What is the purpose of our Privacy Policy?
DB Global Limited, which manages the Hiros platform, attaches great importance to the protection and confidentiality of your personal data, which is a guarantee of our reliability and trust.
As such, our Personal Data Privacy Policy specifically reflects our willingness to ensure that DB Global Limited complies with the applicable rules on the protection of personal data and, more specifically, those of the General Data Protection Regulation ("GDPR").
In particular, our Privacy Policy aims to inform you about how and why we process your personal data in the context of the services we provide to you.
Who should read our Privacy Policy?
Our Privacy Policy is addressed to you, regardless of where you live, if you are at least 13 years old and are users of our Hiros platform.
If you are under the legal age detailed above, you are not authorised to use our services without the prior and explicit consent of one of your parents or the holder of parental authority, which must be sent to us by email at legal@gethiros.com.
If you believe that we are holding personal data about your children without your consent, please contact us at the dedicated address detailed above.
Why do we process your personal data and on what basis?
We process your personal data primarily for the following purposes:
To use and benefit from our automated sourcing and engagement of candidates by artificial intelligence (Rose) and all its features based on our terms and conditions of use.
To manage user accounts (e.g. account creation, access to the service and account deletion) on the basis of our general terms and conditions of use.
For exchanges between users via our internal messaging system made available on the basis of our general terms and conditions of use.
Please contact our support department via our chat/chatbot on the basis of our general terms and conditions of use.
To pay online on the basis of our general terms and conditions of sale.
To receive our technical emails and SMS (e.g. password changes, notifications, alerts, etc.) on the basis of our legitimate interest in ensuring the security of your account and providing you with the information necessary for the proper operation of the service.
To guarantee and enhance the security and quality of our services on a day-to-day basis (e.g. statistics, data security, etc.) on the basis of our legal obligations, our general terms and conditions of use and our legitimate interest in ensuring the proper functioning of our services.
Your data is collected directly from you when you use our Hiros platform and we undertake to process your data only for the reasons described above.
However, we may also obtain your personal data indirectly from partners if you have given your prior consent to them.
What personal data do we process and for how long?
We have summarised below the categories of personal data and their respective retention periods:
Professional identification data (e.g. surname, first name, position, company, etc.) and co-ordinates (e.g. email address and business telephone number, etc.) retained for the duration of the provision of the service, plus the statutory limitation periods, which are generally 5 years.
When there is confusion between the name of your organisation and your personal name (e.g.: self-employed entrepreneur, very small business, etc.), economic and financial data (e.g.: bank account number, verification code, etc.) will be retained for as long as is necessary for the transaction and for the management of invoicing and payments, plus the statutory limitation periods, which are generally between 5 and 10 years.
Email address and telephone number to receive our technical messages by email and SMS retained until your account is deleted.
Connection data (e.g. logs, IP address, etc.) retained for 1 year.
Once the applicable retention periods have expired, the deletion of your personal data is irreversible and we will no longer be able to communicate it to you after this period. At most, we may only retain anonymous data for statistical purposes.
Please also note that in the event of litigation, we are obliged to retain all of your data throughout the processing of the case, even after the expiry of the retention periods described above.
What rights do you have to control the use of your personal data?
The applicable data protection regulations give you specific rights which you may exercise, at any time and free of charge, in order to control the use we make of your data.
The right to access and copy your personal data, provided that this request does not conflict with business secrecy, confidentiality or the confidentiality of correspondence.
Right of rectification of personal data that is erroneous, obsolete or incomplete.
The right to oppose the processing of your personal data where such processing is based on our legitimate interests, unless there are compelling legitimate grounds for such processing which override your interests, rights and freedoms.
The right to request the deletion ("right to be forgotten") of personal data that is not essential to the proper functioning of our services.
Right to limitation of your personal data which allows you to photograph the use of your data in the event of a dispute over the legitimacy of processing.
Right to portability of your data which allows you to retrieve part of your personal data so that it can be easily stored or transmitted from one information system to another.
The right to give directives on the fate of your data in the event of your death either through you or through a trusted third-party or successor in title.
For a request to be considered, it is essential that it is submitted directly by you or your representative to the address legal@gethiros.com.
Requests may only be made by you or your representative. We may therefore ask you to provide proof of identity if there is any doubt as to the identity of the person making the request, as well as evidence of your authority to act on behalf of another person.
We will respond to your request without undue delay, within a maximum of one month from receipt, unless the request is technically complex or we receive a large number of requests at the same time. In such cases, the response time may be up to three months.
Please note that we reserve the right to refuse to respond to any excessive or unfounded requests, particularly those of a repetitive nature.
Who can access your personal data?
Your personal data is processed by our teams and by our technical service providers for the sole purpose of operating our service.
We specify that we check all our technical service providers before recruiting them to ensure that they scrupulously comply with the applicable rules on the protection of personal data.
IN ADDITION, WE GUARANTEE THAT WE WILL NEVER TRANSFER OR SELL YOUR DATA TO THIRD PARTIES OR BUSINESS PARTNERS.
May your personal data be transferred outside the European Union?
The personal data processed by our platform Hiros is hosted on servers located outside the European Union. In order to protect your personal data, we take great care to ensure that our hosting provider implements the appropriate guarantees required to ensure the confidentiality and protection of your data.
We may also use technical tools located outside the European Union. If this is the case, we guarantee that they comply strictly with the applicable rules on transfers in order to guarantee confidentiality and adequate protection of your personal data.
How do we protect your personal data?
We implement the following technical and organisational means to guarantee the security of your personal data on a daily basis and, in particular, to combat any risk of destruction, loss, alteration or disclosure.
Technical security measures
Organisational security measures
Double authentication of users ("Front" side), Double user authentication ("Back" side), Encryption of user database at rest and in transit, HTTPS protocol, Access traceability, Duplication of the user database on backup servers
Information systems charter, Access and password management policy, Data breach management procedure, Personal rights management procedure, Rules of good conduct, Team awareness and training twice a year
Do we use cookies or pixels when you browse our platform?
We guarantee that we do not use any advertising cookies for the operation of this platform.
On the other hand, we would like to inform you that we use statistical cookies when you browse our platform, as well as technical pixels in connection with our technical emails and SMS in order to guarantee their proper delivery and functioning. For more information, please consult our Cookie Policy.
Who can you contact for more information about the use of your personal data?
To best ensure the protection and integrity of your data, we have officially appointed an Data protection officer ("DPO") independent from our Supervisory authority.
You may at any time and free of charge contact our DPO at legal@gethiros.com to obtain further information or details on how we process your data.
How can you contact the CNIL (French Data Protection Authority)?
You may contact the “CNIL (French Data Protection Authority)” at any time using the following contact details: CNIL Complaints Department, 3 place de Fontenoy – TSA 80751, 75334 Paris Cedex 07 or by telephone on 01 53 73 22 22.
You may contact the Information Commissioner’s Office (ICO) at any time using the following contact details: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Telephone: 0303 123 1113. Fax: 01625 524510.
Can the Privacy Policy be amended?
We may amend our Privacy Policy at any time to bring it into line with new legal requirements and any new data processing activities we may implement in the future.