We are responsible for the processing of your personal data as described herein, as a data controller (as defined in the General Data Protection Regulation 2016/679, the “GDPR”). Please do not hesitate to reach out to us if you have any questions or comments on your privacy and our processing of your personal data. You can reach us by sending an email to firstname.lastname@example.org or contact us atExparang AB, Idunavägen 32, 181 61 Lidingö, Sweden
Personal Information that We Process
We collect information about you when you use the Platform or contact us. We receive and store this information when you enter it on our website, send it to us, or provide it to us in any other way.
Information collected from you
- Contact information like name, email address and phone number.
- Your job-preferences provided when you fill out your candidate profile. This includes preferences on salary, values, country of work, prior job experience.
- Resume, and all information included in it, such as your picture. Your resume will not be visible to potential employers using the Platform (“Employer”) unless you choose to share your full profile with the Employer. In that case the resume will be made available to that specific Employer, who may retain a copy of it. Once your resume has been disclosed to an Employer, they will act as a separate data controller. We strongly recommend that your resume does not contain sensitive data relating to your (i) racial or ethnic origin (ii) political beliefs (iii) philosophical or religious beliefs (iv) membership of a trade union or political party (v) physical or mental health or biometric details or genetic makeup (vi) addictions or sexual life (vii) the commission of criminal offences or proceedings and associated penalties or fines, (viii) the commission of any unlawful or objectionable conduct and associated penalties, or any Social Security Number or national identification number.
- Information imported by you from third party sources, e.g. LinkedIn.
- Communications data, i.e. conversations on the platform when you are in contact with us or the Employer.
- Information provided in the free-text fields in the Platform.
- Referrals. We may collect personal information about others from you. For instance, if you share your friend's name and email address for us to contact. We will automatically send your friend a one-time email inviting him or her to visit the site. We temporarily store this information for the sole purpose of sending this one-time email. Therefore, it is your responsibility to ensure that the person is aware and have consented to that you have forwarded his/her details.
- Special categories of personal data (“sensitive data”), if you have provided us with such information.
Please note that you can correct or remove the above information by accessing your account settings.
Information automatically collected about you when you use the Platform
- Matching opportunities you view and respond to.
- Technical data. We will collect technical data from mobile device in connection with your use of the Platform, such as IP address, browser type and version, screen resolution, preferred language, operating system and computer platform. Technical data may also include information about how you use the Platform, and if you encounter any technical errors. Even though we do not normally use technical data to identify individuals, sometimes individuals can be recognized from it.
- User activity logs. We save information about your activity in the Platform in order to analyze users’ use of the Platform for improving the Platform, but also to enable user support.
How We Use Your Personal Information and Legal Grounds
We process your personal data for the following purposes and based on the following legal grounds:
- To register your account. We will process your personal data (email-address) to register your account. This is necessary to enter into a contractual relationship with you regarding the Platform and to pursue our legitimate interests, such as our interest in simplifying the registration process for our users and administering the contractual relationship.
To create matching opportunities (i.e. automated decision-making).
The personal data we collect and hold about you will be used in order for us to provide you with matching opportunities with potential employers, based on information you have provided, and information Employers have provided in the Platform.
The matching opportunities is created through an algorithm built on machine learning, that learns from the personal data we hold about our users including preferences and choices surrounding which matching opportunities is reviewed and declined or accepted.
As a consequence of this automated decision making, a matching opportunity is either created or not.
Please note, that we only process your personal data in relation to the purposes stated herein and therefore will not use it in any manner incompatible with these purposes.
- For marketing of our Platform and other services. Your contact information will be used to send newsletters or other information regarding the Platform, e.g. updates of the Platform and Exparang AB to you. This processing is based on our legitimate interest of being able to market the Platform and Exparang AB to our existing users. Feel free to set or turn off notifications in your account settings, or you can follow the unsubscribe instructions contained in the email received from us.
- To conduct user surveys. Your contact information may be used to conduct user surveys. By continuously collecting qualitative feedback from you and other users, we can gain a deeper understanding of our users’ problems and needs. This processing is necessary to pursue legitimate interests, such as our interest in developing and improving the Platform. Participation in user surveys is optional.
- To develop and improve the Platform. We use technical data, survey data, and other aggregated and non-personal information to develop and improve the Platform, including troubleshooting, data analysis, research, statistical purposes and testing (such as beta testing and evaluation of new features, in line with the fundamental nature of the Platform). For example, we may collect and evaluate technical data about your use of the Platform for analytical purposes, to understand how people use the Platform in order to make it more intuitive. This processing is partly necessary to provide the Platform to you but mainly to pursue legitimate interests, such as our interest in developing and improving the Platform and its features.
- To fulfil our legal obligations. We are obligated to follow applicable laws. This means that your personal data is processed, including transferred and retained, to the extent necessary for us to uphold our obligations under applicable laws or other legal obligations, e.g. bookkeeping and reporting to the authorities.
- To protect our legitimate business interests and defend us against or enforce legal claims. Your personal information will be used where we believe it is necessary to protect ours, yours or others legal rights, or other legitimate interests. Processing for this purpose can become necessary to defend us against or enforce legal claims or to detect, investigate and prevent activities that may violate our policies or be illegal. The legal ground for this processing is our legitimate interest to protect us, you and others and for us to defend against or enforce legal claims or misconduct in the Platform.
- In connection with a merger or acquisition. In connection with, due to strategical or business-oriented reasons, a potential merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company, the personal data we retain about you may be processed, shared or transferred, to parties involved in the process. This processing is based on our legitimate interest of being able to develop our business.
- Sensitive data you have provided to us. If your resume or other information you have provided us with contains special categories of personal data, you consent to us processing it for the purpose of providing you with the Platform.
How and to Whom We Share Personal Information
Please note, that a Professional’s name, e-mail, profile picture, gender identity or age will never be shown to an Employer unless the Professional explicitly agrees to reveal its full profile to that Employer. We provide you with a platform to broadcast information about yourself to maximize your career opportunities. The information we gather will be shared with the following categories of third parties:
- Employers will never be able to see any of your personal information exposing your real identity before you have responded to an opportunity presented to you.
- By default, you will only share the information gathered in your anonymous profile, enabling you to be matched but disabling Employers to draw conclusions on who you are.
- When registering a profile, you will see clearly marked what data is going to be shown for Employers and what data is only shown for Exparang AB for the purpose of creating matching opportunities
Our service providers.
We transfer to or share your personal data with our suppliers and subcontractors who help us provide the Platform to you or supply other services to us which require the processing of personal data.
We provide personal data to service providers solely for the purpose of delivering the Platform and to manage our daily operations. Our suppliers and subcontractors are not authorized by us to use or disclose your personal data except as necessary to perform services on our behalf or to comply with legal requirements.
- Merger, acquisition or other business transfer. We may share or transfer your personal data in connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
- Other third parties, when you give your consent to such sharing, for example personality assessment companies.
Where We Process Your Personal Information
We always strive to process and store your data within the EU/EEA.
However, your data may in certain situations be transferred to, and stored at, a destination outside of the EU/EEA territory.
Please note that privacy laws in countries outside of the EU/EEA may not be the same as, and in some cases may be less protective than, privacy laws in your country. However, we always select our service providers carefully and take all the necessary steps to ensure that your personal data is processed with adequate safeguards in place in accordance with the GDPR. These safeguards are either that we sign the EU Commission Standard Contractual Clauses or ensure that the service provider is located in a country which the EU Commission has deemed as having adequate privacy protection including, if the company is located in the United States, abides by the Privacy Shield.
You can always contact us for information about the applicable safeguards.
Storage of Your Personal Information
We keep your personal data only as long as necessary to fulfil the purposes for which it was collected.
How long depends on the type of information and why we process it. We regularly review our need to keep data, taking applicable legislation into account.
Because achieving professional flow and actively managing your career is a lifelong process, we retain all the information we gather about you in an effort to make repeat use of our Platform more efficient, practical and relevant until you change or remove your personal information as described below.
As a main rule we keep most of your personal data until you delete your account.
After you have deleted your account, we will provide you with an option where you can consent to our storage of your personal information for up to 12 months, for the purpose of enabling a smooth re-activation of your account. Please note that in this case the personal data will only be “resting” on our servers and not actively used for creating matching opportunities or any such action.
If you are located in the European Union and you do not sign in to your account or interact with our Platform for more than five years, your account will expire and be scheduled for removal from our site.
Personal data processed with your consent is kept until you withdraw your consent, or until the purpose is no longer valid.
- Right to access your data. You have the right to request a transcript of personal data processed by us, and additional information on how the data have been collected, processed, shared, etc. The first transcript may be requested free of charge. However, upon repeated and unreasonable requests we might charge you with an administrative fee.
- Right to transfer your data. You also have, under certain circumstances, the right to transfer your personal data to another controller.
Right to object.
You have right to object to processing based on legitimate interest.
This means we may no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests.
You can always contact us for more information on the balance test that has been made.
You may also object to your personal data being processed for direct marketing purposes.
- Right to rectification. You have the right to correct inaccurate or incomplete information about yourself.
- Right to erasure (‘right to be forgotten’). You have the right to request that we delete personal data about you, for example if the data is no longer necessary in relation to the purposes for which it was collected or otherwise processed, or if there is no legal basis for processing the data.
- Right to restriction. You are entitled to request that the processing of your personal data should be limited until inaccurate or incomplete information about you has been corrected, or until an objection from you have been handled.
- Right to withdraw your consent. You may at any time withdraw any consent you have given us. However, please note that it will not affect any processing that has already taken place.
- Right to complain. You have the right to lodge a complaint to the supervisory authority (as defined in the GDPR) in the country you live or work in, if you believe that we have not complied with our obligations regarding your personal data. For Swedish purposes, such authority is Datainspektionen.