PRIVACY POLICY APPLICANTS FOR EMPLOYMENT

Requests for applications and verification of the prerequisites for employment and/or initiation of collaboration at Saint Louis Music Center S.r.l. involves the collection of information that constitutes personal data in accordance with Legislative Decree. 196/2003 and ss.mm.ii. (hereinafter, the “Code“) as well as Regulation (EU) 2016/679 (hereinafter, the “GDPR“).

1. DATA CONTROLLER

The data controller is Saint Louis Music Center S.r.l. (“the Company”), headquartered at Via Cimarra 19/B, Rome CF and VAT 05731131008, (hereinafter, the “DataController” or “Saint Louis“) and provides applicants (hereinafter, the “Applicants“), who send an application, with the privacy policy pursuant to Art. 13 of the GDPR.

At any time you can contact the Holder at the following addresses: at e-mail address info@saintlouis.eu , or at the above address.

The Owner has not identified a Data Protection Officer (DPO or DPO), as it is not subject to the designation requirement under Art. 37 of the Regulations.

2. DATA PROCESSED.

The data processed, through the submission and analysis of the application for the purpose of employment and/or initiation of a collaboration, are first name, last name, place and date of birth, nationality, residence/domicile (hereinafter, the “Personal Data“), telephone number and e-mail (hereinafter, the “Contact Data“) and any additional data contained within the Applicant’s resume. Therefore, the candidate should not indicate personal data belonging to special categories – such as, pursuant to Art. 9 of the GDPR, data capable of detecting racial and ethnic originality, religious, philosophical or other beliefs, political opinions, membership in parties, trade unions, associations or organizations of a religious, philosophical, political or trade union nature, as well as personal data capable of revealing health and sex life – which will, however, in the case conferred voluntarily by the Candidate, be immediately deleted.

3. PURPOSE AND LEGAL BASIS FOR PROCESSING

The Biographical Data, Contact Data, and all additional data provided by the Applicant (hereafter, jointly, the “Data“) are processed only for the evaluation of the application. More specifically, the Data are used to (i) review the Applicant’s application and (ii) proceed to verify the prerequisites for hiring and/or starting a collaboration. The legal basis for the processing of the collected data is the performance of a contract to which the data subject, in his or her capacity as data subject, is a party and/or to the performance of pre-contractual measures taken at the request of the data subject (Art. 6(1)(b) GDPR). Should it become necessary, the data may also be used against the legitimate interest of the Data Controller to carry out defensive activities or assert or defend a right in court pursuant to Art. 6(1)(f) of the GDPR.

4. RECIPIENTS OF DATA COMMUNICATION

The Data conferred may be known: (i) by the employees and collaborators of the Owner, duly designated for processing pursuant to Art. 29 of the GPDR; (ii) by third parties providing ancillary or instrumental services from an IT point of view to the management of the Holder’s application activities, duly appointed as external data controllers or autonomous data controllers; (iii) consultants to give litigation management and legal assistance, as independent owners, in the event of any litigation for which their involvement would be necessary. The Applicant may also request from the Controller the list of individuals who will act as data controllers (in which case, they are appointed in writing by the Controller, pursuant to Article 28 of the GDPR, and will process personal data on behalf of the Controller) or as autonomous data controllers. In any other case, the Data will not be disclosed to third parties, unless this is necessary to comply with requests from public authorities.

5. PLACE OF DATA PROCESSING

The Processing of Data will take place at the aforementioned location of the Data Controller. Data will be stored at servers and/or physical archives located exclusively within the European Union. However, in the event that Data is transferred outside the European Union, the Data Controller will ensure that the transfer takes place in accordance with the GDPR and, in particular, in accordance with Articles 45 (Transfer on the basis of an adequacy decision) and 46 (Transfer subject to adequate safeguards) of the GDPR. Therefore, no processing or transfer of Data will be carried out in any case outside the territory of the European Union or to countries that do not provide adequate guarantees of personal data protection.

6. PROCESSING METHODS, STORAGE PERIOD AND SECURITY MEASURES

The Data Controller will process the Data with and without the aid of electronic, computerized or automated tools, taking specific logical, organizational and technical security measures to prevent data loss, illicit or incorrect use and unauthorized access. Data will not be processed and stored for longer than is strictly necessary to achieve the purposes for which it was collected. Specifically, a period that allows for the evaluation of the application and selection of the Candidate and in any case no later than one year after their collection except for the possible establishment of the employment and/or collaboration relationship. This is without prejudice to any defensive needs of the Data Controller and the Candidate for which the Data may be retained beyond the terms indicated.

7. MANDATORY NATURE OF THE PROVISION OF DATA

The provision of Data for the purposes set forth in paragraph 3 of. (i) and (ii) is optional and is left to the will of the candidate who, without any solicitation from the Holder, submits his/her curriculum vitae. With regard to the Data subsequently and possibly requested by the Data Controller, failure to provide it means that it will be impossible to proceed with the verification of the prerequisites for hiring and/or the start of the collaboration and, therefore, the possible establishment of the relationship with the Data Controller.

8. RIGHTS OF THE DATA SUBJECT

Candidates, as data subjects (i.e., individuals to whom the Data refer), have rights conferred by the GDPR. In particular, under articles 15-22 of the GDPR, they have the right to request and obtain (i) Of the origin of personal data; (ii) Of the purposes and methods of processing; (iii) of the logic applied in case of processing carried out with the aid of electronic tools; (iv) of the identification details of the owner and responsible parties; (v) of the individuals or categories of individuals to whom the personal data may be communicated or who may become aware of them in their capacity as managers or appointees.

In addition, Applicants have the right to obtain:

  1. access,update, rectify or, when they have an interest,supplement the data;
  2. the cancellation, transformation into anonymous form or limitation of data processed in violation of the law, including data whose retention is not necessary in relation to the purposes for which the data were collected or subsequently processed;
  3. A statement that the operations referred to in paras. (a) and (b) have been brought to the attention, also as regards their content, of those to whom the data have been communicated or disseminated, except where this proves impossible or involves the use of means manifestly disproportionate to the right protected.

In addition, Candidates have:

  1. The right to withdraw consent at any time if the processing is based on their consent;
  2. The right to data portability (the right to receive all personal data concerning them in a structured, commonly used, machine-readable format);
  3. the right to object:
  1. in whole or in part, for legitimate reasons to the processing of personal data concerning them, even if relevant to the purpose of collection;
  2. in whole or in part, to the processing of personal data concerning them for the purpose of sending advertising or direct sales material or for carrying out market research or commercial communication;
  3. where personal data are processed for direct marketing purposes, at any time to the processing of their data carried out for that purpose, including profiling insofar as it is related to such direct marketing.
  1. should they believe that the processing concerning them violates the GDPR, the right to lodge a complaint with a Supervisory Authority (in the Member State where they usually reside, in the Member State where they work, or in the Member State where the alleged violation occurred). The Italian supervisory authority is the Garante per la protezione dei dati personali, based at Piazza Venezia no. 11, 00187 – Rome (http://www.garanteprivacy.it/). In order to exercise your rights, you can always contact the Controller at the contact details above.
keyboard_arrow_up