Skip to main content

Processing of (personal) data by the entity in charge of the online application process

Privacy policy for the application process 

We provide this privacy policy to inform you about how D4L data4life gGmbH (hereinafter: "Data4Life") processes your personal data collected during the application process. Further below you will find the privacy policy on the processing of personal data by the operator of the recruiting site, which informs you about how Personio GmbH processes your data when you visit the recruiting site.


  1. Controller and data protection officer

The responsible controller according to Art. 4 para. 7 of the General Data Protection Regulation (GDPR) is 

D4L data4life gGmbH

c/o Digital Health Cluster (DHC) im Hasso-Plattner-Institut (HPI)

Rudolf-Breitscheid-Straße 187

14482 Potsdam

Germany
hr@data4life.care

You can contact our data protection officer by email (dataprotection@data4life.help) or by sending a letter to our postal address (to the attention of "the data protection officer").


2. Purposes and legal bases of the processing of personal data by Data4Life

a. Data processing for applications and in the application process

If you apply to us electronically, i.e. by email or via our web form, we will collect and process your personal data for the purpose of conducting the application procedure and carrying out pre-contractual measures.

By submitting an application on our recruitment website, you express your interest in pursuing employment with us. In this context, you transmit personal data, which we will use and store exclusively for the purpose of your job search / application process.

In particular, the following data is collected during this process: 

  • name (first and last names)

  • email-address

  • phone number (optional)

  • targeted date of entry

  • channel through which you found us (optional)

  • expected salary 

Furthermore, you can choose to upload expressive documents such as a cover letter, your CV and reference letters. These may contain additional personal data, e.g.date of birth, postal address etc.

Data4Life conducts several rounds of interviews during the application process. In the process, Data4Life summarizes the interview content necessary to evaluate your application and makes it available to the personnel responsible in the recruiting process. In addition, the contact details of your reference contact provided by you are used to schedule and conduct a reference interview.  

Only authorized HR staff and/or staff involved in the application process have access to your data.

Yourpersonal data is stored, as a rule, exclusively for the purpose of filling the vacancy for which you have applied. The legal basis for processing your personal data is mainly Section 26 of the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG). According to this law, the processing of data required in connection with the decision to establish an employment relationship is permitted.

Your data will be stored for a period of six months after the application process has been concluded. This is usually done to fulfill legal requirements and/or defending ourselves against any claims arising from legal provisions. The legal basis for the processing of your personal data is our legitimate interest for the fulfilment of legal obligations or the defence of any claims arising from legal regulations in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.

Once the storage periods have expired or in the course of exercising your right to deletion and/or objection, we are obliged to delete or anonymize your data. In this case, the data is only available to us as data without direct personal reference for statistical analysis (e.g. number of applications per period etc.).

Should you be offered and accept a position with us during the application process, we will store the personal data collected as part of the application process for at least the duration of your employment with Data4Life.


b. Data processing in "Coding Challenges”

If you applied for a technical position, e.g. as a software developer, we will process your personal data that will be collected during your participation in a test of your software development skills on the platform of Alva Labs AB. You can find more information on how your personal data is processed on the Alva Labs AB platform in their privacy policy: https://app.alvalabs.io/terms.

We have an interest in delivering a pleasant application screening process and in ensuring that your skillset is best suited for the position you applied for. The legal basis for the described processing of your personal data is our legitimate interest in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.


c. Data processing in our "Talent Pool”

In addition, we reserve the right to ask for your consent to include your data in our "Talent Pool" for 24 months after the end of the application process in order to identify any other interesting positions for you. The legal basis for inclusion in the "Talent Pool" is your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR. You can revoke your consent for inclusion in our "Talent Pool" at any time (see also section 5 "Data subject rights").  


d. Contact

When you contact us via one of our contact options, for example, email, post, or telephone, we process the data you provide (for example your email address and the content of your enquiry) necessary for us to answer your question. If your enquiry contains optional personal data, e.g. your name, we will process that data in order to provide improved support. 

The legal basis for the collection of data in the context of contacting and support requests is Section 26 para. 1 BDSG, if an employment relationship exists or is intended. The legal basis is Art. 6 para. 1 sentence 1 lit. b GDPR (processing is necessary for the fulfillment of a contract with the data subject) when we are in the process of entering into or already have a contractual relationship other than an employment relationship. The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR (processing is necessary to safeguard the legitimate interests of the controller) if we do not have or do not plan a contractual relationship, for example, when the contact is of a general nature. Our legitimate interest in the latter case is to respond to your request in a reasonable manner. 

We delete the data collected in this context after storage is no longer required (depending on the respective purpose of the contact) or restrict processing if there are statutory retention obligations. 


3. Disclosure of data to third parties

The data transmitted as part of your application will be transmitted using TLS encryption and is stored in a database for which our company is responsible and which is operated by our dataprocessor Personio GmbH, Rundfunkplatz 4, 80335 Munich, Germany. We have concluded a corresponding data processing agreement in accordance with Article 28 para. 3 GDPR with Personio GmbH, which offers a personnel administration and applicant management software and stores data exclusively on ISO-certified servers in Germany.

To enable email communication through the email address hr@data4life.care, making video calls and sending appointment requests, Data4Life uses Google Workspace provided by our data processor Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes your contact information, for example, email address and the content of your email. Google stores your personal data on servers based in the European Economic Area (EEA). However, we cannot exclude that Google accesses and therefore transfers your personal data to the United States. We have concluded a data processing agreement pursuant to Art. 28 para. 3 GDPR and EU standard contractual clauses with Google. 

We regularly audit our processors on the level of protection provided by the standard contractual clauses and, if necessary, take additional measures to ensure an appropriate level of protection.

If you participate in a Coding Challenge, your personal data collected during the Coding Challenge will be processed by our data processor Alva Labs AB, Luntmakargatan 66, 113 51 Stockholm, Sweden. We have concluded a corresponding data processing agreement with Alva Labs AB in accordance with Article 28 para. 3 GDPR.

If you apply for a position that is offered in Singapore, we will transfer your data to D4L data4life Asia Limited, 68 Circular Road #02-01, Singapore 049422 to carry out the application process. 


4. Employer Rating Websites

a. Kununu

As a part of employer branding, Data4Life interacts with current and former employees as well as applicants who anonymously review the company. Data4Life uses the employer rating portal Kununu. Kununu is a product by NEW WORK SE, Am Strandkai 1, 20457 Hamburg, Germany. Kununu processes your voluntarily entered data and, if applicable, evaluates content shared or viewed by you.  Information on what data is processed by Kununu and for what purposes can be found in Kununu's privacy policy: https://privacy.xing.com/en/privacy-policy


b. Glassdoor

As a part of employer branding, Data4Life interacts with current and former employees as well as applicants who anonymously review and inform about the organization which may include salary, provided company benefits, CEO ratings and uploading photos on the employer rating portal Glassdoor. Glassdoor is a product by Glassdoor, Inc., 300 Mission Street, 16th Floor, San Francisco, CA 94105, USA. The responsible establishment for customers in the European Economic Area is Glassdoor Hiring Solutions Ireland Ltd., 70 Sir John Rogerson’s Quay, 662881, Ireland. Data4Life has concluded EU standard contractual clauses with Glassdoor. You can find more information on how Glassdoor processes your personal data in their privacy policy: https://www.glassdoor.com/privacy/index.htm


5. Rights of data subjects

If we, as the controller, process personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular:

  • Right of access (Art. 15 GDPR),

  • Right to rectification (Art. 16 GDPR),

  • Right to erasure (Art. 17 GDPR, “right to be forgotten”),

  • Right to restriction of processing (Art. 18 GDPR),

  • Right to object to processing (Art. 21 GDPR),

  • Right to data portability (Art. 20 GDPR).

If your personal data is processed with your consent, you have the right to withdraw this consent under Art. 7 para. 3 GDPR.

To claim your data subject rights with regard to the data processed in this online application procedure, please contact our data protection officer (see No. 1) or the human resources department at hr@data4life.care.

You also have the right to complain to a data protection supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement if you consider that the processing of personal data related to you is unlawful. The responsible supervisory authority for us is:

Die Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht
Stahnsdorfer Damm 77
14532 Kleinmachnow
Germany

Telephone: + 49 33203/356-0
Telefax: + 49 33203/356-49
Email: poststelle@lda.brandenburg.de

6. Additional information on your right to objection

Please note that if your personal data is processed on the basis of a legitimate interest pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR and/or if your personal data is processed for the purposes of direct marketing, you have the right to object to the processing of your personal data at any time.


Last updated: Jan 2024

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.