MindMatch collects some personal data from its Users.
Data Controller of the website “https://mindmatch.ai” pursuant to Art. 4 (7) of the EU General Data Protection Regulation (GDPR):
Schlesische Straße 26, Eingang B, Etage 5
10997 Berlin, Germany
Chamber of Commerce of Berlin, no. of registration: HRB 191247 B
Contact email: firstname.lastname@example.org
Types of Data collected
Each time a User accesses a page of our website and every retrieval of a file access data about that process is stored in a log file on the server. In particular, this applies to the following information:
- Date and time of the request
- Time zone difference to Greenwich Mean Time (GMT)
- Content of the request (concrete page)
- Access status/ HTTP status code
- Transferred amount of data
- Website from which the request was initiated
- Operating system and its interface
- Language and version of the browser software
- IP address
The IP address is stored for the period of use only and will be deleted or anonymized afterwards immediately. This data will neither be used to identify users nor be combined with other data, but serves to provide this website only. MindMatch collects the aforementioned data as this is technically necessary for us to be able to display our website and to ensure the stability and security of the website. The legal basis of this processing is Art. 6 (1) sentence 1 lit. f) GDPR. If you use our website not only for information purposes, you will generally need to provide further personal data, such as name, date of birth, email address, address or telephone number, which we use to provide the respective services. We will collect the relevant personal data only if this is permitted by law (for example, for the performance of a contract or for legitimate interests) or if you consent to the processing of personal data. In case of your consent the legal basis of the processing is Art. 6 (1) sentence 1 lit. a) GDPR. With respect to the performance of a contract the legal basis is Art. 6 (1) sentence 1 lit. b) GDPR. The legal basis concerning processing of your data with respect to legitimate interests is Art. 6 (1) sentence 1 lit. f) GDPR. You may withdraw your consent to the processing of personal data at any time. A revocation has direct influence on the admissibility of the processing of your personal data as soon as directed to us. If the processing of your personal data is based on legitimate interests, you have the right to object to processing the personal data. If you exercise your right of objection, we kindly ask you to explain the reasons why we should not process your personal data. If your objection is justified, we will review the facts and adjust or modify the processing of data or inform you about imperative legitimate reasons for the processing. Among the types of personal data that MindMatch collects, by itself or through third parties, there are: - name, last name and email address of Clients using MindMatch and/or the natural person using MindMatch on the Client's behalf - personal data contained in each Candidate's application documents. The personal data collected from Candidates, who use MindMatch autonomously and for their own scopes in particular to apply for a specific job, are all those included in their personal professional profiles and/or application documents, including: name, surname, place of domicile, e-mail address, date of birth, gender and photograph, previous academic and professional experiences and background, personal skills (such as languages spoken), personal interests, hobbies, social media accounts, certificates, diplomas and other qualifications, preferences in terms of working hours and working places, a presentation video or a video interview and further documents (such as motivation letters, CVs etc.).
Users are responsible for any personal data of third parties obtained, published or shared through MindMatch and confirm that they have the third party's consent or another legal basis to provide the Data to the MindMatch.
Mode and place of processing the Data
Methods of processing
The Data Controller processes the Data of Users in a proper manner and shall take all appropriate technical and organizational security measures to protect the data against manipulation, loss, destruction or unauthorized access by third parties. Our systems are secured against unauthorized access. In particular, your personal data is encrypted by us. We use the coding system SSL (Secure Socket Layer). We expressly point out that despite all technical precautions, the Internet does not allow absolute data security. We are not liable for acts of third parties.
The Data is kept for the time necessary to provide the service requested by the User, or stated by the purposes outlined in this document, and the User can always request that the Data Controller suspend or remove the data. Mindmatch will delete the personal data of Users as soon as the data is no longer necessary for the respective purpose. It may occur that personal data is kept for the time during which possible claims may be asserted against MindMatch (for example statutory limitation period of three or thirty years). Furthermore, MindMatch is required by law to store certain data due to the duties of proof and retention, inter alia with respect to the German Commercial Code, the German Tax Code or the Money Laundering Act. The storage periods can be up to ten years. As personal data are submitted by Candidates through the apply form on the website of MindMatch the Client offering the job is responsible for the timely erasure of personal data on the platform according to legal deletion periods. MindMatch will erase or make anonymous these personal data on the platform submitted by Candidates upon instruction of the Client or, at the latest, two month after application of the Candidate.
The use of the collected Data
The Data concerning the User is collected to allow Mindmatch to provide its services, as well as for the following purposes: Registration and authentication, Analytics, User database management, Tag Management, Managing contacts and sending messages, Contacting the User and Remarketing and behavioral targeting. The personal Data used for each purpose is outlined in the specific sections of this document.
Rights of Users
You have the right of access, rectification or erasure, restriction of processing, objection to the processing, and data portability with respect to your personal data. We are available for corresponding requests or messages at the specified address below. Please note that the deletion of data is only possible if there are no precluding legal regulations. Information concerning your requests or messages is transmitted in electronic form (by email). Should you use this option of providing information via email, the specified email address (both sender and recipient) will not be used for any purpose other than the provision of information and its documentation. You also have the right to lodge a complaint concerning the processing of your personal data by us with a supervisory authority. If we are legally required to disclose data to local, state, national or international authorities, we will comply with this obligation. We will also disclose information to third parties when required by applicable laws and regulations. In addition, we may disclose information to investigate, prevent, or initiate countermeasures against illegal activities or suspected fraud, or to apply or enforce any of our contracts and licensing rights.
Detailed information on the processing of Personal Data
In addition, personal data is collected for the following purposes and using the following services:
The services contained in this section enable MindMatch to monitor and analyze web traffic and can be used to keep track of User behavior.
Google Analytics with anonymized IP (Google Inc.)
MixPanel is an analytics service provided by Mixpanel Inc., San Francisco CA94105, 405 Howard Street, 2nd Floor.
For this purpose, cookies can be used. Mixpanel collects and stores usage data in pseudonymous profiles. The pseudonymous usage profiles, as required by § 15 (3) Telemediengesetz (TMG), are not merged with personal data about the bearer of the pseudonym.
You can object to the collection and storage of data for the purpose of web analysis at any time with effect for the future by deactivating the service by clicking the button "Opt out" below.
In this case, please note that a cookie is set on your device, which ensures that no further data is collected and evaluated by you. Therefore, you should not delete this cookie.
In addition, we use Mixpanel to send targeted push notifications if you have consented to this. In case you no longer want notifications, you can deactivate them at any time.
MixPanel is part of the EU-US-Privacy-Shield, https://www.privacyshield.gov/EU-US-Framework. Personal Data collected: Cookies and Usage Data.
Contacting the User
Mailing list or newsletter (MindMatch)
With our newsletter service we inform you by email about our services. This requires your consent.If you wish to subscribe to our newsletter service we ask you to provide your email address. However, before we send you the newsletter you will receive an email notification with a link. By clicking the link you confirm to receiving the newsletter and, hence, you will be included in our distribution list. This ensures that nobody other than you used your email address for subscription to or newsletter (so-called double opt in procedure). If you do not confirm the registration within 96 hours we block your information immediately and delete them automatically after one month. In addition, we only store your IP address as well as the time of registration and confirmation in order to be able to prove your registration and to have the possibility to disclose the misuse of your data. To receive our newsletter you only need to enter your email address, name and surname. Providing further data is voluntary. We store your email address for the purpose of sending our newsletter only. The legal basis is Art. 6 (1) sentence 1 lit. a) GDPR. You may withdraw your consent to receive the newsletter at any time by sending a message to us or simply by clicking the link provided at the bottom of each newsletter. A message in text form to contact details provided below (email, letter) will be sufficient.
Personal Data collected: email address.
If you contact us via the contact form on our website or by email or fax, the information provided will be stored and processed in order to process the request as well as follow-up questions. We will delete the relevant data after the storage is no longer required or restrict the processing if statutory retention periods exist. The legal basis of this processing is Art. 6 (1) sentence 1 lit. f) GDPR. Our legitimate interest is to answer your request.
We currently use the following social media plug-ins on our website: Facebook, Twitter, LinkedIn, GitHub.
We use the so-called two-click solution. This means that, by visiting our website, no personal data is initially passed on to providers of such plug-ins.
The provider of the plug-in can be identified on our website by the corresponding logo. Via the respective button we provide the opportunity to communicate directly with the provider of the plug-in. The plug-in provider only receives the information that you have accessed its website through our online service, if you click on the designated field and activate it.
According to the information of the respective provider when using the Facebook plug-in, in Germany the IP address will be anonymized immediately after collection .
Please note that by activating of the plug-in personal data about you will be transferred to and stored by the respective plug-in provider (in case of US providers in the USA). Data collection is mainly done by plug-in providers via cookies. So we recommend to delete all cookies on the security settings of your browser before clicking on the button.
We have no influence on the collected data and the data processing operations. We are also not aware of the full scope of the data collection, the purpose of the processing and the storage periods. In addition, we have no information on the deletion of the data collected by the plug-in provider. The respective plug-in provider stores the data collected about you in profiles and uses them for marketing, market research and/or tailored design of its website. Such an evaluation is carried out in particular (also for non-logged-in users) for the presentation of tailor-made advertising and to inform other users of the social network about your activities on our website. You have a right to object against the creation of such usage profiles. To exercise, you need to contact the respective plug-in provider. The plug-ins allow us to interact with social networks and other users so that we can improve our offer and make it more interesting for you. The legal basis for the use of the plug-ins is Art. 6 (1) sentence 1 lit. f) GDPR. A transfer of data takes place regardless of whether you have an account with the plug-in provider and are logged-in. However, if you are logged in to the plug-in provider, your data collected from us will be assigned directly to your user account. If you activate the social media button and, for example, link the page, the plug-in provider also stores this information in your user account and shares it publicly with your contacts. For this reason, we recommend to log out regularly after using a social network, but especially before activating a button, as this will prevent you from being assigned to your profile with the plug-in provider.
For more information on the purpose and scope of the data collection and its processing by the plug-in provider, please refer to the privacy statements of the relevant provider, which are provided below. You will also get further information about your rights and settings options to protect your privacy.
Addresses of respective plug-in providers und URL with privacy policies:
Facebook Inc., 1601 S California Ave, Palo Alto, California 94304, USA; http://www.facebook.com/policy.php; further information to the collection of data: http://www.facebook.com/help/186325668085084, http://www.facebook.com/about/privacy/your-info-on-other#applications and http://www.facebook.com/about/privacy/your-info#everyoneinfo. Facebook is part of the EU-US-Privacy-Shield, https://www.privacyshield.gov/EU-US-Framework. Twitter, Inc., 1355 Market St, Suite 900, San Francisco, California 94103, USA; https://twitter.com/privacy. Twitter is part of EU-US-Privacy-Shield, https://www.privacyshield.gov/EU-US-Framework. LinkedIn Corporation, 2029 Stierlin Court, Mountain View, California 94043, USA; http://www.linkedin.com/legal/privacy-policy. LinkedIn is part of the EU-US-Privacy-Shield, https://www.privacyshield.gov/EU-US-Framework. GitHub, 88 Colin P Kelly Jr St, San Francisco, CA 94107, United States;
https://help.github.com/articles/github-privacy-statement/. GitHub is part of the EU-US-Privacy-Shield, https://www.privacyshield.gov/EU-US-Framework.
Managing contacts and sending messages
This type of service makes it possible to manage a database of email contacts, phone contacts or any other contact information to communicate with the User.
These services may also collect data concerning the date and time when the message was viewed by the User, as well as when the User interacted with it, such as by clicking on links included in the message.
MailChimp (The Rocket Science Group, LLC.)
MailChimp is an email address management and message sending service provided by The Rocket Science Group, LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA. With MailChimp the dispatch of newsletters can be organized and analyzed. If you enter personal information for the purpose of subscribing to newsletters (e.g., email address), the information will be stored on MailChimp's US servers. MailChimp is part of the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework. The legal basis of this processing is Art. 6 (1) sentence 1 lit. f) GDPR. There is a possibility that MailChimp may use the pseudonymous data of the recipients of newsletters to improve their own services, e.g. for technical optimization of shipping or statistical purposes. An assignment to a user does not take place. In addition, the data of MailChimp are not used to contact recipients of newsletters. Also, no data will be disclosed to third parties.
If you do not wish to be analyzed by MailChimp, you may unsubscribe from the newsletter using the link provided in the newsletter or by sending a text message to the contact details provided (e.g. email, letter).
We save the data provided by you for the purpose of receiving the newsletter until your cancellation of the newsletter. Thereafter, the data will be deleted both from our servers and from the servers of MailChimp.
Personal Data collected: email address.
Registration and authentication
By registering or authenticating, Users allow MindMatch to identify them and give them access to dedicated services. Depending on what is described below, third parties may provide registration and authentication services. In this case, MindMatch will be able to access some Data, stored by these third party services, for registration or identification purposes.
Linkedin OAuth (LinkedIn Corporation)
· Linkedin Oauth is a registration and authentication service provided by Linkedin Corporation and is connected to the Linkedin social network. Candidates can apply for jobs of Clients with their LinkedIn profile without using a CV. For more information please see provision about Social-Media-Plug-ins also.
· Remarketing and behavioral targeting
This type of service allows MindMatch and its partners to inform, optimize and serve advertising based on past use of MindMatch by the User. This activity is performed by tracking Usage Data and by using Cookies, information that is transferred to the partners that manage the remarketing and behavioral targeting activity.
Facebook Remarketing (Facebook, Inc.)
Facebook Remarketing is a remarketing and behavioral targeting service provided by Facebook, Inc., 1601 South California Avenue, Palo Alto, CA 94304, USA, that connects the activity of MindMatch with the Facebook advertising network.
This allows us to display individually tailored and interest-based advertising on Facebook for certain groups of pseudonymised visitors to our website who also use Facebook. For this purpose, a Facebook custom audience pixel is integrated on our website, which stores non-personal data about the use of the website, e.g. IP address, browser as well as source and destination pages. The corresponding information is transmitted to Facebook servers in the USA. Here we can compare whether you have saved a Facebook cookie and belong to the relevant target group. In this case, we will display appropriate ads on Facebook. You will not be personally identified by us or Facebook. The legal basis for the use of the plug-ins is Art. 6 (1) sentence 1 lit. f) GDPR.
Twitter Remarketing (Twitter, Inc.)
Twitter Remarketing is a remarketing and behavioral targeting service provided by Twitter, Inc. that connects the activity of MindMatch with the Twitter advertising network.
This allows us to display individually tailored and interest-based advertising on Twitter for certain groups of pseudonymised visitors to our website who also use Twitter. For this purpose, a Twitter pixel is integrated on our website, which stores non-personal data about the use of the website, e.g. IP address, browser as well as source and destination pages. The corresponding information is transmitted to Twitter servers in the USA. Here we can compare whether you have saved a Twitter cookie and belong to the relevant target group. In this case, we will display appropriate ads on Twitter. You will not be personally identified by us or Twitter. The legal basis for the use of the plug-ins is Art. 6 (1) sentence 1 lit. f) GDPR.
· User database management This type of service allows MindMatch to build user profiles by starting from an email address, a personal name, or other information that the User provides to MindMatch, as well as to track User activities through analytics features. This personal data may also be matched with publicly available information about the User (such as social networks' profiles) and used to build private profiles that MindMatch can display and use for improving MindMatch. Some of these services may also enable the sending of timed messages to the User, such as emails based on specific actions performed on MindMatch.
Intercom (Intercom Inc.)
Intercom Inc.,55 2nd Street, 4th Fl., San Francisco, CA 94105, USA, is a User database management service provided by Intercom Inc. Intercom can also be used as a medium for communications, either through email, or through messages within our product(s). The legal basis of this processing is Art. 6 (1) sentence 1 lit. f) GDPR. In particular, we transmit some of your information (such as your email address and the date of your registration) to Intercom and use Intercom when you visit our website or use our services. Intercom analyzes your use of our website and / or our services and tracks the evolution of our customer relationship so that we can improve our service to you. If you do not want this information to be collected by Intercom or transmitted to Intercom, please contact us. Intercom is part of the EU-US-Privacy-Shield, https://www.privacyshield.gov/EU-US-Framework.
Further information about Personal Data
· Profiling of Candidates If the Candidate consents to the profiling, MindMatch may store and use certain data provided during the registration or the use of the Service as well as navigation data, also in aggregate form, in order to create databases containing profiles relating to the Candidates and possibly transfer them to potential employers or recruiters interested in a specific Candidate's profile. Candidates, whose profiles have been thus forwarded, also agree to be contacted by such third parties via one of the contact details they provided, unless otherwise specified in their personal profile on MindMatch.
Candidates may withdraw their consent at all times with effect for the future sending a respective communication to the contact details specified above.
User profiles are created through the use of automated tools (mainly algorithms) and allow MindMatch to analyse the Candidate's preferences and make forecasts on his or her profile's suitability for a specific job offering.
Consent can always be revoked through the relevant settings of the Service, or by notifying MindMatch via the contact details specified at the beginning of this document. When subjected to profiling, the Users, in addition to exercising their general rights (see section “Rights of Users”), may also:
- request information on the profiling procedures adopted by MindMatch;
- request not to be subjected to decisions based solely on automated processing, including profiling, which produce legal effects affecting the User, or which have a significant effect on him or her.
Client A User benefitting of MindMatch's Services acting as potential employer or recruiter. Candidate A User benefitting of MindMatch's Services acting as potential employee. Data Subject The legal or natural person to whom the personal data refers.