Information about data processing

V2 (022024)

prismat GmbH uses the onlyfy one service (by XING) to process job applications. This Privacy Policy will inform you about the processing of your data by the onlyfy one service and by prismat GmbH.

Shared responsibility

With regard to interaction within the company account of prismat GmbH, prismat GmbH and New Work SE have shared responsibility pursuant to Article 26 GDPR, as they jointly determine the purposes and means of processing pursuant to Article 4 (7) GDPR. The current version of the agreement on shared responsibility pursuant to Article 26 GDPR, which New Work SE concludes with companies that use onlyfy one, can be viewed here https://www.xing.com/terms/onlyfy-one to gain information on the key aspects of the agreement.

Data processing by New Work SE

onlyfy one is part of the extensive XING service operated by New Work SE, which pursues the aim of improving and simplifying users’ working lives with a variety of applications (onlyfy one, as well as the XING social and jobs network, kununu, etc.), and creates a more fulfilling working world of work for individuals while boosting the performance of companies. As part of the extensive XING service, onlyfy one is an online platform on which or through which talent and companies meet.

With regard to data processing for which New Work SE is solely responsible or is responsible within the scope of the shared responsibility with prismat GmbH, detailed information is available in the XING Privacy Policy at https://privacy.xing.com/en/privacy-policy. You will also find contact details for New Work SE, as well as for the New Work SE data protection officer there.

Job applications with onlyfy one

When submitting an application, you enter into a user relationship with New Work SE for the purpose of processing applications. In addition, you will receive support and New Work SE can present you with other opportunities in support of your career. A public profile will not be automatically created for you on the XING social and jobs network. The legal basis for New Work SE processing your data is, in particular, Article 6 (1)(b) GDPR (processing necessary for the performance of a contract).

Pausing your online application

You can pause the creation of your online application at any time and continue at a later point. Cookies are used for this purpose. The data you provide to create the user account, as well as any uploaded documents, are recorded in the company account of prismat GmbH in onlyfy one. The data remains recorded even if an application is paused and/or not completed. In this case, your application is flagged as incomplete and the data remains visible to prismat GmbH only.

Visibility of your data

The data you have provided as part of the online application can be read, edited, or updated in your candidate profile at any time.

Notes on the special functions of onlyfy one

Calendar function

If the calendar function is used, your data is processed during and for the purpose of setting appointments within the application process. The legal basis is Article 6 (1)(f) GDPR. The calendar function is provided by an IT service provider (Cronofy Ltd., United Kingdom). The United Kingdom is classified as a secure third country based on the adequacy decision of the European Commission. Further information on data protection at Cronofy is available here: https://www.cronofy.com/gdpr/ and https://docs.cronofy.com/policies/privacy-notice/

WhatsApp application

If you use the apply using WhatsApp function, your consent, which can be withdrawn at any time, forms the legal basis for communication (Article 6 (1)(a) GDPR). When applying via WhatsApp, all required applicant information is requested during a WhatsApp chat. The data is then sent directly to onlyfy one through a service provider, and is processed further there as part of and for the purpose of the normal application process.

The apply via WhatsApp function is provided by an IT service provider (PitchYou) that can gain access to your data for this purpose. More information is available here: https://www.pitchyou.de/en/pitchyou-gdpr. Candidate data from apply via WhatsApp are transferred to onlyfy one via an interface. Immediately after this transfer, candidate data are deleted from the apply via WhatsApp infrastructure in PitchYou. Further processing then takes place exclusively in onlyfy one.

Please note that you use your personal WhatsApp account for applications, and therefore we cannot rule out that messages will be transferred, to the USA in particular. WhatsApp data protection information, such as its processing or exercising of data protection rights with regard to WhatsApp is available here: https://www.whatsapp.com/legal/privacy-policy-eea.

Subject to your consent, your application will be sent from WhatsApp via the PitchYou infrastructure to onlyfy one. You have the right to withdraw your consent to this at any time. Either way, your application data will be deleted from the PitchYou infrastructure once transferred to onlyfy one, meaning that PitchYou will not process your data any further.

Applicability of the Swiss Federal Data Protection Act (FADP)

The FADP applies to circumstances which have an impact on Switzerland, even if said circumstances are initiated outside of Switzerland. Correspondingly, this privacy policy applies to information in line with the EU GDPR and the FADP. Here, EU GDPR terminology is used in favour of FADP terminology. However, FADP terminology is used if the FADP applies and the terminology differs from EU GDPR terminology in a given language. The About this site section on XING contains the name and address of our representative in Switzerland.

YOUR PERSONAL DATA IN THE APPLICATION PROCESS

Information about data protection

We are pleased you have chosen to apply at prismat GmbH. Transparent and trustworthy handling of your personal data is an important foundation for successful collaboration. We wish to inform you how we process your data and how you can exercise your rights according to the General Data Protection Regulation (GDPR). The information below offers an overview of the collection and processing of your personal data in connection with the application process. Please read this Data Protection Declaration carefully before submitting your application.

  1. General information
  2. Who is responsible for the data processing?

The controller as defined by Art. 4 (7) GDPR is:

prismat GmbH

Stockholmer Allee 30a-c

44269 Dortmund

Telefon: 0231 44665 0

E-Mail: datenschutz@prismat.de

www.prismat.de

  1. How can you contact the data protection officer?

For questions about data protection, please contact our data protection officer Jörg ter Beek by email datenschutz@prismat.de.

  1. What is personal data?

According to Art. 4 (1) GDPR, personal data is all data that refers to an identified or identifiable natural person.

  1. Which data is used?

The following data and data categories are processed within the application process:

  • Applicant master data (first name, last name, title, email address, telephone number, address, date of birth, citizenship)
  • Qualifications data (cover letter, personal statement, resume, previous experience, professional qualifications and skills)
  • Voluntary information, such as a photo, disability status or other information that you voluntarily share with us in your application or voluntarily upload
  • Additional questions depending on the respective position (e.g. driver’s license, citizenship)
  • Communication between you and us as well as comments and evaluations concerning you that are created during your application process
  • Other data / data categories, e.g. publicly accessible professional data such as profiles on professional social media networks like XING or LinkedIn.
  • Special categories of personal data: If you provide information in your application documents that falls into special categories of personal data as defined by Art. 9 (1) GDPR (e.g. information that implies your sexual orientation; information on your health; information that implies your ethnicity or religion), we will also process this data only within the legally permissible framework.
  1. For what purposes do we process your data and on what legal basis?
  2. Data processing for purposes of employment – Section 26 BDSG (German Data Protection Act)

Your personal data is used for purposes of selecting personnel to fill open positions, in other words for initiating a contract of employment. The necessity and the scope of data collection are determined according to the position to be filled, among other factors. More extensive data collection may be required if your desired position is associated with particularly confidential duties, entails significant responsibilities in the areas of human resources and/or finance, or requires certain physical and mental capabilities. The legal basis is Section 26 (1) German Data Protection Act (BDSG).

  1. Consent 6 (1) (a) and Art. 9 (2) (a) GDPR, Section 26 (2) BDSG

If you have declared to us your consent for processing specific personal data, this consent then forms the legal basis for processing of this data.

In the following cases, we process your personal data on the basis of your consent:

  • Inclusion in the candidate pool; in other words, we save your application documents after the current application process in order to consider you in subsequent application processes.
  • To be added by the company: Possibly other processing scenarios that are based on consent (e.g. forwarding of documents to other group companies / group-wide candidate pool, sending of feedback questionnaire). The data you have already provided in the application process will also be processed.

If we base data processing on your consent, you have the right to withdraw this consent at any time with future effect. Please inform us of this revocation by email to datenschutz@prismat.de. The legality of the processing of your data up to the time of revocation remains hereby unaffected.

  1. Data processing based on a legitimate interest 6 (1) (f) GDPR

In certain cases, we process your data to safeguard a legitimate interest of ours or of third parties. A legitimate interest applies, for example, if your data is required for the establishment, exercise or defense of legal claims in connection with the application process (e.g. claims according to the General Equal Treatment Act). In the event of a legal dispute, we have a legitimate interest in processing the data for evidential purposes.

  1. Feedback questionnaire

To optimize our application process and to improve as an employer, we offer you the opportunity to provide personal feedback. For this purpose, we will send (with prior consent) a feedback questionnaire to you at the specified email address. If you participate in the survey, our service provider Prescreen (see item 5 “With whom is your data shared?”) will collect the feedback, position title, location of the position, job category and type of employment for which you have applied. This information will then be shared with kununu GmbH and possibly other verified evaluation platforms and published there without inclusion of your name. Kununu cannot establish a relationship to your person. However, please note that other parties, such as your employer, may be able to identify you based on the information provided in the published feedback.

  1. With whom is your data shared?

Your data is primarily processed by our Human Resources department. In some cases, other internal and external parties also participate in processing the data.

Internal parties could be specialized areas or departments or the works council of our company.

Our external service provider is Prescreen International GmbH. Prescreen International GmbH, Mariahilfer Straße 17, 1060 Vienna (hereafter “Prescreen”), operates the e-recruiting system Prescreen under the domain *.jobbase.io (hereafter “jobbase.io”), where companies can post job ads as well as receive and manage applications.

As part of these activities, Prescreen processes personal data solely on behalf of and for the purposes of prismat GmbH and is therefore considered a processor according to Art. 4 (8) GDPR.

Jobbase.io is the central platform for our applicant tracking. When using our online form, your personal data is entered directly into jobbase.io. When an application is submitted by post or email, your data may also be transferred to the e-recruiting system.

  1. For how long is your data stored?
  • We store your personal data for as long as necessary for making the decision concerning your application. If you are not hired for the position in question, we may continue to store your data to the extent necessary for defending against possible legal claims. Your data will normally be deleted within six months after the end of the application process.
  • If you are not hired but you have granted us consent to save your data (“candidate pool”), we will store your data until revocation of your consent or for a maximum of three additional years. Where specifically justified, we may also store your data for a longer time period for the purpose of defending against possible legal claims.
  • If you retract your application before the end of the application process (in other words, if you delete your data and your account), the stored data will be restricted for the period of the continued application process and permanently deleted once six months have elapsed after the end of the application process.
  • If you are no longer using your candidate profile and have not granted consent for continued data storage in the candidate pool, the data will be deleted within six months after the end of the application process.
  • You can delete your candidate profile and your application documents, submit a deletion request or request a restriction of processing at any time.
  1. What rights do you have in connection with the processing of your data?
  • You can request information on whether we are storing personal data concerning you. Upon your request, we will inform you of what data is involved, the purposes for which the data is processed, who the data is shared with, for how long the data will be stored and what other rights you have in relation to this data.
  • You also have the right to rectification or erasure of your data. You can also request that we make all personal data that you have shared with us available to you, another person or a company of your choice in a structured, commonly used and machine-readable format.
  • You also have the right not to be subjected to a decision based solely on automated processing (including profiling) that produces legal effects concerning you. Within the context of the application process, we do not use any exclusively automated processes for making decisions.
  • You have the right to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you which is based on Art. 6 (1) (e) GDPR (data processing for reasons of public interest) or on Art. 6 (1) (f) GDPR (data processing for safeguarding of a legitimate interest), including profiling based on those provisions. If you lodge an objection, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms or for the establishment, exercise or defense of legal claims.
  • You also have the right to lodge a complaint with the competent supervisory authority.
  • To exercise your rights, you can contact us by email datenschutz@prismat.de. We will process your requests as quickly as possible according to the statutory requirements and inform you of the measures we have taken or will take.
  1. Are you obligated to provide your personal data?

The provision of personal data is required neither by law nor by contract, nor are you obligated to provide the personal data. However, the provision of personal data is required for conducting the application process. In other words: if you do not provide us with any personal data along with an application, we cannot conduct the application process.

  1. What happens if you interrupt your online application?

You can interrupt the creation of your online application at any time and continue it later. The platform utilizes technically necessary cookies for this purpose. Data is transmitted to jobbase.io during the application process. In other words: data you have provided for creation of a user account and any uploaded documents are entered into jobbase.io. The data remains here if you interrupt and/or do not conclude an application. In this case, your application is marked as incomplete, but the data remains visible to our company, to a limited extent.

You can view, edit or update the data you have provided within the context of the online application at any time in your candidate profile.

 

If you make no further changes in your candidate profile, such as concluding an ongoing application, starting a new application or changing the data of an existing application, your data will be deleted within six months after completion of the last active application process.

You can submit a request for erasure of your candidate profile and your application documents at any time. After the request for erasure has been submitted, you will be informed of the exact erasure date, and your data will be automatically deleted according to the conditions established in this Data Protection Declaration.

  1. Supplement to the Data Protection Declaration by Prescreen

Prismat GmbH is not responsible for the data processing described below; the controller in this case is Prescreen:

Prescreen International GmbH

Mariahilfer Straße 17

A-1060 Vienna

If you have questions for Prescreen International GmbH concerning data protection law, please contact datenschutz@prescreen.io.

  1. Automated collection of usage data

When accessing the domain jobbase.io, your web browser automatically sends certain usage data for technical reasons. This information is stored separately from other data in log files. Prescreen collects the following information:

  • Date and time as well as duration of the access
  • Browser type/version
  • Operating system
  • URL of the previously visited web page
  • Quantity of data transmitted
  • A GeoIP lookup is performed based on your IP address (Internet Protocol address)
  • Names of the accessed files
  • http status code (e.g. “request successful”)
  • URL of the accessed web page
  • Access type (GET, POST)

This data is technically required in order to offer the functions of the e-recruiting system and to ensure the stability and security of the system. It is stored by Prescreen for a period of 12 months. Data that must be further retained for evidential purposes is excepted from the erasure until final clarification of the respective case.

The legal basis for processing of the data is Art. 6 (1) (f) GDPR.

  1. Cookies

Prescreen uses cookies. These serve for making the online application more user-friendly and efficient. The cookies are technically required in order to make this website available to you. It would not be possible to operate the website without using the cookies. There is therefore no option to refuse use of the cookies.

The legal basis for processing of the data is Art. 6 (1) (f) GDPR.

The following cookies are used by Prescreen:

Provider

Cookie

Purpose

Duration of storage

Prescreen

PHPSESSID

This cookie serves identify the user during the use of Prescreen. The cookie is absolutely necessary for correct functionality of the website. The cookie is valid only until closing of the browser.

Until the browser window is closed (session cookie).

Prescreen

REMEMBERME

This cookie serves to restore an expired session. The cookie is absolutely necessary for correct functionality of the website.

The cookie is valid for 2 weeks.