Data Protection Notice

eGym Privacy and Cookies Policy of the Career Page

Contents

  1. Responsible authority
  2. Contact data of the privacy officer
  3. Governed services of eGym
  4. Purpose of processing and legal base

4.1. Personal data

4.2. Legal base for the use of your data

4.3. Collection, processing and use of your personal data

4.3.1. General Information
4.3.2. Data access
4.3.3. Specific national rules (only relevant when applying in the particular country):
4.3.3.1. Varying storage periods
4.3.3.2. Specific national laws and regulations
4.3.4. Declaration of consent for privacy purposes

4.4. Collection, processing and use of anonymized and pseudonymized data

4.4.1. Cookies

4.4.2. Server log files

4.4.3. Google Analytics

4.4.4. WordPress.com

  1. Date security and encryption
  2. Recipients
  3. Transfer of data to third countries
  4. Duration of storage
  5. Rights of the data subject
  6. Right to withdraw your consent
  7. Right to lodge a complaint with a supervisory authority
  8. Obligation to provide personal data

Privacy is a matter of trust and trust is what matters to us. We respect your Privacy. Therefore, the protection and collection, processing and use of your personal data in compliance with the law is an important concern for us. In order to make you feel safe when using our services we strictly observe the legal provisions when processing your personal data.

 

1.Responsible authority

 

Responsible authority for the collection, processing and use of your personal data in terms of the EU general data protection regulation (GDPR) is eGym GmbH, Prannerstrasse 2-4, 80333 Munich, Germany (hereinafter “eGym”).

 

If you have any concern, don’t hesitate to contact us:

eGym GmbH
Prannerstraße 2-4
80333 Munich
telefax: +49 89 921 31 05 99
mail address: privacy@eGym.com

 

2.Contact data of the privacy officer

 

The privacy officer for eGym is René Hanschke. The designation refers to Art. 37 Abs. 1 lit. b) GDPR. He performs the tasks referred to in Art. 38 and 39 GDPR.

 

Data protection officer: René Hanschke

E-Mail: datenschutz@privacy

 

3.Governed services of eGym
This privacy and cookies policy applies to the following:

 

  1. Purpose of processing and legal base

 

The individual processing operations and the referring legal base of such shall be substantiated hereinafter:

 

  • Personal data

 

Personal data means any information relating to an identified or identifiable natural person (data subject). This includes, for example, your full name, your telephone number, your address as well as all communicated details of your application.

 

Anonymous statistic data don’t belong to the above mentioned.  For example, when you visit our website we collect anonymous statistic data, which cannot or can only be associated with you with unreasonable high effort. Such data might be statistics about the popularity of the individual parts of our services or how many users visited specific sites of the eGym career page.

 

 

  • Legal base for the use of your personal data

 

The legal base for processing your personal data may be provided by more specific rules from the member states to ensure the protection of the rights and freedoms in respect of the processing of employees’ personal data in the employment context according to Art. 88 paragraph 1 GDPR safeguarding the guidelines of paragraph 2. The derived § 26 Bundesdatenschutzgesetz (neu) (German national data protection law, hereinafter BDSG (neu)) defines that personal data of employees can only be processed to enter an employment when the processing is governed by the consent of the employee or when processing is required for the setting up, performance or termination of the contract of employment or to execute or fulfil the rights and duties of representing bodies of employees that are derived by law or from a company agreement. Processing for the prosecution of criminal offences is only allowed when reasonable indications induce the suspicion that the data subject has committed a crime during the employment, the processing is required for the detection of the crime and the legitimate interest of the procedure of exclusion of the data subject doesn’t prevail (especially when nature and scope regarding the occasion are not disproportionate). The employment in a foreign establishment or subsidiary refers to the specific national legal terms for employment in the respective country.

 

4.3. Collection, processing and use of your personal data

4.3.1. General Information

 

Any personal data that you provide to the recruiting team using these services including attached files to your application letter that contain personal data will be collected, processed and used to review your application. Therefor we collect the following data:

 

  • Contacts details (name, e-mail address, postal address, telephone number)
  • Any information provided in your application

Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation are not collected on purpose, unless otherwise required by law in individual cases.

 

If eGym uses your data (meaning your application profile) apart from the current job posting we will ask for your consent.

 

4.3.2. Data access

 

Only employees of eGym responsible for the recruiting process access to personal data provided by you.

To ensure a proper workflow only selected employee have access to your data.

Within this workflow and to maintain the online career page, eGym employs external service providers. Our service providers are located within the European Economic Area (EEA), who guarantee the same level of data protection. We do not employ external service providers outside the EEA.

 

4.3.3. Specific national rules (only relevant when applying in the particular country):

 

4.3.3.1. Varying storage periods

 

Up to twenty-four (24) months: Belgium, Finland, France, Italy, Luxembourg, Sweden

 

Up to thirty-six (36) months: Brazil, Greece, Great Britain, Ireland, Norway, Austria, Russia, United States

 

Up to sixty (60) months: Switzerland

 
4.3.3.2. Specific national laws and regulations

 

Belgium:

Your personal data intended for application and recruitment purposes is processed in conformity with the law of 8 December 1992 on privacy protection in relation to the processing of personal data.

If you voluntarily give us certain types of personal data (sensitive personal data such as details of race or ethnic origin or membership of a trade union organization, or health details), you give us your consent for this to be processed relating to an application and recruitment process.

The entity responsible can pass your data (including the types of personal data referred to above) to suppliers who provide services to this entity in the field of selection and handling of applications. The applicable laws will be complied with in all cases.

The party responsible for processing is eGym GmbH, with its registered office at Prannerstrasse 2-4, 80333 München, Germany.

Your request for inspection, rectification and removal can be sent by e-mail to the e-mail address jobs@egym.de or by normal letter to the above address for the attention of recruitment HR service address, Prannerstrasse 2-4, 80333 München, Germany.

 

Finland:

The following companies will have access to the personal data given by you on this job application site:

  1. a) eGym GmbH, Prannerstrasse 2-4, 80333 München, Germany;

You will have the right to correct or remove the information given by you, should you notice any incorrect, unnecessary, faulty or outdated personal data. Your request for removal and / or amendment of data can be sent by e-mail to the following address:

jobs@egym.de

By accepting this declaration of consent, you hereby give your consent to the handling of your personal data in the manner described in this declaration of consent, including the described transfer of your personal data outside EU/EEA.

 

Greece:

Your personal data intended for application and recruitment purposes are processed in conformity with Law 2472/1997 on the protection of individuals with regards to the processing of personal data.

If you voluntarily give us certain types of personal data (sensitive personal data such as details of race or ethnic origin or membership of a trade union organization, or health details), you give us your consent for such data to be processed relating to the application and recruitment process.

The party responsible for processing is eGym GmbH, Prannerstrasse 2-4, 80333 München, Germany.

The party responsible, can transfer your data (including the types of personal data referred to above) to suppliers who provide services to this entity in the field of selection and handling of applications. The applicable laws will be complied with in all cases. By accepting this declaration of consent, you hereby give your consent to the handling of your personal data in the manner described in this declaration of consent, including the described transfer of your personal data outside EU/EEA.

Your request for the exercise of the rights of Law 2472/1997 can be sent by letter to the above address for the attention of recruitment HR service address, eGym GmbH, Prannerstrasse 2-4, 80333 München, Germany.

 

Italy:

According to and due to section 13 of the Personal Data Protection Act as per legislative decree no. 196 dated 30 June 2003.

 

Be informed that:

  1. The requested data in the on-line form is necessary for recruiting process: an exhaustive filling of it allows a proper evaluation of the application;

 

  1. The data owner is eGym GmbH, the data responsible is the Human Resources Manager, who is liable pro tempore;

 

  1. The rights as per Section 7 will follow next:

 

 

Section 7 (Right to Access Personal Data and Other Rights)

 

1.A data subject shall have the right to obtain confirmation as to whether personal data concerning him or her exist, regardless of their being already recorded, and communication of such data in intelligible form.

 

  1. A data subject shall have the right to be informed a) of the source of the personal data; b) of the purposes and methods of the processing; c) of the logic applied to the processing, if the latter is carried out with the help of electronic means; d) of the identification data concerning data controller, data processors and the representative designated as per Section 5(2); e) of the entities or categories of entity to whom or which the personal data may be communicated and who or which may get to know said data in their capacity as designated representative(s) in the State’s territory, data processor(s) or person(s) in charge of the processing.

 

  1. A data subject shall have the right to obtain a) updating, rectification or, where interested therein, integration of the data; b) erasure, anonymization or blocking of data that have been processed unlawfully, including data whose retention is unnecessary for the purposes for which they have been collected or subsequently processed; c) certification to the effect that the operations as per letters a) and b) have been notified, as also related to their contents, to the entities to whom or which the data were communicated or disseminated, unless this requirement proves impossible or involves a manifestly disproportionate effort compared with the right that is to be protected.

 

  1. A data subject shall have the right to object, in whole or in part, a) on legitimate grounds, to the processing of personal data concerning him/her, even though they are relevant to the purpose of the collection; b) to the processing of personal data concerning him/her, where it is carried out to send advertising materials or direct selling or else for the performance of market or commercial communication surveys.

 

Poland:

By accepting this declaration of consent, you hereby give your consent to the handling of your personal data in the manner described in this declaration of consent, including the described transfer of your personal data outside EU/EEA.

 

Schweiz:

Das verantwortliche Unternehmen kann Ihre Daten an Auftragnehmer übermitteln, die für das Unternehmen im Bereich der Bewerbungsauswahl und -bearbeitung tätig sind. In allen Fällen werden die geltenden gesetzlichen Bestimmungen eingehalten. Mit Annahme dieser Einverständniserklärung stimmen Sie der Verwendung Ihrer persönlichen Daten in der hier beschriebenen Weise zu, einschließlich der beschriebenen Übertragung Ihrer persönlichen Daten außerhalb der EU / des EWR. Ihre Daten werden für den Zeitraum von bis zu 5 Jahren aufbewahrt und bei Ihrem Einverständnis für zukünftige Positionen innerhalb des Landes geprüft.

Sie haben jederzeit das Recht, Ihr Einverständnis zurückzuziehen. Ihre Unterlagen werden in diesem Fall umgehend gelöscht.

 

Spain:

Personal data which has been provided by you shall be included in a data file under the responsibility of the affiliated entity of eGym in the Spanish territory to which you have applied for a position and maintained under its responsibility. Your specifically and unmistakably accept the transfer of your data to the suppliers of this entity in the field of selection and the management of candidates as well as for the maintenance of this tool in accordance with point 3. Data access.

You can, at any time, exercise the rights of access, correction, cancellation and opposition regarding your personal data, with a request in writing addressed to eGym GmbH, Prannerstrasse 2-4, 80333 München, Germany or via e-mail to jobs@egym.de.

4.3.4. Declaration of consent for privacy purposes

Please read the following terms carefully and agree to them to proceed with the recruitment process. Once agreed upon, you may withdraw this declaration of consent at any time using the mail address mentioned at the top (privacy@egym.com).

  1. I agree with the collection, processing and using of my personal data as described in the “eGym Privacy and Cookies Policy of the Career Page”
  2. Furthermore, I expressly agree to the processing of special categories of personal data as described in the “eGym Privacy and Cookies policy of the Career Page” if communicated in my application documents (for instance information included in your attachments).

By submitting your application, you consent to the above-mentioned declaration. Your declaration of consent will be stored.

In case you don’t consent, your application won’t be accepted and won’t be processed by eGym.

 

  • Collection, processing and use of anonymized and pseudonymized data

 

We use distinctive procedures based on anonymized and pseudonymized data to continually improve our offer and to organize it more user-friendly and interesting. By using our services, you declare your consent to the use of exclusively anonymized and pseudonymized data.

There is no possibility to assign the data to any specific person. Nevertheless, we want to inform you about this kind of data as well as about your right to object to processing data in order to create anonymous user profiles for the purpose of advertising, market research and in order to customize our services.

 

4.4.1. Cookies

 

When you interact with the Site, we try to make that experience simple and meaningful. When you visit our Site, our Web server sends a cookie to your computer or mobile device (as the case may be).

The acceptance of cookies is not a condition for visiting our Site or Applications. However, we would point out that use of the Site or Applications could be restricted if the cookie function is deactivated.

 

Cookies are small text files which are issued to your computer or mobile device (as the case may be) when you visit a website or access or use a mobile application and which store and sometimes track information about your use of the site or application (as the case may be).  Several cookies we use last only for the duration of your web or Application session and expire when you close your browser or exit the Application.  Sessions cookies are needed to provide your login information for several Sites. Other cookies are used to remember you when you return to the site or application and will last for longer (persistent cookies). The information will be transmitted to the server every time the user visits the website that it belongs to, or every time the user views a resource belonging to that website from another website (such as an advertisement). These cookies will be stored locally on your hard disk and will be deleted automatically after the allotted time.

 

No personal data is stored in the cookies used by eGym. The cookies which we use can therefore not be assigned to any specific person and hence not to you either. When the cookie is activated, an identification number is allocated to it. No assignment of your personal data to this identification number is possible at any time and this is not attempted. Your name, your IP address or similar data which would enable a cookie to be assigned to you is never linked with this information. On the basis of cookie technology, all we receive is anonymized information, for example about which pages of our shop have been visited, which products have been looked at, etc. In individual cases, it is permitted for our partner companies to collect, process or use data from our Site in the form described above by means of cookies. This applies in particular to the web analytics or social media services named below. In addition, data will be collected on the basis of cookie technology in order to optimize our advertising and the entire range of online services. This data too will not be used in order to identify you personally but will only serve to produce an anonymous evaluation of the use of the services. At no time will your data be put together with the personal data stored with us. Using this technology, we can present you with advertising and/or particular offers and services where the content is based on the connection with the information obtained by the clickstream analysis. Our aim here is to make our range of online services as attractive as possible for you and to present you with advertising which corresponds to your areas of interest.

 

eGym uses the services of a few partners who help us to design the internet service and the eGym Site in a way which is interesting for you. Therefore, when you visit the eGym Career Page, cookies from partner companies will also be stored on your hard disk. These are temporary/permanent cookies which are automatically deleted after the pre-set time (see above). The cookies of our partner companies do not contain any personal data either. Only pseudonymous data under a user ID is collected. This data relates to such things as which products you have looked at, whether anything has been purchased, etc. In this context, a few of our advertising partners also collect information via the eGym Career Page about which pages you have previously visited or which products you may for example have been interested in, so that advertising can be displayed to you which best corresponds to your interests. This data will at no time be put together with your personal data. It serves the exclusive purpose of enabling our advertising partners to approach you with advertising which might actually be of interest for you.

 

You can choose a setting in your browser which allows the storage of cookies conditional upon your consent. If you only want to accept the eGym cookies but not the cookies from our service providers and partners, you can select the setting „Block third-party cookies“ in your browser. Generally, there will be a display via the Help function in the menu list of your web browser telling you how to reject new cookies and disable ones already received. With shared-use computers which are set to accept cookies and flash cookies, we recommend that you always sign out completely after the end of a session.

 

4.4.2. Server log files

 

Each time you access the pages of the eGym Site or Applications, usage data is transmitted by the relevant internet browser and stored in server log files. The datasets stored in this case contain the following data: date and time of retrieval, name of the page accessed, IP address, referrer URL (the source URL from which you accessed the eGym Site), the volume of data transmitted plus product and version information for the browser used. The user’s IP addresses are deleted or anonymized after the end of use. Anonymizing means that the IP addresses are altered in such a way that the particular details about personal or factual circumstances cannot be assigned to a specific or identifiable person, or only at disproportionately high expense in terms of time, costs and manpower. We evaluate the log file datasets in anonymized form in order to improve our range of services on the Site even further and make it more user-friendly, to locate and eliminate errors more quickly and to control server capacities.

 

4.4.3. Google Analytics

 

To constantly improve and optimize our range of services, we use so-called tracking technologies. We use the services of Google Analytics.

 

Google Analytics is a service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA („Google“).

 

eGym uses the Google Analytics functionality “User ID” via all platforms on the eGym Site /mobile Site, the eGym fitness application and the trainer application to gather pseudonymous (non-personal) information on the usage of our services, both locally and globally to improve and help us analyze the eGym services. In detail:

Google Analytics uses „cookies“, i.e. text files, which are stored on your computer and enable an analysis of the use of our range of services by Google. As a rule, the information gathered by the cookie about the use of our Site (including your IP address) is transmitted to a Google server in the USA and stored there. We would point out that on the web page ‚Google Analytics‘ has been expanded by the code „gat._anonymizeIp();“ in order to ensure an anonymized collection of IP addresses (so-called IP masking). At our instigation, your IP address is therefore only collected by Google in abbreviated form, which guarantees anonymity and does not allow any conclusions as to your identity. In the case of the activation of IP anonymity on this web page, your IP address will first be abbreviated by Google within the member states of the European Union or in other states which are contracting parties to the Agreement on the European Economic Area.

Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and abbreviated there. Google will use the said information in order to evaluate your usage of our Site, to compile reports on Site activities for us and to provide us with other services associated with the use of web pages and the Internet. The IP address transmitted by your browser in the context of Google Analytics will not be put together with other Google data. A transmission of these data by Google to third parties only occurs on the basis of legal stipulations or when processing order data. In no case will Google put your data together with other data collected by Google.

In your use of this Site you declare that you agree with the processing of data collected about you by Google and the ways and means in which the data is processed described above as well as with the purpose stated. You can prevent the storage of cookies by making a corresponding setting in your browser software; we would however point out that sometimes this will prevent you from using the functions of this Site to their full extent. In addition, you can prevent the collection of the data produced by the cookie and relating to your use of the Site (including your IP address) for Google and the processing of this data by Google by downloading and installing the browser plug-in available under the following link (http://tools.google.com/dlpage/gaoptout?hl=de). More information can be found on Google Analytics and data protection at http://tools.google.com/dlpage/gaoptout?hl=de or http://www.google.com/intl/de/analytics/privacyoverview.html.

 

4.4.4. WordPress.com

 

We use WordPress.com as a Web-Software to operate our Website and Blog. WordPress.com uses so called “Cookies”. These are small text files stored on your computer to enable the analysis of the use of our websites.  The information generated by the cookies about your usage of the Websites will be stored at a server in the U.S.  Your IP – address will be anonymized immediately after processing before storing. You can avoid the installation of Cookies by appropriately adjusting your browser software. We would like to make you aware of the fact, that in this case it is possible that you will not be able to use all the functions of this website.

 

You can object the collecting, processing and use of your personal data of WordPress.com via the tracking tool “Quantcast” with future effect by using the following link http://www.quantcast.com/opt-out.

In case you might delete or reset all your cookie settings on your computer you will have to set again the opt-out for WordPress.com with the link mentioned above.

 

  1. Date security and encryption

 

Your application details are transmitted safely through encryption. This relates to the application as well as to the user log-in. For communicating between the eGym Career Page and the eGym server we exclusively use TLS 1.0 to 1.2 (Transport Layer Security).  Reverting to older versions is not possible. This also affects the inserted encryption (cipher) that uses PFS (perfect forward security). Furthermore, eGym uses only HSTS procedures that exist less than 1 year. This is generally called SSL coding and guarantees maximum safety for transmitting data.

We place great importance on the security of all personal data associated with our users.  We have security measures in place to safeguard our website and other systems against the loss, destruction, access, misuse, alteration and distribution by unauthorized persons of personal information under our control.  Whilst we cannot ensure or guarantee that loss, destruction, access misuse, alteration or distribution of information by unauthorized persons will never occur, we use all reasonable efforts to prevent it.

You should bear in mind that submission of information over the internet is never entirely secure.  We cannot guarantee the security of information you submit via the Site or Application whilst it is in transit over the internet and any such submission is at your own risk.

 

All servers that store eGym application details are located in the European Union(EU)/ European Economic Area (EEA).

 

  1. Recipients

 

A recipient according to Art. 13 Par. 1 lit. e) GDPR is any natural or legal person, public authority, agency or any other body to whom personal data are disclosed, whether a third party (Art. 4 Nr. 10 GDPR) or not.  The data subject must be informed about every recipient at the time the personal data are collected.

As already mentioned in Number 4.3.2. of this policy, only selected employees that are responsible for the recruitment process and for the staff of eGym have access to your data. Those employees are to be seen as recipients.

 

Furthermore, we use the software Staffboard as a service of the Staffboard UG (limitation of liability), Tulbeckstrasse 32, 80339 Munich, Germany. This service helps to organize internal human resource processes. We will create an individual digital coworkers file, that e.g. serves for the vacation management. This requires the full name and the business mail address as well as your private mail address and your phone number for emergencies. The employee decides by himself/herself which personal data is visible for all other employees on Staffboard. In this respect, also other employees are recipients within the meaning of Art. 13 Abs. 1 lit. e).

 

  1. Transfer of data to third countries according to Art. 44 et seq. GDPR

 

All servers storing information of the application are located within the EU/EEA.

 

 

  1. Period of storage

 

We adhere to the principles of data avoidance and data economy. We store your personal data only if it is required to reach the aims mentioned above or as prescribed by the legislature. After ending of the respective purpose or expiry of these deadlines, the corresponding data are routinely blocked or deleted in accordance with legal requirements.
The application documents will be deleted after 90 days if the applicant does not enter into an employment.

If an appropriate position can’t be offered to the applicant, he/she can apply for the talent pool of eGym (this requires the consent). In this way, the application documents can be stored until a suitable position can be found or the applicant withdraws his/her consent.

In case of an employee leaving eGym all local stored data will be deleted except the private address for the sole purpose of enabling subsequent contact with the applicant. If applicable, former employees will be registered for the pool of eGym alumni in case their explicit consent to stay in touch (e.g. email notification for upcoming events is granted).

Former working students or interns can be registered for the pool of heroes. They will be informed about positions to promote (ambassadors) as well about upcoming events (cancellation of this newsletter possible at any time).

 

  1. Rights of the data subject

 

According to the GDPR our applicants are entitled to receive information concerning the data stored in relation to their person at any time (Art. 15 GDPR). They also have the right to demand rectification (Art. 16 GDPR), erasure (“right to be forgotten” Art. 17 GDPR) and restriction of processing (Art. 18 GDPR). The right to data portability according to Art. 20 GDPR entitles the user to transmit his/her personal data from one responsible authority to any other.

 

  1. Right to withdraw your consent

 

If the usage of your data requires your approval, you will be asked to give your explicit consent in each case and eGym will record it.

To withdraw your consent or to object, a short message to eGym will suffice.

Please note that in case of a revocation of certain data the provision of services is no longer possible. The legality of processing remains untouched up to its revocation.
Don’t hesitate to ask for further information.

 

  1. Right to lodge a complaint with a supervisory authority

 

According to Art. 77 Par. 1 GDPR every data subject has the right to lodge a complaint with a supervisory authority if considered that the processing of personal data was unlawful.

 

  1. Obligation to provide data

 

Providing the personal data is required to the decide about a hire, the set-up, performance or termination of the contract of employment. It might be also required to execute or fulfil the rights and duties of representing bodies of employees that are derived by law or from a company agreement.

 

Last update: August 2017