General Information
We provide this privacy policy, which applies exclusively to data collected as part of the online application process, to inform you about how we handle your personal data collected during the application procedure.
Controller
The data controller under data protection law is:
Natsana GmbH
Mittelstr. 11–13
Phone: +49 (0)251-20319100
Registered in the Commercial Register
Registration Number: HRB 246277
Register Court: Local Court of Munich
Personal Data in the Application Process
Personal data refers to information about the personal or factual circumstances of a specific or identifiable natural person. This includes information such as your name, address, phone number, and date of birth, as well as details about your professional background that can be reasonably linked to your identity.
Information that cannot (directly or indirectly) be associated with your real identity is not considered personal data.
Legal Basis and Purposes for Processing Personal Data in Applications and the Application Procedure
If you apply to us electronically—via email or through our web form—we collect and process your personal data for the purpose of handling your application and carrying out pre-contractual measures.
By submitting an application via our recruiting site, you express your interest in becoming employed with us. You transmit personal data that we use and store exclusively for the purpose of your job search/application.
In particular, the following data is collected:
First and last name
Email address
Telephone number
You also have the opportunity to upload supporting documents such as a cover letter, resume, and references. These may contain additional personal data such as your date of birth, address, etc.
Only authorized HR staff and employees involved in the application process have access to your data.
The storage of personal data is generally limited to the purpose of filling the specific position for which you applied.
Your data will be retained for 90 days beyond the end of the application process. This is usually done to fulfill legal obligations or defend against potential claims based on legal regulations. After that, we are obligated to delete or anonymize your data. In that case, the data will only be available as so-called metadata with no direct personal reference for statistical evaluations (e.g., gender ratio among applicants, number of applications per period, etc.).
We also reserve the right to retain your data in our “Talent Pool” for several days after the end of the application process in order to identify other potentially interesting positions for you. This also applies to applications for training or internship positions. By accepting this privacy policy, you consent to this extended data retention and inclusion in our Talent Pool.
If you receive and accept an offer of employment from us, we will retain the personal data collected during the application process for at least the duration of your employment.
Data Disclosure to Third Parties
The data you submit during your application is transmitted via TLS encryption and stored in a database. This database is operated by Personio GmbH, which offers HR and applicant management software (https://www.personio.de/impressum/). In this context, Personio is our data processor under Article 28 of the GDPR.
The legal basis for processing is a data processing agreement between us, as the controller, and Personio.
Data Subject Rights
If we process your personal data as the controller, you, as the data subject, have specific rights depending on the legal basis and purpose of the processing. These include, in particular, the right of access (Art. 15 GDPR), the right to rectification (Art. 16 GDPR), the right to erasure (Art. 17 GDPR), the right to restriction of processing (Art. 18 GDPR), the right to data portability (Art. 20 GDPR), and the right to object (Art. 21 GDPR).
If the processing of personal data is based on your consent, you have the right to withdraw this consent at any time in accordance with Art. 7(3) GDPR.
To exercise your data subject rights regarding the data processed in this online application procedure, please contact our data protection officer (see Section 2).
Final Provisions
We reserve the right to update this privacy policy at any time to ensure it complies with current legal requirements or to reflect changes in the application process or similar. The updated privacy policy will apply to any subsequent visit to this recruiting site or application.
Processing of (personal) data by the operator of the recruitment website
General information
This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (
https://www.personio.com/legal-notice/).
Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio.
In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.
The controller
The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact:
privacy@personio.com
Access logs (“server logs”)
Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual.
Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG.
Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web.
These access logs are stored for a period of up to 7 days. There is no right to object to this.
Error logs
So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG.
When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected.
These error logs are stored for a period of up to 7 days. There is no right to object to this.
Use of cookies
So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”).
On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR).
Period of storage: up to 1 month or until the end of the browser session
Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.
Rights of data subjects
If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR.
To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).
Concluding provisions
Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.