Skip to main content

Processing of (personal) data by the entity in charge of the online application process

https://keyless.io/privacy

This privacy policy illustrates the management of the website https://keyless.io/ (hereinafter, the "Site") with reference to the processing of personal data of users.

This is a general information notice provided in accordance with Article 13 of Regulation (EU) No. 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, the "GDPR") to all users who to interact with the services provided through the Site by Keyless Technologies S.r.l., with registered office in Viale Luca Gaurico no. 9-11, Rome, in the capacity of data controller (hereinafter, "Keyless" or the "Controller").

This privacy policy explains the purposes and methods by which the Controller collects and processes your personal data, which categories of data are processed, which are the rights of the data subjects and how they can be exercised.

The processing of users’ personal data will be carried out by means of suitable instruments, whether electronic, paper-based or telematic. Processing activities will be conducted with an approach strictly related to the purposes of this document and, in any case, in such a way as to ensure security and confidentiality of data.

Users are invited to read this policy before providing personal information of any kind through the Site.

  1. Categories of personal data
    1. Navigation dataComputer systems and software procedures used to operate this Site acquire, during their normal operation, some personal data whose transmission is implicit in the use of internet communication protocols.
      This information is not collected to be associated with identified data subjects, but due to its very nature could allow users to be identified through processing and association with third party data.
      This category of data includes IP addresses or domain names of the devices used by users connecting to the website, URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (success, error, etc.) and other parameters relating to the operating system and computer environment of the user.
      These data are used for the sole purpose of obtaining anonymous statistical information on the use of the Site and to check its correct functioning and are deleted immediately after processing. The data could be used to ascertain responsibility in case of hypothetical computer crimes against the Site.
    2. Data provided voluntarily by the userKeyless will acquire some of your personal data you voluntarily provided through the form you reach by clicking on the "Schedule demo" button on the homepage of the Site, i.e., name, surname, email address, job title and company, as well as the subject of the message and any other data that the user will communicate, on their initiative, by means of the contact tools made available on the Site.
  2. Purposes, legal basis of processing and data retention period
    1. Enabling navigation on the SiteThe data indicated in paragraph 1, letter a) will be processed by the Controller to enable the navigation on the Site and the use of related functions. The provision of such data is necessary for the proper functioning of the Site.
    2. Providing requested servicesThe data indicated in paragraph 1, letters b) will be processed by the Controller in order to provide the services or information requested by filling in the contact form. The providing of such data is necessary in order to perform the contractual relationship that will be established with the Controller following the user’s request. The provision of any data not included in those required by the forms on the Site is not, in any event, mandatory.
      The processing is necessary to fulfill a request made by the user and, therefore, the legal basis falls under Article 6(1)(b) of the GDPR.
      The user’s personal data will be processed only for the time necessary to respond to requests of services or information submitted through the Site.
    3. Marketing activityThe data indicated in paragraph 1, letters b) will be processed by the Controller in order to send to the user, using the email address provided, commercial communications concerning its products or services.
      The processing of personal data carried out for this purpose is based on the legitimate interest pursued by the Controller pursuant to Article 6(1)(f) of the GDPR.
  3. Categories of subjects to whom personal data can be communicated and purposes of communicationThe Controller may communicate, for the same purposes above, some of the users’ personal data to subjects designated and expressly authorised to process such data, in accordance with the provision of Article 29, GDPR.
    For the same purposes, the Controller may also communicate some of the users’ personal data to third parties, who will process such data as data processors pursuant to Article 28 of the GDPR (e.g., companies that provide marketing services). The complete list of data processors may be requested from the Controller at any time by writing to gdpr@keyless.io.
    Furthermore, the data may be communicated to the competent authorities, in the event of specific requests which the Controller is compelled to fulfil. If applicable, these entities will act as autonomous data controllers.
    Personal data will not be disseminated or disclosed under any circumstances.
  4. Rights of the data subjectIn their quality of data subjects and in accordance with current regulations, users have the following rights:
    • right of access (Article 15, GDPR): you may request and obtain information about the existence of your data available to the Controller and access to such data;
    • right to rectification (Article 16, GDPR): you may request and obtain the amendment and/or correction of your personal data if you believe it is inaccurate or incomplete;
    • right to erasure / "Right to be forgotten" (Article 17, GDPR): in certain circumstances, you may request and obtain the erasure of your personal data if it is not necessary – or no longer necessary – for the purposes mentioned above, once the retention period indicated in paragraph 4 has expired;
    • right to restriction of processing (Article 18, GDPR): in certain circumstances, you may request and obtain a restriction of the processing activities involving your personal data;
    • right to data portability (Article 20, GDPR): in certain circumstances, you may request and obtain the personal data concerning you, in a structured, commonly used, machine-readable format. You may also request and obtain that such data be transmitted to another data controller without hindrance by the Controller;
    • right to object (Article 21, GDPR): at any time, you may object to processing of personal data concerning you based on Article (1)(f), GDPR.

Requests to exercise your rights may be addressed to Keyless Technologies S.r.l., with registered office in Viale Luca Gaurico no. 9-11, 00143, Rome or to gdpr@keyless.io, as well as by writing to the Data Protection Officer appointed by Keyless, available at the following email address: dpo@e-lex.it.

We would also like to inform you that, in accordance with the regulations in force, you may lodge any complaints regarding the processing of your personal data with the Italian Data Protection Authority.

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.