Privacy Policy

GENERAL PRIVACY POLICY AND INFORMATION FOR DATA SUBJECTS

INTRODUCTION

This Privacy Policy is designated to generally describe how personal data is collected, used, processed and protected in connection with the business operations of.

  • Peruzzi Services Limited
    (registered address: H-1022 Budapest, Bimbó út 1-5, B lph. III/4, Hungary) and
  • Peruzzi Solutions Limited
    (registered address: 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF)

hereinafter: PERUZZI GROUP or Data controller, acting as Data controller and in certain cases as Data processor while complying with the applicable legal regulations.

This Privacy Policy also gives thorough information for the data subjects on their rights pertaining to the processing of their personal data.

This Privacy Policy applies to the processing of the personal data of our Website Users, Clients, Users of Our Products and Services, guests and also those data who aim to engage in a contractual relationship and those who were in a contractual relationship earlier; and any other person whom we may contact while operating our business. This Privacy Policy does not apply to employment related data processing.

In addition to compliance with the General Data Protection Regulation (GDPR), Peruzzi Group ensures full compliance with the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018). These regulations govern the collection, use, and storage of personal data for UK-based individuals and entities. All references to GDPR in this document also include applicable provisions under the UK GDPR, ensuring adherence to the highest standards of data protection across jurisdictions.

Please be advised that PERUZZI GROUP may unilaterally amend this Privacy Policy at any time.

This Privacy Policy does not apply to the processing of personal data related to PERUZZI GROUP employees, temporary staff, or contractors engaged through our HR services. Such data is managed under a separate Employment Privacy Policy available upon request.

DEFINITIONS

What constitutes as “personal data”?

“Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

What is data processing?

“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Who is the data controller?

“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

Who is the data processor?

“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Who is a third party?

“Third party” means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

Who is a recipient?

“Recipient” means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.

What is a consent?

“Consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

What is a data breach?

“Personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

UK GDPR:

The United Kingdom General Data Protection Regulation (UK GDPR) is the UK’s implementation of the General Data Protection Regulation (EU GDPR) following the UK’s exit from the European Union. It provides the legal framework for processing personal data in the UK, ensuring that individuals' privacy and data rights are protected. References to GDPR in this policy include provisions of the UK GDPR, where applicable.

Data Protection Act 2018 (DPA 2018):

The Data Protection Act 2018 is a UK law that supplements the UK GDPR by addressing specific aspects of data protection, including exemptions, additional safeguards, and rules for processing certain types of personal data. Together with the UK GDPR, the DPA 2018 forms the foundation of the UK's data protection regime.

1. BASIC INFORMATION ABOUT THE DATA CONTROLLER

1.1 Data controller/processor

This Privacy Policy regulates the data processing by PERUZZI GROUP, and it is therefore PERUZZI GROUP who generally qualifies as data controller in respect of your personal data. There are however certain cases where PERUZZI GROUP does not act as a data controller but instead acts as a subordinate of another data controller, which case PERUZZI GROUP is understood to be a data processor (acting on behalf of another controller while processing the personal data – in such case PERUZZI GROUP proceeds in accordance and based on the instructions of the data controller and processes data only to the extent as prescribed by the data controller).

In all cases internal policies and procedures regulate the access to the databases to ensure that while we aim to provide the best service possible all data processing are in compliance with the legal regulations.

1.2 Contact details

PERUZZI GROUP’s contact details for data protection and privacy related matters are as follows:

Name: PERUZZI SERVICES LIMITED
Email address: privacy@peruzzisolutions.com
Postal address: H-1022 Budapest, Bimbó út 1-5, B lph. III/4, Hungary
Phone number: +36.20.234.6007

Name: PERUZZI SOLUTIONS LIMITED
Email address: privacy@peruzzisolutions.com
Postal address: 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF
Phone number: +36.20.234.6007

1.3 Designation of data protection officer

Please note that PERUZZI GROUP examined the need to appoint a data protection officer according to Article 37 of the GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, GDPR) and drew the conclusion that PERUZZI GROUP is not required to do so in light of the mandatory appointment criteria, in particular, PERUZZI GROUP core activities do not include processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale. However, since PERUZZI GROUP has always added considerable weight to the privacy of personal data, PERUZZI GROUP appoints a data protection officer and dedicated sufficient staff, resources to ensure that it is able to discharge its obligations under the GDPR.

Availabilities of the data protection officer:
Position: Data Protection Officer
E-mail: privacy@peruzzisolutions.com
Telephone number: +36.20.234.6007

1.4 Websites and services using this Privacy Policy

This Privacy Policy applies to the privacy practices of PERUZZI GROUP’s websites as well concerning all websites operated by PERUZZI GROUP (“Websites”), which include, without limitation, the following:

as well as our products, online services and applications that include a link to this Privacy Policy and as such, sets out the basis on which any personal information we collect from you, or that you provide to us whether on the above websites, or otherwise (for example: in connection with the purchase of a product or service from us, or when we purchase service from you), will be processed by us. Importantly, this Privacy Policy also applies to PERUZZI GROUP’s marketing and advertising practices, as described below. Please be advised that details of each individual data processing include at least the following information:

  • identification and contact details of data controller if any; identification and contact details of data processor(s);
  • the purpose of processing;
  • the legal basis for the processing;
  • where the processing is based on the legitimate interests pursued by PERUZZI GROUP or by a third party then detailed description of this legitimate interest;
  • the recipients or categories of recipients of the personal data, if any;
  • where applicable, the fact that the data is being transferred to a third country (including if access is being granted to another controller/processor from a third country) and how suitable safeguards are provided.

1.5 Data Processing Purposes

For recruitment and headhunting services, PERUZZI GROUP collects and processes specific data, including résumés, interview evaluations, and professional assessments. This data is shared with clients only for purposes explicitly agreed upon with the candidate. Data shared with clients is anonymized or pseudonymized unless explicit consent is provided by the data subject.

Candidate data is shared with clients or hiring partners only after obtaining explicit consent from the candidate. Before sharing, candidates are informed about:

  • The identity of the client or hiring partner.
  • The purpose and scope of data sharing.
  • Their right to withdraw consent at any time by contacting privacy@peruzzisolutions.com.

As part of the headhunting services provided by Peruzzi Solutions, the purposes of data processing include:

  • Collecting and storing candidate data.
  • Analyzing and profiling data using artificial intelligence.
  • Preparing recommendations related to training and job opportunities.

Legal Bases

Data processing is based on Article 6(1)(a) of the GDPR, which provides for processing based on the data subject's consent. Consent can be withdrawn at any time.

Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

2. GENERAL RULES

2.1 GENERAL PRINCIPLES

Personal data shall be:

processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’)

collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with GDPR, not be considered to be incompatible with the initial purposes (‘purpose limitation’);

adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);

accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);

kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of the GDPR subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’);

processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).

The data controller shall be responsible for, and be able to demonstrate compliance with the above principles (‘accountability’).

2.2 LEGAL BASIS OF THE DATA PROCESSING – LAWFULNESS

Processing of personal data by PERUZZI GROUP is conducted in compliance with both the General Data Protection Regulation (GDPR) and the United Kingdom General Data Protection Regulation (UK GDPR), as well as the Data Protection Act 2018 (DPA 2018). These regulations ensure that personal data is processed lawfully, fairly, and transparently.

Processing shall only be lawful if at least one of the following applies:

  • the data subject has given consent to the processing of his or her personal data for one or more specific purposes – i.e. if you signed a consent form or given your consent via electronic means (pressing consent button or link, or giving consent over recorded telephone etc.).
  • processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract – i.e. in case you are or want to be in a contractual relationship with PERUZZI GROUP and the processing of your data is necessary for the performance of the contract. Please note that in such case your separate consent is not required, and your data is processed as long and to the extent as required for the performance of the contract.
  • processing is necessary for compliance with a legal obligation to which the controller is subject – i.e. in case a EU or national piece of legislation prescribes for PERUZZI GROUP to process your data (data of invoices, data of customer complaints etc.). Please note that in such case also your separate consent is not required, and your data is processed as long and to the extent as required and prescribed by law.
  • processing is necessary in order to protect the vital interests of the data subject or of another natural person;
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  • processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
  • IN ORDER TO MEET THE ABOVE REQUIREMENTS AND TO GIVE YOU PROPER INFORMATION ON THE PROCESSING OF YOUR PERSONAL DATA AND YOUR RIGHTS AND OBLIGATIONS, WE COLLECTED THE MOST FREQUENT CASES WHEN WE PROCESS PERSONAL DATA. PLEASE NOTE THAT THE LIST OF DATA PROCESSING IN THIS PRIVACY POLICY IS NOT EXHAUSTIVE; BESIDES WHAT IS DETAILED HEREIN THERE COULD BE OTHER SPECIFIC CASES WHEN WE NEED TO PROCESS YOUR PERSONAL DATA. IN ALL CASES YOU WILL BE ADVISED DULY BEFORE YOUR PERSONAL DATA IS COLLECTED FOR OTHER PURPOSES THAN DESCRIBED IN THIS PRIVACY POLICY. PLEASE BE INFORMED THAT IN CASE YOU ARE USING OUR GROUP VIA OUR WEBSITES THEN THE DETAILS OF THE DATA PROCESSING ARE DESCRIBED ALSO AT THE GIVEN PERUZZI GROUP WEBSITE.

2.3 PROFILING AND ARTIFICIAL INTELLIGENCE

Our artificial intelligence technology enables analysis and the creation of personalized profiles for candidates. These profiles are used exclusively for developing training opportunities and job recommendations.

Candidates are informed about profiling activities during the data collection process, and their explicit consent is obtained for this purpose. Candidates have the right to opt-out of profiling at any time by contacting PERUZZI GROUP at privacy@peruzzisolutions.com . This ensures compliance with GDPR Article 22 on automated decision-making and profiling. The results of profiling:

  • Are reviewed by human experts to ensure accuracy and fairness.
  • Do not solely determine hiring decisions but are used as an additional recommendation tool.

Data subjects may request further information about the profiling process and underlying criteria by contacting privacy@peruzzisolutions.com.

It is important to note that the results of these analyses do not serve as the sole basis for automated decisions. All recommendations and decisions are reviewed and approved by human experts to ensure the interests of data subjects are respected.

3. IF YOU ARE USING OUR WEBSITES

Please note that the below description is a general guideline and advisory and specifics of each data process are detailed on the relevant Website.

3.1 WHAT INFORMATION DOES PERUZZI GROUP COLLECT ABOUT YOU?

In case you are using our Websites, PERUZZI GROUP collects several types of personal, aggregated and anonymous data about you, which may include the following:

Aggregated Data including statistical, demographic or other data which is related to you, but may not be used to directly or indirectly identify you, and which therefore does not fall as personal data.

Contact Data includes company name, e-mail address, phone number, contact preferences.

Eligibility Data includes information about your company name and company size data, and website.

Identity Data includes your full name, position, company name.

Marketing and Communications Data includes your preferences in receiving marketing from PERUZZI GROUP and its affiliates and also upon your consent from third parties, and your communication preferences.

Technical Data includes referral URL, internet protocol (IP) address, connection IP address, WIFI network (SSID), your login data, browser type and version, time zone setting and location, operating system and platform and other technology on the devices you use to access our websites indicated above.

Usage Data includes information about how you use our or our partners’ websites, products and services.

The following types of personal data are processed as part of the recruitment / headhunting services:

  • Professional résumé (e.g., name, contact information, education, qualifications).
  • Skills and experience (e.g., technical expertise, language proficiency).
  • Employment history (e.g., previous positions, employers).
  • Preferences (e.g., desired working conditions, salary expectations, geographical location).

3.2 HOW AND WHERE DOES PERUZZI GROUP COLLECTS THIS INFORMATION?

3.2.1 PERUZZI GROUP support lines

Being subject to individual agreement you may contact us for support in technical issues and other service questions by a designated telephone line or e-mail address. When you call this support line PERUZZI GROUP collects Identity Data about you. Based on the type of your request additional information might be required to provide the best solution.

3.2.2 PERUZZI GROUP Websites

We collect Technical and Usage Data, including information about how you use our websites and applications with or without registration or log-in. We collect information that your browser or device typically sends to our servers whenever you use (e.g. input text) on or visit a PERUZZI GROUP website. For example, your browser or device may tell us your IP address (which may also tell us your location) and the type of browser and device you used. When you visit a PERUZZI GROUP Website, your browser may also tell us information such as the page that led you to our website (referral URL) and the websites you generally visit. To collect this information, PERUZZI GROUP may use cookies (please see our cookie information notice below) and similar technologies, and our servers may collect similar information when you are logged in to the website or application. As mentioned below, you may always refuse or opt out of the use of cookies or similar technologies. If you identified yourself or registered at a Website or application, this information may be associated with you or if you have not identified yourself or registered at a Website or application it will be anonymous.

3.2.3 PERUZZI GROUP Emails

Emails we send you, on the basis of your prior written (including electronic means) consent if you are an individual, usually include technologies that tell PERUZZI GROUP whether you have received or opened the email, or clicked a link within the email. If you do not want us to collect this information from PERUZZI GROUP marketing emails, you may withdraw your consent at any time and can either opt out of receiving PERUZZI GROUP marketing emails by clicking “unsubscribe” at the end of the message. For more detailed description of your rights, please also refer to clause 10.

3.2.4 PERUZZI GROUP Online Advertising

PERUZZI GROUP advertises online in a variety of ways, including displaying PERUZZI GROUP ads on websites and in apps. We collect your Technical and Usage Data on our websites, including information about which ads are displayed, which ads are clicked on, and on which web page the ad was displayed, and which campaign has generated certain user actions – such as web page views and web page interactions, mobile app interactions, mobile app purchases, file downloads, contact form submissions or registration to PERUZZI GROUP’s online services.

3.2.5 Buttons, Tools, and Content from Other Companies

PERUZZI GROUP websites and applications may include buttons, tools, or content that link to other companies’ services (for example, a Facebook “Like” button). Using these features is completely voluntary, should you decide to use them then please note that we collect information about your use of these features. In addition, please note that when you see or interact with these buttons, tools, or content, or view a PERUZZI GROUP Website containing them, some information from your browser may automatically be sent to the other company (usually at least a javascript code snippet is downloaded from the web server of the other company, which action –being a standard web request– sends most of the details listed under the Technical Data ). Please read that company’s Privacy Policy for more information.

3.2.6 Third-Party Sites and Services

PERUZZI GROUP websites, products, online services, and applications may contain links to third-party websites, products, and services. Our products and services may also use or offer products or services from third parties. PERUZZI GROUP will not transfer any of your data while you are using these links or navigate to third-party website, in such case it will be these third parties who will advise you on their data processing and collect information from you, which may include such things as Contact Data, these data processing are governed by the privacy practices of these third parties. We encourage you to learn about the privacy practices of those third parties.

We are also working closely with third parties (including, for example, business partners, sub-contractors in technical, delivery services, advertising networks, analytics providers, search information providers, credit reference agencies, such as Google, Facebook, Linked In based inside or outside the EU) and may receive Technical Data or information about you from them that we usually combine with other information we have about you.

3.2.7 Public sources

To help keep our databases current and to provide you the most relevant content and experience, we may combine information from you with information from public sources and our trusted partners, in accordance with applicable law.

3.3 FOR WHAT PURPOSES AND ON WHAT BASES DOES PERUZZI GROUP USE THE INFORMATION IT COLLECTS ABOUT YOU?

3.3.1 In most cases, PERUZZI GROUP will use your personal data on the following legal bases:

Consent: when PERUZZI GROUP send you marketing communications via electronic means, such as e-mail, text messages, personal messages (point a) Article 6(1) of the GDPR).

Legitimate interest: where processing is necessary for our legitimate interests (or those of a third party), and your interests and fundamental rights do not override those interests, and we may verify that a favourable balance of interest test has been carried out (point f) Article 6(1) of the GDPR).

Performance of contract: where PERUZZI GROUP needs to perform the contract, we are about to enter into or have entered into with you as natural person (point b) Article 6(1) of the GDPR).

Legal obligation: where PERUZZI GROUP needs to comply with a legal obligation, such as tax or other regulatory obligations and requirements (point c) Article 6(1) of the GDPR).

3.3.2 By way of background information

By way of background information, in general, legitimate interest means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). Please be advised if you need further information on the summary of the balance of interest tests carried out by PERUZZI GROUP in relation to the activities set out in the below table, please contact us. Of course, you can always obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.

3.3.3 Performance of contract

3.3.3 Performance of contract means processing your data where it is necessary for the performance of a contract to which you as a natural person are a party or to take steps at your request before entering into such a contract.

3.3.4 Legal obligation

Legal obligation means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we are subject to.

general overview on relevant purposes

3.3.5 The below table includes a general overview on relevant purposes for which PERUZZI GROUP processes your data in the context of various activities, and the relevant legal basis PERUZZI GROUP relies on.

Purpose/Activity Data type Legal basis
Customer registration
To register you as customer
(1) Identity Data
(2) Contact Data
(3) Profile Data
Performance of contract
(natural persons)/ Legal obligation and Legitimate Interest
Candidate registration
To register you as a candidate
(1) Identity Data
(2) Contact Data
(3) Profile Data
Performance of contract
(natural persons)/ Legal obligation and Legitimate Interest
Provision of products and services
To provide you with the PERUZZI GROUP website for which you have registered, as well as any services, products, support, or information you have requested
(1) Identity Data
(2) Contact Data
(3) Marketing and Communications Data
Performance of contract
(natural persons)/ Legal obligation and Legitimate Interest
Regular (not marketing related) notifications
To manage our relationship with you which will include notifying you about changes to our terms or Privacy Policy
(1) Identity Data
(2) Contact Data
(3) Profile Data
(1) Performance of contract (natural persons)/ Legal obligation and Legitimate Interest
(2) Necessary to comply with a legal obligation, including the requirement to notify you about changes
(3) Legitimate interests (to keep our records updated and to monitor how customers use our products/services)
Administration of websites
To administer and protect the PERUZZI GROUP website (including diagnosing problems, troubleshooting, data analysis, testing, system maintenance, support services, reporting and hosting of data)
(1) Identity Data
(2) Contact Data
(3) Technical Data
(4) Usage Data
(1) Legitimate interests (for the provision of administration and IT services, network security, to prevent information security and personal data breaches)
(2) Necessary to comply with a legal obligation such as e-commerce, electronic communications and data protection legislation
Data analytics
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences
(1) Technical Data
(2) Usage Data
(3) Aggregated Data
Legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)
Customized content
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising PERUZZI GROUP serves you
(1) Identity Data
(2) Contact Data
(3) Profile Data
(4) Usage Data
(5) Marketing and Communications Data
(6) Technical Data
Consent
Electronic direct marketing
To contact you and send you via electronic means (such as e-mail, text messages, MMs, private messages etc.) newsletters, information about the goods or services of PERUZZI GROUP to make suggestions and recommendations to you about goods or services that may be of interest to you
(1) Identity Data
(2) Contact Data
(3) Profile Data
Consent
Telemarketing
To ensure that PERUZZI GROUP may contact you via phone to share information about the goods of services of PERUZZI GROUP, to make suggestions and recommendations to you about goods or services that may be of interest to you
(1) Identity Data
(2) Contact Data
(3) Profile Data
Consent
Market research
To contact you for market research and customer satisfaction purposes and also to measure the effectiveness of marketing campaigns
(1) Identity Data
(2) Contact Data
(3) Profile Data
Legitimate interest (to protect our intellectual and industrial property rights and economic interests).

4. WHAT ARE COOKIES AND HOW DOES PERUZZI GROUP USE THEM?

4.3 PERUZZI GROUP and third-party vendors

PERUZZI GROUP and third-party vendors including Google and Facebook use first-party and third-party cookies and related user behaviour tracking technologies to measure desktop software, mobile application and website usage; record different user activities in its software and on its web sites; and display advertisements based on the user’s previously recorded activities. PERUZZI GROUP does not disclose any personally identifiable information to these third-party vendors. However, third-party vendors automatically receive IP addresses when activity tracking occurs. PERUZZI GROUP may connect user activity data gathered by third-party vendors with information collected by its websites and applications and such data may therefore become Profile or Usage Data.

4.4 You can set your browser so that the browser informs you

You can set your browser so that the browser informs you about cookies or automatically prevents their storage. If you do not store our cookies, you will still be able to visit our website or use our services; however, the use of individual offers or features might be limited.

4.5 You can also prevent your data from being used by third-party

You can also prevent your data from being used by third-party vendors by installing browser extensions, such as:
https://youradchoices.com/
https://tools.google.com/dlpage/gaoptout/
Or setting your preferences at web sites like:
http://www.youronlinechoices.com/uk/your-ad-choices
https://optout.networkadvertising.org/
https://www.google.com/settings/u/0/ads/anonymous

5. DOES PERUZZI GROUP SHARE/DISCLOSE MY PERSONAL DATA?

(A) DISCLOSURE TO DATA PROCESSORS

5.1 PERUZZI GROUP as a business entity is subject to tax related obligations

PERUZZI GROUP as a business entity is subject to tax related obligations and also is subject to authority reviews, the course of which we could be obliged to share your data with the authorities. These obligations are imposed on PERUZZI GROUP by laws and regulatory decisions, we are legally bound to fulfil these requirements.

5.2 PERUZZI GROUP also works with companies that help us run our business

Among these are companies that are not linked to PERUZZI GROUP providing services for us. These services vary in subject and term: external consultants, professional advisers such as lawyers or auditors, technical support functions (IT and document storage providers, professionals delivering customer support and sending emails on our behalf). These are called data processors are engaged in all cases based on written contract with appropriate guarantees to safeguard the security of the data and the rights of the data subjects. In some cases, these companies have access to some of your personal information in order to provide services to you on our behalf. They are not permitted to use your information for their own purposes and we ensure by data processing contracts (including electronic format) that your data are being processed in accordance with the legal regulations.

5.3 Currently, PERUZZI GROUP is using the following data processors

Name Full postal address Activity
Google, Inc. 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA processing of user traffic and analytics data
Facebook, Inc. Facebook Headquarters 1 Hacker Way, Menlo Park, CA 94025, USA processing of user data
Microsoft Corporation One Microsoft Way, Redmond, WA 98052-6399, USA data hosting
A2 Hosting, Inc. P.O. Box 2998 Ann Arbor, MI 48106 data hosting

5.4 It is PERUZZI GROUP’s legitimate interest to prevent and respond to fraud

It is PERUZZI GROUP’s legitimate interest to prevent and respond to fraud, to defend our Websites and applications against attacks, to protect the property and safety of PERUZZI GROUP, our customers, users, the public. That is why our distributors and specific companies are retained as data processors to assist us to combat piracy. Please note that it is PERUZZI GROUP’s legitimate interest from the above reasons not to identify our service providers. We share Your IP address, MAC address, software version and language with them exclusively for the above purposes.

(B) DISCLOSURE TO OTHER DATA CONTROLLERS

5.5 In other cases, we provide your data to other entities to use such data under their own name and for their own benefit

In other cases, we provide your data to other entities to use such data under their own name and for their own benefit. Sometimes we may need to do this to comply with a legal obligation (such as when we need to provide certain Transaction, Technical or Identify Data to the police or other authorities), and in other cases, we rely on other legal grounds, such as our legitimate interests or your written (including electronic means) consent.

5.6 We may share or publish Aggregate Data that doesn’t specifically identify you

We may share or publish Aggregate Data that doesn’t specifically identify you, such as statistical information about visitors to our websites or statistical information about how customers use our applications.

5.7 We require all third parties to respect the security of your personal data

We require all third parties to respect the security of your personal data and to treat it in accordance with the law and the data processing contract if any. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

5.8 In the context of recruitment and headhunting services

In the context of recruitment and headhunting services, candidate data may be shared with clients or hiring partners strictly for evaluating job opportunities. PERUZZI GROUP ensures that any shared data is covered by confidentiality agreements and processed in accordance with GDPR. Data subjects are informed and must consent before their personal data is shared with clients.

6. INTERNATIONAL TRANSFERS

6.1 Many of our external third parties are based outside the European Economic Area (EEA)

Since many of our external third parties are based outside the European Economic Area (EEA) (such as Microsoft, Inc., A2 Hosting, Inc., Salesforce.com, Inc.), so their processing of your personal data will involve a transfer of data outside the EEA.

Whenever we transfer your personal data outside of EEA, we contractually ensure a similar degree of protection

Whenever we transfer your personal data outside of EEA, we contractually ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

6.2.1 we will only transfer your personal data to countries that have been deemed to provide an adequate level of protection

we will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see European Commission: Adequacy of the protection of personal data in non-EU countries.

6.2.2 where we use certain service providers

where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see European Commission: Model contracts for the transfer of personal data to third countries.

6.2.3 where we use providers based in the US or other non-EEA countries

where we use providers based in the US or other non-EEA countries, we ensure that data transfers comply with the Standard Contractual Clauses (SCCs) as approved by the European Commission, providing adequate safeguards for personal data.

6.3 In addition to GDPR

In addition to GDPR, PERUZZI GROUP ensures compliance with regional data protection laws such as the UK GDPR for operations in the United Kingdom. For other jurisdictions, PERUZZI GROUP evaluates local laws and aligns its practices with applicable standards to ensure lawful data processing.

7. IS MY PERSONAL DATA SECURE, AND WHERE WILL IT BE STORED?

7.1 We understand that the security of your personal information is important

We understand that the security of your personal information is important. We provide reasonable administrative, technical, and physical security controls to protect your personal information. All information you provide us is stored on secure servers. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our websites, you are responsible for keeping this password confidential. We ask you not to share a password with anyone. Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot warrant or guarantee the security of your data transmitted to us; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access. In case your data is provided by registering on our websites than we ensure that this registration is completed on a secured platform where we apply our security measures. In case you would like to have more information on the specific security measures taken in order to save your data than please contact us.

7.2 We have put in place appropriate security measures

Also, we have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

7.3 Finally, we have put in place procedures to deal with any suspected personal data breach

Finally, we have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

7.4 Your personal information and data files are stored on PERUZZI GROUP’s servers

Your personal information and data files are stored on PERUZZI GROUP’s servers and the servers of companies we hire to provide services to us. As shown in clause 7 above, your personal information may be transferred across national borders because we have servers located worldwide and the companies we hire to help us run our business are located in different countries around the world (for example, Germany, Ireland, the United States). As mentioned in clause 7 above, the data that we collect from you may therefore be transferred to, and stored at, a destination outside the European Economic Area (“EEA”). It may also be processed by staff operating outside the EEA who work for us or for one of our suppliers. Such staff maybe engaged in, among other things, the fulfilment of your order and the provision of support services.

7.5 To protect the personal data of our candidates

To protect the personal data of our candidates, we implement technical and organizational measures, including:

  • Encryption and pseudonymization of data.
  • Restricting access permissions.
  • Defining retention periods (e.g., deleting data when candidates are no longer part of the service).

7.6. In the event of a personal data breach

In the event of a personal data breach, PERUZZI GROUP will:

  • Notify the affected data subjects and the relevant supervisory authority without undue delay and within 72 hours of becoming aware of the breach, where feasible.
  • Provide details of the breach, including its nature, the number of data subjects affected, potential consequences, and mitigation steps taken.
  • Maintain a record of all data breaches regardless of their severity as part of our accountability obligations.

8. HOW LONG WILL PERUZZI GROUP HOLD AND USE MY PERSONAL DATA?

8.1 We only retain your personal data for as long as necessary to fulfil the purposes we collected it for

We only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

8.2 To determine the appropriate retention period for personal data

To determine the appropriate retention period for personal data, we take into account the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

8.3 Résumés and profiles of unsuccessful candidates will be retained for a maximum of 1 year

Résumés and profiles of unsuccessful candidates will be retained for a maximum of 1 year after the recruitment process unless consent for longer retention is provided.

8.4 Data of successfully placed candidates will be retained for 5 years post-employment placement

Data of successfully placed candidates will be retained for 5 years post-employment placement, to comply with contractual and legal obligations. These periods are subject to extension where required by applicable laws or ongoing disputes. Data beyond retention limits will be securely deleted or anonymized.

8.5. By law we have to keep basic information about our customers

More specifically, and without limiting the generality of the foregoing, by law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for at least 5, in certain cases 8 years after they cease being customers for tax, financial auditing, and record keeping purposes.

8.6 In some applicable circumstances you can ask us to delete your data

In some applicable circumstances you can ask us to delete your data: see the clause dealing with ‘Right To Erasure’ below for further information.

8.7 In some circumstances we may anonymize your personal data

In some circumstances we may anonymize your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.

9. YOUR RIGHTS REGARDING YOUR PERSONAL DATA

9.1 Your right to access

You have the right to access your personal data, including requesting information on whether PERUZZI GROUP processes your data, which data are processed, and you may also request a copy of the data that you or a third person provided to PERUZZI GROUP and which data is being processed by PERUZZI GROUP.

If you request that PERUZZI GROUP confirm whether or not PERUZZI GROUP processes your personal data, then you have the right that obliges PERUZZI GROUP to confirm that it processes your personal data, or does not process your personal data.

Your right to obtain confirmation whether PERUZZI GROUP processes (or does not process) your personal data
(a) does not include data that is anonymous;
(b) includes the personal data that concern you;
(c) does not include personal data that does not concern you; and
(d) includes pseudonymous data that can be clearly linked to you.

PERUZZI GROUP shall give you access to your personal data if
(a) you request PERUZZI GROUP to confirm whether or not it processes your personal data, and
(b) PERUZZI GROUP confirms that it processes your personal data, and
(c) you request access to your personal data.

PERUZZI GROUP shall provide you with a copy of your personal data if
(a) you request PERUZZI GROUP to confirm whether or not it processes your personal data, and
(b) PERUZZI GROUP confirms that it processes your personal data, and
(c) you request a copy of your personal data.

9.2 Your right to rectification

You have the right to the correction of your personal data without undue delay. This enables you to ask that any incomplete or inaccurate data we hold about you be corrected.

Your right to obtain rectification of your data that are inaccurate
(a) does not include data that is anonymous;
(b) includes the personal data that concern you;
(c) does not include personal data that does not concern you; and
(d) includes pseudonymous data that can be clearly linked to you.

PERUZZI GROUP shall rectify your personal data if
(a) PERUZZI GROUP processes your personal data, and
(b) the personal data in question are inaccurate, and
(c) you request the rectification of your personal data.

PERUZZI GROUP shall complete your personal data if
(a) PERUZZI GROUP processes your personal data, and
(b) the personal data in question are incomplete, and
(c) you request the completion of your personal data and if necessary you provide supplementary information for completion.

PERUZZI GROUP may verify any and all data provided to it. PERUZZI GROUP shall taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to communicate the rectification of your personal data to recipients of such personal data (if any). However, PERUZZI GROUP shall not communicate the rectification of personal data to recipients if the communication to such recipients is either impossible or involves a disproportionate effort.

Please also note that many of our websites and applications allow you to edit your personal information by accessing the “my profile,” or a similar feature of the website or application you are using. Likewise, you can edit files or delete photos you have stored in our online services by logging in and using the functions they make available.

9.3 Your right to erasure (‘right to be forgotten’)

Subject to certain conditions and in certain cases, you have the right to the erasure of your personal data. This means that you may request that we delete your personal data that we may have processed unlawfully or where the use of your data is no longer needed for a purpose. Please keep in mind that PERUZZI GROUP may not be able to meet your request for specific legal reasons that will be notified to you, if applicable.

PERUZZI GROUP shall erase your personal data without undue delay if
(a) PERUZZI GROUP processes your personal data, and
(b) you request to obtain the erasure of your personal data, and
(c) the personal data are no longer necessary to the purposes for which PERUZZI GROUP collected them;

PERUZZI GROUP shall erase your personal data without undue delay if
(a) PERUZZI GROUP processes your personal data based on your consent, and
(b) you request to obtain the erasure of your personal data, and
(c) you withdraw your consent on which the processing of your data is based, and
(d) there is no alternative legal basis for the processing of your data any further.

PERUZZI GROUP shall erase your personal data without undue delay if
(a) the processing is based on being necessary for the purposes of the legitimate interests of PERUZZI GROUP or a third party, and
(b) you object to PERUZZI GROUP’s processing of your personal data, and
(c) the legal ground for the processing of your personal does not override your objection.

PERUZZI GROUP shall erase your personal data without undue delay if
(a) you request to obtain the erasure of your personal data, and
(b) the processing by PERUZZI GROUP of such data is unlawful, or
(c) if the erasure is required under applicable law, or
(d) your data is collected in relation to the offer of an information society service.

PERUZZI GROUP shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to communicate the erasure of your personal data to recipients of such personal data (if any). However, PERUZZI GROUP shall not communicate the erasure of personal data to recipients if the communication to such recipients is either impossible or involves a disproportionate effort.

Please note that there are certain cases when you may not request erasure of your data. These reasons will be communicated to you if your request for erasure cannot be completed.

Please also note that many of our websites and applications allow you to edit or delete your personal information by accessing the “my profile,” or a similar feature of the website or application you are using. Likewise, you can delete files or photos you have stored in our online services by logging in and using the functions they make available.

9.4 Your right to the restriction of processing

You may also request the restriction of the processing of your personal data. For instance, you may request that we suspend the processing of your personal where our use of the data is unlawful but you do not want us to delete it.

Your right to request the restriction of the processing of your personal data
(a) does not include data that is anonymous;
(b) includes the personal data that concern you;
(c) does not include personal data that does not concern you; and
(d) includes pseudonymous data that can be clearly linked to you.

PERUZZI GROUP shall restrict the processing of your personal data for a period to verify the accuracy of such data if you request to obtain the restriction of the processing of your personal data, and you contest the accuracy of such data.

PERUZZI GROUP shall restrict the processing of your personal data if you request to obtain the restriction of the processing of such data, the processing of which is unlawful, and you opposes the erasure of such data.

PERUZZI GROUP shall restrict the processing of your personal data if
(a) you request to obtain the restriction of the processing of such data, and
(b) PERUZZI GROUP does not need such data for the purposes of its processing, and
(c) you require your data for establishment, exercise or defence against a legal claim.

PERUZZI GROUP shall restrict the processing of your personal data if
(a) you object to the processing of your personal data that are necessary for the purposes of the legitimate interests that PERUZZI GROUP pursues, and
(b) you wait to verify that the legitimate ground of PERUZZI GROUP’s processing of your personal does not override your objection.

PERUZZI GROUP shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to communicate the restriction of processing of your personal data to recipients of such personal data (if any). However, PERUZZI GROUP shall not communicate such restriction to recipients if the communication to such recipients is either impossible or involves a disproportionate effort.

If PERUZZI GROUP restricts its processing of your personal data, then it may
(a) store such personal data,
(b) process such personal data on the basis of your consent,
(c) process the personal data for establishing, exercise or defend a legal claim, or for protecting the rights of another person.

In case you have obtained restriction of processing as per the above than you shall be informed by PERUZZI GROUP before the restriction of processing is lifted.

9.5 Your right to data portability

Where the processing of your data is either based on your consent (e.g. in respect of electronic direct marketing), or is necessary for the performance of a contract (e.g. customer registration data and data relating to your orders), and the processing is carried out by automated means, than you may request the provision of your personal data that you have provided to us in a standard format, and you may also request that such data be transferred to another entity.

Without prejudice to your rights above, you have the right to receive the personal data concerning you, which you provided to PERUZZI GROUP, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance (where technically feasible) from PERUZZI GROUP, where the processing is based on your consent, or is necessary for the performance of a contract, and the processing is carried out by automated means.

Your right to data portability
(a) does not include data that is anonymous;
(b) includes the personal data that concern you;
(c) does not include personal data that does not concern you; and
(d) includes pseudonymous data that can be clearly linked to you.

9.6 Your right to object

Importantly, when we process your data on the basis of our legitimate interests as indicated in the above table, you may object to such processing and request that any of those activities be stopped. Similarly, you may opt-out of any of our direct marketing activities at any time by contacting us at privacy@peruzzisolutions.com , by adjusting your preferences in the privacy dashboard provided as part of some of our services or by using the ‘unsubscribe’ function at the end of our messages.

9.7 Your rights in relation to automated decision making and profiling

You have the right to request not to be the subject of automated decision-making including profiling where the decision produces legal effects or equally has a significant effect on you and can insist on human intervention where appropriate. There are exceptions to this right, which are, if the decision:

  • Is necessary for concluding or performing a contract
  • Is authorized by law
  • Is based on the data subject’s explicit consent

9.8 Data subjects have the right to:

  • Know what data we store about them and for what purposes we use it.
  • Request corrections, deletions, or restrictions on the processing of their data.
  • Object to profiling and request further information about the technologies we use.
  • Withdraw their consent at any time without affecting the lawfulness of prior data processing.

9.9 Your right to withdraw consent

Also, you have the right to withdraw your consent at any time where we rely on your consent for processing your data (e.g. for certain electronic direct marketing purposes). You may do this at any time by contacting us at privacy@peruzzisolutions.com , by adjusting your preferences in the privacy dashboard provided as part of some of our services, or by using the ‘unsubscribe’ function at the end of our messages. Remember that the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal and that in some cases we may need time to process request.

PERUZZI GROUP shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to communicate your objection/withdrawal of consent to recipients of such personal data (if any). However, PERUZZI GROUP shall not communicate such restriction to recipients if the communication to such recipients is either impossible or involves a disproportionate effort.

9.10 Your right to lodge a complaint

Without prejudice to any other administrative or judicial remedy that you may have (such as the right to claim compensation for damages suffered as a result of PERUZZI GROUP’s breach of the GDPR), you have the right to lodge a complaint with supervisory authority, or another data protection supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the GDPR.

Supervisory authority in Hungary:
Hungarian Data Protection and Freedom of Information Authority (NAIH)
The contact details of the NAIH are as follows: H-1125 Budapest, Szilagyi Erzsébet fasor 22/C; phone: +36 1 391-1400; telefax: +36 1 391 1410; e-mail: ugyfelszolgalat@naih.hu; website: www.naih.hu.

Supervisory authority in UK: Information Commissioner’s Office (ICO) The contact details of the ICO are as follows: phone: 0303 123 1113; e-mail: icocasework@ico.org.uk; website: www.ico.org.uk.

In any case, we would highly appreciate the chance to deal with your concerns before you approach the regulatory authority above, so please contact us in the first instance if you have any problems.

9.11 Restrictions on the above rights

Please be advised that based on GDPR Member States are allowed to restrict by way of a legislative measure the scope of the rights you may have as per the above. In case such restriction is applicable in your respect, we will advise you accordingly when you contact us on exercising any of your above rights.

9.12 Contact details

If you wish to exercise any of your rights mentioned above, please contact us at the addresses set out in clause 1.2 above.

9.13 No fee usually required

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a fee of HUF 10.000,- if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

9.14 Verification of your identity

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

10. CHANGES TO THIS PRIVACY POLICY

This Privacy Policy is effective as of the date indicated on the top. Earlier versions may be obtained by contacting us at privacy@peruzzisolutions.com . We will inform you in case of any changes to this Privacy Policy in due course.