Privacy Policy
Privacy notices concerning the collection and processing of your personal data within the scope of application processes within the BESTSECRET Group
(Last revised: 12/2024)
The following information is intended to provide you an overview of the collection and processing of your personal data within the scope of application processes within the BESTSECRET Group. Which of your personal data we process, and for what purpose this is done, depends on the scope of the respective application process.
DATA PROCESSING WITHIN THE BEST SECRET GROUP
General information
As part of our business activities, it is essential for data to be exchanged between branch locations and divisions on a regular basis in order to promote and facilitate cooperation within the Group. For this reason, central processes are not limited to a single Group company, but likewise include other Group companies. Companies within the BESTSECRET Group therefore work together in many areas and act as so-called joint controllers within the meaning of data protection law. A contract was concluded between the companies for this purpose.
Information about the primary contents of the contract in the case of joint controller authority within the BESTSECRET Group
In light of their joint role, the member companies of the BESTSECRET Group have concluded a contract as joint controllers within the meaning of Art. 26 in conjunction with Art. 4(7) GDPR in order to guarantee the security of processing and the effective exercise of your rights.
Without limitation, this contract addresses the following points:a) Subject, purpose, means and scope as well as competences and responsibilitieswith regard to data processingb) Informing data subjectsc) Fulfilment of the other rights of the data subjectsd) Security of processinge) Involvement of contract data processorsf) Procedure in the event of personal data breachesg) Other joint and reciprocal obligationsh) Cooperation with supervisory authoritiesi) Liability
Which of your personal data will we use as part of the application process?
We process your personal data to conduct the application process to the extent necessary.
This includes the following categories of data:
- Job applications with personal data, contact details, qualification data, activities etc.
- References and certificates with address data, performance data, evaluation data, etc.
- Work-related data that has been made publicly available, such as profiles on professional social media networks
Where does this data come from?
We process data that we receive directly from you or from publicly available media.
FOR WHAT PURPOSES AND ON WHAT LEGAL BASIS DO WE PROCESS YOUR DATA?
a) Data processing for job application related purposes (Art. 6(1)(b) GDPR and section 26 (1) of the German Data Protection Act (BDSG)
Personal data of applicants may be processed within the scope of the application process to the extent necessary to make a decision concerning the establishment of an employment relationship. In the event that an employment relationship is established between us, we may process the personal data already received from you for the purposes of the employment relationship, if this is necessary for the execution or termination of the employment relationship or for the exercise or fulfilment of the rights and obligations of the representation of the interests of the employee resulting from a law or a collective agreement, a company or service agreement (collective agreement).
The following processing activities are necessary to conduct the application process:
- Applicant intake
- Review of application related documents by the personnel department and the respective operational department
- Contact by email, telephone call and/or SMS
It may be necessary to share the data referred to above within the BESTSECRET Group in order to conduct the application process. In particular, this is relevant for conducting the application process in optimal fashion as well as recruiting and allocating positions within the Group.
b) Based on your consent (Art. 6(1)(a) GDPR and section 26 (2) BDSG (Germany))
You may provide the following forms of consents as part of the application process:
- Retention of application related documents for consideration in a later application process within the corporate group (talent pool).
If you have given your consent to the collection, processing, or transmission of certain personal data for possible use in subsequent application procedures, this consent comprises the legal basis for the processing of your data to the extent necessary to achieve the purpose.
You can withdraw your consent at any time. This also applies to consents given to us before 25/5/2018. However, such a revocation does not affect the lawfulness of processing carried out before you have withdrawn your consent.
WHO WILL RECEIVE MY DATA?
In order to conduct the application process and to fulfil legal obligations, various public bodies or internal departments, as well as external service providers, will receive access to your personal data.
a) Within the BESTSECRET Group:
The following companies within the BESTSECRET Group may have access to your data for internal administrative purposes:
-Best Secret Group SEMargaretha-Ley-Ring 27D-85609 AschheimHolding functions (e.g. Legal Department), company management
-Best Secret GmbHMargaretha-Ley-Ring 27D-85609 AschheimHR department, operational department for the vacancy to be filled, company management
-Best Secret Logistik GmbHParsdorfer Str. 13D-85586 PoingOperational department for the vacancy to be filled, employees responsible for personnel related matters, company management
-Best Secret Retail Wien GmbHBerggasse 16AT-1090 ViennaOperational department for the vacancy to be filled, employees responsible for personnel related matters, company management
-Best Secret Hellas S.M. S.A.131 DodonisGR-45221 IoanninaOperational department for the vacancy to be filled, employees responsible for personnel related matters, company management
-Best Secret Poland Sp. z.o.o.ul. Stefana Banacha 2PL-66-100 K KrężołyOperational department for the vacancy to be filled, employees responsible for personnel related matters, company management
-Best Secret s.r.l. a socio unicoVia Generale Gustavo Fara 26IT-20104 MilanoOperational department for the vacancy to be filled, employees responsible for personnel related matters, company management
Your data may also be shared within the BESTSECRET Group if you consent to the retention of application related documents in order to be considered in later application processes.
b) External service providers:
- Provider of a web-based applicant management system
- IT service providers (e.g. maintenance service providers, hosting service providers)
- Service provider for file and data destruction
- Recruiters
If you have any questions about a specific recipient, please contact us at: TalentAcquisition@bestsecret.com.
Will my data be transferred to countries outside the European Union (so-called third countries)?
No, BESTSECRET only processes data in the EU or the European Economic Area (EEA).
How long will my data be retained?
We store your personal data for as long as it is necessary to make a decision concerning your application. If an employment relationship between you and us does not materialize, we may also further store data, insofar as this is necessary to defend against possible legal claims. As a rule, your data will be erased within 6 months of the end of the application process.
In cases in which an employment relationship is not established but you have consented to the continued retention of your data, we will store your data until the later of when you withdraw your consent or a maximum of six additional months. If you do not log in to the career portal again during this period, we reserve the right to contact you before the six months have expired in order to be able to inform you of the deletion. When you log in again, the period will be extended. If there are specific grounds, we may also store your data for a longer period of time for the purpose of defending against possible legal claims.
Do I have an obligation to provide my personal data?
Providing personal data is neither required by law nor by contract, nor are you obliged to provide personal data. However, providing personal data is necessary to conduct the application process, i.e. if you do not provide us personal data in connection with an application, we will not be able to conduct the application process.
Is automated decision making or profiling used?
Neither automated decision making nor profiling are used.
Collection of general data when visiting our jobsite
If you use the jobsite for information purposes only, i.e. if you do not register or otherwise provide us with information, we only collect the personal data which your browser transmits to our server. This data is technically necessary for us to display our website to you and to ensure stability and security (the legal basis is the provision of our service pursuant to Art. 6(1)(f) GDPR).
For technical reasons, this data is stored by default as so-called "log files".
Job applications via our career portal
You can use the career portal on our website to apply for vacant positions.
We use applicant management tool - SAP SuccessFactors- in connection with the operation of our career portal.
We have concluded a contract data processing agreement with SAP SuccessFactors in accordance with Art. 28 GDPR for the use of SAP.
This means that if are interested, you will be automatically redirected to our SuccessFactors website when you open one of our job advertisements.
Registration
Registration (user account) is first required if you would like to apply via our career portal. Personal data that must be provided is marked as mandatory in the respective registration form; any additional information is voluntary.
Your online application via our career portal is transferred directly from there to SuccessFactors via an encrypted connection and accordingly sent to the HR department and, of course, treated confidentially. Please note that unencrypted e-mails are in a lot of cases not protected from access during transmission. If you send us an application in the mail, the human resources department will collect and enter your data into the tool.
Cookies & other tracking technologies
Our jobsite uses tracking technologies such as cookies. Cookies are text files which are saved in the user's web browser or on the user's computer system by the user's web browser. If a user visits a website, a cookie may be stored on the user's operating system. This cookie contains a distinctive character string that enables unique identification of the browser when the website is accessed again.
You can find more details about the individual cookies in our cookie banner.
What rights do I have in connection with the processing of my data?
Each data subject has the right of access under Article 15 GDPR, the right to rectification under Article 16 GDPR, the right to erasure under Article 17 GDPR, the right to restriction of processing under Article 18 GDPR, the right of objection under Article 21 GDPR and the right to data portability under Article 20 GDPR. The restrictions according to sections 34 and 35 of the German Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG) or sections 44 and 45 of the Austrian Data Protection Act of 2018 (Datenschutzgesetz 2018 - DSG 2018), respectively, apply to the right of access and right of erasure.
In addition, there is a right to lodge a complaint with the competent supervisory authority (Article 77 GDPR in conjunction with section 19 BDSG under German law or section 7 DSG 2018, respectively).
You may withdraw your consent to our processing of your personal data at any time. This also applies to the withdrawal of any declaration of consent provided to us before the General Data Protection Regulation entered into force, i.e. before 25 May 2018. Please note that any such withdrawal only applies with future effect. Processing operations that are performed prior to such withdrawal are not affected.
What rights do I have in the case of data processing based on a legitimate or public interest?
Under Art. 21(1) GDPR, you have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you which is based on Art. 6(1)(e) (data processing in the public interest) or (f) (data processing based on a weighing of interests) GDPR; this also applies to profiling based on those provisions.
In the event of your objection, we will no longer process your personal data unless we can prove compelling grounds for processing that outweigh your interests, rights and freedoms, or such processing is for the purpose of establishing, exercising or defending legal claims.
Who is the controller?
The controller is the BESTSECRET Group (as referred to above) jointly. You may assert your rights either against the controller listed below, or directly against the Group company to which you have applied, if different:
Best Secret GmbHMargaretha-Ley-Ring 27D-85609 Aschheim
How do I contact the data protection officer?
You may contact our data protection officer at the controller listed below, or at the respective Group company to which you have applied, if different:
Data Protection OfficerBest Secret GmbHMargaretha-Ley-Ring 27D-85609 AschheimE-Mail: datenschutz@bestsecret.com