Privacy policy
In the following, we inform you about the processing of your personal data in the context of your application with us. In addition, we refer you to our data protection information for website visitors.
Personal data is all data that can be related to you personally, e.g. name, address, e-mail address and user behavior.
1. Controller
The controller pursuant to Art. 24 GDPR for the processing is:
Dermanostic GmbH
Merscheider Straße 1
42699 Solingen, GermanyYou can contact both parties at any time regarding your concerns using the contact details above or by email at datenschutz@dermanostic.com.
2. Contact details of the Data Protection Officer
You can contact the Data Protection Officer of the controller by email at datenschutzbeauftragter@dermanostic.com.
3. Your rights
You have the following rights with respect to your personal data:
-
Right of access and to receive a copy of your data
-
Right to rectification
-
Right to erasure and to be forgotten
-
Right to restriction of processing
-
Right to object to processing
-
Right to data portability
You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data by us.
-
4. Data processing for your application at dermanostic
To submit an application for a job opening, we accept applications by email at karriere@dermanostic.com or via the job portal Indeed (Indeed Ireland Operations Ltd.). Alternatively, we offer applicants the option to send their application by post to Dermanostic GmbH, HR Department, Merscheider Straße 1, 42699 Düsseldorf.
4.1. Purpose
We process your personal data in the context of a potential new employment.
4.2. Legal basis
The legal basis for processing is the implementation of pre-contractual measures in the form of the application process or the review of your speculative application pursuant to Art. 6(1)(b) GDPR, as well as the decision on the establishment of an employment relationship pursuant to Art. 88(1) GDPR in conjunction with § 26(1) BDSG. Processing is necessary to carry out pre-contractual measures regarding a potential employment relationship, which are carried out at your request as an applicant, i.e., your application for the advertised position or speculative application. Failure to provide the data required for an application will result in the applicant not being considered in the application process.
4.3. Storage period
Your application data will be stored in our application management system for six months after the conclusion of the respective application process. The legal basis for this is our legitimate interest in asserting, exercising, or defending legal claims pursuant to Art. 6(1)(f) GDPR. The storage period is derived from the requirements pursuant to § 61b(1) ArbGG in conjunction with § 15 AGG.
If you consent to a longer storage of your data, e.g., so that we can consider you for another position, we will store your data for two years. After two years, your data will be deleted, or your consent will be requested again.
If your application was submitted via an agency, we will store the data until the contract with the agency expires.
4.4. Recipients
Applications and the associated personal data are accessible to authorized employees of our company. This includes HR staff and those responsible for the job posting and its fulfillment.
For storing our applicant data and personnel files, we use a cloud system from Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA. We have set the data location to Germany for this service. Microsoft acts as our processor for this processing, and we have concluded a data processing agreement with Microsoft Corporation pursuant to Art. 28 GDPR. The legal basis for the transfer to a third country is standard contractual clauses pursuant to Art. 46 GDPR.
Microsoft provides adequate data protection guarantees, which can be viewed in the Online Services Data Protection Addendum.
Indeed.com acts as an independent controller. An application via the Indeed.com job portal is associated with the transfer of your data to the USA.
4.5. Right to object
If the processing of your application data is based on our legitimate interests pursuant to Art. 6(1)(f) GDPR, you may object to this processing. Please contact our Data Protection Officer at datenschutz@dermanostic.com.
4.6. Right to withdraw
If the processing is based on your consent pursuant to Art. 6(1)(a) GDPR, in this case to include you in our applicant pool, you may withdraw your consent at any time. Please contact our Data Protection Officer at datenschutz@dermanostic.com or our HR Department at karriere@dermanostic.com.
5. Your rights
As a data subject, you can contact our Data Protection Officer at any time with an informal message using the contact details listed in section 2 to exercise your rights under the GDPR. These rights include:
-
Right of access to data processing and a copy of processed data (Art. 15 GDPR)
-
Right to rectification of incorrect data or completion of incomplete data (Art. 16 GDPR)
-
Right to erasure of personal data and, if publicly disclosed, to request other controllers to delete it (Art. 17 GDPR)
-
Right to restriction of data processing (Art. 18 GDPR)
-
Right to receive personal data concerning you in a structured, commonly used, and machine-readable format, and to transmit it to another controller (Art. 20 GDPR)
-
Right to object to data processing (Art. 21 GDPR)
-
Right to withdraw your consent at any time for processing based on consent (Art. 7 GDPR)
-
Right to lodge a complaint with a supervisory authority if you believe data processing violates the GDPR (Art. 77 GDPR)
-