RECRUITMENT PRIVACY STATEMENT
XP PLC is committed to protecting the privacy of your personal information
This statement explains how XP PLC treats the personal information you as an individual submits and we collect via the SmartRecruiters platform (“SmartRecruiters”) during the recruitment process and tells you about your privacy rights and how the law protects you. As used in this privacy statement, “XP PLC”, “we”, and “us” refer to XP PLC. The data controller of your personal information provided to us in connection with a specific application will be XP PLC.
This privacy statement applies to personal data provided to us, either by you or by others (such as your employer or a third party such as LinkedIn). When collecting and using personal data our policy is to only collect what we need and to be transparent about why and how we process personal data. We may use personal data provided to us for any of the purposes described in this privacy statement or as otherwise stated at the point of collection. The term “personal information” also refers to “personal data” and means any information about an individual from which that person can be identified.
By using SmartRecruiters and providing personal information to us and confirming your agreement to this privacy statement, you acknowledge you have read this privacy statement and to the extent your consent is necessary and valid under applicable law, you consent to the collection, use and disclosure of such personal information, including any sensitive personal information you choose to provide by XP PLC and any third party recipients in accordance with this privacy statement.
The information we collect and how we collect it
To help us with the recruitment process and your application for a position with XP PLC we will collect personal information about you from our Smart Recruiters platform, from third party websites and applications that you agree may share your information with us and during the recruitment process.
The recruitment process may include a telephone, video or face to face interview in addition to a technical assessment so we can assess your suitability for the role you’ve applied to.
We will also use your data to update you on the status of your application, invite you to interviews, extend you an offer of employment as well as inviting you to join our talent community.
If you log in to SmartRecruiters to progress your application for employment with XP PLC you will be asked to provide information about you (including your name, email address, telephone number, address, your academic or professional qualifications, experiences, CV/Resume).
In connection with your application, you may choose to provide other information about yourself such as a photograph or additional biographical information; we will use and process that information in the manner described in this Privacy Statement.
XP PLC may seek additional data and/or verify your personal information by contacting your references, referrer and other third parties.
XP PLC may also collect information about you from publicly available information sources.
As permitted under applicable law, may also conduct background checks, criminal record checks and assessments and use and store such information during the recruitment process.
The information you provide to XP PLC via SmartRecruiters, both now and in the future, will be held and processed by or on behalf of XP PLC for purposes related to current or future employment with XP PLC.
Third party website and applications
You may also choose to import information about yourself into SmartRecruiters from third party sites and applications (for example from LinkedIn).
Sensitive personal information
XP PLC will not require you to provide sensitive personal information about yourself through SmartRecruiters, except to the extent the collection of such information is required under applicable law.
Updating and accessing your information
It is your responsibility to keep your personal information accurate and up to date and to inform us of any changes. You can access your SmartRecruiters profile at any time to review or update your personal information.
Using your information
Any personal information you submit through SmartRecruiters will be used by us to assist with recruitment activities as set out below. We use your data on the basis of the consent you have given to us and this consent can be withdrawn by you at any time by your deletion of your SmartRecruiters profile.
XP PLC or any of its associated companies with which your personal information is shared may use your personal information for any or all of the following purposes:
- Managing your application(s) for employment, evaluating you for open positions throughout the XP PLC network, and managing your candidate profile.
- Evaluating your suitability for employment (including for example providing your personal information to third parties to conduct background checks).
- Sending you email notifications and other announcements, requesting additional information, or otherwise contacting you about your candidacy, conducting statistical analyses and reports including for example regarding usage of SmartRecruiters, demographic analyses of candidates, reports on XP PLC recruitment activities, and analyses of candidate sourcing channels.
- Using data for making an offer.
- Administering and managing SmartRecruiters and communicating with you about it; and relating to any other purposes for which you provided the information to XP PLC.
Should you become an employee of XP PLC or any of its associated companies any personal information you submit through SmartRecruiters may be used in connection with your employment as permitted by applicable laws and we will no longer rely on consent as the legal basis for processing that information.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
Data retention – how long we will use your personal information for
We will retain your personal data for as long as is reasonably necessary for the purpose(s) for which it was collected (including as required by applicable law or regulation).
If your application is unsuccessful, XP PLC may retain and use the information you provided to XP PLC via SmartRecruiters for a reasonable period to deal with any matter which may arise in connection with your application, for purposes of contacting you regarding other employment opportunities.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
Details of retention periods for your personal data are available in our retention policy which you can request from us by contacting us.
We may keep your personal data for longer periods where extended retention periods are required by law or regulation and to establish, exercise or defend our legal rights.
In some circumstances you can ask us to delete your data: see Individuals’ rights and how to exercise them below for further information.
When and how we disclose personal data and locations of processing
We may share your personal data with the parties and for the purposes set out below.
When we transfer or share personal data, we put contractual arrangements and security mechanisms in place that comply with our data protection, confidentiality and security standards and applicable laws and regulations.
We may share your personal information with XP Power Limited group companies
XP PLC is a global business with locations around the world. Your personal information may be transferred and disclosed to other XP PLC locations and group companies in connection with your application for employment. As a result your personal information may be transferred and stored outside the country where you are located. This includes countries and regions outside the European Economic Area (EEA) and countries or regions that do not have laws that provide specific protection for personal information. For a list of countries and regions where XP PLC operate please see Where we operate
We may need to disclose your data to external third parties
We use external third parties to help provide, run, and manage our internal IT systems and to provide other services to us. For example, providers of information technology, cloud-based software as a service provider, identity management, website hosting and management, data analysis, data back-up, security and storage services. We also may use third parties when arranging for the electronic execution of a document.
The third party providers may use their own third party subcontractors that have access to personal data (sub-processors). It is our policy to use only third party providers that are bound to maintain appropriate levels of security and confidentiality, to process personal information only as instructed by XP PLC, and to flow those same obligations down to their sub-processors.
Our external third parties include:
- Service providers (acting as processors) who provide IT and system administration services such as:
- SmartRecruiters who are based in the EEA
- Amazon Web Services which is our cloud service provider
- Microsoft which provides software and services to us
- WhatsApp and WeChat which provide messaging services to us
- Docusign which enable electronic offers
- Professional advisers acting as processors or joint controllers including lawyers, auditors and insurers
- Law enforcement, regulatory and other government agencies, and to professional bodies and other third parties, as required by and/or in accordance with applicable law or regulation. This includes disclosures outside the country or region where you are located.
We share your data within the XP PLC Group. This will involve transferring your data outside the UK and the EEA. In addition, many of our external third parties are based outside the UK and the EEA so their processing of your personal data will involve a transfer of data outside the UK and the EEA.
Where we collect your personal information from within the EEA or the UK and need to transfer it outside the UK or EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
- To a recipient in a jurisdiction approved by the European Commission and/or the UK Information Commissioner (as applicable) as offering an adequate level of protection for personal data.
- Under an agreement which covers the EU or UK requirements (as applicable) for the transfer of personal data to data processors or data controllers outside the EEA or the UK (as applicable)
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the UK or the EEA.
Individual’s rights and how to exercise them
You may have certain rights under your local law in relation to the personal information we hold about you. In particular you may have a right to:
- Request a copy of personal information we hold about you.
- Ask that we update the personal information we hold about you or correct such personal information that you think is incorrect or incomplete.
- You may delete personal information that we hold about you or restrict the way in which we use such personal information.
- Restrict or object to our processing of your personal information.
- Request a copy or transfer of your data (data portability); and/or
- Withdraw your consent to our processing of your personal information
- To exercise any of the above-mentioned rights, please contact us as set forth below. We will process any requests in accordance with applicable law and within a reasonable period. We recommend you include documents that prove your identity and a clear and precise description of your request. We may charge for a request to access your information, if permitted by applicable law.
Withdrawal of your consent and deletion of your personal data
You may request that your personal information be deleted from SmartRecruiters and to the extent the processing of your information is based on consent, revoke your consent to XP PLC’s processing of your personal data.
Because XP PLC must process your personal data to consider you for a position as part of the recruitment process, if you delete your personal information from SmartRecruiters, XP PLC may need to terminate your application.
XP PLC may retain certain information related to your application for a reasonable but limited period to meet applicable legal or records retention requirements.
XP PLC has implemented generally accepted standards of technology and operational security to protect your personal information from loss, misuse, unauthorised access, alteration or destruction.
XP PLC has put in place appropriate technical and organisational security measures to prevent any unauthorised or unlawful disclosure or processing of personal information and the accidental loss or destruction of or damage to personal information. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
If you have any questions about this privacy statement or to exercise a legal right in relation to your personal data, or an enquiry if you have a question or complaint about the handling of your personal data, please contact us at firstname.lastname@example.org
You may also have the right under applicable law to lodge a complaint with your local supervisory authority responsible for data protection matters. We would however, appreciate the chance to deal with your concerns before you approach the relevant supervisory authority so please contact us in the first instance.
Changes to this privacy statement
This privacy statement was last modified in September 2022. We may update this privacy statement at any time by publishing an updated version here. The new modified or amended privacy statement will apply from that revision date. Therefore, we encourage you to review this privacy statement periodically to be informed about how we are protecting your information.