Graswald GmBH (referred to as "we," "us," or "our"), with its registered office in Germany, is committed to protecting the privacy and security of your personal data. This Data Privacy Statement describes how we collect, use, and process the personal data of job applicants for both domestic and international roles.2. Data Controller
The data controller responsible for the processing of your personal data is:
Graswald GmBH
Berckhusenstraße 89 30625 Hannover Germany
simon@graswald.ai
3. Data Collection and Types of Personal Data
We collect and process personal data that you provide to us directly during the application process, which may include:
Contact Information: Name, address, phone number, email address.
Application Documents: CV/résumé, cover letter, references, academic records, and professional certifications.
Job-Related Information: Current and desired salary, employment history, qualifications, and other information relevant to the application.
Identification Data (where legally required): Information necessary to verify your identity and your right to work in the relevant jurisdiction.
Special Categories of Data: In limited circumstances and where permitted by law, we may process data such as information about your health, trade union membership, or criminal records. This is only done where strictly necessary for the position, or with your explicit consent.
4. Purposes and Legal Basis for Processing (GDPR)
We process your personal data for the following purposes, based on the corresponding legal grounds under the GDPR:
Purpose of Processing | Legal Basis (GDPR) |
Recruitment and Selection: Evaluating your suitability for employment, managing the hiring process, and communicating with you. | Art. 6(1)(b) GDPR (Performance of a contract or steps prior to entering a contract): Processing is necessary to take steps at your request prior to entering into an employment contract. |
Compliance: Meeting legal and regulatory requirements (e.g., equal opportunity, visa requirements). | Art. 6(1)(c) GDPR (Legal obligation): Processing is necessary for compliance with a legal obligation to which we are subject. |
Talent Pool: Retaining your application for future opportunities (with your permission). | Art. 6(1)(a) GDPR (Consent): We will seek your explicit consent to keep your data for this purpose. |
Defense of Legal Claims: Establishing, exercising, or defending legal claims. | Art. 6(1)(f) GDPR (Legitimate interests): Our legitimate interest in protecting our legal rights. |
5. Recipients of Personal Data
Your personal data may be shared with the following parties:
Internal Departments: Relevant employees, including the HR team, hiring managers, and interviewers.
Service Providers: Third-party providers who assist us with the recruitment process, such as Applicant Tracking System (ATS) providers, IT service providers, and background check providers. These parties are contractually bound to maintain confidentiality and comply with data protection laws.
6. International Data Transfers
As we recruit internationally, your personal data may be transferred to, and processed in, countries outside of the European Union (EU) or European Economic Area (EEA).
Adequacy: Where data is transferred to a country recognised by the European Commission as providing an adequate level of data protection, no further safeguards are necessary.
Lack of Adequacy: If data is transferred to a country not deemed adequate, we will implement appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs), or rely on a derogation, such as your explicit consent, to ensure your data receives the same level of protection as it would within the EU/EEA.
7. Data Retention
We will retain your personal data for the duration of the recruitment process.
If your application is successful, your data will be transferred to your employee file and retained in accordance with our employee privacy policy.
If your application is unsuccessful, we will delete or anonymise your data within [Specify a period, e.g., 6 months] after the application process is complete, unless:
Retention for Talent Pool: We have obtained your explicit consent to retain your data for future vacancies, in which case we will retain it for up to [Specify a period, e.g., 2 years].
Legal Necessity: We are required by law to retain the data for a longer period (e.g., to defend against legal claims).
8. Your Rights (Data Subject Rights under GDPR)
Under the GDPR, you have the following rights regarding your personal data:
Right of Access: To request a copy of the personal data we hold about you.
Right to Rectification: To request the correction of inaccurate or incomplete data.
Right to Erasure ("Right to be Forgotten"): To request the deletion of your personal data under certain conditions.
Right to Restriction of Processing: To request that we limit the way we use your data.
Right to Object to Processing: To object to the processing of your data, particularly when based on legitimate interests.
Right to Data Portability: To receive your personal data in a structured, commonly used, and machine-readable format.
Right to Withdraw Consent: Where we rely on your consent, you have the right to withdraw it at any time.
To exercise any of these rights, please contact the Data Protection Officer (DPO) or the contact person listed in Section 2.9. Data Protection Officer (DPO)
Graswald GmBH has appointed a Data Protection Officer who can be contacted for all questions and concerns regarding the processing of your personal data:
Data Protection Officer
simon@graswald.ai
You also have the right to lodge a complaint with a supervisory authority, particularly the one in the German federal state where our company is headquartered.
Processing of (personal) data by the operator of the recruitment website
General information
This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (
https://www.personio.com/legal-notice/).
Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio.
In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.
The controller
The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact:
privacy@personio.com
Access logs (“server logs”)
Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual.
Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG.
Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web.
These access logs are stored for a period of up to 7 days. There is no right to object to this.
Error logs
So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG.
When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected.
These error logs are stored for a period of up to 7 days. There is no right to object to this.
Use of cookies
So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”).
On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR).
Period of storage: up to 1 month or until the end of the browser session
Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.
Rights of data subjects
If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR.
To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).
Concluding provisions
Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.