Skip to main content

Processing of (personal) data by the entity in charge of the online application process

1.Statement of Policy

At Nordic Innovators, we prioritise the protection of your personal data and your privacy. This Privacy Policy outlines how we collect, process, store, and protect your personal data in connection with our recruitment and hiring processes. It also explains your rights under Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation or “GDPR”). 
We are committed to processing your personal data lawfully, fairly, and transparently, ensuring your information is secure and used only for legitimate purposes. 
 

2.Personal Data We Collect

In the context of recruitment, we may collect the following types of personal data directly from you or third parties: 
1. Identification and Contact Data 
  • Name, email address, phone number, and postal address.
  • LinkedIn profile or other professional social media accounts.
2. Professional and Employment Data 
  • Curriculum Vitae (CV), cover letters, and details of your education, qualifications, skills, and experience.
  • Employment history, references, and other information you provide during the recruitment process.
3. Assessment and Evaluation Data 
  • Notes taken during interviews or meetings.
  • Results from tests, assessments, or practical exercises.
4. Sensitive Personal Data (Special Categories of Data) 
We may process certain sensitive personal data, such as: 
  • Health-related information (e.g., if reasonable accommodations are required).
  • Information regarding diversity and inclusion, such as disability status, gender, or ethnicity (processed only if required by law or provided voluntarily by you).
5. Background Check Data (if applicable) 
Where relevant and permitted by law, we may collect information from background checks, such as criminal records or financial checks. 
 
6. Communications 
Any correspondence you have with us, such as emails or notes from calls and interviews. 
 

3.How We Collect Your Personal Data 

We collect your personal data in the following ways: 

1. Directly From You 
  • When you submit an application via our careers page, email, or recruitment platforms.
2. From Third Parties 
  • Recruitment agencies or headhunters acting on your behalf.
  • References you provide.
  • Publicly available sources, such as LinkedIn or professional profiles, to verify or complement information you have shared.

4.Purpose of Processing Your Personal Data

Your personal data is collected and processed solely for the purposes of recruitment, including: 
  • Evaluating your qualifications, skills, and suitability for the role you have applied for.
  • Communicating with you about your application, interviews, and recruitment status.
  • Verifying information provided, including contacting references with your consent.
  • Performing pre-employment background checks (where permitted by law and relevant to the role).
  • Retaining your data for future job opportunities if you provide consent or if permitted by local regulations.
  • Complying with legal or regulatory obligations, such as anti-discrimination and equal opportunity laws.
 

5.Legal Basis for Processing 

We process your personal data under the following lawful bases: 

1. Consent: When you voluntarily provide your application and personal data. 
2. Legitimate Interests: To evaluate and select qualified candidates for employment opportunities while balancing your data protection rights. 
3. Legal Obligations: To comply with employment laws, such as diversity monitoring and reporting. 
4. Contractual Obligations: To take necessary steps prior to entering into an employment contract with you. 
 

6.Data Sharing 

We may share your personal data with: 

1. Internal Personnel: Employees or departments directly involved in the recruitment process, such as HR and hiring managers. 
2. Third-Party Service Providers: 
  • Recruitment platforms or job portals.
  • Background check providers, where applicable.
  • IT and data hosting service providers who securely process or store your data on our behalf.
3. Legal Authorities: When required by law, such as in response to legal obligations or proceedings. All third parties are bound by confidentiality and data processing agreements to ensure your personal data is protected and processed in accordance with GDPR. 
 

7.International Data Transfers 

If your personal data is transferred outside the European Economic Area (EEA) to a country that does not offer the same level of data protection as the GDPR, we will implement safeguards to ensure your data is adequately protected. These measures may include: 
  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Relying on adequacy decisions for countries deemed to provide adequate protection.
 

8. Data Retention 

We will retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including: 
  • For unsuccessful candidates, we will retain your data to consider you for future job opportunities, unless you request erasure.
  • For successful candidates, your data will be retained as part of your employment record and processed according to our Employee Privacy Policy. 
 

9. Your Rights as a Data Subject 

Under GDPR, you have the following rights concerning your personal data: 
  1. Right to Access: Request access to the personal data we hold about you.
  2. Right to Rectification: Request correction of inaccurate or incomplete data.
  3. Right to Erasure: Request deletion of your data, subject to legal obligations.
  4. Right to Restrict Processing: Request limited processing of your data under certain circumstances.
  5. Right to Object: Object to processing based on legitimate interests.
  6. Right to Data Portability: Request transfer of your data to you or a third party in a structured, commonly used format.
  7. Right to Withdraw Consent: If processing is based on consent, you may withdraw your consent at any time.
To exercise these rights, please contact us.
You also have the right to lodge a complaint with the Data Protection Authority in your country if you believe your rights have been violated. 
 

10. Security Measures 

We take appropriate technical and organisational measures to protect your personal data, including: 
  • Encryption of sensitive data during storage and transfer.
  • Access controls to limit access to personal data to authorised personnel.
  • Regular training for employees on data protection practices.
  • Regular audits and testing of our security measures.
 

11. Updates to Privacy Policy 

We may update this Privacy Policy to reflect changes in our processing practices or regulatory obligations. Changes will be posted on our careers page with the updated effective date. 
 

12. Further Guidance 

If you have any questions or concerns about this Privacy Policy or the processing of your personal data, please contact us.

You may also contact the Data Protection Authority in your jurisdiction if you have concerns about how your personal data is handled. 
 
This expanded Privacy Policy reflects Nordic Innovators’ commitment to transparency, fairness, and accountability in handling your personal data. 

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.