1INTRODUCTION
Welcome to trafilead.com. We value your privacy and strive to ensure the proper protection of your personal data in accordance with applicable personal data protection legislation, including the Law of Ukraine «On Personal Data Protection» and, where relevant, the General Data Protection Regulation (GDPR) for users located in the territory of the European Union.
We also adhere to the principles of transparency, purpose limitation, data minimisation and giving users control over their personal information, regardless of the country or region from which the site is accessed.
This Privacy Policy explains how trafilead.com collects, uses, stores, transfers and protects users' personal information when they visit and use the site, including where the user is a job applicant, a potential partner, a representative of a company or an ordinary visitor.
By using the trafilead.com site, you confirm that you have read this Privacy Policy and understand the principles of personal data processing described in it.
2DEFINITIONS
For the purposes of this Privacy Policy the following terms are used with the meanings indicated:
Personal data— any information that relates directly or indirectly to an identified or identifiable natural person. Such information may include a name, contact information, a CV, an IP address and other details provided by the user or obtained in the course of using the site.
Data processing— any operation or set of operations performed on personal data, including collection, recording, organisation, storage, alteration, use, transfer, granting of access, anonymisation or erasure.
User, «you» or «your»— any natural person who visits, views or otherwise interacts with the trafilead.com site.
Cookies— small text files that are stored on the user's device when a website is visited and that make it possible to retain certain settings and to obtain information about the user's interaction with the site.
Service provider— a third-party organisation or natural person that provides services within the operation of the site and may process personal data on our instructions. Such services may include hosting, technical maintenance, analytics, information security and data management.
GDPR— the General Data Protection Regulation of the European Union (Regulation (EU) 2016/679).
Applicable law— the legislative and regulatory requirements governing the protection of personal data and privacy, including, where applicable, the GDPR and the Law of Ukraine «On Personal Data Protection».
3WHAT DATA WE COLLECT
We may receive various categories of information necessary for the operation of the site, the handling of enquiries, the improvement of the user experience, the provision of security and the fulfilment of obligations prescribed by law.
3.1DATA PROVIDED BY THE USER
Depending on the site features being used, the user may voluntarily provide:
- first name and last name
- email address
- telephone number
- a CV, a résumé and other documents
- a cover letter
- answers to questions contained in forms
- the name of a company or organisation
- information given in contact forms
- the content of messages and enquiries
- other details that the user provides themselves through the site or by email correspondence.
We recommend that users do not send through the site any information that is not required for the relevant purpose of the enquiry.
3.2INFORMATION COLLECTED AUTOMATICALLY
When trafilead.com is visited, certain technical information may be collected automatically, including:
- IP address
- browser details
- browser version
- operating system
- type of device used
- interface language
- time zone and approximate technical location details
- the address of the page from which the user came to the site
- pages visited
- date and time of the visit
- session duration
- user actions on the pages of the site, including interaction with interface elements
- technical logs
- details of errors and failures.
Such information may be used for technical support, analysis of the operation of the site, identification of problems and provision of security.
3.3COOKIES AND SIMILAR TECHNOLOGIES
Depending on the functionality of the site, we may use the following categories of cookies and similar technologies:
- strictly necessary cookies that ensure the basic operation of the site
- functional cookies that retain the settings chosen by the user
- analytical cookies that make it possible to assess the use of the site
- technologies for measuring effectiveness and performance
- tracking tools used where there is an appropriate legal basis and the necessary user permissions
- cookies and identifiers related to storing the user's privacy settings.
In certain cases third-party analytics tools may be used, for example Google Analytics, if the corresponding tools are connected to the site.
We do not aim to knowingly collect personal data of persons under 18 years of age. If we become aware that a minor has provided us with personal data without proper grounds, we will take reasonable steps to delete it.
4PURPOSES OF USING PERSONAL DATA
The data received may be used for the following purposes:
- handling users' applications and enquiries
- considering candidates and organising recruitment processes where the user submits a corresponding application
- contacting the user regarding a request they have sent
- responding to questions, comments and suggestions
- ensuring the operation and availability of the site
- technical maintenance and improvement of the site
- analysing traffic and user interaction
- identifying and eliminating technical errors
- preventing fraud, abuse and unauthorised access
- protecting information systems and infrastructure
- complying with the requirements of legislation
- fulfilling lawful requests of state authorities
- ensuring compliance with the applicable rules and terms of use of the site
- fulfilling other purposes of which the user was duly notified at the moment the data was provided.
If a particular type of processing requires the user's consent, that processing is carried out on the basis of such consent.
We do not sell users' personal data and do not provide it to third parties for the purpose of sale or independent use by third parties.
If the nature of the use of the data changes materially, the relevant provisions of this Policy will be reviewed and updated.
5LEGAL BASES FOR PROCESSING
Depending on the nature of the particular processing of personal data, we may rely on one or more of the following legal bases:
Consent of the user— where the user provides data themselves and gives consent to its processing in cases where such consent is necessary.
Pre-contractual steps or performance of a contract— where the processing is necessary to take steps at the user's request prior to entering into a contract, or to perform contractual obligations.
Legitimate interest— where the processing is necessary for the pursuit of legitimate interests, for example ensuring the security of the site, preventing abuse, technical administration or improving services, provided that the rights and freedoms of the user are respected.
Legal obligation— where the processing is required in order to comply with the requirements of legislation, court decisions, regulatory acts or lawful requests of competent state authorities.
When processing the data of users falling within the scope of the GDPR, we strive to apply the appropriate legal basis to each specific purpose of processing.
6TRANSFER AND DISCLOSURE OF PERSONAL DATA
We do not sell or rent out users' personal data.
At the same time, personal information may be made available or transferred in a limited number of cases:
To authorised employees and representatives— access to data is granted only to persons who need the information to perform the relevant work duties.
To technical and other service providers— certain data may be processed by third-party contractors providing hosting, technical support, analytics, information security, document storage or other necessary functions. Such providers receive access only to the data necessary to perform the relevant services.
To state authorities and other authorised persons— information may be disclosed where this is required by legislation, by a court decision or by a valid official request of a competent authority.
In the event of corporate changes— in the case of a reorganisation, merger, acquisition, sale of part or all of the assets or another corporate transaction, personal data may be transferred to the relevant party to the extent permitted by applicable law.
In the event of international data transfers— depending on the infrastructure used, personal data may be processed in the territory of other states. In cases where the law requires special protection mechanisms for international transfers, we strive to use the safeguards provided by law, including adequacy decisions, standard contractual clauses or other permissible mechanisms.
7PERSONAL DATA RETENTION PERIOD
We store personal data only for the period that is reasonably necessary to achieve the purposes of its processing, unless a longer period is prescribed by legislation.
The duration of storage depends on the nature of the data, the purpose for which it was obtained, the nature of the relationship with the user, the requirements of legislation and the need to protect our legitimate interests.
In particular, certain data may be retained for the period necessary to:
- provide the relevant services
- consider applications
- maintain business records
- comply with legal and regulatory requirements
- resolve disputes
- protect legitimate interests
- prevent fraud and abuse.
After the end of the necessary retention period, the data is deleted, destroyed or anonymised, unless its further storage is required or permitted by legislation.
Certain details may be retained in an anonymised or aggregated form for statistical, analytical and research purposes, provided that such details no longer make it possible to identify a particular user.
8USERS' RIGHTS
Depending on applicable law and the circumstances of the processing, the user may have the following rights:
Right of access— the ability to obtain information about what personal data is being processed and for what purposes.
Right to rectification— the ability to request the correction of inaccurate or incomplete personal data.
Right to erasure— in the cases provided for by law, the user may request the deletion of their personal data.
Right to restriction of processing— the ability to request the restriction of the processing of personal data where there are grounds provided for by law.
Right to object to processing— the user may object to certain types of processing, in particular where the processing is carried out on the basis of legitimate interest or is used for direct marketing, where applicable.
Right to data portability— in the cases provided for by the GDPR, the user may receive the data they have provided in a structured, commonly used and machine-readable format, or request its transfer to another controller.
Right to withdraw consent— if the processing is based on the user's consent, that consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Right to lodge a complaint— the user may apply to the competent data protection authority if they consider that the processing of their personal data breaches applicable law.
The exercise of these rights may be limited in the cases provided for by law, for example where the retention of certain information is mandatory.
To exercise their rights or to obtain information about the processing of personal data, the user may contact us at:
We consider such enquiries within the time limits and in the manner provided for by applicable law.
9INFORMATION SECURITY
We apply reasonable technical and organisational measures to protect personal data against unauthorised access, unlawful use, alteration, disclosure, loss or destruction.
Depending on the infrastructure used, the security measures may include:
- secure server infrastructure
- access control systems
- the use of HTTPS/TLS to protect the transmission of information
- restriction of employee access on a need-to-know basis
- a role-based access model
- monitoring of the technical infrastructure
- backup copying
- information system security controls
- incident response procedures
- periodic assessment of technical and organisational risks.
Despite the measures taken, no method of transmitting or storing information over the Internet can be considered absolutely secure. We therefore cannot guarantee the absolute protection of personal data against all possible threats.
If a user considers that their interaction with the site or with us is no longer secure, they can report this at info@trafilead.com.
10COOKIES AND TRACKING TECHNOLOGIES
The trafilead.com site may use necessary and functional cookies to ensure the correct operation of individual elements of the site, to retain user settings and to improve the interface.
Where the relevant tools are in place, analytical or other technologies may be used to assess traffic, performance and user interaction with the site.
The use of individual categories of cookies may depend on the user's settings and on the requirements of applicable law.
The user can change cookie settings through the settings of their browser or through the consent management tools available on the site, where such tools are provided.
Disabling certain categories of cookies may result in the limitation of individual functions or a reduction in the convenience of using the site.
11THIRD-PARTY SITES AND SERVICES
The trafilead.com site may contain links to, or integrations with, external websites, platforms, services or other resources that are operated by third parties.
We do not control the content, security or data processing practices of such third-party resources and are not responsible for their privacy policies.
When following a link to an external resource, the user interacts with the relevant third party on their own. We recommend reviewing the privacy policy and terms of use of the relevant service before providing it with personal data.
12CHANGES TO THE PRIVACY POLICY
We may periodically amend this Privacy Policy to reflect changes in the operation of the site, the technologies used, the methods of data processing, legislative requirements or internal processes.
The current version of the Policy is published on the trafilead.com site.
Where material changes are made, we may additionally notify users by placing a corresponding notice on the site or by another available means, if this is required by applicable law.
We recommend reviewing this Privacy Policy periodically in order to stay aware of the current rules on the processing and protection of personal data.
CONTACTS
For questions relating to the processing of personal data, privacy or the exercise of the rights provided for by law, you can contact us:
- info@trafilead.com
- Website
- trafilead.com