instances, regulated by our Cookie Policy.
Users can at any time disable the use of cookies by changing the local settings in their devices. Disabling of cookies can affect the experience of the Service, for example disabling some functions in the Service.
8. Changes
We have the right to, at any time, make changes or additions to the Privacy Policy. The latest version of the Privacy Policy will always be available through the Service. A new version is considered communicated to the Users when the User has either received an email informing the User of the new version (using the e-mail stated by the User in connection to the use of the Service) or when the User is otherwise informed of the new Privacy Policy.
9. Contact
For questions, further information about our handling of personal data or for contact with us in other matters, please email us at people@sbha.org.uk, or write to us at SBHA, South Bridge House, Whinfield Road, Selkirk, TD7 5DT.
PRIVACY NOTICE
This document outlines SBHA’s duties in controlling and processing data, and how this data will be managed. SBHA’s data protection responsibilities are laid out in the General Data Protection Regulation (EU) 2016/679 (the GDPR), the Data Protection Act 2018 and other associated legislation, regulations, regulatory guidance, and good practice.
What we need
Scottish Borders Housing Association (SBHA) will be a "controller" of the personal information that you provide to us in completing SBHA’s Job Application Form, and any subsequent data provided to, or produced by, SBHA in the course of your employment with SBHA, unless otherwise stated in this privacy notice.
When you apply for a job with SBHA, and during the course of your employment, we will ask you for the following personal information:
- contact details – name, address, phone number, email address, National Insurance number, date of birth;
- details of past employment and qualifications – place of work/study, role/course description, dates, reference details;
- emergency contact details – their name, address and phone number for health and safety reasons;
- declarations of interest – as set out in SBHA’s Entitlement’s, Payments and Benefits Policy;
- equality information – age, marital status, gender, sexual orientation, ethnic origin, religion and belief, disability;
- criminal convictions – including a Disclosure Scotland check, and a full PVG where relevant for your role;
- health information– this may include a pre-employment health questionnaire, and any return to work sickness forms (with accompanying information where required, including letter/reports from medical professionals) completed in the course of your employment;
- evidence of your right to work in the UK – which could include a copy of a passport;
- evidence of your right to drive – copy of driving licence, vehicle registration, vehicle MOT details, vehicle ownership details, copy of vehicle insurance certificate;
- payroll details – bank account number, sort code, salary, pay slips;
- the date of birth of any children for whom you have taken parental leave; and
- other information that may result from your employment with SBHA – including sickness records, disciplinary records and personal development reviews.
Why we need your personal information – contractual purposes
We need to collect your personal information so that we can assess your application for, and administer any contract of, employment with SBHA. This may also involve confirming that the information provided in your application form is correct, and obtaining information from the references that you have provided which is relevant to your application.
We will also use your data to confirm your right to work in the UK, and, where relevant to your role, confirm your right to drive, including that your vehicle is properly insured and registered.
We will use your personal information to carry out SHBA’s obligations under your contract of
employment and ensure that you are also complying with your responsibilities under this contract.
If you do not provide us with all of the personal information that we need to collect, this may affect our ability to assess your application for employment with SBHA.
Why we need your personal information – legal obligations
We are under a legal obligation to process certain personal information relating to our employees for the purposes of complying with our obligations under:
- the Protection of Vulnerable Groups (Scotland) Act 2007 to check that our employees are able to undertake regulated work with children and vulnerable adults;
- the Equality Act 2010, which requires us to process personal information to make reasonable adjustments where necessary;
- the Housing (Scotland) Act 2010, which requires us to report certain statistical data on our employees to the Scottish Housing Regulator;
- the Statistics of Trade Act 1947 Act, which requires us to provide certain statistical data on our employees to the Office for National Statistics; and
- the Maternity and Parental Leave etc. Regulations 1999 (as amended by the Parental Leave (EU Directive) Regulations 2013) to ensure that entitlement to parental leave is tracked and passed on to any future employer(s) on request.
Why we need your personal information – legitimate purposes
We also process your personal information in pursuit of our legitimate interests to issue communications to you related to your job at SBHA, and keep you informed about SBHA in general.
Where we process your personal information in pursuit of our legitimate interests, you have the right to object to us using your personal information for the above purposes. If you wish to object to any of the above processing, please contact us by emailing us at people@sbha.org.uk, or writing to us at SBHA, South Bridge House, Whinfield Road, Selkirk, TD7 5DT.
If we agree and comply with your objection, this may affect our ability to undertake the tasks above for the benefit of your application and/or employment with SBHA.
Why we need your personal information – equality monitoring requirements
We use your personal information relating to your age, marital status, gender, sexual orientation, ethnic origin, religion and belief and disability to help us identify and keep under review the existence or absence of equality of opportunity or treatment between groups of people within the same categories to promote or maintain equality within SBHA.
Other uses of your personal information
We may ask you if we can process your personal information for additional purposes. Where we do so, we will provide you with an additional privacy notice with information on how we will use your information for these additional purposes.
Who we share your personal information with
We may be required to share personal information with statutory or regulatory authorities and organisations to comply with statutory obligations. Such organisations include the Health & Safety Executive, when we are required under the Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (RIDDOR), and HMRC for tax purposes. Depending on your role at SBHA, we may also be required to send your details to the Gas Safe Register in accordance with the Gas Safety (Installation and Use) Regulations 1998.
If you are completing an apprenticeship, we will also be required to share your personal details with your apprenticeship’s governing body for the purposes of registration with the relevant organisation.
We may also share your name (and work contact details) with third party training providers to allow you to access to training relevant to your role at SBHA.
We may also share personal information with our professional and legal advisors for the purposes of taking advice.
Depending on your role, some employees working for SBHA are required to have a basic Disclosure Scotland check carried out. Employees will be asked to provide their personal details directly to Disclosure Scotland and provide SBHA with the outcome of the check. In these circumstances, Disclosure Scotland will become the “controller” of your personal data. Disclosure Scotland is an agency of the Scottish Government, operating under the Police Act 1997 and the PVG Scheme Act 2007, and they have their own Data Protection and Privacy Statement.
For certain roles, a full PVG Scheme Membership (from Disclosure Scotland) is required (where relevant, this will be advertised in the job description). If this applies to you, you will be asked to complete the PVG application form. Once this information has been received by Disclosure Scotland, they will become the “controller” of your personal data. Disclosure Scotland is an agency of the Scottish Government, operating under the Police Act 1997 and the PVG Scheme Act 2007, and they have their own Data Protection and Privacy Statement.
SBHA employs third party suppliers to provide services for our employees, specifically in relation to payroll, pensions, life insurance and occupational health services. These suppliers may process personal information on our behalf as "processors" and are subject to written contractual conditions to only process that personal information under our instructions and protect it. In the case of SBHA’s pension provider, they will also act as the “controller” of your information once it is transferred to them.
In the event that we do share personal information with external third parties, we will only share such personal information strictly required for the specific purposes and take reasonable steps to ensure that recipients shall only process the disclosed personal information in accordance with those purposes.
How we protect your personal information
Your personal information is stored on our electronic filing system and our servers based in the UK and is accessed by our employees for the purposes set out above. Where hard copies of documentation are retained in line with SBHA’s data retention schedule, these will be stored securely at SBHA’s Head Office (or secure offsite storage).
We will not ordinarily transfer your data out with the EU. If this position changes and your personal information is proposed to be transferred out with the EU, we will provide you with information regarding the safeguards that we have put in place with the recipient country to protect your personal information.
How long we keep your personal information
We will only keep your personal information for as long as necessary to comply with our employment law obligations and to safeguard SBHA in the event of any claims, complaints, litigation, enquiries or investigations during or following the termination of your employment.
Unless you ask us not to, we will review and possibly delete your personal information 6 years after the cessation of your employment with SBHA. Where your job application has been unsuccessful, we will retain your personal information for 1 year after you have been notified of this.
Where you have taken parental leave during your employment with SBHA, a record of this will be kept until the relevant child’s 18th
birthday. This will only include your name, the child’s date of birth, and the dates of the parental leave taken.
We may keep certain personal information of employees for longer in order to confirm your identity and how long you were an employee of SBHA. We need to do this to in the event of a claim against SBHA.
We have a data retention schedule that sets out the periods for retaining and reviewing all information that we hold. This sets out different retention periods and you can request a copy by emailing us at people@sbha.org.uk, or writing to us at SBHA, South Bridge House, Whinfield Road, Selkirk, TD7 5DT.
Your rights
You can exercise any of the following rights by emailing us at people@sbha.org.uk,
or writing to us at SBHA, South Bridge House, Whinfield Road, Selkirk, TD7 5DT.
Your rights in relation to your personal information are:
- you have a right to request access to the personal information that we hold about you by making a "subject access request";
- if you believe that any of your personal information is inaccurate or incomplete, you have a right to request that we correct or complete your personal information;
- you have a right to request that we restrict the processing of your personal information for specific purposes; and
- if you wish us to delete your personal information, you may request that we do so.
Any requests received by SBHA will be considered under applicable data protection legislation. If you remain dissatisfied, you have a right to raise a complaint with the Information Commissioner's Office at www.ico.org.uk