Effective date: July 8th, 2020
SECT.1 - GENERAL INFORMATION
RChilli Inc. is an entity organized and existing under the laws of California, USA, with registered office at 2603 Camino Ramon, Ste 272, San Ramon, CA 94583 (hereinafter “RChilli”, “us”, “we” or “our”), knows how important privacy is to its customers (hereinafter “you” or “your”), and strives to be clear about how personal data is collected, used and disclosed.
We act as “Data Controller” of your Personal Data.
“Data Controller” means the entity (in most cases, an organisation, but sometimes a person) that directs the reason why Personal Data is processed in the first place and it is the entity that first receives personal data and is responsible for it.
“Processor” means the entity (again a person or organisation, etc.) that actually does the processing or analysis of Personal Data on behalf of the Data Controller.
“Personal Data” means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
SECT. 2 - PRINCIPLES OF THE PROCESSING
We are committed to fully complying with data processing requirements worldwide. This includes but is not limited to the European Regulation no. 2016/679 (General Data Protection Regulation; hereinafter, the “GDPR”), in case our processing activities involve data subjects that are either physically located in, or citizens of, the European Union or Switzerland.
Therefore, we have configured our Site and Services so that the use of Personal Data is kept to the minimum necessary. We have also adopted safeguards and technical and organizational measures in order to protect the rights of data subjects, and to ensure that, by default, only Personal Data which are necessary for each specific purpose of the data are being processed.
SECT. 3 - PERSONAL DATA WE PROCESS
When you access the Site and use our Services, we may collect the following Personal Data:
3.1. Information you provide us. You may, through various means (e.g., e-mail, website contact form, sign-on through our Services, etc.), voluntarily provide us Personal Data and/or other information containing Personal Data. In particular, the said Personal Data include:
3.1.a. Contact and Account Data, such as your login details (username and password), name, complete address, e-mail, financial and payment information.
3.1.b. Resume Data, such as third-party’s Personal Data contained in resumes that are processed through our Services.
3.1.c. Technical and Server details, such as server details, your company IP address, credentials etc.
We will process the above Personal Data in accordance with the applicable law (including, where applicable, the GDPR) and on the assumption that they refer to you or to third parties who have authorized you to provide them pursuant to an appropriate legal basis which legitimize the processing at stake. In this case, unless you accepted a specific data processing agreement with us, you act as independent data controller, taking on all relevant obligations and responsibilities according to the applicable law (including, where applicable, the GDPR). In this regard, you shall indemnify and hold us harmless from and against all damages, losses, and expenses of any kind (including reasonable legal fees and costs) arose by any claim made by any third party whose Personal Data have been processed in breach of the applicable law as regards to your obligations as independent data controller.
3.2. Information on service use and your device. We log your visits and use of our Services, such as your interaction with content thereof, your user status (active/inactive), your last session, etc. Furthermore, we also get information about your IP address, proxy server, operating system, web browser and add-ons, device identifier and features, number of sessions, language and location. To such purpose, we use log-ins, cookies, device information and internet protocol (“IP”) addresses to identify you and log your use.
SECT. 4 - PURPOSES AND LEGAL BASIS OF THE PROCESSING
4.1. Purposes. Personal Data above will be processed by us for the purposes and legal basis specified below:
Personal Data involved
Contact and Account Data
To provide you with the Services that you requested from us.
This processing is necessary for the performance of our mutual contractual obligations and/or carried out with your consent.
To Process Resume and extract data from given resumes.
This processing is necessary for the actual execution of our product, carried out with your consent and/or necessary for the establishment, exercise or defense of legal claims.
Technical and Server details
To provide you with the Services that you requested from us.
This processing is based on a legitimate interest pursued by us and/or does not involve Personal Data (in case the relevant data are anonymized).
To provide you session of your panel, and other relevant information.
This processing is necessary for the performance of our online panel, to show your account relevant information.
4.2. Voluntary nature of the processing. Providing Personal Data for the above-mentioned purposes is voluntary and not mandatory. However, any refusal to provide any of such data may not allow us to establish and/or continue a contractual relationship with you, or to fulfil your requests, or to comply with legal obligations to which we are subject.
SECT. 5 - WHAT IS THE DATA RETENTION PERIOD?
5.1. Data retention. Personal Data collected by us will be processed for the time strictly necessary to achieve the purposes referred to in above. In particular:
5.1.a. Personal Data needed for the provision of our newsletter service will be processed until you decide to unsubscribe;
5.1.b. Personal Data needed for the provision of our Services will be processed until the lapse of 5 (five) years from the end of the account termination;
5.1.c. Personal Data whose retention is mandatory under the applicable laws (e.g., tax laws, bookkeeping, etc.) will be retained for a period necessary or permitted to comply with such laws.
SECT. 6 - WHAT SECURITY MEASURES HAVE BEEN TAKEN FOR YOUR PERSONAL DATA SAFEGUARD?
6.1. Security measures. We warrant to maintain (and continue to maintain) appropriate and sufficient technical and organisational security measures to protect your Personal Data against accidental or unlawful destruction or accidental loss, damage, alteration, unauthorised disclosure or access, as well as against all other unlawful forms of processing. Please be aware that no security measures are perfect or impenetrable, so we cannot guarantee that unauthorised access, hacking, data loss or a data breach will never occur. Notwithstanding the preceding, we operate with the aim of mitigating the risks associated with processing your Personal Data through several measures, including without limitation: (i) process only Personal Data that is essential to carry out our services and legal obligations (data minimisation); (ii) use encryption for securing the Personal Data that we process (e.g., Secure Sockets Layer – SSL); (iii) use company-wide restriction methods for restricting access into the foundation of our processes, systems and structure, in order to ensure that only those with authorisation and/or a relevant purpose have access to Personal Data and always with their private keys; (iv) make sure that our third-party services provider to whom we may transfer your Personal Data put in place an adequate level of protection thereof when carry on their processing activities.
SECT. 7 - WHO ARE THE RECIPIENTS OF YOUR PERSONAL DATA?
7.2. Third-party service providers or consultants. We engage certain trusted third parties to perform functions and provide services to us, including hosting and maintenance, e-mail, web analytics, database storage and management, operations, customer relationship, and advertising operations. We also require these third parties to maintain the confidentiality and security of your Personal Data they process on our behalf. Here is a list of service providers involved in any user-data related operations grouped by scenario, to make this policy easier to understand https://www.rchilli.com/vendor-list.
7.3. Third parties required by laws or authorities. We may disclose your Personal Data to a third party if: (i) we believe that disclosure is reasonably necessary to comply with any applicable law, regulation, legal process or governmental request (including to meet national security or law enforcement requirements), or (ii) to protect ourselves, our customers, or the public from harm or illegal activities. If we are required by law to disclose any of your Personal Data, then we will use reasonable efforts to provide you with notice of that disclosure requirement, unless we are prohibited from doing so by statute, subpoena or court or administrative order. Further, we object to requests that we do not believe were issued properly.
7.4. Third Parties recipients of anonymised, de-identified and aggregated data. We may transform your Personal Data in such a manner (i.e., through anonymisation, de-identification and aggregation) that these data can no longer be attributed to you. Such anonymised, de-identified or aggregated data will be shared to third parties for various purposes, including for business or marketing purposes or to assist third parties in understanding our users’ interest, habits and usage patterns for certain programs, content, services and functionalities of our Site.
SECT. 8 - WHERE YOUR PERSONAL DATA MAY BE TRANSFERRED
8.1. General. We are based in United States of America, India and other global locations and your Personal Data may be further transferred to, and stored at, any of our affiliates, partners or service providers mentioned in previous Sect. 7. In any case, when we transfer or disclose your Personal Data, we will ensure that the data transfer agreement entered into with the respective third party includes the “Standard Contractual Clauses for data transfers between EU and non-EU countries” adopted by the European Commission.
8.2. Further measures. In addition to the safeguards mentioned in previous Sect. 8.1, RChilli also has in place further measures in compliance with the “EU-U.S. and Swiss-U.S. Privacy Shield Frameworks” as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of Personal Data transferred from the European Union and/or Switzerland to the United States. In particular, RChilli has certified to the U.S. Department of Commerce that it adheres to the Privacy Shield Principles.
SECT. 9 - YOUR RIGHTS
9.1. Right of access. You are always entitled to receive confirmation as to whether your Personal Data are being processed or not and, where that is the case, access and receive copy of such Personal Data in an intelligible form. Furthermore, you are also entitled to receive information concerning: the purposes of the processing; the categories of Personal Data concerned; the recipients (or categories thereof) to whom the Personal Data have been or will be disclosed; where possible, the envisaged period for which the Personal Data will be stored, or, if not possible, the criteria used to determine that period; the existence of the right to request from us rectification or erasure of personal data or restriction of processing of your Personal Data or to object to such processing; the right to lodge a complaint with a supervisory authority; the source of the Personal Data; the existence of automated decision-making; where Personal Data are transferred to a third country or to an international organization, the appropriate safeguards relating to the transfer.
9.2. Right to withdraw consent. You are always entitled to withdraw, at any time, your consent to the processing of your Personal Data, both on legitimate grounds (even though they are relevant to the purpose of the collection) and if the processing is carried out for direct marketing purpose. The preceding will not affect the lawfulness of your Personal Data processing based on consent before the withdrawal.
9.3. Right to rectification, erasure and restriction. You are always entitled to obtain from us, without undue delay: the rectification or integration of your Personal Data that are inaccurate or incomplete; the erasure of your Personal Data that have been processed unlawfully or whose retention is unnecessary for the Purposes; the restriction of processing, in case you challenge either the accuracy of your Personal data or the lawfulness of the processing, or in case we no longer need the Personal Data for the Purposes, but they are required by you for the establishment, exercise or defense of a legal claim.
9.4. Specific rights for European or Swiss data subjects. If you are a Swiss citizen or a citizen of any Country in the European Union to whom GDPR applies, you will be afforded also the following rights:
9.4.a. Right to data portability. You have the right to receive your Personal Data in a structured, commonly used and machine-readable format, as well as the right to transmit those data to another controller without hindrance from us, where technically feasible.
9.4.b. Right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects. We may in some cases use automated decision-making, if it is authorized by legislation, if you have provided an explicit consent or if it is necessary for the performance of a contract. You can always request a manual decision- making process instead, express your opinion or contest decision based solely on automated processing, including profiling, if such a decision would produce legal effects or otherwise similarly significantly affect you.
9.4.c. Right to lodge a complaint. You have the right to lodge a complaint with the Supervisory Authority located in your place of residence.
9.5. Contacts. Requests to exercise the rights above must be sent by e-mail to firstname.lastname@example.org or by post to RChilli Inc., 2603 Camino Ramon, Ste 272, San Ramon, CA 94583, United States of America. Any access request is always completed within one month; however, where the retrieval or provision of information is particularly complex or is subject to a valid delay, the period may be extended by two further months. If this is the case, we will write to the individual within one month and keep him/her informed of the delay and the reasons thereof.
SECT. 10 - AMENDMENTS TO THIS POLICY