PRIVACY & DATA PROTECTION
If you are reading these words, it means that we are on a dedicated website used by entities from the limango group for recruitment. Below you will find information on how we process your personal data in the recruitment process and during further employment or as part of an established business cooperation, as well as in connection with this website. We encourage you to read it - it is important.
INFORMATION FOR EMPLOYEES AND CONTRACTORS
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, “GDPR”), we inform you as follows:
1. Controller of personal data
The controller of your personal data is:
- For recruitment processes marked with Munich, Germany as the place of work - limango GmbH
- For recruitment processes marked with Wrocław, Poland as the place of work - Limango Polska Sp. z o.o.
Detailed information about each of these entities can be found in the “Impressum” or “About us” section. Each of these entities is hereinafter separately referred to as the “Controller”.
Limango Polska Sp. z o.o. operates an online shop at limango.pl. Limango GmbH operates online shops at limango.de and limango.nl. On these websites you can find more information about the companies and their activities.
2. Contact details
For matters related to the processing of your personal data, please contact us using the details provided in section 1. The Controller has appointed a Data Protection Officer, who may also be contacted using the above details or by email at: iod@limango.com or datenschutz@limango.com
3. Purposes and legal bases for processing personal data
Your personal data will be processed for the following purposes:
- participation in the recruitment process (for job candidates and candidates for contractors) - based on Article 6(1)(a) GDPR (consent) and Article 6(1)(c) GDPR in connection with labour law provisions, to the extent required by law;
- conclusion and performance of an employment contract (for employees) - based on Article 6(1)(b) GDPR in connection with the Labour Code and relevant labour law provisions (processing of data necessary to exercise rights and obligations arising from the employment relationship and legal provisions);
- conclusion and performance of civil-law contracts (for contractors) - based on Article 6(1)(b) GDPR in connection with civil-law provisions;
- fulfilment of legal obligations incumbent on the Controller, in particular obligations arising from tax and accounting regulations, social security and health insurance regulations, occupational health and safety and occupational medicine regulations, and disclosure of an employee’s personal data, including data concerning members of their family, where the obligation to provide such data results from separate regulations - based on Article 6(1)(c) GDPR and, in the scope of health data (if applicable in any scope), based on Article 9(2)(b) GDPR;
- ensuring the security and protection of the Controller’s property, including video monitoring, access control systems and monitoring of activity in IT systems (if such monitoring is carried out, of which the Controller informs separately) - based on Article 6(1)(f) GDPR (the Controller’s legitimate interest);
- pursuing or defending against claims - based on Article 6(1)(f) GDPR (the Controller’s legitimate interest consisting in the possibility of protecting its rights, including in court proceedings);
- storing candidates’ data for future recruitment processes - based on Article 6(1)(a) GDPR (consent) - this applies only to candidates who have given such consent.
Please note that this information covers a number of factual situations involving data processing, and some processing activities are characteristic only of candidates for employment, while others apply to persons already employed. In case of any doubts, the Controller remains at your disposal to clarify them.
4. Categories of personal data processed and data subjects
The Controller processes personal data of persons (a) applying for employment or to become contractors in recruitment processes, (b) employed under an employment contract, and (c) cooperating under civil-law contracts. This information clause is addressed precisely to those persons. If cooperation is undertaken in a B2B form, please read the information on how we process personal data of our business contractors (at the bottom of the page).
The Controller processes the following categories of personal data of these persons:
For job candidates and candidates for contractors:
data contained in application documents (CVs, cover letters, application forms); identification and contact data (first name, surname, address, telephone number, email); data concerning education, professional experience and qualifications; data from the recruitment process (test results, interview assessments); image (if recruitment is conducted using videoconferencing);
For employees:
identification data (first name, surname, identity card number, PESEL number); contact data (residential address, telephone number, email); data concerning education and professional qualifications; data necessary for the performance of the employment contract and settlements (bank account number, data for tax and insurance purposes); health data to the extent required by occupational health and safety and occupational medicine regulations; image in IT systems for identification and security purposes; data concerning activity in the Controller’s IT systems;
For contractors:
identification data (first name, surname, identity card number, PESEL number or another identification number); contact data (address, telephone number, email); data necessary for contract performance and financial settlements (bank account number, data for tax purposes); data concerning education and qualifications to the extent necessary to perform the assignment; image in IT systems (if the contractor receives access to the Controller’s systems); other data provided by you in connection with the performance of the contract.
In each of the indicated cases, we do not process more data than the law provides for in the given situation.
5. Sources of personal data
The Controller obtains personal data:
- directly from you (when submitting applications, signing contracts and during the performance of contracts);
- from publicly available sources where, as a rule, you have placed them specifically for the purpose of receiving employment offers (social networking portals related to careers and employment);
- from other entities, where you have consented to this.
6. Recipients of personal data
The recipients of your personal data may include:
- other entities from the limango group (Limango Polska Sp. z o.o. or limango GmbH), as well as other entities from the OTTO Group;
- entities processing personal data on behalf of the Controller under relevant data processing agreements, including IT service providers, entities providing accounting, legal, advisory, courier and postal services, and entities providing occupational health and safety and occupational medicine services;
- entities to which the Controller is obliged to disclose data pursuant to legal provisions (e.g. tax authorities, ZUS, courts, bailiffs, supervisory authorities);
- banks and payment institutions to the extent necessary to process payments;
- other entities where this is necessary for the performance of the contract, in particular other contractors of the Controller, if necessary to provide services.
7. Transfer of data to third countries or international organisations
As a rule, your personal data will not be transferred outside the European Economic Area (EEA). Such processing may occur incidentally in connection with our use, mainly, of IT services involving temporary data processing in services outside the EEA (in the case of IT services, this will most often mean processing in the USA). If data must be transferred outside the EEA, the Controller will ensure appropriate safeguards and guarantees for the protection of personal data required by GDPR provisions, in particular by using so-called standard contractual clauses or transferring data to entities in countries for which the European Commission has issued a so-called adequacy decision. For the USA, the European Commission issued such a decision on 10 July 2023: the “EU-U.S. Data Privacy Framework”.
8. Personal data retention period
As a rule, your personal data will be stored for the following periods:
- in relation to candidates’ data - for the duration of the recruitment process and additionally for 6 months after its completion for the purpose of possible claims; if consent is given to store data for future recruitment processes - no longer than 3 years from the date consent is given;
- in relation to data processed for the purpose of concluding and performing a contract - for the duration of the contract and, after its termination, for the limitation period for claims arising from that contract (as a rule, 3 years, and in some cases longer in accordance with legal provisions);
- in relation to data processed to fulfil legal obligations - for the period required by law (e.g. tax regulations - 5 years, accounting records, employee documentation);
- in relation to data processed on the basis of the Controller’s legitimate interest - until an objection is lodged or until that interest ceases to exist.
9. Rights of data subjects
In connection with the processing of your personal data, you have the following rights:
- the right of access to data and to receive a copy of it;
- the right to rectification (correction) of data;
- the right to erasure of data (in certain situations);
- the right to restriction of data processing;
- the right to data portability (in certain situations);
- the right to object to data processing on grounds relating to your particular situation, where we process data on the basis of our legitimate interest;
- the right to withdraw consent to the processing of personal data, if you have previously given such consent (withdrawal of consent will not affect the lawfulness of processing carried out on the basis of consent before its withdrawal);
- the right to lodge a complaint with the competent personal data protection supervisory authority.
10. Information on the requirement / voluntary nature of providing data
Providing personal data is:
- for candidates: voluntary, but necessary to participate in the recruitment process - refusal to provide data will prevent participation in recruitment;
- for employees and contractors: a condition for concluding and performing the contract - refusal to provide data may result in the inability to conclude or perform the contract, or in a limitation of available options;
- a statutory requirement in the case of data whose processing is necessary to fulfil legal obligations incumbent on the Controller;
- voluntary in the case of data processed on the basis of consent (Article 6(1)(a) GDPR).
11. Automated decision-making and profiling
Your personal data will not be subject to automated decision-making by the Controller, including profiling within the meaning of the GDPR, which produces legal effects concerning you or similarly significantly affects you.
12. Data security
The Controller applies appropriate technical and organisational measures ensuring the security of processed personal data, in particular preventing access to them by unauthorised persons or their processing in violation of legal provisions, and preventing data loss, damage or destruction.
13. Whistleblowers
The Controller informs that the internal reporting procedure (if the Controller is required to have one at a given time) can be found at limango.pl and https://www.limango.de/compliance
INFORMATION FOR CONTRACTORS (ENTREPRENEURS PROVIDING SERVICES TO LIMANGO GROUP ENTITIES UNDER B2B CONTRACTS)
Persons who would like to cooperate with entities from the limango group as independent entrepreneurs (B2B) are informed as above, with the following information replacing the relevant sections of the above privacy notice:
Purposes and legal bases for processing personal data
Your personal data will be processed for the following purposes:
a) taking steps prior to entering into a contract and for the purpose of concluding and performing a contract to which you (or your employer, service provider, etc.) are a party - based on Article 6(1)(b) GDPR;
b) fulfilment of legal obligations incumbent on the Controller, in particular obligations arising from tax and accounting regulations and, in particular, obligations related to counteracting money laundering and terrorist financing - based on Article 6(1)(c) GDPR (in particular: accounting settlement of the contract);
c) pursuing or defending against claims related to the concluded contract or to the processing of your personal data - based on Article 6(1)(f) GDPR (the Controller’s legitimate interest consisting in the possibility of protecting its rights, including in court proceedings);
d) conducting marketing of products and services as well as for analytical and statistical purposes - based on Article 6(1)(f) GDPR (legitimate interest - conducting own business activity and competing on the market).
Categories of personal data processed and data subjects
The Controller processes personal data concerning contractors (business partners), their representatives, authorised representatives and employees involved in the performance of concluded contracts, commercial negotiations and other activities aimed at maintaining B2B relationships. The Controller processes the following categories of personal data of these persons:
- identification data (e.g. first name, surname, company name, NIP, REGON);
- contact data (e.g. correspondence address, email, telephone number);
- data concerning the function performed at the contractor or the representation of the contractor;
- data necessary for contract performance and financial settlements (e.g. bank account number);
- other data provided to us by you in connection with the performance of the contract.
OTTO GROUP TALENT POOL SYSTEM
In some cases, we offer you the opportunity to be included in the internal Otto Group Talent Pool System. The Otto Group Talent Pool System is used to identify, retain and promote talent as well as to secure succession planning through the active promotion of internal mobility within the Otto Group. If you have consented to the transfer of your data to other group companies of the Otto Group and thus decided to have your data stored in the Otto Group Talent Pool System, we will transfer data that you provided as part of profile creation to Otto (GmbH & Co KG) (hereinafter “OTTO”), which stores it in the Otto Group Talent Pool System. With regard to the inclusion of your person in the internal Otto Group Talent Pool System and the provision of the Otto Group Talent Pool System, we are joint controllers together with Otto (GmbH & Co KG) and the other group companies of the Otto Group participating in the internal Otto Group Talent Pool System. We are primarily responsible for collecting, transferring and submitting your data, while OTTO is responsible for storing your data and providing the Otto Group Talent Pool System. After your data has been transferred by Otto (GmbH & Co KG) to the companies participating in the Otto Group Talent Pool System, the group companies process this data as controllers under data protection law for purposes such as contacting you. A potential application process then takes place normally and directly via the processes of the respective company.
Data processing is carried out on the basis of your consent (Article 6(1)(a) GDPR). You may withdraw your consent at any time by email to yournextmove@ottogroup.com.
We and OTTO are available to you as central contact points with regard to processing under joint controllership, each within our own area of responsibility. Please contact yournextmove@ottogroup.com for any inquiries regarding data protection and to exercise your data subject rights. You may also exercise your rights against us. If you contact us, we will coordinate in accordance with the joint controllership agreement in order to answer your request and ensure the implementation of your data subject rights.
COOKIES
If our website uses cookies, you are informed of this through the standard cookie banner visible on the website when you first enter it. We encourage you to carefully read the information contained in it. All information about specific services / cookies present on our website can be found in the cookie banner. Below we explain what cookies are and how you can manage them using your browser settings.
Cookies are small text files that your browser automatically creates and that are stored on your device (laptop, tablet, smartphone or similar). The cookie stores information that arises in connection with the specific device used. However, this does not mean that we thereby obtain direct knowledge of your identity. Some of the cookies we use are deleted again after the end of the browser session (so-called session cookies). These allow us, for example, to offer you (as it happens at our e-commerce websites, like limango.de or limango.pl) a cross-page shopping cart display, where you can see how many items are currently in your shopping cart and what your current purchase value is. Other cookies remain on your computer and enable us to recognize your computer on your next visit (so-called permanent or cross-session cookies).
Under statutory requirements, storing information on end devices (desktops, mobile phones, tablets or similar) - e.g. by setting cookies - and retrieving information from end devices (tracking) is generally only permitted if you have given your prior consent. However, consent is not required where such storage / retrieval is necessary for the provision of the website (including technically necessary cookies). With regard to data processing that is necessary for operating the website, you do not have a right to object. Therefore, within the consent preferences in the consent tool, the “Necessary” option is always activated and cannot be deselected.
You may use the website without data from your device being retrieved or stored on it for purposes that are not necessary for providing the website. For this reason, when using the website - unless you give further consent - only “basic tracking” may be activated.
Of course, you can configure your browser so that it does not place certain cookies on your device. The help function in the menu bar of most web browsers explains how to prevent your browser from accepting new cookies, how to have your browser notify you when you receive a new cookie, and how to delete all cookies already received and block all further cookies.
Please proceed as follows:
In Internet Explorer:
1. In the “Tools” menu, select “Internet Options”.
2. Click the “Privacy” tab.
3. You can now set the security settings for the Internet zone. Here you can specify whether and which cookies should be accepted or rejected.
4. Confirm your setting with “OK”.
In Firefox:
1. In the “Tools” menu, select “Settings”.
2. Click “Privacy”.
3. In the drop-down menu, select “Use custom settings”.
4. You can now set whether cookies should be accepted, how long you want to keep these cookies, and add exceptions specifying which websites you always or never want to allow to use cookies.
5. Confirm your setting with “OK”.
In Google Chrome:
1. Click the Chrome menu in the browser toolbar.
2. Select “Settings”.
3. Click “Show advanced settings”.
4. Under “Privacy”, click “Content settings”.
5. Under “Cookies”, you can make the following cookie settings:
- delete cookies
- block cookies by default
- delete cookies and website data by default when the browser is closed
- allow exceptions for cookies from certain websites or domains
If you would like to delete individual cookies set in your browser or find out which service providers / vendors have set cookies in your browser, you can also do this / find this out using a “preference manager”. Such a tool is available, for example, at https://www.youronlinechoices.com/ .