Privacy Statement

  1. WHO ARE WE, AND WHAT DO WE DO?
  2. We are MrWork B.V. We offer services in the field of online recruitment processes through social media, search engines and other online marketing ("Services"). You can find more information about our Services on www.mrwork.nl ("Website").

    This privacy policy applies to the use of our Website and the Services we offer.

  3. WHAT IS THIS?
  4. This is a Privacy Policy. This document explains what kind of personal data we collect through our Website and Services. We also explain the purposes for which we use the data and how we secure and store it.

  5. PRIVACY AND RELEVANT LEGISLATION
  6. Your privacy is very important to us. We comply with the new General Data Protection Regulation ("GDPR"), which replaced the various privacy laws in European member states as of May 25, 2018. This legislation will be referred to below as the "Relevant Legislation".

  7. APPLICABLE LAW AND COMPETENT COURT
  8. Personal data refers to any information by which you can be directly or indirectly identified. This definition is in line with Relevant Legislation. Incidentally, this is a broad definition: even dynamic IP addresses qualify as personal data under the circumstances.

  9. OUR POSITION AS PROCESSOR AND DATA CONTROLLER
  10. We collect and process most personal data on behalf of our customers in the context of our Services. Our customers determine the purpose and means of these personal data processing operations, meaning they act as "Data Controller" within the meaning of the Relevant Legislation. We process this personal data only in accordance with our customers' instructions and not for our own purposes. Therefore, we act as a "Processor" within the meaning of the Relevant Legislation.

    Apart from processing personal data on behalf of our customers, we also collect and process some personal data for our own purposes. In this context, we ourselves act as Data Controller within the meaning of the Relevant Legislation.

  11. WHAT PERSONAL DATA DO WE COLLECT?
  12. As a Processor

    As a Processor, we collect and process the following personal data on behalf of our customers:

    Data of applicants
    • Name;
    • Email;
    • Phone number (optional);
    • Personal details described in motivation;
    • Personal details as described in CV.

    As Data Controller

    As the Data Controller, we collect and process the following personal data:

    Data of potential applicants who email a job offer to themselves
    • Email address.
    Contact details of our customers
    • Company name;
    • Phone number;
    • Email address;
    • Position within the company;
    • Company address;
    • Other data shared via email, contact form, phone or other messaging services;
    • Bank account number;
    • VAT number;
    • Chamber of Commerce number.
    Login details of our users' accounts
    • Name;
    • Email;
    • User ID;
    • Password;
    • IP address;
    • Browser data;
    • Registration details;
    • Registration time;
    • History time of login;
    • History time of password change.
    Contact details of potential customers of persons filling in a form on, for example, our website
    • Name (optional);
    • Company name (optional);
    • Phone number (optional);
    • Email address;
    • Position within the company (optional);
    • Other data shared within the message (optional).

  13. WHAT WILL PERSONAL DATA BE USED FOR?
  14. As a processor

    Data of applicants

    We process personal data on behalf of our customers solely to transfer an applicant's data to the customer. This includes that we will never view this personal data for our own purposes or store a copy for ourselves. Furthermore, we will also delete personal data as soon as our customers request it. These and other agreements are set out in the data processing agreement [link] that we enter into with our customers.

    Data of potential applicants

    We process potential applicants' data on behalf of our customers solely to provide our Services to them. This includes using trackers to show personalised ads (also known as 'interest-based ads' or 'retargeting') and to measure the conversion of an online campaign. We will delete personal data as soon as our customers request it. These and other agreements are set out in the data processing agreement [link] we enter into with our customers.

    As Data Controller

    We use personal data as a Data Controller for the following purposes:

    Details of potential applicants emailing the job to themselves
    • This data is used to send an email as a reminder to yourself or to alert an acquaintance to a vacancy. This data is only used to enable the email to be sent. We do not use this data for other purposes or share it with our customers or other parties.
    Contact details of our customers
    • To identify our customers, to maintain contact about the cooperation and to send our customers invoices for the Services we perform for them.
    Login details of our users' and customers' accounts
    • To create and manage user and customer accounts on our Website;
    • Recognition of the logged-in user;
    • Protection of data in case of misuse via the same IP address;
    • Securing IP address when requesting a password reset.
    Contact details of potential customers of persons filling in forms on, for example, our website
    • To approach and inform companies' recruitment and HR departments about our Services.
    Data of potential customers and job applicants (at MrWork)

    We process the data of potential customers and job applicants (at MrWork) to use trackers to show personalised ads (also known as 'interest-based ads' or 'retargeting') and to measure the conversion of an online campaign.

  15. HOW LONG DO WE KEEP PERSONAL DATA?
  16. As a Processor

    As a Processor, we retain personal data for our customers for as long as the relevant customer uses our Services and uses the personal data in that context. If the cooperation with the customer ends, we will keep the data for another two (2) months. After this period, we will delete or destroy the personal data and all copies thereof, unless we are required by law to keep the data for longer.

    As Data Controller

    As the Data Controller, we delete personal data as soon as it is no longer necessary for the above purposes. Personal data will never be kept longer than five years from the date it was last changed. We will retain data on our own staff for as long as required by law.

  17. DO WE SHARE YOUR PERSONAL DATA WITH OTHERS?
  18. As a Processor

    As a Processor, we process personal data on behalf of our customers only according to their instructions. We will never share this personal data with anyone unless our customers instruct us to do so.

    However, we may use the services of "Sub-Processors" (on behalf of our customers), for example, for data storage and monitoring recruitment campaigns. In this context, these Sub-Processors will receive personal data. The Sub-Recessors must strictly follow our instructions and those of our customers on the processing of this personal data. They will, therefore, not use the personal data for their own purposes. We ensure that all Sub-Processors comply with the requirements set out in the Relevant Legislation. The Sub-Processors we may use as Processors for this purpose with the consent of our customers include Amazon Web Services, Google and Mandrill.

    In addition, we may also use Sub-Processors' services for personalised advertising (also known as 'interest-based advertising' or 'retargeting'). The Sub-Processors we may use as Processors for this purpose with the consent of our customers include Google, Facebook, Twitter and LinkedIn. These third-party vendors may display your ads on sites across the internet.

    As Data Controller

    We also use Sub-Processors' services for the personal data we process for our own purposes. The Sub-Processors we may use as Processors include Amazon Web Services, Google, MailChimp, and Salesforce.

    Apart from the above, we will not share your data with third parties - unless we are required to do so by law.

  19. EXPORT OF DATA OUTSIDE THE EUROPEAN UNION
  20. We may transfer personal data to parties outside the EU if requested by our customers or if one of our Sub-Processors is located outside the EU. Personal data will only be transferred to countries and/or parties that provide adequate protection that meets European standards. Among other things, we will check whether a non-EU organisation is on the Privacy Shield List and whether the European Commission has approved the third country's level of protection.

    If, for the benefit of our customers, we use processors located outside the EU that do not provide an adequate level of protection that meets European standards, we will stipulate this in the agreements with the customer. The customer, as Data Controller, will ensure the required consent of data subjects for the use of these parties.

    The transfer of data outside the EU will always be done in accordance with Relevant Legislation (such as Article 76(1) of the Personal Data Protection Act - as of May 25 2018 replaced by Chapter 5 of the GDPR).

  21. GENERAL AGGREGATED (NOT PERSONAL) DATA
  22. We may convert your personal data into non-personal data. This means that the data will be completely and irreversibly anonymised and aggregated: it will no longer contain personal data because no identification can take place based on the data. We may share this aggregated data with trading partners to analyse, build demographic profiles, and improve our services.

  23. HOW DO WE PROTECT PERSONAL DATA?
  24. We protect all personal data we process against unauthorised or unlawful access, modification, disclosure, use and destruction. We take the following technical and organisational measures to protect the data:

    • Securing network connections via Transport Layer Security (TLS);
    • Limited access to (personal) data for employees via two-step verification;
    • Encryption for passwords and authentication tokens;
    • Passwords that are complex and need to be replaced every two (2) months;
    • Encryption with personal data using XTS-AES-128 encryption with a 256-bit code;
    • While signing the employment contract, the employee agreed, in addition to the general terms and conditions and the privacy policy, to the confidentiality of all data and details both during and after employment;
    • Every employee at MrWork is aware of the latest developments in the privacy policy.
    • Furthermore, there is a privacy FAQ and hotline where people can ask questions;
    • Every employee at MrWork is aware of the clean desk policy. Hardcopy documents are physically stored in locked cabinets, and laptops are automatically locked within 15 minutes.
    • Annual internal audits of security.

  25. COOKIES
  26. We may use cookies on our Website. In doing so, we act as the Data Controller. A cookie is a simple small text file that may be placed on your computer when you visit the Website. This text file identifies your browser and/or computer. When you revisit our Website, the cookie ensures that our Website recognises your browser or computer.

    We use the following types of cookies:

    Functional cookies

    Functional cookies are essential for the operation of our Website. They enable you to navigate our Website and use the features incorporated therein.

    Analytical or statistical cookies

    Analytical cookies are used to examine the quality and effectiveness of the Website. For example, we can see how many users visit the Website and which pages are visited. We use this information to improve our Website and services.

    If you do not want cookies to be sent to your computer, you can change this using your browser's cookie settings. Please note that some features or services of our Website may not function or may function less well without cookies.

    Tracking cookies

    Tracking cookies track the click and browsing behaviour of our visitors. Cookies from external suppliers, including Google, Facebook, Twitter and LinkedIn, may be used to display advertisements based on a user's previous visits to our (job) website.

    We use the following cookies
    - Google Tag Manager;
    - Cookie Consent;
    - Facebook Connect;
    - Google Analytics;
    - Hotjar;
    - Linkedin Analytics;
    - Twitter Analytics;
    - Google Analytics Audiences;
    - DoubleClick;
    - Marketo;
    - Linkedin ads.
    - Twitter advertising.
    - Facebook Custom Audiences;
    - Twitter Conversion Tracking;

    If you do not want cookies to be sent to your computer, you can opt out of using a third-party vendor by visiting the Network Advertising Initiative opt-out page.

    You can also opt out of Google cookies. Information on this is available in Google's Ads Settings.

  27. THIRD-PARTY WEBSITES
  28. You may find (hyper)links on our Website that link to the websites of partners, suppliers, advertisers, sponsors, licensors or other third parties. We have no control over the content or links that appear on these websites, and we are not responsible for the practices of websites linked to or from our Website. In addition, these websites, including their content and links, may change constantly. These websites may have their own privacy policies, terms of use and customer policies. Browsing and interaction on any other website, including websites linked to or from our Website, are subject to the terms and policies of that website.

  29. CHANGES TO THIS PRIVACY POLICY
  30. We are constantly looking for ways to improve our Website and Services. We may therefore update this privacy policy from time to time. If we change the privacy policy significantly, we will post a notice along with the updated privacy policy on our website.

  31. YOUR RIGHTS AND OUR CONTACT DETAILS
  32. As defined in the Relevant Legislation, you have the right to:

    • Request us to correct or update your data;
    • Request us to remove your data from our database without giving reasons;
    • Request from us a copy of any personal data we have processed about you;
    • We may also forward this copy to another data controller at your request;
    • Revoke your consent to the processing of your data. This does not affect the validity of the processing operations before the moment you withdraw your consent;
    • Object to the processing of your data with us;
    • File a complaint with the Personal Data Authority if you think we are processing your data unlawfully.

    If you have any questions, comments or concerns about how we handle your personal data, please get in touch with us using the contact details below.

    MrWork B.V.
    Haringvliet 100
    3011 TH Rotterdam
    T: +31 (0)10 737 15 21
    M: privacy@mrwork.nl
    W: www.mrwork.io
    Chamber of Commerce number: 57298890
    VAT number: NL852521480