Privacy Notice for applicants, employees, workers and contractors

Version 1.0

Effective Date: 11.12.2023

ALLSTARSIT is committed to protecting the privacy and security of your personal information.

This privacy notice describes how we collect and use personal information about you during and after establishing business or employment relationship with us, in accordance with applicable data protection law, including the General Data Protection Regulation (GDPR).

This is a global privacy notice and applies to information collected in all countries where ALLSTARSIT are located or doing business, and contractors are v, or employees and workers are hired. The actual information collected may vary by country, as permitted by law. Therefore; there may be content in this document that not apply specifically to you. It is also depends from your location and type of relationship with us. If you have any questions about this policy, please contact dpo@allstsrsit.com

It applies to all (current and former) applicants, contractors, employees and workers.

It is important that you read this notice, together with any other privacy notice that is provided on specific occasions when we are collecting or processing personal information about you, so that you are aware of how and why we are using such information.

The purposes of processing your personal data are:

i. assessment of your personal abilities, knowledge and skills before concluding an employment or other contractual relationship with ALLSTARSIT, on the basis of which you will develop activities for ALLSTARSIT;

ii. creating an offer of our services and negotiating such an offer before concluding your contractual relationship with ALLSTARSIT;

iii. performing of the contract and related communications, accounting of business operations

iv. legal obligation compliance.

Scope of personal data processed by ALLSTARSIT

Personal data, or personal information means any information about an individual from which that person can be identified. We may collect, store, and use some or all of the following categories of personal information about you:

Personal identification data: name, surname, academic degree, date of birth, tax ID, martial information, image (for pass and HR system).

Contact information: contact address, telephone number, instant messengers username, email, emergency contacts of close persons, post office information, zip code.

Information on previous and current jobs and customers: previous employers or customers, positions held including description of work performed, references from previous employers, location of employment or workplace, references, details from background checks and other due diligence processes, employment records (including job titles, work history, working hours, promotion, absences, attendances, training records and professional memberships), performance reviews.

Data on personal knowledge and skills, characteristics: education, professional knowledge and experience, language skills, certifications.

Recruitment information: information forwarded by recruitment agencies, training and certifications, links to social media profiles.

Sole trader (proprietorship) registration, finance and tax information: address of registration, payroll records, tax status, residency and citizenship, bank account information, payment services providers ID.

Other relevant personal data provided by you, or contained in your CV/Resume, or cover letter or as part of the application process or general onboarding process and submission of all relevant forms and data within our Human Resources Information System (HRIS).

Information related to the ordinary course of business and related employment activities: photographs, videos, information about your use of our information, equipment and communications systems.

Subject to any local or national requirements or restrictions on the collection of specific data referenced below, we may also collect, store and use the following special categories of more sensitive personal information (Special Categories):

  • Information about your race or ethnicity, veteran status, religious beliefs (if applicable).
  • Trade union membership (if applicable).
  • Information about your health, including disability status, medical condition, health and sickness records (if applicable).
  • Information about criminal convictions and offences (if applicable).

How is this information collected?

We collect personal information about you through the application and recruitment process, either directly from you or sometimes from an employment agency or background check provider. We may sometimes collect additional information from third parties including former employers, credit reference agencies or other background check agencies. We will also collect additional personal information in the course of job- or service-related activities throughout the period of your engagement by us.

Our legal basis for using your personal information

We may use the categories of information in the list above:

  • to enter into and/or perform our contract or employment obligations with you; and/or
  • with your consent; and/or
  • to enable us to comply with legal obligations; and/or
  • in some cases, to pursue other legitimate interests of our own.

We may also use your personal information in the following situations, which are likely to be rare:

  • Where we need to protect your interests (or someone else’s interests).
  • Where it is needed in the public interest or for official purposes.

How we may use your personal information

The types of situations in which we may process your personal information are listed below:

  • Making a decision about your recruitment, appointment or signing contract with you.
  • Determining the terms on which you engaged by us.
  • Checking you are legally entitled to work in the country you will be employed or engaged.
  • Paying you renumeration.
  • Providing the following benefits to you, if applicable:

i. healthcare;

ii. other local benefits .

  • Liaising with your pension provider.
  • Administering the contract or employment relationship we have entered into with you.
  • Business management and planning, including accounting and auditing.
  • Conducting performance reviews, managing performance and determining performance requirements.
  • Making decisions about renumeration, salary reviews and compensation.
  • Assessing qualifications for a particular job or task, including decisions about promotions.
  • Gathering evidence for possible grievance or disciplinary proceedings.
  • Making decisions about your continued employment or engagement.
  • Making arrangements for the termination of our relationship.
  • Dealing with legal disputes involving you, or other employees, workers and contractors.
  • Managing sickness absence (if applicable).
  • Complying with health and safety obligations (if applicable).
  • To prevent fraud.
  • To monitor your use of our information and communication systems to ensure compliance with our IT, information security and confidentiality policies.
  • To ensure network and information security, including preventing unauthorised access to our computer and electronic communications systems and preventing malicious software distribution.
  • To conduct data analytics studies to review and better understand your retention and attrition rates.
  • Equal opportunities monitoring.

Some of the above grounds for processing will overlap and there may be several grounds which justify our use of your personal information. Where a particular benefit is operated by a third party, they will be a data controller for your personal data and their privacy notice(s) will apply for any applicable benefits you have chosen to access.

Special Categories of personal information

When we can use it

Special Categories of personal information require higher levels of protection. We may process such information in the following circumstances:

  • In limited circumstances, with your explicit written consent.
  • Where we need to carry out our legal obligations and in line with our engagement or employment or data protection policies, or for government reporting.
  • Where it is needed in the public interest, such as for equal opportunities monitoring and in line with our employment or data protection policies.
  • Where it is needed to assess your working capacity on health grounds, and evaluate the need for reasonable accommodations subject to appropriate confidentiality safeguards.
  • Less commonly, we may process this type of information where it is needed to protect your interests (or someone else’s interests) and you are not capable of giving your consent (such as a medical emergency), or where you have already made the information public.

How we may use it

We may use Special Categories of personal information in the following ways, as permitted by law:

  • We may use information relating to leaves of absence, which may include sickness absence or family related leaves, to comply with contract or employment and other laws.
  • We may use information about your physical or mental health, or disability status, to ensure your health and safety in the workplace and to assess your fitness to work or service providing.
  • We may use information about your race or national or ethnic origin, veteran status, disability status, religious, philosophical or moral beliefs, to comply with government reporting or equalities legislation and ensure meaningful equal opportunity monitoring and reporting.

Consent

In most instances, we rely on other legal grounds, including but not limited to contracts, to process your data. In circumstances, where consent is required, we will comply with any applicable local or national requirements.

Information about criminal convictions

We may only use information relating to criminal convictions where the law allows us to do so. We will only collect information about criminal convictions if it is appropriate given the nature of the role /or where we are legally able to do so and in order to establish whether you can be employed or engaged by ALLSTARSIT. Where appropriate, we will collect information about criminal convictions as part of the recruitment process or we may be notified of such information directly by you in the course of you working or provide service for us.

Automated decision making

Automated decision-making takes place when an electronic system uses personal information to make a decision without human intervention. We do not envisage that any decisions will be taken about you using automated means, and we will notify you by updating this notice if this position changes. Any use of automated decision making will not have a significant impact on you and will only be used if we have a lawful basis for doing so in the following circumstances:

  • Where we have notified you of the decision and given you reasonable term to request a reconsideration.
  • Where it is necessary to perform the contract with you and appropriate measures are in place to safeguard your rights.
  • In limited circumstances, with your explicit written consent and where appropriate measures are in place to safeguard your rights.

Data Sharing

Why might you share my personal information with third parties?

We may have to share your data with third parties, (including third-party service providers and other entities in the group) where required by law, where it is necessary to administer relationship with you or where we have another legitimate interest in doing so.

If we do share data, we require third parties to take appropriate security measures and only process your data for specified purposes.

Which third-party service providers process my personal information?

“Third parties” includes third-party service providers (including contractors and designated agents) and other entities within our group. Third parties may process personal information about you for the following purposes:

  • payroll processing;
  • accounting services;
  • background and credit reference checking;
  • to operation offices and workspaces;
  • the operation of ALLSTARSIT’s IT systems;
  • the operation and support of ALLSTARSIT’s IT systems;
  • the operation of ALLSTARSIT’s finance, legal, information security functions.

Transferring information outside the EU

We may transfer and process the personal information we collect about you to another country, including countries outside the EU to enable ALLSTARSIT and its service providers to process your information consistent with this Privacy Notice. These countries may include, but are not limited to, the following:

  • Poland
  • USA
  • the UAE
  • Israel
  • Ukraine
  • Colombia
  • Any other country where ALLSTARSIT employs or engage staff. To ensure that your personal information receives an adequate level of protection all information is transmitted in a secure manner in accordance with our Privacy Policy and will only be used for the purposes that it was originally collected. We also ensure that model clauses are in force in any relevant legal contracts and agreements (including agreements between ALLSTARSIT group companies) to ensure that your personal information is treated by third parties and other ALLSTARSIT companies in a way that is consistent with and which respects all applicable local and national laws on data protection. If you require further information about this, please contact the Data Privacy Office.

Method of processing your personal data and their recipients

In connection with the selection procedure, your personal data will also be processed by the company subcontractors, which conducts the selection process for us.

In the event that a selection procedure to fill a job position or engagement by contract includes your placement with our client to whom ALLSTARSIT provides its services, your personal data will also be provided for inspection to this client. The client does not further process your personal data without prior contractual arrangements with ALLSTARSIT or without your prior explicit consent.

In connection with the selection procedure, some of your personal data and information about you may be ascertained/verified according to publicly available sources, such as public registers or professional social networks, but only to the extent that is necessary and relevant for the given job position or engagement by contract.

Data Security

At ALLSTARSIT, we take data security seriously and have implemented robust measures to ensure the protection of your personal information. We understand the importance of keeping your data safe and confidential, and we strive to maintain the highest standards of security.

To safeguard your personal information from any unauthorized access, use, alteration, or disclosure, we have put in place a variety of technical, physical, and administrative security measures. These measures are designed to prevent any accidental loss or unauthorized access to your data.

Our technical security measures include the use of encryption technology to protect your data during transmission and storage. We also regularly update our security systems to ensure that they are up-to-date and able to withstand any potential threats.

In addition to technical measures, we have physical security measures in place to protect our physical premises and any physical copies of your data. Access to our facilities is restricted to authorized personnel only, and we have implemented strict controls to prevent unauthorized entry.

Furthermore, we have implemented administrative controls and procedures to ensure that only authorized individuals have access to your personal information. We provide regular training to our employees on data protection and security best practices to ensure that they understand their responsibilities in handling your data.

In the event of a suspected data breach, we have established procedures to detect, investigate, and respond to such incidents promptly. We conduct regular audits and assessments of our systems and processes to identify any vulnerabilities and address them proactively.

While we have taken these measures to protect your data, it is important to note that no method of transmission or storage is completely secure. However, we continuously monitor and review our security practices to ensure that we are providing the highest level of protection for your personal information.

If you have any concerns about the security of your data or if you believe that your data has been compromised, please contact us via email dpo@allstarsit.com immediately. We will investigate the matter thoroughly and take appropriate actions to address any security issues.

Your privacy and the security of your data are of utmost importance to us, and we will continue to prioritize data security to maintain your trust and confidence in our services.

Data Retention

We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Details of retention periods for different aspects of your personal information are available below.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

Your personal data is processed only for the purposes of the selection procedure for which you applied. Your personal data will only be processed for the duration of this selection procedure, i.e. until a contract is concluded with the selected candidate. This period shall not exceed a period of six (6) months from the start of the selection procedure.

In the event that you are interested in other job offers or engagement as contractor from ALLSTARSIT, we may process your personal data even after the end of the selection procedure for which you applied, and only on the basis of your explicit consent, which you can revoke at any time. If you grant us such consent, we will process your personal data for a period of twelve (12) months from its granting, unless you revoke this consent before this period expires. The revocation of your consent to the processing of personal data does not affect the legality of their processing based on your consent granted to us before its revocation.

If we enter into a contract with you for the provision of services, your personal data as described above will be processed for the duration of the contract until its termination or expiration and for thirty-six (36) months thereafter.

Your Rights

Your personal data is processed in a transparent manner. Please note that you have the right to access and obtain copies of your personal data processed by our Company.

You have the right, in particular, to provide information about whether the Company processes your personal data or not, and if so, then you have the right to request information about the identity and contact details of the administrator, as well as about the purposes of processing, the scope of processed personal data and its sources, about categories of personal data concerned, about recipients or categories of recipients of personal data, about authorized administrators, about the list of your rights, about the possibility to contact of the Personal Data Protection Office and about automated decision-making and profiling.

You have the right to correct and supplement your personal data if you discover that we are processing your incorrect, inaccurate or incomplete personal data.

Under certain conditions established by law, you have the right to delete your personal data (the right to be forgotten). These are special cases where your personal data are no longer needed for the purposes for which they were collected or otherwise processed, or if your personal data was processed unlawfully. We are under no obligation to delete your personal data, especially if their processing is necessary for the determination, exercise or defense of our legal claims.

Under certain conditions established by law, you have the right to restrict the processing of your personal data. We will limit the processing of your personal data in particular in cases where you deny the accuracy of your personal data, until we verify the accuracy of this personal data, or if the processing is unlawful and you request the restriction of the processing of personal data instead of its deletion.

If you exercise the right to restrict the processing of your personal data, we will make a record of the restriction of processing of your personal data and will no longer actively process them. In the event that the reasons for the restriction of processing no longer apply, we will cancel the restriction on the processing of your personal data. We will inform you about this in advance.

We may process your personal data automatically.

You therefore also have the right to the portability of your personal data, which we process on the basis of your consent or for the implementation of measures taken before the conclusion of the contract. At your request, we are obliged to transfer your personal data to you or another administrator in a structured, commonly used and machine-readable format.

If we process your personal data for the purposes of our legitimate interests, then you also have the right to object to such processing. If you raise such an objection, we will not process your personal data unless we demonstrate serious legitimate reasons for its processing that outweigh your interests or rights and freedoms.

We may also process your personal data for the determination, exercise and defense of our legal claims.

Regarding the processing of your personal data, you have the right to file a complaint with the personal data protection authority (”Data Privacy Office”).

In all matters related to the processing of your personal data, whether it is a question, exercising a right, filing a complaint or any other matter, you can contact ALLSTSRSIT in writing at the address as defined below, or by email sent to the email address: dpo@allstsrsit.com.

No fee usually required

You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measures to ensure that personal information is not disclosed to any person who has no right to receive it.

Further questions or complaints

If you have any questions about this privacy notice or how we handle your personal information, please contact the Data Privacy Office. You have the right to make a complaint at any time to the information commissioner’s office or the supervisory authority for data privacy issues in your country.

Changes to this privacy notice

We reserve the right to update this privacy notice at any time, and we will provide you with a new privacy notice when we make any substantial updates. We may also notify you in other ways from time to time about the processing of your personal information.

ALLSTARSIT COMPANIES

Depending on the location and type of engagement, your personal information may be collected by one of ALLSTARSIT companies listed below. In this case, such company will act as the Data Controller; other ALLSTARSIT companies may act as Data Processors.

Name

Location

🇲🇨 ALLSTARSIT Poland, LLC – Złota 75A/7, 00-819 Warsaw, Poland

🇺🇦 ALL STARS-IT Ukraine, LLC – 1A Sportyvna Square 17 floor , 01023 Kyiv, Ukraine

🇨🇴 ALLSTARSIT COLOMBIA S.A.S. – Bogota at Cl 139 No. 7 C - 51 Ap 504

🇦🇪 ALLSTARSIT INFORMATION TECHNOLOGY Sole Establishment – Office 2F - 14, Al Safiya Building, Hor Al Anz, Deira, Dubai

🇮🇱 Test-Pro CO.IL.LTD – Ramat Gan, at 2 Jabotinsky Street, 52505 Ramat Gan, Israel