0% found this document useful (0 votes)
58 views9 pages

Data Protection and Privacy Statement IAC Job Applicants and Customers Final Updated Clean 26.10.18 PDF

This document outlines an organization's data protection and privacy statement regarding how personal data from job applicants and commercial customers is collected, used, stored, and protected. It states that personal data will only be processed with consent and for legitimate purposes related to recruitment, sales, marketing, or receiving/paying for products/services. The data collected may include information needed to assess job applications or respond to inquiries/requests. Strict security, access, and disclosure controls are used to protect personal data in compliance with GDPR regulations. Individuals have rights to access or delete their personal data.
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
58 views9 pages

Data Protection and Privacy Statement IAC Job Applicants and Customers Final Updated Clean 26.10.18 PDF

This document outlines an organization's data protection and privacy statement regarding how personal data from job applicants and commercial customers is collected, used, stored, and protected. It states that personal data will only be processed with consent and for legitimate purposes related to recruitment, sales, marketing, or receiving/paying for products/services. The data collected may include information needed to assess job applications or respond to inquiries/requests. Strict security, access, and disclosure controls are used to protect personal data in compliance with GDPR regulations. Individuals have rights to access or delete their personal data.
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 9

DATA PROTECTION AND PRIVACY STATEMENT

For

Job Applicants and Commercial Customers

CONTENTS
1.0 Statement Overview: ............................................................................................................................ 2
2.0 Purpose, Scope and Consent: ................................................................................................................ 2
3.0 Principles, Practice and Compliance: ..................................................................................................... 3
3.1 Our Data Collection…………………………………………………………………………………………………………………………………….3
3.1.1 Job Applicants ...................................................................................................................................... 3
3.1.2 Customers ............................................................................................................................. ……………..3
3.2 Personal Data Content………………………………………………………………………………………………………………………….…...4
3.3 Usage, Storage, Security and Disclosure Controls…………………………………………………………………………………..…..4
3.3.1 Job Applicants ...................................................................................................................................... 5
3.3.2 Customers ............................................................................................................................................ 5
3.4 How we use Cookie Technology…………………………………………………………………………………………………………….……5
3.5 Links to other sites………………………………………………………………………………………………………………………………….….6
3.6 Controlling your Personal Data…………………………………………………………………………………………………………………..7
3.6.1 Accessing, Accuracy and/or Deletion of Personal Data ....................................................................... 7
3.6.2 Data Usage, Objections and Decision Making ..................................................................................... 7
3.6.3 Transfer of Personal Data .................................................................................................................... 7
3.6.4 Complaints ........................................................................................................................................... 8
3.6.5 Breach of Personal Data ...................................................................................................................... 8
3.7 Future Reviews / Changes…………………………………………………………………………………………………………………..……..8
4.0 Further Information: ............................................................................................................................. 9

_________________________________________________________________________________________________________________
1 of 8| P a g e Registered Office: East Ramp, Shannon Airport, Co. Clare, Ireland, V14 K283.
1.0 Statement Overview:
International Aerospace Coatings Limited, EMEA Head Quarters (“HQ”) at East Ramp, Shannon Airport,
Co. Clare, Ireland, V14 K283 (company registration number: 480686) and its global subsidiaries (collectively the
“Company”, “we”, “our”, “us”) is fully committed as Data Controller, to protecting your “Personal Data”
(defined at Clause 3.2 below) and privacy, in full compliance with the General Data Protection Regulations Bill
2018 (GDPR). This Data Protection and Privacy Statement (“Statement”) sets out how we collect, use, disclose
and retain any Personal Data received and how individuals may co-operate with us about it
(“Process”/“Processed”/“Processing”); specifically provided by prospective employees (“Job Applicant(s)”),
commercial customers and suppliers and prospective commercial customers and suppliers (collectively
“Customers”), [collectively “you”, “your”]; when using the ‘Contact’ portal and/or ‘Careers’ page of our
website. Should we ask you to provide certain information by which you may be identified when using this
site, you can be assured that it will only be used in accordance with this Statement.

The intended use of your Personal Data is either purely for a) recruitment purposes, b) related to the sales
and marketing of our products and/or services and/or c) receiving and payment of products and/or services
from vendors (i.e. including sub-contractor companies); including as may be required in completing
professional services and/or products to us and/or our clients to mandatory quality and regulatory
standards; and should the aforementioned ever change this Statement will be updated accordingly.

This Statement is effective from 25th May 2018 and supersedes any/all other communications we may have
made to you on how we Process job applications/customers’ enquiries/requests to the Company.

2.0 Purpose, Scope and Consent:


2.1 Job Applicants: 2.2 Customers:
This Statement extends to the Processing of Job This statement also covers the Processing of
Applicants’ Personal Data which is required as part of Customers’ Personal Data in respect of any of our
our impartial and legally compliant recruitment and products and/or services for the purposes of
selection process; and Processed exclusively in providing a quotation, responding to enquiries,
determining your potential suitability for any job marketing, recommending, requesting, payment,
vacancies within the Company; and thereby help you to surveying any of our existing, modified or new
make an informed decision on whether you wish to services and/or products, administering your
disclose any such Personal Data to us. account, managing any current or future business
relationship. It is intended to assist you in making
You should note that failure to provide us with sufficient an informed decision(s) as to whether you wish to
information might result in our inability to complete our disclose any such Personal Data to us; so as to
initial assessment, progress further in any recruitment continue to deliver/enhance our products and
process(es) or form/manage any potential future services to your satisfaction or to enable you to
employment contract/relationship. provide us with information and/or
supply/continue to supply your products and/or
We will only Process your Personal Data if you have services to us.
given your consent. By reason of freely submitting your
Personal Data in accordance with this Statement The Personal Data provided for this purpose is
through this ‘Careers’ page of our website (i.e. by being requested on a legitimate interest basis and
proceeding with any job applications and/or you should note that failure to provide us with
enquiries/requests through the ‘Contact’ portal of our sufficient information may result in our inability to
website/email) your Personal Data is entered onto our complete your enquiry(ies)/request(s) or to
internal database; and you are authorising us to Process, form/manage any potential future business
solely for any/all of our recruitment and selection contract(s)/relationship(s).
activities; and communicate in this regard by email,
telephone and/or skype (or other similar service). By reason of freely submitting your Personal Data
in accordance with this Statement, through the
‘Contact’ portal of our website and/or by email,
market research/surveys, such information is
entered onto our searchable database and you are
thereby authorising us to Process any/all of your
requests/enquiries and communicate generally;

_________________________________________________________________________________________________________________
2 of 8| P a g e Registered Office: East Ramp, Shannon Airport, Co. Clare, Ireland, V14 K283.
We may also consider/contact you about other (i.e. by email and telephone), in relation to our
potentially suitable/relevant opportunities to your products and/or services that you have requested
experience/interests within the Company, other than or any of your products and/or services that we
role(s) you originally apply(ied) for (either of a similar or may wish to purchase from you).
different nature); and will seek your explicit consent to
do so by email, telephone and/or skype (or other similar Under the terms of GDPR 2018, please note that
service), through the ‘Careers’ page of our Company we will seek your explicit consent to use and/or
website; where you will have an opportunity to continue to use your Personal Data, as
subscribe, or remain opted in during any such contact. appropriate; specifically for marketing purposes
(i.e. by email and telephone), to make you aware
If you decide at the time of your job application(s) not to of any/all Company updates, events, promotions
be contacted in the aforementioned regard, you may and/or products and services that may be of
subsequently do so by letting us know separately at any interest to you.
stage by email, post or through the ‘Contact’ portal on
our website. Therefore, you may decide how much marketing
you wish to accept upon initial contact and at any
Where you have agreed you may unsubscribe or update stage throughout our business relationship; by
your preferences at any time; and we will include a link providing you always with the opportunity to
to our Update Preferences’ and ‘Contact’ pages in all our subscribe, remain ‘opted in’, ‘update preferences’,
information messages. We may also seek your explicit or ‘unsubscribe’ from receiving any of our periodic
consent to Process sensitive Personal Data should you direct Company marketing information. We will
progress further in our selection process (refer to include a link to our ‘Update Preferences’ and
section 3.2.1). ‘Contact’ pages in all our messages. This will not
affect the lawfulness of any Processing we have
In the event that your application results in an offer and conducted prior to the withdrawal of your
acceptance of offer of employment, your Personal Data consent.
will become part of your employment record for
employment purposes.

3.0 Principles, Practice and Compliance:


3.1 Our Data Collection
3.1.1 Job Applicants: 3.1.2 Customers:
We normally collect your Personal Data when you apply Customers’ Personal Data is obtained via the
directly for any individual jobs(s) via our ‘Careers’ page ‘Contact’ page on our website, email,
on our website. Interested candidates must use our telephone/voicemail, skype (or other similar
‘Careers’ page to complete a job application(s); including service), social media, referrals, MRO shows,
cover letter and curriculum vitae; which will be conventions, on-site Customer visits and formal
channelled directly through to our central Human business meetings (including via CCTV footage and
Resources Department. Personal Data, may also be GDPR compliant visitors’ signage manual); from
obtained separately via subsequent general email when initial requests or enquiries are made and
communications, telephone/voicemail, skype (or other subsequently processed by our sales, supply chain,
similar service), onsite visits (including via CCTV footage finance, quality and administration teams. Such
and GDPR compliant visitors’ signage manual), contact may be made directly or indirectly.
throughout our recruitment and selection process.

However, we also reserve the right to select and


contract with third party service providers for any
specific recruitment services to Process any such related
data on our behalf within appropriate security
measures. Your Personal Data received and accepted
from third party agencies will only be with prior
discussion and agreement of your potential suitability
for role(s); otherwise, we will delete immediately
without our viewing, until appropriate agreement has
been reached.

_________________________________________________________________________________________________________________
3 of 8| P a g e Registered Office: East Ramp, Shannon Airport, Co. Clare, Ireland, V14 K283.
3.2 Personal Data Content
Personal Data is defined by the General Data Protection Regulations (EU Regulation 2016/679) as ‘any
information relating to an identifiable person who can be directly or indirectly identified in particular by
reference to an identifier’. Such data attained by the Company may encompass both individual Job Applicant(s)
and Customers’ name, address, contact details [including telephone number, email address, skype ID (or ID
from other similar service), online professional profile address(es)], identification number, salary, job
title/occupation, relevant information relating to satisfaction surveys.

Onsite CCTV footage (i.e. containing sensitive biometric and geometric data) is recorded and retained in
accordance with GDPR compliance internal procedures; including where there is a legitimate basis and/or for
legal reasons including where EU or member state law prohibits reliance on consent.

3.2.1 Job Applicants: 3.2.2 Customers:


Other Personal Data may include Personal Public Service The Company may request further
(PPS) number, pseudonyms, educational qualifications’ information including business name,
verification and languages. Where the Company either registration number, payment/bank details,
reviews your initial application or progresses to final offer contact information, including email address,
stage we may also seek to collect further data, including demographic information such as postcode,
interview notes and also sensitive Personal Data from preferences and interests, relevant
third parties (i.e. pre-employment medicals and information relating to offers.
references); but only with your explicit consent. You
should note that it is your responsibility to attain consent
from any referees prior to submitting to us any personal
information about them.

Depending on your use of our website, we may collect some or all of the aforementioned data.

3.3 Usage, Storage, Security and Disclosure Controls


We will only collect Personal Data that is absolutely necessary for our legitimate business interests in
facilitating an effective recruitment and selection process and any subsequent employment with us;
and/or in relation to all aspects of our sales, marketing and supply chain, including payment, quality and
customer service processes; and where such interests are not overridden by the right to conduct/complete
such processes, as appropriate.

We are committed to ensuring that your Personal Data is secure and selected employees of the Company [i.e.
including management and authorised employees within their appropriate functional area(s)] have access to
Personal Data). In an effort to prevent unauthorised access or disclosure, we have implemented appropriate
physical, electronic and managerial procedures to safeguard and protect the information we collect online to
established GDPR standards. Such security measures include firewalls, IP anonymisation, password protection
and website SSL Card/encryption to verify the website’s authenticity for electronic data between sender and
receiver and lockable / restricted access.

All Personal Data recorded by the Company (for Job Applicants and Customers alike) are audited at least
once every twelve (12) months, or sooner as may be necessary, so that we maintain accurate and relevant
information only and strictly for no longer than is absolutely necessary. Approved Vendor lists are also
audited and updated monthly to ensure compliance with ISO 9001 is maintained at all times. CCTV footage
will be retained for twenty eight (28) days - after which it will normally be overridden unless there are other
legitimate and/or legal reasons requiring such data to be retained for longer periods. Where no longer
required, any unnecessary data (both hard and/or soft copy versions) will be destroyed/overridden safely and
confidentially in accordance with the Company’s GDPR compliant internal procedures.

_________________________________________________________________________________________________________________
4 of 8| P a g e Registered Office: East Ramp, Shannon Airport, Co. Clare, Ireland, V14 K283.
3.3.1 Job Applicants: 3.3.2 Customers:
If you are not hired by the Company after completion of We will retain Personal Data for Customers
our recruitment and selection process for any vacant specifically for the duration of any legitimate
position, under the terms of our internal procedures we continuing business relationship/interest,
will normally retain your Personal Data in a central and including in the marketing and sales of our
secure location (manually and also electronically on our products and services
internal applicant tracking and email management
systems), for up to a total maximum period of fourteen We also share information with sub-
(14) months from the date of submission. contractor companies that may collaborate in
the delivery of some of our services or for
During these fourteen (14) months your Personal Data will marketing purposes [within or outside the
remain in a confidential and secure manner for enquiry European Economic Area (“EEA”) - i.e.
handling/reference and/or possible consideration for member states of the European Union,
other potential opportunities within the Company; together with Norway, Lichtenstein and
otherwise and after which will be destroyed safely and Iceland, where compliant with Data Protection
completely without further notification or reason. legislation].

Should you decide to re-apply for another vacant position To manage the Company’s interaction with
after completion of this timeframe, you will be required to Customers, your Personal Data is/will be
complete and submit a new application, including updated stored within the EU, via our internal customer
curriculum vitae. contact spreadsheet; Materials Relationship
Planning (MRP) system, internal approved
Where you may wish to apply for more than one role, you vendor list, internal calibration log, internal
will be required to complete separate applications per central visitor register and emails stored in the
role; to ensure we have the relevant accurate and up to Cloud Office 365.
date Personal Data, as appropriate. Our recruitment
process activities will be impacted by the information
provided. Your Personal Data will be shared with our
Human Resources Department and relevant hiring
manager(s) of the respective country(ies) where you
applied. Following collection of your Personal Data, the
Company undertakes to use, disclose and retain and in any
event that we should cease progression of your job
application(s), your Personal Data may also be disclosed to
subsidiaries of the Company regarding other possible
opportunities, but only with your prior explicit written
consent.

Job applications for vacant positions throughout Dublin,


and Shannon will be managed and stored exclusively from
our EMEA Head Quarters in Shannon (“HQ”). For roles
outside of our HQ jurisdiction (including Ostrava, Rome
and North America), Personal Data from Job Applicants
will be Processed within these individual offices.

3.4 How we use Cookie Technology


The Company uses Google Analytics, a web analytics service made available by Google, Inc. (“Google”). Google
Analytics uses “cookies”, which are small text files and at the request of our server are placed on your
computer’s hard drive.

Once you agree for the file to be added, the information generated by the cookie helps analyse web traffic or
your visit/use of a particular site (including your IP address), and will be transmitted and stored by Google
servers. Cookies allow web applications to respond to you as an individual.

The web application can tailor its operations to gather data on your interests and save your personal
preferences so that you do not have to re-enter each time you visit the website. In certain circumstances, it
may facilitate the Company to use data to contact you in relation to any job vacancy that you accessed that
may be of interest to you.

_________________________________________________________________________________________________________________
5 of 8| P a g e Registered Office: East Ramp, Shannon Airport, Co. Clare, Ireland, V14 K283.
Overall cookies help us to provide you with a better website, by enabling us to monitor which pages of our
website that you find useful and which you do not. A cookie alone generally will not identify you personally
and in no way provides us with access to your computer or any information about you (other than the data
you choose to share with us). We will not use this information in connection with any personally identifiable
information you have provided.

Before cookies are placed on your computer or device, you may choose to accept or decline, following an
automatic prompt which will appear requesting you to do so. Most web browsers automatically accept cookies,
but you can usually modify your browser setting to decline cookies if you would prefer, however this may
prevent you from availing full advantage of our website. The Company has set a fixed time limit of
twenty six (26) months before automatic expiry.

The Company has a standard SSL card with IP anonymisation switched on at all times, which enables the
Company to attain statistics without pinpointing individual sessions on to our website.
You should note that neither the Company nor Google will link or seek to link an IP address with the identity
of the computer user.

The following cookies may be placed on your computer or device:

Cookie Name First or Third Source Purpose Strictly Expiration


Party Necessary Time
(Y or N)
“_ga” Third Originates from To keep a record of N 1 (one)
Google visitor statistics. minute
Analytics
“_gid” Third Originates from To keep a record of N 1 (one)
Google visitor statistics. minute
Analytics
“_gat” Third Originates from To throttle request N 1 (one)
Google rate. minute
Analytics
“IDE” Third Created by To show N Varies –
Google personalised decided
DoubleClick advertisements by google
(ads).
“YSC, VISITOR_ Third An embedded Collects visitor N Varies –
INFO1_LIVE, PREF” YouTube-video information and decided
adjusted preferred by google
settings.
“GPS” Third Created by To show N Varies –
YouTube personalised decided
advertisements by google
(ads).
"catAccCookies” First Local Tracks if cookie Y 1 (one)
consent has been month
agreed

3.5 Links to other sites


Our website may contain links to enable you to visit other websites of interest easily; which are exclusive
to us. Once you use these links to leave our website we do not have any control over that other
website(s) and cannot be responsible for the protection and privacy of any information provided whilst
visiting any such other site(s). We would advise you to check the privacy policies of any such websites
before providing any data to them.

_________________________________________________________________________________________________________________
6 of 8| P a g e Registered Office: East Ramp, Shannon Airport, Co. Clare, Ireland, V14 K283.
3.6 Controlling your Personal Data
3.6.1 Accessing, Accuracy and/or Deletion of Personal Data
Under Article 15 of the GDPR 2018, you have the right to make a Data Access Subject Request “DASR”, to obtain
a copy of any Personal Data relating to you and retained on the Company’s computer system, in a structured
manual filing system or intended for such a system by the Company. You may contact us at any time to request
access/copy of your personal data, which we hold about you; however, such requests may be subject to certain
restrictions in some circumstances. To do so you must submit your request in writing by post or email to the
Company’s GDPR Administration Officer(s) [refer to Section 4.0].

You are asked to be as specific as possible in relation to the Personal Data; and in the interests of
safeguarding the documentation and to ensure it is given to the correct person, you will be asked to
provide evidence of your personal identification.

Unless there are manifestly unfounded or excessive requests, an administration fee may apply; but otherwise
normal requests will be free of charge and submitted to you within thirty (30) days after requested; or
alternatively provide a reason why a refusal may be necessary (refer to the Company’s GDPR Administration
Officer(s) for any further information).

If requests are numerous or complex, an extended timeline of a further two (2) months may be deemed
appropriate. As well as updating any requests you may make to correct any inaccurate, incorrect or incomplete
data, we may also contact you periodically to review such Personal Data.

You may also receive information about the categories and purpose of Processing your Personal Data and to
whom your Personal Data has been transmitted. It will be restricted use for the main purpose only intended
or supplied. Should your Personal Data be incorrect and/or deemed to be unfairly obtained, you should
explain in writing by email or post to the appropriate Company GDPR Administration Officer(s), outlining why
and the Company will respond within thirty (30) days; either confirming the change or possible reason for
refusal. Should you object to the manner in which your Personal Data is Processed, you may also at any time
request to fully erase from our records.

3.6.2 Data Usage, Objections and Decision Making


As well as interacting with you in writing, online or by telephone to evaluate further either your job
application(s), or products and services we may also use your Personal Data to assess/survey your
experiences of our recruitment, sales and/or marketing process(es), where relevant with a view to
making any further enhancements/changes as may be deemed appropriate over time.
All such relevant information for jobs may be utilised and maintained by our human resources, sales and
marketing teams respectively, as applicable within the appropriate offices as set out in Section 3.1 and in
accordance with GDPR regulations. You have the right to object; and the Company confirms that by
forwarding such information you will not be subject to automated decision making or profiling by the
Company.

3.6.3 Transfer of Personal Data


3.6.3.1 Job Applicants: 3.6.3.2 Customers:
In any situations where a job application(s) is As the Company operates internationally, it may be
received for another location(s) outside of the necessary in the course of business to transfer Personal
Company’s job vacancy(ies) designated Data within the Company and to other group
jurisdiction(s), that application(s) will be companies; in countries outside the European
transferred, via email in PDF format and Economic Area, which do not have comparable data
password protected, to the appropriate protection laws.
location(s) for Processing; following which the
application(s) will be deleted by the first
recipient.

_________________________________________________________________________________________________________________
7 of 8| P a g e Registered Office: East Ramp, Shannon Airport, Co. Clare, Ireland, V14 K283.
We will notify you if transferring to a subsidiary The transfer of such data may be necessary for
of the Company outside of the EEA; and should administration of sales, marketing and procurement
this be required, the Company will act purposes. Where this may be necessary, the Company
appropriately to ensure the data has the same will take necessary steps to ensure that the data has the
level of protection as it does within the EEA. same level of protection as it does inside the EEA. You
also have the right to data portability enabling you with
You also have the right to data portability the right to require us to electronically transmit
enabling you to require us to Personal Data to another organisation, as requested.
electronically transmit your Personal Data to The Company will only transmit to companies that
another organisation, as requested. agree to guarantee this level of protection and will
notify you should this be a requirement.

Any such Personal Data may be transferred by email


and password protected in all/any formats; including
the Company’s internal customer contact spreadsheet
and MRP System.

3.6.4 Complaints
If for any reason you may not be satisfied with the Processing of your Personal Data, you reserve the right
to make a complaint to the Data Protection Commissioner tel: +353 761 104 800 | email:
[email protected] and/or may contact the Company’s GDPR Administration Officer(s) [refer to
Section 4.0].

3.6.5 Breach of Personal Data


Mandatory breach notification has been introduced under GDPR 2018, which means that unless
anonymised or encrypted must be reported to the Data Protection Commissioner within seventy two (72)
hours. Essentially this may result in most data breaches, any breaches that are likely to cause harm to an
individual (including breach of confidentiality or identity) must also be reported to the individuals affected.

Any/all breach(es) or indeed any suspected breach(es) must be immediately reported to the Company’s
GDPR Administration Officer(s) for assessment.

3.7 Future Reviews / Changes


We reserve the right to review this Statement periodically and where necessary, due to changes in business
operations or applicable new employment legislation; to make any future changes to our practices and this
Statement, in the management of your Personal Data. Any updated versions of this Statement will be posted
on our website so that you are consistently aware of what and how data is Processed. We recommend that
you check our website from time to time to ensure that you remain satisfied with any such changes; and
any/each time you send us new or additional information. If your Personal Data is to be used in a manner
significantly different from that stated in this Statement, or otherwise disclosed to you at the time it was
collected, we will notify you by email and you will be provided with the option as to whether you wish it to be
used in the new manner.

_________________________________________________________________________________________________________________
8 of 8| P a g e Registered Office: East Ramp, Shannon Airport, Co. Clare, Ireland, V14 K283.
4.0 Further Information:
Please note that GDPR in the Czech Republic is governed by its own regulations. Please contact
[email protected] for more information.

In addition to the ‘Contact’ page on our website, should you have any enquiries, concerns or requests
regarding this Statement, how your Personal Data is Processed, including to subscribe, update your
preferences or to unsubscribe from any of our marketing campaigns and/or on contacting you about job
opportunities within the Company other than which you apply for; you may also contact the appropriate
Company GDPR Administration Officer(s) in writing to;

International Aerospace Coatings (IAC) Limited (HQ), Shannon Airport, Co. Clare, Ireland, V14 K283;
OR by email to:

Both Job Applicants and Customers:


Email Address Location
[email protected] Shannon and Dublin, Ireland Offices
[email protected] Rome, Italy Offices
[email protected] Ostrava, Czech Republic Offices

_________________________________________________________________________________________________________________
9 of 8| P a g e Registered Office: East Ramp, Shannon Airport, Co. Clare, Ireland, V14 K283.

You might also like