The following policy details the personal data we collect from you, and the purpose for which it is collected. This policy applies to all potential job candidates as well as our employees, temporary or agency workers and self-employed contractors both current and former.
Firefish Software Limited (SC370891) takes the issue of security and data protection very seriously and will strictly adhere to the General Data Protection Regulation (EU) 2016/679 (“GDPR”) which is applicable from the 25th May 2018, and all UK data protection legislation. Firefish Software Limited is notified as a Data Controller with the Office of the Information Commissioner under registration number Z2405571, and we are the data controller of any personal data that you provide to us. Firefish Software (“the Company”) acts as an employer. We will act as a data controller so that we can consider your application and keep you updated on potentially suitable roles with our company.
Our data protection lead may be contacted by you in relation to any queries or concerns or you have regarding your Personal Data or if you wish to exercise any of your rights. Please contact Richard Mullan at dpo@firefishsoftware.com or 0141 648 8520.
Last updated: August 2018
1. What are our Obligations?
The law says that the personal information we hold about you must be:
- Used lawfully, fairly and in a transparent way.
- Collected only for legitimate purposes that we have clearly explained to you and not used in any way that is incompatible with those purposes.
- Relevant to the purposes we have told you about and limited only to those purposes.
- Accurate and kept up to date.
- Kept only for as long as is necessary for the purposes we have told you about.
- Kept securely.
2. Personal information that we collect
Firefish Software will collect your personal data (which may include sensitive personal data) and will process your personal data for the purposes of considering your application to a position with Firefish Software, or to provide you with information relating to positions which may be of interest to you based upon the information you have provided and agreed to.
2.1 Personal Information
During our recruitment process we will collect the following information:
- Name
- Contact information such as email addresses and telephone numbers
- Demographic information such as post code
- Current and historic employment details
- CV
- Employment preferences
- IP address (automatically collected)
- Web browser type and version (automatically collected)
- Operating system (automatically collected)
- A list of URLS starting with a referring site, your activity on this Website, and the site you exit to (automatically collected)
- Cookie information (see clause 7 below)
2.2 Sensitive personal data "Special Categories"
- Eligibility to work in the UK
- Disability/health condition relevant to the role
- Criminal convictions
3. How we process your Data
You agree to the Company processing the above personal data for the following purposes:
- For us to provide you with updates on job applications to Firefish Software either directly via our website or via a third party Job board.
- Enabling you to submit your CV, apply online for our jobs, review and update your personal data and preferences, or to subscribe to alerts about jobs we think may be of interest to you;
- Verifying details you have provided to request information (such as references, qualifications and potentially any criminal convictions, to the extent that this is appropriate and in accordance with local laws)
- If you choose to subscribe into receiving details of reports, promotions, offers, events and general information which we think might be of interest to you
- When executing candidate sourcing for a position with the Company, and a candidate has placed their details publicly on a job board, social network, or publicly accessible 3rd party source. We would make contact with you to discuss this opportunity or establish interest in working with Firefish Software.
The “special categories” of particularly sensitive personal information listed above require higher levels of protection. We need to have further justification for collecting, storing and using this type of personal information. We may process special categories of personal information in the following circumstances:
- In limited circumstances, with your explicit written consent (which you are entitled to withdraw at any time);
- Where we need to carry out our legal obligations;
- Where it is needed in the public interest, such as for equal opportunities monitoring or in relation to our occupational pension scheme;
- Where it is needed to assess your working capacity on health grounds, subject to appropriate confidentiality safeguards.
Less commonly, we may process this type of information where it is needed in relation to legal claims or where it is needed to protect your interests (or someone else’s interests) and you are not capable of giving your consent, or where you have already made the information public.
We will use your particularly sensitive personal information in the following ways:
- We will use information relating to absence which may include sickness absence or family related leave to comply with employment and other laws.
- We will use information relative to health where appropriate in the context of our provision of private medical cover.
- We will use information about your physical or mental health, or disability status, to ensure your health and safety in the workplace and to assess your fitness to work, to provide appropriate workplace adjustments, to monitor and manage sickness absence and to administer benefits.
- We will use information about your race or national or ethnic origin, religious, philosophical or moral beliefs, or your sexual life or sexual orientation, to ensure meaningful equal opportunity monitoring and reporting.
- Processing relates to personal data which are manifestly made public by the individual.
Your personal data is required by law and/or is a requirement necessary to enter into a contract. You are obliged to provide the personal data as information is necessary for the conclusion of a contract in the interest of the data subject between the controller and the data subject. Failure to provide the personal data would mean that we would be unable to consider your application and/or set up a contract of employment.
You have a right to unsubscribe or request to remove your details at any time via your online record or by emailing info@firefishsoftware.com and informing the Company that you wish to do so.
4. Third Party Websites and Services
Firefish may, from time to time, employ the services of other parties for dealing with matters that may include, but are not limited to, recruitment, delivery of services, search engine facilities, advertising and marketing. The providers of such services do not have access your personal data unless it is necessary for them to perform the services that Firefish requests. Any data that is shared is limited to only what is required for them to provide the service. Any use for other purposes is strictly prohibited. Furthermore, any data that is processed by third parties must be processed within the terms of this statement and in accordance with the General Data Protection Regulation (GDPR). This may include the transfer of your personal data to one or more countries outside the UK, or the European Economic Area.
5. Data retention
Firefish will retain your personal data only for as long as is necessary. Different laws require us to keep different data for different periods of time.
Once employed, we must also keep your payroll records, holiday pay, sick pay and pensions auto-enrolment records for as long as is legally required by HMRC and associated national minimum wage, social security and tax legislation. These details are provided at the point of induction into your position with Firefish.
Where Firefish has obtained your consent to process your personal and sensitive personal data, we will do so for 2 years. Upon expiry of that period Firefish will seek further consent from you. Where consent is not granted Firefish will cease to process your personal data and sensitive personal data.
The General Data Protection Regulation (GDPR) regulates the way that we manage the data of job applicants. If you apply for a position with Firefish and are unsuccessful in your job application, we would like to keep your details (your data) on file so that we can contact you if a further vacancy arises for which you may be suitable.
Under GDPR, we need your consent to do this, and we are asking you to provide your consent for us to keep your data by agreeing to the terms of this statement.
The Company is committed to complying with the GDPR with regard to processing your data. If you are to give consent, it must be:
- Freely given
- Specific
- Informed
- Unambiguous
You are entirely in control of your decision to give consent to our use of your data as requested in this form. You do not need to give consent. There will be no repercussions if you choose to withhold consent and your data will be deleted/destroyed.
6. Your Rights
You have the absolute unrestricted right to withdraw your consent at any time. Please be aware that you have the following data protection rights:
- The right to be informed about the personal data Firefish processes on you
- The right of access to the personal data Firefish processes on you
- The right to rectification of your personal data
- The right to erasure of your personal data in certain circumstances
- The right to restrict processing of your personal data
- The right to data portability in certain circumstances
- The right to object to the processing of your personal data that was based on a public or legitimate interest
- The right not to be subjected to automated decision making and profiling
- The right to withdraw consent at any time
If the purpose of using the data for which we have received your consent changes, we will seek new consent, setting out the new purpose.
7. Security
Data security is of great importance to Firefish Software and to protect your Data we have put in place suitable physical, electronic and managerial procedures to safeguard and secure Data collected online.
8. Cookies
Firefish Software may set and access Cookies on your computer. Cookies may be placed on your computer when you visit certain parts of the website. Firefish Software use these to identify and track visitors, their usage of the website, their access preferences and for advertising. Currently we do not have the technical ability to get your express permission to opt out of our cookies so we encourage you to use your browser settings if you want to control these. You can view our full Web Privacy & Cookies Policy here.
9. Changes to this Policy
Firefish Software reserves the right to change this Candidate Agreement from time-to-time as we deem necessary, or as may be required by law. Any changes will be immediately posted on the website and we will additionally notify you of any significant changes by sending a notice to your primary email address as specified in your Firefish Software account or by a notice on the website. You are deemed to have accepted the revised terms of the Candidate Agreement on your first use of the website following the alterations.
Please check back frequently to see any updates or changes to our Candidate Agreement.
10. Complaints or Queries
If you wish to complain about this privacy notice or any of the procedures set out in it please contact: Richard Mullan, dpo@firefishsoftware.com / 0141 648 8520.
You also have the right to raise concerns with Information Commissioner’s Office on 0303 123 1113 or at https://ico.org.uk/concerns/ if you believe that your data protection rights have not been adhered to.
11. Applicant declaration
By agreeing to the Candidate Agreement I confirm that:
- I am giving my consent to the Company to use my data as indicated above
- I understand that I am not required to give consent to the Company’s use of my data in the ways set out in this form. Where I have done so, I have done so of my own free will
- I understand the ways in which the Company wishes to use my data as set out above
- I understand there will be no repercussions if I refuse to give consent in this form
- I know that I can withdraw my consent at any time.