1. WHAT IS THE PURPOSE OF THIS PRIVACY POLICY?
The purpose of this policy is to fulfill the information obligations of Exide Technologies (hereinafter “the company” or “we”) under the GDPR (Article 12) and any applicable regulations, and to document the rights and obligations of candidates and contacts regarding the data processing of their personal data.
This policy sets out the terms under which we carry out data processing on the personal data to which we have access during the selection and recruitment process.
It is important that you read this policy because by submitting your application, you confirm that you have read and understood it.
2. WHAT TYPE OF PERSONAL DATA DO WE COLLECT?
Non-technical data
- Identity and identification data (last name, first name, date of birth, username);
- Contact information (phone number, mailing address, email address, social media accounts, etc.);
- Professional data (education, experience, contact information for current and former employers, professional interests, travel and location interests, etc.);
Photograph (optional); - Information gathered during the interview and any other information provided.
Technical data (if applicable)
- All logs/log data from the company’s technical environment to which candidates have access.
We do not ask candidates to provide us with sensitive data such as racial or ethnic origin, political opinions, religious beliefs, sexual orientation, trade union affiliation, etc.
Since this data is not necessary for the selection and recruitment of candidates, we ask that you limit the information you provide to us to that which is strictly professional and relevant to your recruitment. Please ensure that the documents you send us do not contain any sensitive data as described above.
3. HOW DO WE COLLECT YOUR DATA?
Data collection may occur in two ways:
- Direct data collection: data is provided directly, for example when you apply for a job posting on our website or social media;
- Indirect data collection: this is carried out by a specialized company, such as headhunters, recruitment websites, etc.
4. WHAT ARE THE PURPOSES AND LEGAL BASES FOR DATA PROCESSING?
Administration and data processing of the application
- Legitimate interest
Assessment of suitability for employment
- Legitimate interest
Background check
- Legitimate interest
Contact to schedule interviews
- Legitimate interest
Creation of a resume database
- Legitimate interest
Data processing of a resume received from a recruitment agency
- Legitimate interest
Statistics
- Legitimate interest
Once the recruitment process is complete, data processing will take place for the performance of the contract.
5. WHO HAS ACCESS TO YOUR PERSONAL DATA?
Internal recipients are:
- Human Resources;
- The operational departments involved in the application;
- Any employee or member of the Exide Technologies Board of Directors, if justified.
External recipients include:
Recruitment agencies;
- Competent authorities, if applicable;
- Any other data controller at Exide Technologies, if justified.
6. DO WE TRANSFER YOUR DATA OUTSIDE THE EUROPEAN UNION ?
The company reserves the right to decide whether or not to transfer the personal data it collects and processes across borders.
Cross-border data transfers are governed by the European Commission’s Standard Contractual Clauses.
7. WHAT ARE THE RETENTION PERIODS?
When an application is selected at the end of the recruitment process, it is retained under the conditions and for the duration defined in Exide Technologies’ employee personal data policy.
Conversely, if an application is not selected, it is immediately deleted. However, Exide Technologies reserves the right, for certain profiles, to retain them for future opportunities, in which case data retention may occur for a maximum period of two years from the last contact, unless the candidate objects.
8. WHAT ARE YOUR RIGHTS ?
You have the right to access your data, to correct inaccurate data or data that needs to be updated, and to delete your data, as well as other rights set forth in:
- Article 17 of the GDPR (Right to erasure)
- Article 18 of the GDPR (right to restriction of data processing)
- Article 21 of the GDPR (Right to object)
- Article 22 of the GDPR (right to object to automated individual decisions under the GDPR, when the criteria set forth in this article are met)
You have the right to file a complaint with the French data protection authority if you believe your rights have not been respected.
9. HOW TO EXERCISE YOUR RIGHTS ?
The company has appointed a data protection officer (DPO) who can be contacted at the following address: Eric Barbry, [email protected].
If you wish to exercise any of your rights, please contact our DPO.
10. DATA SECURITY AND PROTECTION
Exide Technologies defines and implements security measures to prevent the destruction, loss, alteration, or unauthorized disclosure of data. The IT systems and paper-based records used are organized and protected to ensure the security and confidentiality of your information.
11. UPDATE
We reserve the right to modify the presentation and content of this policy. We therefore encourage you to review it regularly.
