Effective as of January 2024
Who we are and what we do?
We at Hi Bob Limited (together with its affiliated companies – “HiBob“, “we“, “our” or “us“) develop and operate a human resources management platform that includes a recruiting and applicant tracking system (“bob Hiring” or the “Hiring Module”), helping companies streamline their recruiting processes for the positions they seek to fill (our “Customer(s)” or the “recruiting organization”).
This notice describes our privacy practices concerning identified or identifiable information (“personal data”) relating to job candidates and applicants (“Applicant(s)”, “data subject”, “you” or “your”) of our Customers using bob Hiring to process your application. It also explains how our Customers typically handle your personal data through bob Hiring.
As further explained in Section 9 below, the responsibility for complying with most legal requirements applicable to a “Data Controller” regarding your personal data processed by us lies with our Customer – the recruiting organization. In other words, your personal data is provided to us in the framework of our relationship with the recruiting organization and we are not responsible for its privacy practices. The recruiting organization may have additional privacy notices explaining its own specific privacy practices, in which case, we encourage you to read them.
Note that this notice does NOT cover our processing of personal data relating to individuals who otherwise interact with HiBob’s assets (such as our Customers’ admins and Recruiters, our website visitors, business contacts and prospects, etc.). To learn more about our privacy practices relating to those activities and individuals, please visit our Privacy Policy.
If you have any questions or requests which pertain to your personal data processed by us on behalf of the recruiting organization, we suggest that you contact the talent acquisition manager of the recruiting organization associated with the role you are applying for (“Recruiter”).
Specifically, this notice describes our practices regarding –
We respect your privacy and are strongly committed to making our practices regarding your personal data transparent and fair. This notice for bob Hiring forms part of our End Users Terms of Use. Please read this notice carefully and make sure that you fully understand and agree to it.
Data collection: Your application for a role at a recruiting organization may be initiated either directly by you (when you submit an application to a role at the recruiting organization) or through other sources, such as talent agencies engaged by the recruiting organization or headhunting efforts by the recruiting organization’s talent team. The data we collect is limited to details deemed relevant by the recruiting organization and is accumulated throughout your progression in the application process.
Through your application and interaction with the recruiting organization, we may process the following information about you: Name and contact details (phone, email, home address), resume/CV (including information such as education, work experience, skills), cover letters and/or notes submitted with your application, your LinkedIn profile and/or website, the role for which you are applying, the source of your application (referral, talent agency, etc.), email correspondence between you and the recruiting organization and/or other sources related to your application (interactions with agency/discussion with your designated referees, etc.), your responses to assignments by the recruiting organization, details of your employment requirements (availability, salary expectations, etc.), technical events of the application process (such as Applicants status and time stamps of advancements through different stages of the application process), evaluations of your candidacy, and additional information relating to your application that may be submitted by you or other parties (such as referees and background check providers where applicable) as deemed relevant by the recruiting organization (collectively – “Applicant Profile”).
When you interact with the online job application form powered by HiBob or with the candidate portal for self-exercising your privacy rights (as detailed in Section 8 below), we may collect, record or generate certain technical data about you. We do so either independently or with the help of third-party Service Providers (as defined in Section 4 below), including through the use of “cookies” and other tracking technologies (as detailed in Section 5 below). Such data consists of connectivity, technical and aggregated usage data, such as IP addresses and general location, device and application data (like type, operating system, browser version, locale and language settings used), date and time stamps of usage, the cookies and pixels installed or utilized on such device and the recorded activity (sessions, clicks and other interactions) of Applicants in connection with bob Hiring (collectively – “Usage Data”).
Data uses: In general terms, the recruiting organization will use bob Hiring to process your personal data in order to manage and improve its recruitment processes, track the progress of your candidacy, assess your suitability for the role you applied for, and (where applicable) consider you for other available positions within the recruiting organization.
HiBob processes your Applicant Profile as is necessary for the performance of our services and to facilitate, operate, and maintain the Hiring Module (all in accordance with the instructions provided to us by the recruiting organization in their role of data controller); to comply with our legal and contractual obligations; to provide customer service and technical support; and to protect and secure our Customers, their Applicants, ourselves and the Hiring Module.
HiBob will process your Usage Data to create aggregated data, inferred non-personal data or anonymized or pseudonymized data (de-identified data), which we will use for quality assurance and development purposes, for improvement of the Hiring Module and its user experience. Our legal basis for this processing under EU law is our legitimate interests in developing, maintaining and improving bob Hiring.
Your personal data may be maintained, processed, accessed and stored by us and our authorized Service Providers (defined in Section 4 below) in different locations.
While privacy laws may vary between jurisdictions, HiBob and its Service Providers are each committed to protecting your personal data in accordance with this notice, customary industry standards, appropriate lawful mechanisms and contractual terms between the recruiting organization, HiBob and such providers as required.
HiBob maintains offices in the EU, UK, US, Israel and Australia. Your personal data may be accessed from any of those locations (or other locations as reasonably necessary for the Hiring Module’s activity) by HiBob employees tasked with handling the recruiting organization’s data. Such access usually occurs in the course of providing the recruiting organization with customer support, technical assistance, etc.
The Service Providers we use to process your personal data on behalf of the recruiting organization, deemed as our “Sub-Processors”, are typically located in the EU. However, HiBob may use Sub-Processors in other locations as reasonably necessary for our activity. A list of our current Sub-Processors is available here.
For data transfers from the European Economic Area, the UK or Switzerland to countries which have not been recognized as offering an adequate level of data protection by the relevant competent authority, we rely on appropriate cross-border data transfer mechanism as established under applicable law, such as the Standard Contractual Clauses adopted by the EU (available here) and the UK (available here).
The period for which your personal data will be stored on bob Hiring and the criteria guiding such duration are determined by the recruiting organization. For example, the recruiting organization may decide to keep your personal data on bob Hiring for an initial retention period (e.g., 30 days) after the earlier of the date on which you are informed of the hiring decision made regarding the job opportunity you are considered for or the closure date of that job opportunity. During such period, the recruiting organization may seek your consent to keep your data for an extended retention period (e.g., 12 months) so that it could consider your suitability for other job opportunities in the future. Alternatively, the recruiting organization may seek your consent for such an extended retention period when you first apply to the job opportunity. If you give your consent to such extended retention period, you will have the option to withdraw it at any time by contacting the Recruiter in accordance with the recruiting organizations’ privacy notice. If you have any questions about our data retention practices, please contact the Recruiter.
Note that if your candidacy is successful and you are hired for the role, the recruiting organization may transfer to your employee record those data contained in your Applicant Profile that are deemed relevant to your ongoing employment. This information may then be retained by the recruiting organization for the duration of your employment or as otherwise specified in its employee privacy notice. If such information is kept on HiBob’s core product suite, it will be processed by us in accordance with our relevant policies.
We may retain some of your personal data after the termination of our engagement with the recruiting organization to the extent reasonably necessary to comply with our contractual and legal obligations (e.g., as required by laws applicable to log-keeping, records and bookkeeping), or to protect ourselves from potential disputes, all in accordance with our agreements with the recruiting organization, applicable laws and, where applicable, our retention policy.
Please note that except as required by applicable law or our specific agreements with the recruiting organization, we will not be obligated to retain your personal data for any particular period, and we are free to securely delete, anonymize or restrict access to it for any reason and at any time, with or without notice to you.
Service Providers: We engage selected third-party companies and individuals to perform services complementary to our own. Such service providers include hosting and server co-location services, communications and content delivery networks (CDNs), data and cyber security services, fraud detection and prevention services, web analytics, e-mail distribution, remote access services, performance measurement, e-mail, support and customer relation management systems, and any other relevant services (collectively – “Service Providers“). These Service Providers may have access to your personal data, depending on each of their specific roles and purposes in supporting bob Hiring, and may only use it for such purposes.
The recruiting organization, its employees and service providers: We share your personal data with the recruiting organization (including your Applicant Profile). In such cases, sharing such data means that the Recruiter may access it on behalf of the recruiting organization, and will be able to monitor, process and analyze your personal data. The Recruiter can determine that your Applicant Profile (or parts of it) will be made available to others in the recruiting organization (such as the hiring manger or other relevant personnel of the recruiting organization). If your application is submitted to the recruiting organization by a third party, such as an employee of the recruiting organization or a talent agency engaged by it, the recruiting organization may grant the third party access to your details and overall application status. This may be done to offer feedback to the third party regarding their submissions.
Please note that any personal data uploaded to the Hiring Module may be accessed, copied or processed by the recruiting organization, and that HiBob is not responsible for and does not control any further disclosure, use or monitoring by or on behalf of the recruiting organization.
HiBob Subsidiaries and Affiliated Companies: We may share personal data internally within our group of companies, for the purposes described in this notice.
Legal Compliance: In exceptional circumstances, we may disclose or allow government and law enforcement officials access to your personal data, in response to a subpoena, search warrant or court order (or similar requirement), or in compliance with applicable laws and regulations. Such disclosure or access may occur if we believe in good faith that: (i) we are legally compelled to do so; (ii) disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, fraud, or other wrongdoing; or (iii) such disclosure is required to protect the security or integrity of our products and services.
For the avoidance of doubt, HiBob may share your personal data in additional manners, pursuant to the recruiting organization’s or your explicit approval, or if we are legally obligated to do so, or if we have successfully rendered such data non-personal and anonymous. We may transfer, share or otherwise use non-personal data at our sole discretion and without the need for further approval.
Our candidate portal (including some of our Service Providers) utilizes “cookies”, anonymous identifiers, pixels, container tags and other technologies in order for us to provide the candidate portal and ensure that it performs properly, and to analyze and improve its overall performance. Such cookies and similar files or tags may also be temporarily placed on your device. Certain cookies and other technologies serve to recall personal data, such as an IP address, previously indicated by an Applicant’s device. To learn more about our practices concerning cookies and tracking, please see our Cookie Policy.
The recruiting organization may use bob Hiring to send you notifications, messages and other updates via email regarding your application. Please note that you will not be able to opt-out of receiving such communications, which are integral to your application process (like requests for consent to extended data retention for future roles consideration).
In order to protect your personal data held with us, we are using sound industry-standard physical, procedural and technical security measures, including encryption as appropriate. However, please be aware that regardless of any security measures used, we cannot and do not guarantee the absolute protection and security of any personal data stored with us or with any third parties as described in Section 4 above. To learn more, please visit https://www.hibob.com/security/.
You may have certain privacy rights under any applicable law, including the EU or UK General Data Protection Regulation (GDPR) – such as the right to know or request access to, and rectification or erasure of your personal data held with HiBob, or to restrict or object to the processing of such personal data, or to port such personal data, or the right to equal services and prices (each to the extent available to you under the laws which apply to you). Should you wish to exercise your rights or make any request or query with regard to your personal data we process on the recruiting organization’s behalf, please use the self-exercise options for making data access, deletion and correction requests available to you through the candidate portal (accessible through the link that is included in email communications you will receive through the Hiring Module) or contact the Recruiter directly.
Certain data protection laws and regulations, such as the GDPR, typically distinguish between two main roles for parties processing Personal Data: the “Data Controller”, who determines the purposes and means of processing; and the “Data Processor”, who processes the data on behalf of the Data Controller. Below we explain how these roles apply to us.
The recruiting organization is the Data Controller of Applicants’ personal data uploaded or submitted to bob Hiring. HiBob processes such data as the Data Processor on behalf of the recruiting organization, in accordance with its reasonable instructions and subject to our terms, our Data Processing Addendum and any other commercial agreements we may have with the recruiting organization.
The recruiting organization is responsible for meeting most legal requirements applicable to Data Controllers. If you would like to make any requests or queries regarding our processing of your personal data on behalf of the recruiting organization, please contact your Recruiter directly.
HiBob assumes the role of Data Controller (solely to the extent applicable under law), with regards to the processing of personal data relating to our website visitors, prospects and business contacts, as well as Usage Data processed through bob Hiring – as further elaborated in our Privacy Policy.
External Links: While the Hiring Module may contain links to other websites or services or provide integrations of third-party solutions, we are not responsible for their privacy practices. We encourage you to pay attention when you leave bob Hiring for the website or application of such third parties, and to read the privacy policies of each and every website and service you visit. This notice applies only to Candidates whose personal data is managed through bob Hiring.
Additional Questions: If you have any comments or questions regarding this notice, please contact the Recruiter or reach out to our Data Protection Officer at [email protected].