Last updated: 07/05/2020
The QFinds application (the "App") and the QFinds platform (the "Platform") accessible from our website at qfinds.io and our related websites, services, applications, products and Content (the "Services") are offered to employers who are looking for potential candidates for jobs and candidates looking for employment. The Services are operated by QFinds Ltd ("QFinds", "us", "we", or "our"). In order to provide the Services to you and to promote our business, we will need to collect and process certain personal information about you.
W1W 7LT We are committed to protecting the privacy and security of your personal information, in accordance with the applicable data protection laws, including, but not limited to, the Data Protection Act 2018 and the General Data Protection Regulation ("GDPR"), together the “Data Protection Laws”.
QFinds is the data controller and is responsible for your personal data.
We have appointed a data protection officer (“DPO”) who is responsible for overseeing questions in relation to this privacy notice. If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact the DPO using the details set out below.
85 Great Portland Street
W1W 7LTEmail address: email@example.com
The Data We Collect About You
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data: your first name, last name, gender, year of birth, age and location, and information you disclose in your user profile and your photograph or video CV;
- Contact Data: your mobile number, home address and email address;
- Profile Data: your username and password, your interests, preferences, feedback, survey responses and research responses, the comments and contributions you may make on the Services and additional information you may provide as you submit queries and requests to us;
- User Content Data: we process the content you generate on the App or Platform, including preferences you set, photographs and videos you upload, comments you make, and your messages or communications with employers within the App or Platform);
- Usage Data: information about how you use our Services;
- Marketing and Communications Data: includes your preferences in receiving marketing from us and your communication preferences;
- Special Categories of Personal Data: this category includes information relating to someone’s health, beliefs, ethnicity, political affiliation or trade union membership, sex life or sexual orientation. We do not actively collect this type of information from candidates, but it may be included in some of the information we receive (for example, your CV video or your profile information). It may also be possible to derive sensitive personal data from other information you provide. We only collect and use sensitive personal data with your explicit consent or where you have made this information public (e.g. by uploading it and sharing it publicly);
- Technical Information: including type of mobile device you use, a unique device identifier, mobile network information, your login information, browser type and version you use, browser plug-in types and versions, operating system and platform; and
- Information about your visit to our Services: including the full uniform resource locators (URL) clickstream to, through and from our Services (including date and time); pages you viewed or information you searched for; page response times, download errors or length of visits to certain pages.
- Personal Data from Employers: We also collect personal data about individuals who work for employers and third parties. These people include individuals, employers and professional advisers (such as lawyers and accountants), service providers and suppliers.
The types of personal data we collect include basic personal details and contact information, such as job title, name, email, address, telephone and the person’s employer. We may receive this from the organisation itself, from third parties or through our dealings with the business (e.g. interactions on social media). We collect this information because it is necessary for us to fulfil our contract with employers and/or for us to pursue our legitimate interest in promoting and running our business (including by marketing the Services to employers) and building relationships with other organisations.
We also collect, use and share aggregated data such as statistical or demographic data for any purpose (“Aggregated Data”). Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your usage data to calculate the percentage of users accessing a specific feature of our Services or how many users have high success scores or low success scores. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.
The extent of the personal data you may be able to share with us will depend on the Services design and the features made available to you, as well as your level of participation in the Services. You are under no obligation to provide any personal data to us at any time. However, if you choose to withhold some personal data, we may be unable to provide you with the Services.
How is your personal data collected?
We use different methods to collect data from and about you including through:
- Direct interactions. You may give us your personal data by filling in online forms, answering questions or by corresponding with us by email or otherwise. This includes personal data you provide when you:
- apply to use our Services or apply to find out more information about our Services;
- create an account to use our Services;
- subscribe to our Services;
- upload content to our Services;
- request marketing to be sent to you;
- enter a competition, promotion or survey;
- take part in our research;
- subscribe for our newsletter; or
- give us some feedback.
- Third parties or publicly available sources. We may receive personal data about you from various third parties such as Technical Data from analytics providers such as Google based outside the EU.
How we use your personal data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- where we need to perform the contract we are about to enter into or have entered into with you;
- where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests;
- where we need to comply with a legal or regulatory obligation;
- to identify you and manage your account in connection with the Services;
- to improve the Services;
- to provide you with support in using our Services;
- promote our business and market our Services;
- manage our business, including for accounting and auditing purposes;
- to use data analytics to improve the Services, marketing, customer relationships and experiences;
- maintain our IT systems and manage hosting of our data;
- deal with legal disputes involving you; and
- to prevent fraud.
Some of the above grounds and purposes for processing will overlap and there may be several grounds which justify our use of your personal information.
We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Information we share with Employers
Lawful Bases for Processing under the GDPR
- Consent: the individual has given clear consent for us to process their personal data for a specific purpose.
- Contract: the processing is necessary for a contract we have with the individual, or because they have asked you to take specific steps before entering into a contract.
- Legal obligation: the processing is necessary for us to comply with the law (not including contractual obligations).
- Legitimate interests: the processing is necessary for our legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.
When you register for an account or interact with our Services, such processing is necessary for the performance of our Services (Art. 6(1)(b) GDPR).
Where we process your location data without consent, for example in order to provide our Services, such processing is necessary for the performance of our Services (Art. 6(1)(b) GDPR).
When you communicate with us or sign up for promotional materials, we process such data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), and our legitimate interest is to provide you with our promotional messages. Where we are required under applicable local law to obtain your consent for sending you marketing information, the legal basis is your consent (Art. 6(1)(a) GDPR).
For all other personal data such processing is necessary for the performance of our Services (Art. 6(1)(b) GDPR or on the basis or our legitimate interests and our legitimate interest is to enhance our services (Art. 6(1)(f) GDPR).
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising.
Promotional offers from us
You will receive marketing communications from us if you have requested information from us or used our Services or if you provided us with your details when you entered a competition or registered for a promotion and, in each case, you have not opted out of receiving that marketing.
You can ask us to stop sending you marketing messages at any time by contacting us at any time. Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of using our Services.
Change of Purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Disclosures of Your Personal Data
We may share your personal data with the parties set out below:
- potential employers, if you are a candidate;
- candidates, if you are a potential employer;
- service providers acting as processors based in the UK who provide IT, hosting and system administration services;
- professional advisers acting as processors or joint controllers including lawyers, bankers, auditors and insurers based in the UK who provide consultancy, banking, legal, insurance and accounting services; and/or
- third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy notice.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
We may use aggregated information and statistics for monitoring usage of the Services in order to help us develop the Services.
These parties are not allowed to use any personally identifiable information except for the purpose of providing the Services.
We may occasionally send out newsletters, offers or alerts to our users. We may also wish to provide you with information about special features of our Services or any other service or products we think may be of interest to you.
Where required by Data Protection Laws (for example, if you have provided your email address in the opt-in for our newsletter option) we will send you such information only if you have specifically elected to receive it. You can opt-out from receiving such communications at any time – please see the “Your legal rights” section below.
From time to time the Services may request information from you via surveys and research questionnaires. Participation in these surveys or research is completely voluntary and you, therefore, have a choice whether or not to disclose this information. Information requested may include contact information (such as name and e-mail address) and demographic information (such as postcode or age range).
Survey information and research questionnaires will be used for purposes of monitoring or improving the use of and satisfaction with the Services.
Some of the services we use are provided by international organisations (such as Google) and/or companies based outside the EEA. Therefore, we may transfer your personal information to countries outside of the EEA.
Such countries do not have the same data protection laws as the UK and EEA. While the European Commission has not given a formal decision that such countries provide an adequate level of data protection similar to those which apply in the UK and EEA, any transfer of your personal information will be subject to appropriate or suitable relevant safeguards (as permitted under the GDPR) that are designed to help safeguard your privacy rights and give you remedies in the unlikely event of a misuse of your personal information.
The only other time we may transfer personal data outside of the EEA is if a legal derogation (i.e. an exception) or requirement under Data Protection Laws or other applicable laws allows or requires us to do so and, even then, we will only do so if the transfer is necessary, legally required or made with your explicit consent.
Keeping Your Data Secure
We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality.
While we will use all reasonable efforts to safeguard your personal data, you acknowledge that the use of the internet is not entirely secure and for this reason, we cannot guarantee the security or integrity of any personal data that is transferred via the internet. If you have any particular concerns about your information, please contact us at: firstname.lastname@example.org.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
In some circumstances, we may anonymise your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you. Once you are no longer a user of our Services, we will retain and securely destroy your personal information in accordance with applicable laws and regulations.
Your Legal Rights and Your Duty to Inform us of Changes
It is important that the personal information we hold about you is accurate and current. Please let us know if your personal information changes during your relationship with us.
Under certain circumstances, by law, you have the right to:
- Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a confirmation from us as to whether we process any of your personal information or not, and if this is the case, to receive a copy of such personal information and to check that we are lawfully processing it.
- Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Request erasure of your personal information (often referred to as “the right to be forgotten”). This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing (see below).
- Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground.
- Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example, if you want us to establish its accuracy or the reason for processing it, or if we no longer need your data for our legitimate interests but we need to hold some of it for the purpose of legal proceedings.
- Request the transfer of your personal information to another party.
If you would like to exercise any of the above rights, please:
- email us at: email@example.com;
- provide us with proof of your identity and address (a copy of your driving licence or passport and a recent utility or credit card bill). This is to allow us to verify your identity and prevent disclosure to unauthorised third parties; and
- let us know the details of your request, for example by specifying the personal data you want to access, the information that is incorrect and the information with which it should be replaced.
Please note that if you request erasure, object to our processing of your personal data or request the restriction of our processing of your personal data we may not be able to provide our Services and we may need to deactivate your account.
You also have the right to ask us not to process your personal data for marketing purposes. You can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your data. You can also exercise the right at any time by contacting us at: firstname.lastname@example.org. You can always unsubscribe from our email communications at any time by following the unsubscribe link in our email communications, or by updating your email preferences on your profile in our Services.
Contact Us or the ICO
If you have any concerns or complaints about our privacy activities, you can contact us at email@example.com.
You have the right to make a complaint at any time to the Information Commissioner's Office (“ICO”), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
For more details about your rights under the Data Protection Laws, the rules we have to adhere to in collecting and storing your information, and how you can check your data records, please visit https://www.gov.uk/data-protection/the-data-protection-act.Created May 2020