PandaDoc Candidate Privacy Statement
Table of contents
1. Personal Information we use
2. How we use your personal information and the basis on which we use it
7. Contact us and changes to the Privacy Statement
PandaDoc, Inc. (“PandaDoc,” “we”, “us”) is committed to protecting your personal information, as well as achieving and maintaining your trust in how we collect, process, and handle that data. Protecting your privacy is very important to us. If you are a Candidate from California or the EU, then this PandaDoc Candidate Privacy Statement (“Privacy Statement”) applies to you.
This Privacy Statement describes the handling of personal information obtained about internal and external job applicants, including referral and applicants who have applied directly through the PandaDoc careers page as well as through third-party agencies and recruiters on behalf of candidates. It also describes the handling of the personal information of any prospective candidates or leads, such as those individuals who expressed an interest in receiving news and details about future PandaDoc opportunities or other related communications. Personal information is information, or a combination of pieces of information, that could reasonably allow you to be identified.
This Privacy Statement describes how PandaDoc and its affiliates relevant to the job in question collect and process personal information about you, how we use and protect this information, and the rights that may be available to you under applicable law in relation to this information.
1. PERSONAL INFORMATION WE USE
We will collect your personal information from you directly and potentially from other sources.
1.1 Data we collect directly from you
The categories of data that we collect directly from you include:
1) Identifiers:
a) personal (e.g. name) and contact details (e.g. phone number, email address, postal address, ip address, and/or mobile number).
b) username and password for the online recruitment system
c) information about family and dependents (e.g. for relocation purposes).
2) Professional and Employment-Related Information:
a) information contained in your resume or CV, and other documents related to the application or recruitment process (e.g. cover letter, transcripts, certifications).
b) other information you may choose to voluntarily submit to us in connection with your application (e.g. information contained in a cover letter, information disclosed in an interview, or information you volunteer regarding your criminal records history, compensation history, family history, or personal situation).
3) Educational Information:
a) educational details (e.g. educational history, qualifications, certifications, skills) and job history (e.g. previous employment, roles, performance history).
4) Personal Characteristics:
a) data for diversity monitoring, where the collection of such data is allowed by law (e.g. race, ethnicity, gender, veteran status, and/or disabilities).
b) citizenship or immigration information (e.g. for visa purposes, right to work information).
5) Health Information:
a) information about any health issues or disabilities (e.g. your disability status, any requests for accommodation in the application or interview process).
b) information about your health status, where appropriate (e.g. confirmation of your wellness prior to attending an in-person interview).
6) Electronic, Visual and Audio Information
a) on-premise location monitoring for security purposes (e.g. video surveillance when attending our premises for an interview, if applicable).
7) Internet Activity Information:
a) information about you using cookies and similar technologies when you use the recruitment system and browse our website (see our Privacy Notice for further information about how this works).
1.2 Data we collect from other sources:
We may collect the following data about you from other sources:
1) Professional and Employment-Related Information:
a) background check data, potentially including your criminal records history, employment history, educational history, and/or compensation history, from employment screening agencies, publicly available registers or databases, former
employers and/or educational institutions (as allowed by local laws).
b) information about your performance or conduct from references, other PandaDoc employees, clients or service providers, or former employers you work with and/or with whom you may have worked in the past who may provide feedback about you.
c) information about you from PandaDoc employees who interview you and who may provide feedback about you.
2) Internet Activity Information:
a) publicly available information from websites or social media, including information that you choose to voluntarily submit to us in connection with your application (e.g. when applying through LinkedIn or online).
2. HOW WE USE YOUR PERSONAL INFORMATION AND THE BASIS ON WHICH WE USE IT
We limit our use of your personal data, including California and EU candidate Sensitive Personal Information.
We only collect and use your personal data for specific, necessary reasons and aim to explain our use of your personal information. For example, we use your personal information to:
(a) create and manage PandaDoc’s recruitment system, job applications, and a database of interested individuals and leads
(b) assess and evaluate your skills, qualifications, and interests against the position applied for and/or other positions
(c) communicate with you in relation to your expressed interest in PandaDoc, job opportunities/ leads, application or the recruitment process
(d) verify your information, including through reference checks and, where applicable, background checks
(e) send you information about the new hire and employee experience at PandaDoc prior to your first day
(f) operate, evaluate and improve the recruitment system, our application tracking, and recruitment activities (this includes analyzing our job applicant base, our hiring practices or trends, identifying qualifications or skills shortages, and using the information to match candidates and potential opportunities)
(g) detect, prevent and respond to fraud or potentially illegal activities (such as intellectual property infringement), misuse of the recruitment system, or other applicable policies
(i) perform audits, assessments, maintenance, and testing or troubleshooting activities related to the recruitment system and our recruitment processes
(h) comply with legal obligations to which we are subject and cooperate with regulators and law enforcement bodies
(i) respond to your enquiries and requests
We must have a legal basis to process your personal data. In most cases the legal basis will be one or more of the following:
(a) to comply with our contractual obligations to you or to take steps to enter into a contract with you
(b) to comply with our legal obligations
(c) with your consent
(d) to meet our legitimate interests, for example, to conduct our recruitment processes efficiently and fairly or to manage applicants effectively.
When we process personal data to meet our legitimate interests, we put in place robust safeguards to ensure that your privacy or other fundamentals rights and freedoms are not overridden by our legitimate interest to comply with our legal obligations, for example obtaining proof of your right to work status to enable us to meet relevant obligations.
When we are required by local law to collect certain personal information about you, your failure to provide this information may prevent or delay the fulfillment of our legal obligations and may impact our ability to employ you.
If we ask for your consent to process your personal information, you may withdraw your consent at any time by contacting us using the details at the end of this Privacy Statement.
3. RIGHTS OF CA RESIDENTS
If you are a California candidate, California Civil Code Sections 1798.83-1798.84, the CPRA, provides you with specific rights regarding your Personal Information and Sensitive Personal Information, subject to certain exceptions.
For instance, we cannot disclose specific pieces of Personal Information if the disclosure would create a substantial, articulable, and unreasonable risk to the security of the Personal Information, your account with us, or the security of our network systems.
PandaDoc does not sell any type of Personal Information. These rights are explained below:
- Right against discrimination. You have the right not to be discriminated against for exercising any of the rights described in this section. We will not discriminate against you for exercising your right to know, delete, or opt-out of sales.
- Right to access. You have the right to request that we disclose certain information to you about our collection and use of your Personal Information over the past twelve (12) months. PandaDoc will provide personal information to a consumer upon request a maximum of two times in a 12-month period. Once we receive and confirm your verifiable consumer request, we will disclose the following to you: (i) the categories of Personal Information we collected about you; (ii) the categories of sources for the Personal Information we collected about you; (iii) the business purpose for collecting (or selling, if applicable) the Personal Information; (iv) the categories of third parties with whom we share such Personal Information; and (v) the specific information we collected about you.
- Right to delete. You have the right to request that we delete any of your Personal Information we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete and will direct our service providers to delete your Personal Information from our records, unless an exception applies. Keep in mind, we may deny your request if it is necessary for us or our service providers to: (i) complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, or otherwise perform services pursuant to our contract with you; (ii) detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities; (iii) debug our website and/or identify and repair errors that impair existing intended functionality; (iv) exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law; (v) comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.); (vi) engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent; (vii) enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us; (viii) make other internal and lawful uses of that information that are compatible with the context in which you provided it; or (xi) comply with a legal obligation.
- Right to Correct. In certain circumstances and upon the receipt of a verifiable consumer request, you have the right to request that PandaDoc correct any inaccurate Personal Information PandaDoc maintains about you. Upon verifying the validity of a verifiable consumer correction request, we will use commercially reasonable efforts to correct your PI as directed, taking into account the nature of the Personal Information and the purposes of maintaining your Personal Information. This can also be done if you have an online account with us.
- Right to opt-out of sharing. You have the right to opt-out of having your Personal Information, including sensitive Personal Information, sold or shared. PandaDoc does not sell Personal Information or Sensitive Personal Information for monetary or other valuable consideration. If you wish to opt-out of sharing your Personal Information, please click here to be redirected to our “Do Not Share or Sell My Personal Information” page.
- Right to Limit the Use and Disclosure of Sensitive Personal Information. Additionally, you have the right to direct PandaDoc to limit our use of your Sensitive Personal Information to that information which is expected by an average individual as necessary to perform our duties as your employer or for your employment.
To exercise your personal privacy rights, please click below for the applicable location:
EU (GDPR and UK GDPR) and the rest of the world
We encourage you to contact us to update or correct your information if it changes or if the personal data we hold about you is inaccurate.
4. RIGHTS OF EU RESIDENTS
If you are an EU resident, PandaDoc will process your personal information in compliance with 2016/679 General Data Protection Regulation (GDPR).
PandaDoc, acting as the Controller, will process your personal information in the manners described in Section 2 and for the basis set out in Section 2. As the Data Subject, you have the:
- Right to be informed. You have the right to be informed about how your Personal Information is being processed.
- Right of Access. You have the right to access the Personal Information PandaDoc holds about you.
- Right to Rectification. In certain circumstances and upon the receipt of a verifiable consumer request, you have the right to request that PandaDoc correct any inaccurate Personal Information PandaDoc maintains about you. Upon verifying the validity of a verifiable consumer correction request, we will use commercially reasonable efforts to correct your PI as directed, taking into account the nature of the Personal Information and the purposes of maintaining your Personal Information. This can also be done if you have an online account with us.
- Right to Restrict Processing. Under certain conditions, you have the right to restrict PandaDoc’s processing of your Personal Information.
- Right to Object. Under certain conditions, you have the right to object to the processing of your Personal Information.
- Rights in relation to Automated Decision Making, Including Profiling. If applicable, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
- Destruction of your personal data without unjustified delay, if:
- The data are no longer necessary for the purposes for which they have been collected or processed;
- A revocation of the consent is submitted and there is no further legal foundation for the processing;
- You oppose the processing and there’s no prevailing legitimate reason to carry out the processing;
- The personal data have been processed illegally;
- The personal data have to be deleted to meet a legal obligation;
- Receiving a notification in case of rectification or destruction of personal data or processing limitation;
- Data portability. Data portability is the right of receiving your personal data in a structured and commonly used format – readable from automatic devices – and the right of transmitting such data to another Data Controller, in case:
- The processing is based on the Data Subject’s express consent for one or more specific purposes or is carried out by virtue of a contract signed with the Data Subject, and
- The processing is carried out by automated means.
- You also have the right to lodge a complaint with a Supervisory Authority.
To exercise your personal privacy rights, please click below for the applicable location:
EU (GDPR and UK GDPR) and the rest of the world
We encourage you to contact us to update or correct your information if it changes or if the personal information we hold about you is inaccurate.
5. DATA SHARING
While we do not sell or market your personal data, we may share your personal data with third parties in limited situations, including with:
- PandaDoc affiliates and acquisitions. We may share your personal data with other companies that fall within the PandaDoc group, for example for recruitment purposes, human resource management, and internal reporting. If another company acquires or plans to acquire, our company, business, or our assets, we will also share information with that company, including at the negotiation stage.
- Service providers and business partners. We may share your personal data with our service providers and business partners that perform business operations for us. For example, we may partner with other companies to host the recruitment system and analyze data to improve performance or engage third parties to audit our systems, products, or practices.
- Law enforcement agency, court, regulator, tax authority, government authority, or another third party. We may share your personal data with these parties if necessary to comply with a legal or regulatory obligation, or otherwise to protect our rights, your rights, or the rights of any third party.
6. DATA SECURITY and DATA RETENTION
Security is an important aspect of our business model and we allocate significant resources to making sure your data is protected.
This involves technical measures (such as implementing security software) and organizational measures (such as only allowing staff to access your data if there is a business need to do so).
These measures are aimed at ensuring the ongoing integrity and confidentiality of personal data. We evaluate these measures on a regular basis to ensure the security of the processing.
For all categories of personal data identified in Section, We will keep your personal data until the position you are applying for has been filled, after which we will retain your personal data for a period of time that enables us to:
- Maintain business records for analysis, understanding market trends and/or audit purposes.
- Comply with record retention requirements as required by local law or other relevant legal or regulatory requirements.
- Defend, establish, exercise or bring any existing or potential legal claims.
- Ensure fraud detection and prevention.
- Respond to any queries or complaints you may have.
- With your consent, suggest roles that may be of interest to you.
For all the categories of personal information listed in Section 1, we will delete your personal information when it is no longer required for these purposes or necessary to be retained pursuant to applicable law.
If there is any personal information that we are unable, for technical reasons, to delete entirely from our systems, we will ensure that appropriate measures are taken to prevent any further processing or use of the personal information
7. CONTACT US AND CHANGES TO THE PRIVACY NOTICE
To exercise your personal privacy rights, please click below for the applicable location:
EU (GDPR and UK GDPR) and the rest of the world
We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy you may have.
We may modify or update this Privacy Statement from time to time. If we make a material change to this Privacy Statement, we will notify you of the change.