Data Handling Policy in Application Management

 

1.Data Protection Commitment

Coindu – Componentes para a Industria Automovel SA, hereinafter referred to as COINDU, a legal entity with the portuguese legal person number 501998055, complies with the applicable Community and national legal rules in the field of data protection, privacy and security of candidates’ personal information, in accordance with the general terms of the Data Protection and Privacy Policy which can be accessed at www.coindu.com or at any of its service points.

2.Personal Data

COINDU collects and processes the following personal data from candidates: name, title, position, company where you work and contacts within the company, as well as business card details and all the data on your CV or application form.

3.Data Sources

COINDU collects candidates’ personal data by sending personal CVs, filling in the application form or from various sources of personal information accessible to the general public (websites, professional networks, media, etc.), as well as on the basis of personal references.

4.Purpose of processing

COINDU processes candidates’ personal data exclusively for the purposes of human resources management and the selection or recruitment of workers.

5.Legitimacy of processing

COINDU bases the legitimacy of the processing of candidates’ personal data according to the specific processing activities, either based on the candidates’ consent, on the basis of the execution of pre-contractual relations, or on the basis of the legitimate interest of human resources management for the pursuit of the selection and recruitment of human resources in the context of the exercise of a legitimate economic activity.

6.Data retention period

COINDU will keep the data for the period necessary to pursue the purposes of the processing, complying with the legal deadlines, with the candidate being able to request, at any time, its deletion or exercise any other right, and with a default retention period of five years for the CVs and personal data of candidates processed by the human resources management services.

7.Communication of Personal Data

Candidates’ personal data is processed exclusively by COINDU’s human resources management services, and no data is communicated to third parties.

8.Data Processing Information Sheets

Under the terms of the principle of loyalty and transparency and to guarantee compliance with the duty to inform, COINDU delivers directly or makes publicly available to all personal data subjects, depending on how their personal data is collected, information sheets on the data processing activities carried out, which are accessible for consultation at any service point or by request to the Data Protection Officer.

The Information Sheet on Data Processing in Application Management is available at www.dataprotectionofficer.help/coindu/information.

9.Candidates’ rights

COINDU facilitates the exercise of candidates’ rights in terms of personal data protection.

In addition to always being able to lodge a complaint with the respective supervisory authority, in order to exercise any type of data protection rights, namely the rights to withdraw consent, information, access, rectification, opposition, restriction of processing or erasure, candidates can contact the COINDU Data Protection Officer directly by emailing dpo@coindu.com,   describing the subject of the request and indicating an email address, telephone contact address or correspondence address for a reply.

A Form for Exercising the Rights of Data Subjects is available at www.dataprotectionofficer.help/coindu/forms/ or at any COINDU service point.

10.Reporting Personal Data Breach Incidents

COINDU has implemented a data protection and information security incident management system.

If any User, Service Recipient or User wishes to report the occurrence of any personal data breach, which accidentally or unlawfully causes the unauthorized destruction, loss, alteration, disclosure or access to personal data transmitted, stored or subject to any other type of processing, they can contact the COINDU Data Protection Officer or use COINDU’s general contacts.

A Personal Data Breach Incident Reporting Form can be found at www.dataprotectionofficer.help/coindu/forms/ or at any COINDU service point and can also be sent by email by contacting the Data Protection Officer.

11.Permanent Security Contact Point

COINDU has implemented a Permanent Contact Point for the management of information security and cyberspace security incidents.

If any Candidate, User, Service Recipient or User wishes to report an information security incident or a cyberspace security incident, they can contact the COINDU Permanent Contact Point through the communication channels available at www.dataprotectionofficer.help/coindu/security/.

An Information Security or Cyberspace Security Incident Reporting Form can be found at www.dataprotectionofficer.help/coindu/forms/ or at any COINDU service point, and can also be sent by email on request to the Permanent Contact Point.

12.Protection of whistleblowers

COINDU has implemented a Whistleblowing Channel, in accordance with the legal regulations in force, guaranteeing the protection of the personal data of data subjects, under the terms of the Whistleblower Protection Policy accessible at www.whistleblowingofficer.com/coindu/regulatory-norms/.

The COINDU Whistleblower Officer can be contacted via the contact details available at www.dataprotectionofficer.help/coindu/whistleblowing/.

The COINDU Whistleblowing Platform is accessible via the link available at https://www.whistleblowingofficer.com/coindu/.

A Whistleblowing Form can be accessed at https://www.whistleblowingofficer.com/coindu/ or at any COINDU service point and can also be sent by email on request to the Whistleblowing Officer.

13.Prevention of Corruption

COINDU has implemented a Regulatory Compliance Program within the scope of Corruption Prevention, in accordance with the legal regulations in force, guaranteeing the protection of the personal data of the data subjects, under the terms of the Corruption Prevention Policy accessible at www.coindu.com.

For the purposes of submitting complaints within the scope of the corruption prevention regime, any interested party can use,

the COINDU Complaints Platform, accessible via the link available at https://www.whistleblowingofficer.com/coindu/ or

the Whistleblowing Form, accessible at www.whistleblowingofficer.com/coindu/ or at any COINDU service point.

14.Data Protection Policies

The Policy on the Processing of Personal Data in the Management of Applications is complemented by COINDU’s General Data Protection Policy, which can be found at www.coindu.com. It is also possible to consult the Data Protection and Privacy Policy in the Employment Context, either by sending a request to the Human Resources Department at the email address info@coindu.com;

or by contacting any service point in person.

15.Versions of the Data Protection and Privacy Policy

This version of the Data Processing Policy within the scope of Application Management has been published under reference Version 202306.

To ensure its updating, development and continuous improvement, COINDU may, at any time, make any changes deemed appropriate or necessary to its various Personal Data Protection Policies, and the respective publication in the various channels is ensured to guarantee transparency and information to Users, Service Recipients, Clients, Employees, Candidates or Suppliers.

To consult previous versions of the Data Protection and Privacy Policy, please send a request by email to dpo@coindu.com.