1. General provisions
1.1 Introduction. Coesia S.p.A. (“Company”) is the holding company of an industrial group made up of several entities operating internationally (“Coesia Entities”). Company, in accordance with the Coesia Group commitment to international compliance with data protection laws, is accordingly committed to protecting personal data collected through use of its website www.coesia.com (“Website”), according to any national legislation in force on personal data protection (“National Data Protection Laws”) and the EU General Data Protection Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing the Directive 95/46/EC (“GDPR”). This Privacy Policy explains how information and data identifying individuals (“Personal Data”) received by Company through its Website are processed for recruitment purposes.
1.2 Joint-Controller. Coesia S.p.a. and its worldwide affiliates (“Coesia Group”), act as joint-controllers under art. 26 of GDPR of the personal data that you decide to provide us through the website for the purposes described by this privacy notice.
1.3 Applicable rules. Coesia Group processes Personal Data in accordance with: (i) provisions of National Data Protection Laws in force as of the date of the Privacy Policy; (ii) provisions of the GDPR and, in particular, with the principles set forth in the same, such as, inter alia, lawfulness, fairness and transparency, purpose limitation, data adequacy and minimization, accountability, accuracy, and – prior to any processing activity – the principles of privacy by design and privacy by default; (iii) guidelines and decisions issued by the competent supervisory authority (“Supervisory Authority”).
2. Data subjects and scope of application
2.1 Data subjects. The data processing activities relate to any candidate for a job position through the website. For the purposes of this Privacy Policy, candidates are to be intended as data subjects (“Candidates” or “Data Subjects”), as defined by the National Data Protection Laws and by the GDPR.
2.2 Scope of application. The Privacy Policy shall be applicable to Candidates, provided that Coesia Group is only liable for the processing of Personal Data, which are under its own powers, duties and liabilities. The Privacy Policy shall not be deemed valid and enforceable for any processing activity made by third parties whose activities may be put in place as autonomous data controller, including platforms owned/managed by third parties for the administration, elaboration and delivery to candidates concerned of aptitude or personality tests (“Platforms”), which may support Coesia Group in carrying out such activities for specific professional profiles (such as, for instance, recent graduates, white collar workers, senior management/candidates for leadership positions),
3. Types and source of processed Personal Data
3.1 Source. The Coesia Group processes the Candidates’ Personal Data – as hereinafter specified – provided by Candidates itself. Furthermore, Coesia Group might process personal data collected or provided by third parties acting as data controller (recruiting service companies, Platforms, LinkedIn ecc.) on the base of the consent provided by the data subject itself to each data controller.
3.2 Identification data. The Coesia Group processes Candidates’ Personal Data, which consist of:
a) your identification data (such as, for example, name, surname, private address, e-mail address, citizenship, phone number, ecc.);
b) data relating to your training and your career (such as, for example, current and previous employment, information on recruitment or vocational training, job curriculum vitae, references provided by third parties in your favor, ecc.);
c) any other document, information or multimedia material that you decide to provide with us (such as, for example, pictures, videos, ecc.);
d) as the case may be, information on your aptitude skills or behavioral characteristics contained in a summary or general reports (“General Reports”), provided by the Platforms, from time to time involved, provided, however, that such General Reports do not include any specific reference to questions and related answers contained in the tests, which are exclusively and directly processed by the Platform involved.
4. Legal basis for and purposes of processing the Personal Data. Period of data retention
4.1 Legal bases and purposes. The Coesia Group processes Personal Data for the following purposes, as specified here in below, in which is furthermore highlighted (a) the Legal Bases as well as (b) the period of data retention:
A. Purpose: Process of Personal Data for recruiting purposes, having your personal data registered into Coesia talent database for further job positions and being contacted by Coesia Group’s companies (including the transfer outside the EU) for the same purposes
Legal Base: Consent
Data retention period: 2 years
B. Purpose: Allow you to apply for the job opportunity published on the section “Work with us” of this website
C. Purpose: as the case may be, process of personal information contained in the General Reports received by Platforms from time to time involved for recruiting purposes, which may include the relevant use by the Company or Coesia Group for further job positions
Data Retention Period: 2 years
We inform you that, pursuant to artt. 5 and 89, co. 1 of the GDPR, your personal data may be stored for longer periods of time than specified in the previous paragraph for statistical purposes only.
4.2 Mandatory provision of Personal Data and consent. Subject to what specified above, the provision of Personal Data for the purposes under art. 4.1 lett. A) and B) and the related consent is mandatory and the failure to provide the consent or your Personal Data may entail failure apply to the job opportunity and to be registered into Coesia talent database and to be contacted by Coesia Group for further job positions.
4.3 Right to withdraw the consent. In relation to the purpose specified under art. 4.1 lett. A) and B), Data Subjects have the right to withdraw its consent writing an email to cpo@coesia.com. The data processing activities performed before the withdrawal of the consent will be valid anyway.
5. Persons in charge of the processing, data processors and other data controllers.
5.1 Persons in charge of the processing. As specified above, the Coesia Group processes Personal Data collected from the Data Subject through the Website. Directors, shareholders and independent collaborators (independently from the contractual relationship concerned) of the Coesia Group may process Personal Data in their capacity as persons in charge of the processing, according to National Data Protection Laws and to art. 29 of the GDPR. The persons in charge of the processing are duly trained to correctly and safely process Personal Data.
5.2 Data processors. The Coesia Group may designate internal and external entities/individuals as Data Processors, including but not limited to (legal and tax) advisors and third companies (in particular, internet service providers and service providers, also using cloud platforms). The complete list of all processors may be required by Data Subjects to the Controller, by sending an email to the Controller email address specified in article 7.1. of this Privacy Policy.
5.3 Other data controllers. The Coesia Group may communicate your personal data to third companies or employment public authorities acting as autonomous data controllers, in particular Universities, Schools, Masters, Employment Offices even for disability recruitment targets, Promoters of internships, Platforms etc. in relation to the purposes described under art. 4.1 of the Table above.
6. Method of processing, storage of Personal Data and security measures
6.1 Methods of processing. The Personal Data of Data Subjects are processed almost exclusively through automated procedures, by using computerized systems and software or, in a limited number of cases, through manual means (e.g. on paper), provided however that in any event such Personal Data are processed adopting methods which are strictly related to the purposes for which such data have been collected and anyway to ensure their security, in accordance with the GDPR and the National Data Protection Laws. In any event, the Personal Data of Data Subjects – including, as the case may be, the information contained in the General Reports, as specified above – are processed through the Coesia Group’s recruiters, personally involved in the recruiting process; as a consequence, the Data Subjects will not be subject to any decision based solely on automated processing, including profiling, pursuant to art. 22 of the GDPR.
6.2 Place of automated data processing. Processing of Personal Data is made by the Coesia Group’s companies as joint-controllers and/or – if appointed – of the processors. Personal Data are stored in the head offices of the Coesia Group’s companies where the physical servers are and in some cases on servers of third parties, which provide cloud services to allow storage of Personal Data.
6.3 Transfer of Personal Data. With the aim of achieve the purposes described above Personal Data may be transferred to other Coesia Group’s companies, acting as joint-controllers, located in EU or in third countries outside the EU. In some cases, the other Coesia Group’s companies to whom the Personal Data will be transferred may be located in countries outside the EU that do not guarantee appropriate safeguards pursuant to Article 46 of the GDPR and has not an adequacy decision pursuant to Article 45 of the GDPR. Though the Joint-Controllers guarantee a high level of safety of your personal data through the use of modern IT systems, your personal data may be at risk under the legislation of the extra EU country. The legal base for the transfer of your personal data outside the European Union to other companies of Coesia Group for purposes described in Article 4.1 letters A) and – as the case may be - C) is represented by your consent.
6.4 Dissemination of Personal Data. Personal Data will not be disseminated.
7. Data Subjects’ rights
7.1 Rights. Data Subjects, when they are individual/natural persons, may directly address to the Controller or the processor/s designated by the same Controller in order to enforce their rights according to provisions of National Data Protection Laws and to the GDPR (articles 15 and subsequent articles), and, in particular, to have access to their own Personal Data, obtain updating and rectification or erasure of the same, restriction of processing, object on legitimate grounds to processing of their Personal Data (with the effects provided for in the Privacy Policy) as well as obtain data portability by sending an email to the email address cpo@coesia.com. In addition, where the consent is given by the Data Subjects, the latter may revoke it at any time – without prejudice to the obligatory requirements provided by legislation in force at the time of the request for withdrawal – by sending an email to the email address indicated above, provided however that such a communication of withdrawal shall not affect the lawfulness of processing based on consent before the withdrawal.
7.2 Complaint. The above notwithstanding, according to articles 13 and 15 of the GDPR, Data Subjects
may lodge a complaint with the competent Supervisory Authority, in order to enforce their rights, as specified above.
2.2 Scope of application. The Privacy Policy shall be applicable to Candidates, provided that Coesia Group is only liable for the processing of Personal Data, which are under its own powers, duties and liabilities. The Privacy Policy shall not be deemed valid and enforceable for any processing activity made by third parties whose activities may be put in place as autonomous data controller, including platforms owned/managed by third parties for the administration, elaboration and delivery to candidates concerned of aptitude or personality tests (“Platforms”), which may support Coesia Group in carrying out such activities for specific professional profiles (such as, for instance, recent graduates, white collars workers, senior management/candidates for leadership positions).
3.1 Source. The Coesia Group processes the Candidates’ Personal Data – as hereinafter specified – provided by Candidates itself. Furthermore, Coesia Group might process personal data collected or provided by third parties acting as data controller (recruiting service companies, LinkedIn ecc.) on the base of the consent provided by the data subject itself to each data controller.
B. Purpose: as the case may be, process of personal information contained in the General Reports received by Platforms from time to time involved for recruiting purposes.
Legal Base: consent
4.2 Mandatory provision of Personal Data and consent. Subject to what specified above, the provision of Personal Data for the purpose under art. 4.1 lett. A) and the related consent is mandatory for the general application and the failure to provide the consent or your Personal Data may entail failure to be registered into Coesia talent database and to be contacted by Coesia Group for further job positions.
4.3 Right to withdraw the consent. In relation to the purpose specified under art. 4.1 lett. A), of the Table above, Data Subjects have the right to withdraw its consent writing an email to cpo@coesia.com. The data processing activities performed before the withdrawal of the consent will be valid anyway.
5. Persons in charge of the processing, data processors and other data controllers
5.3 Other data controllers. The Coesia Group may communicate your personal data to third companies or employment public authorities acting as autonomous data controllers, in particular Universities, Schools, Masters, Employment Offices even for disability recruitment targets, Promoters of internships etc. in relation to the purposes described under art. 4.1 of the Table above.
6.1 Methods of processing. The Personal Data of Data Subjects are processed almost exclusively through automated procedures, by using computerized systems and software or, in a limited number of cases, through manual means (e.g. on paper), provided however that in any event such Personal Data are processed adopting methods which are strictly related to the purposes for which such data have been collected and anyway to ensure their security, in accordance with the GDPR and the National Data Protection Laws. In any event, the Personal Data of Data Subjects – including as the case may be, the information contained in the General Reports, as specified above – are processed through the Coesia Group’s recruiters, personally involved in the recruiting process; as a consequence, the Data Subjects will not be subject to any decision based solely on automated processing, including profiling, pursuant to art. 22 of the GFPR.
6.3 Transfer of Personal Data. With the aim of achieve the purposes described above Personal Data may be transferred to other Coesia Group’s companies, acting as joint-controllers, located in EU or in third countries outside the EU. In some cases, the other Coesia Group’s companies to whom the Personal Data will be transferred may be located in countries outside the EU that do not guarantee appropriate safeguards pursuant to Article 46 of the GDPR and has not an adequacy decision pursuant to Article 45 of the GDPR. Though the Joint-Controllers guarantee a high level of safety of your personal data through the use of modern IT systems, your personal data may be at risk under the legislation of the extra EU country. The legal base for the transfer of your personal data outside the European Union to other companies of Coesia Group for purposes described in Article 4.1 letter A) and – as the case may be – B is represented by your consent.
7.2 Complaint. The above notwithstanding, according to articles 13 and 15 of the GDPR, Data Subjects may lodge a complaint with the competent Supervisory Authority, in order to enforce their rights, as specified above.
The data processing activities performed before the withdrawal of the consent will be valid anyway.
By giving your consent, your LinkedIn profile can be viewed by our recruitment staff and connected to our recruitment tool. You authorize the sharing of information between LinkedIn and our recruitment tool.