BUYIN DATA PRIVACY INFORMATION
Data protection and data security have a high priority for BuyIn. We therefore attach great importance to the protection of personal data in all business processes and ensure the compliance with all applicable data protection and data security laws.
- you visit our Web site (see sec. A),
- we maintain business relations with you or a company to which you belong (suppliers, service providers, other contractual partners, together: “Business Partners”, sec. B), or
- you have contacted us with a request by email (sec. C), or
- you want to apply for a job at BuyIn by sending us an email or using the Career section of our Web sites (sec. D).
BuyIn will process your data in accordance with the Regulation (EU) 2016/679 (“General Data Protection Regulation”, hereinafter the “GDPR”), the data protection provisions of the German Federal Data Protection Act (“Bundesdatenschutzgesetz”) and the French Law on Computer Technology and Freedom (“Loi informatique et liberté”).
A. DATA PRIVACY INFORMATION FOR VISITIORS TO THE BUYIN WEB SITE
Who is responsible for data processing when you visit our web site?
BuyIn SAS, 12, rue Rouget de Lisle, 92442 Issy-les-Moulineaux, France (“BuyIn SAS”), and BuyIn GmbH, Friedrich-Ebert-Allee 71, 53175 Bonn, Germany (“BuyIn GmbH”), are responsible for processing your personal data and act therefore jointly as data “controllers” within the meaning of Articles 4 No. 7 and 26 GDPR.
What data do we use?
When you visit our Web sites our Web server temporarily registers the domain name or the IP address of the requesting computer as well as the date of access, the HTTP request, method, return code, the HTTP response code and the client agent used.
Why do we process your data (purpose of the processing) and on what legal basis ?
BuyIn will process personal data in order to make our Web sites accessible and for the purpose of system security, The legal basis for processing these personal data as Article 6 para. 1 sub-para 1 (f) GDPR.
How long will my data been stored?
Please find here information on the processing of personal data when you log in to our account „My.BuyIn.Pro“.
B. DATA PRIVACY INFORMATION FOR BUSINESS PARTNERS OF BUYIN
Who is responsible for data processing?
For any processing of personal data in the course of their corporation with their Business Partners both entities, BuyIn SAS and BuyIn GmbH are equally responsible and act therefore jointly as data controllers within the meaning of Article 4 No. 7 GDPR
What personal data do we use?
BuyIn SAS and BuyIn GmbH will process the following categories of personal data:
- contact information, especially first name and last name, title if applicable, address, telephone number, email address,
- bank account details.
Which data sources do we use?
BuyIn SAS and/or BuyIn GmbH receive personal data only either directly from the data subjects (e.g. when corresponding with contact persons at the Business Partner) or from other contacts at the Business Partner as the employer of the data subject.
Why do we process your data (purposes of data processing) and on what legal basis?
BuyIn SAS and BuyIn GmbH will process the personal data in order to establish, implement and execute the contractual relationship with their respective Business Partner. The legal basis for this processing activities is, insofar as personal data of the Business Partner is processed, Article 6 para 1 sub-para (b) GDPR; otherwise, Article 6 para 1 sub-para 1 (f) GDPR applies.
How long will my data be stored?
Personal data will be stored for as long as it is necessary to process these for the purposes described above, unless statutory provisions prescribe a longer storage period.
C. DATA PRIVACY INFORMATION FOR SENDERS OF EMAIL REQUESTS
If you send an email to one of the BuyIn email addresses shown on our Web sites your email address and any personal data you disclose in your email will be processed by SAS and/or BuyIn GmbH as the data controller within the meaning of Article 4 no. 7 GDPR. Personal data transmitted to SAS and/or BuyIn GmbH will be used exclusively in order to process your enquiry. The legal basis for processing data is Article 6 para 1 sub-para 1 (f) GDPR. The data will be erased when they are no longer necessary for these purposes, unless a longer storage period is required by applicable law.
D. DATA PRIVACY INFORMATION FOR USERS OF OUR CAREER SECTION
Who is responsible for data processing and whom can I contact?
BuyIn SAS and BuyIn GmbH are equally responsible and act therefore jointly as data controllers within the meaning of Article 4 No. 7 GDPR
What data do we use?
BuyIn will process personal data that has been made available by the candidate. We may also collect personal data from third parties, such as references supplied by former employers, and to whom you have made your data available for sharing with potential employers.
BuyIn will in particular process the following personal data:
- Personal data allowing the candidate to be identified, e.g. name, surname, data of birth, phone number, address,…
- Data regarding the professional background in order to select the candidate: e.g. languages, education, working experience, etc.
- Application letter
- Other documents made available by the candidate
Why do we process your data (purpose of the processing) and on what legal basis?
Processing personal data from job applicants allows BuyIn to manage the recruitment process, assess and confirm candidate’s suitability for employment and decide to whom to offer a position. BuyIn processes personal data for the purpose of recruitment on the basis of Art. 6 1. (b) General Data Protection Regulation as well as of § 26 of the German Federal Data Protection Act (“Bundesdatenschutzgesetz”) in conjunction with Art. 88 of the GDPR if you apply for a position at BuyIn GmbH.
Who has access to my data?
Your information may be shared within BuyIn for the purposes of the recruitment process. This includes members of the Human Ressources team, interviewers and managers involved with the open position.
How long will my data be stored?
If your application is successful, personal data gathered during the process will be transferred to your Human Resources files and processed for the performance of your employment contract. It will be processed as long as it is required to fulfill our contractual and legal obligations.
If your application does not result in a job offer right away, BuyIn may retain your personal data after the application process has been completed for a maximum time period of six months in order to notify you of future job openings at BuyIn We will ask you for consent before we keep your data for a longer period and you are free to withdraw your consent at any time by contacting email@example.com. At the end of that period, or once you withdraw your consent, your data will be deleted.
To what extent does automated decision-making take place?
To create and execute the employment relationship we generally do not use fully automated decision-making in accordance with Art. 22 of the GDPR. If we use these processes in individual cases, we will inform you separately in accordance with legal requirements.
E. RECIPIENTS OF YOUR DATA
For certain technical data processing tasks, BuyIn is assisted by third party service providers who will receive access to your personal data to provide such services. Those service providers have been carefully selected and meet high data privacy and data security standards. They are subject to strict duties of confidentiality and process data only on behalf and in accordance with the instructions of BuyIn.
F. DATA TRANSFERS TO THIRD COUNTRIES
As a general rule, your personal data are processed within the European Union especially in France and Germany. If, in exceptional cases BuyIn needs to transfer your personal data outside the European Union (i.e., in third countries), this is done only if you have explicitly given your consent, if it is required so we can provide you with services, or if it is prescribed by law (Art. 49 GDPR). Furthermore, your data is processed in third countries only if certain measures ensure a suitable level of data protection (e.g EU Commission’s adequacy decision or suitable guarantees, Art. 44 et seq. GDPR).
G. YOUR DATA PRIVACY RIGHTS
You have the right to be provided with information about your personal data that are stored by BuyIn and, if certain legal requirements are satisfied, rights to rectification, erasure, and restricted processing. In addition, you have the right to receive personal data that you have made available to us in a structured, standard, and machine-legible format. This includes the right to transfer such data to another controller. If technically feasible, you may also demand that BuyIn transfer your personal data directly to other controllers.
If processing of your personal data is based on a weighing of interests within the meaning of Article 6 para 1 sub-para 1 (f) GDPR, you have the right to object to this processing under the conditions described in Article 21 GDPR.
You may also lodge complaints with a data protection supervisory authority.
H. CONTACT DETAILS
If you want to exercise your data privacy rights, please contact BuyIn at firstname.lastname@example.org or BuyIn SAS, 12, rue Rouget de Lisle, 92442 Issy-les-Moulineaux, France, or BuyIn GmbH, Friedrich-Ebert-Allee 71, 53113 Bonn, Germany