Applicant Privacy Policy

Name and Contact details of Data Controller

LeanIX GmbH (“LeanIX”)
Friedrich-Ebert-Allee 37-39
53113 Bonn
+49.228.2862992-0
dataprivacy@leanix.net

Data Collection and Processing

The following applicant’s data is collected and processed within the scope of your application and during the recruitment process:

  • Contact information, such as first and last name, e-mail, phone number, address.
  • Pre-employment screening information, where applicable and in compliance with applicable law(s).
  • ID documents details during the preparation of the contract offer.  
  • Information gathered during face-to-face interviews, video or phone calls, job interview notes.  
  • Current or desired salary, other terms related to compensation or benefits, type of employment, notice period in relation to current employment, earliest starting date.
  • Geographic mobility, work permit details and employment visa sponsorship needed.  
  • Reference information or and/or information received from SAP or LeanIX employees as part of the recruitment process.
  • Application documents (letter of application, curriculum vitae, references, language and/or other professional certificates, employment history, cover letter, etc.)

In addition, technical information might be transmitted to us from your web browser when you visit our pages. This includes, for example, information about the browser you are using, information about the operating system, the time and date of your visit and, if applicable, the referrer URL. This data will be processed solely as necessary to enable the technical delivery of the online application to your device, and be deleted thereafter, except as necessary to protect us against attacks on our web server or misuse of our online application (based on our legitimate interests in ensuring the effective and secure online application process according to Art. 6(1) lit. f) GDPR). It is not possible for us to combine this data with data from your online application.

During visiting our website, we may collect data about the users of www.leanix.net (and relevant subdomains) using cookies or similar technologies. Details about the information collected through cookies and similar technologies, as well as how it is used, can be found in Cookie Statement.

To manage your cookie preferences, simply click on the "Cookie Preferences" link below.

 

Application Channel

Applications for job advertisements of LeanIX GmbH and its affiliates are possible in the following way:
via online application or e-mail to jobs@leanix.net

If you apply via email, we will collect and process the personal data that your reveal to us in the context of your application. Please ensure that you do not reveal any sensitive personal data about your person in the context of your application (such as health data, racial or ethnic origin, political opinions, religious beliefs, trade union membership or sexual orientation) since we do not require such information for deciding on your application.

Purpose of Processing and Legal Basis

Your personal application data is collected and processed exclusively for the purpose of processing your application and deciding on the establishment of an employment relationship with you. This may involve reviewing and managing your application, arranging interviews, either independently or with assistance from third-party providers, conducting interviews by phone or in person, processing interview feedback, communication with you about the recruitment process, assisting with work permit and employment visa, etc.

If a LeanIX employee refers you for a specific job posting through LeanIX's employee referral program, the referring employee will also be kept informed of your progress in the recruitment process. This is intended to ensure the employee is eligible for a referral bonus should LeanIX decide to hire you.

If it should be necessary during the application procedure to collect information on an applicant from a third party, the requirements of the corresponding national laws have to be observed (e.g. applicant background screening in accordance with local law).

If you receive a contract offer, your data will be used after completion of the application procedure for the preparation of the contract offer and for the organization of the training.
Legal basis for the processing of your personal application data for the purposes of establishing the employment are Art. 6 (1)(b) GDPR and Section 26 para. 1 sentence 1 Federal Data Protection Act (“BDSG”). We may share your personal information with government bodies, regulatory authorities (such as tax offices), social security institutions, judicial entities, and public agencies, as permitted by relevant legal requirements under Article 6(1)(c) of the GDPR. Additionally, we may disclose such information to external consultants functioning as independent controllers (including legal advisors, accountants, auditors, etc.) in line with Article 6(1)(f) of the GDPR.

If you’re not hired, we may ask for your consent to keep your personal data in our database, in line with Article 6 (1)(a) of the GDPR.  If you ever want to withdraw this consent, you can do so at any time according to Article 7, paragraph 3 of the GDPR by reaching out to us at dataprivacy@leanix.net

To the extent that the processing of your personal data is carried out in accordance with Art. 6 (1)(f) GDPR to safeguard legitimate interests, you have the right, according to Art. 21 GDPR, to object to the processing of such data at any time on grounds relating to your particular situation. LeanIX will then no longer process this personal data unless LeanIX can demonstrate compelling legitimate grounds for the processing. These reasons must override your interests, rights, and freedoms, or the processing must serve to establish, exercise, or defend legal claims.

Retention Period of Application Data

Personal data may only be stored for as long as it is necessary for the purpose for which the data is being processed. This means that personal data will be deleted or anonymized as soon as the purpose of its processing has been fulfilled or otherwise lapses.

If you are employed by LeanIX, data collected during the recruitment process will be incorporated into your employee record and managed according to our internal data retention policies for employees. Additional details will be provided in employee privacy policy. If you are not employed by LeanIX, LeanIX may keep your data for inclusion in our talent pool. In this case, your personal information collected during the job application process will be retained as long as we have your consent according to Article 6 (1)(a) GDPR or a valid reason to do so.

Data Security

We have taken various technical and organizational precautions to protect the data collected in the context of your application against manipulation and unauthorized access. In particular, the transmission of your online application is encrypted in accordance with the current technical state of the art.

Disclosure of Data

We may share your personal data with the following categories of third parties, who may act as controllers in their own right, including:

  1. Group companies. To the extent necessary to process your application, such as where the position is with another group company or the relevant personnel overseeing your position or deciding on your application are employed with another group company, LeanIX will also share your personal data with the relevant group companies (subject to our intra-group data transfer agreement). In November 2023, LeanIX became part of SAP. For more information, visit www.leanix.net. Your application information might be therefore shared across both SAP and LeanIX recruiting and hiring teams.
  2. Service providers. We may share your information with third-party service providers to assist us in recruitment process.
  3. External advisers. We may disclose relevant data to external consultants functioning as independent controllers (including legal advisors, accountants, auditors, etc.).
  4. Background verification partners. We may share your information with trusted third parties to carry out pre-employment screening, in accordance with applicable laws.
  5. Global mobility partners. If you need global mobility services, such as obtaining a work visa or residency permit to work at LeanIX, we will share your contact details with a mobility service provider to make sure you receive the necessary support.
  6. Governmental authorities. We may also share your personal data with government agencies and regulators (such as tax authorities), social insurance carriers, courts, and other government bodies, all in line with applicable laws.

Your personal data will be stored in our applicant management system. The stored data is only made available to the employees within LeanIX and the relevant group of companies that need to know the data for the above recruitment purposes (see section on purposes).

The application management system is a software-as-a-service solution of a specialized provider. The data protection requirements with regard to the transfer are fulfilled. The data transmitted as part of your application is transferred in a secure way (e.g. TLS encryption) and stored in a database. This database is operated by Greenhouse Software, Inc. (“Greenhouse”) which offers personnel administration and applicant management software (https://www.greenhouse.io). In this context, Greenhouse is our processor according to Art. 28 GDPR. 

Transfer of Personal Data to Third Countries

A transfer of personal data to countries outside the European Union or the contracting states of the European Economic Area (so-called “third countries”) is generally not intended but may occur especially when personal data is forwarded to our affiliated group companies, as necessary for recruitment purposes. The laws of third countries outside the EU/EEA may not provide for the same level of data protection as considered adequate within the European Union. However, we have – to the extent legally required – put into place appropriate safeguards and guarantees (such as contractual commitments on the basis of the EU Standard Contractual Clauses and the implementation of supplementary safeguards) to ensure that your personal data will always be protected in accordance with legal requirements. To the extent your personal data is transferred to our affiliated companies in third countries, such as in the USA, we have entered into an intra-group data transfer agreement on the basis of the EU Standard Contractual Clauses.

For more information on the appropriate safeguards in place, and in order to receive a copy of them (as applicable), please contact us at the contact details set out in this Applicant Privacy Notice.

Your Rights

To the extent you are affected by the data processing carried out by LeanIX, you have the right subject to applicable legal provisions:

  • to obtain information on the personal data processed concerning you and to obtain a copy of such data (right of access, Art. 15 GDPR);
  • to obtain the rectification of any inaccurate personal data and, having regard to the purposes of the processing, the completion of incomplete personal data (right to rectification, Art. 16 GDPR);
  • if there are legitimate reasons, to request the deletion of your personal data (right to erasure, Art. 17 GDPR);
  • to request the restriction of the processing of your personal data, if the legal requirements are met (right to restriction of processing, Art. 18 GDPR);
  • if the legal requirements are met, to receive the personal data provided by you in a structured, commonly used and machine-readable format and to transfer this personal data to another controller or, if technically feasible, to have it transferred by LeanIX (right to data portability, Art. 20 GDPR); and
  • not to be subject to a decision based solely on automated processing which produces legal effects concerning you or significantly affects you in a similar way, if the legal requirements are not met. An automated decision-making process is not carried out by LeanIX.

If LeanIX is using your personal data based on your consent, you can withdraw the consent at any time. Additionally, if we process your personal data based on legitimate interest, you have the right to object to that use at any time, in accordance with applicable laws. 
If you have any questions about the collection, processing or use of your personal data or to exercise your rights, please refer to dataprivacy@leanix.net or contact us via other means at the contact details set out in this Applicant Privacy Notice.

Right to lodge a complaint with the Supervisory Authority

You have the right of lodge a complaint with a data protection supervisory authority if you believe that the processing of personal data concerning you violates applicable data protection law (in particular the EU General Data Protection Regulation).

Consequences of Assignment/Change in Control

In the event that LeanIX sells or transfers all or part of its business to a different entity, we may transfer your data to such new entity as part of such transaction, merger/acquisition.

Contact

If you require further information regarding the processing of your personal data, please contact LeanIX at the contact details set out at the beginning of this Applicant Privacy Notice or via email to the data protection team at dataprivacy@leanix.net