Effective as of March 12th 2024.
Introduction
This privacy policy (“Policy”) provides information about how the Flo Health group of companies (collectively, “Flo,” “we,” or “us”) collect and process your personal data in the context of recruitment. Read this Policy carefully, as it contains important information about the data we process, the purposes and legal basis for processing, recipients of your data, personal data protection rights, and other useful information.
What personal data we collect from you
The personal data that we collect from job applicants can include (and will apply to the extent such data collection is reasonably necessary):
- Full name
- Contact information (e.g., email, phone number, address)
- Education, skills, and training
- Current workplace and employment history
- Recommendations
- CV and its attachments
- Publicly available information (e.g., information from professional social networks);
- Recruitment tasks data (such as the presentations and tests performed by you, interview notes about you, etc.)
- Desired salary
- Visa status
- Verification data, which includes the outcomes of background verification checks performed in relation to you (such as outcomes of previous employment and identity checks)
- Information required to prepare your employment contract
- Other information submitted by you
If you choose to disclose it, we may also collect information relating to your:
- Gender
- Veteran status
- Ethnic origin
- Disabilities
The collection of such data is entirely voluntary, and you are under no obligation to disclose this information. Your decision to provide or withhold such information will not affect your job application for candidacy.
When applying, please avoid including any information that is unnecessary for the recruitment process.
Why we collect your personal data
We are constantly looking for new talent to help us build a better future for female health. When you apply or are contacted by us regarding open positions at Flo (either directly or through a recruitment agency), we collect and process your personal data for recruitment purposes which may include to:
- Communicate with you
- Verify your information
- Assess your application and suitability for entering into an employment agreement with Flo
- Comply with applicable laws, legal processes, or enforceable government requests
- Notify you of future job opportunities where we have your consent
- Monitor diversity, equal opportunities, and your candidate experience
- Carry out background and reference checks as appropriate and in accordance with applicable law
We might get in touch with you through our background verification provider to start your verification process. After you have agreed to proceed, the provider will reach out to you. They will ask for your permission to contact other third parties, for example, your past employers, and verify employment dates. Once this verification is completed, this information will be shared with Flo.
How we process your personal data
We will not collect or process your personal data without letting you know. We will process your personal data based on one or more of the following legal bases:
- Your consent: For example, you are required to give us permission to process your personal data when applying for a job position and to retain your CV for future opportunities within Flo.
- Legal obligation: We may be obligated to process some of your personal data to comply with applicable laws and regulations, for example, to make reasonable adjustments for applicants with disabilities or to conduct checks for eligibility to work in a particular territory, as required by immigration laws.
- Legitimate interest: We may process your personal data in relation to our interests in conducting the recruitment process and filling a vacancy within Flo.
- Contract: We may also process your data when we assess your suitability for the role and when we have the intention to enter into a contract with you.
Where we get your data
Generally, we collect the information directly from you. We may also obtain information from:
- Other Flo companies (e.g., when you are referred to another job position at Flo)
- Job portals and recruitment agencies
- Recruitment tools (e.g., Greenhouse Inc., Glassdoor Inc., Indeed Inc.)
- Professional social media networks (e.g., LinkedIn)
- Flo employees (e.g., referrals)
- Background-checking service provider (e.g., Veremark Ltd.)
Whom we share your data with
Your personal data may be shared with other Flo companies to carry out recruitment activities as provided in this Policy or if we see that your profile is more suitable for other positions at Flo.
We may also share your data with our contracted service providers (“processors”) that help us with the recruitment process, such as:
- Crosschq Inc. (TalentWall) (United States; hiring management platform)
- Greenhouse Software Inc. (United States; recruitment software provider)
- Hi Bob Inc. (Israel; people management platform)
- Remote Technology Services Inc. (United States; hiring management platform and employer of record)
We use data processors who provide us with services such as emailing platforms, IT infrastructure service, and analytics. When using service providers, we ensure that they protect our candidates’ personal data in accordance with applicable legal requirements.
In some cases, your personal data is processed within the territory of the European Union and the European Economic Area (EEA). However, the data may be transferred and processed beyond those territories when necessary. If we share your personal data with recipients based outside of the EEA (e.g., in the United States), we make sure that they process personal data with an adequate level of protection, and we rely on our certifications under the EU–US Data Privacy Framework (EU–US DPF), the Swiss–US Data Privacy Framework, and the UK Extension to the EU–US DPF. Should these certifications lapse or become otherwise invalidated, Flo Health will rely on the standard contractual clauses, including supplementary measures as necessary for transfers to the United States.
Data Privacy Framework Participation
Flo is certified under the EU–US Data Privacy Framework and Swiss–US Data Privacy Framework (together, the “DPF”) for personal data transfers from the EU to the US and from Switzerland to the US. You may view our certification here.
How long we store your personal data
In general, your personal data is stored until the end of the recruitment process and as necessary to comply with our legal obligations or resolve any disputes within the hiring process.
- When you give Flo consent to contact you about future job positions, Flo will keep your data for three years in addition to the initial recruitment retention term.
- If you become an employee at Flo, we will save your information within the employee file in accordance with our internal data retention terms for employee data.
- Information from background checks is retained for six months after the verification takes place unless Flo has a legal requirement to keep the data longer.
Automated decision-making
As part of our recruitment process, we may utilize systems whereby candidates may be automatically rejected if they do not meet specific criteria, such as location or qualification requirements. However, our decisions about your candidacy are not solely determined by automated processes. We consider various factors beyond automated criteria to ensure fair and comprehensive evaluation of all applicants.
What happens if you don’t provide us with your personal data
You are not obliged to provide your personal data to Flo; however, as this is required for us to consider you for a job or otherwise engage with you, we will not be able to offer employment without certain personal data.
Your rights
Privacy laws, including the General Data Protection Regulation, provide certain rights to individuals in relation to their personal data. Except as limited under applicable laws, the rights afforded to you are as follows:
Right of access: You have the right to access any personal data that Flo processes about you and to request information about what personal data we hold about you, the purposes of the processing, and other related information.
Right to rectification: If you believe that we hold any incomplete or inaccurate data about you, you have the right to ask us to correct and/or complete the information, and we will strive to do so as quickly as possible.
Right to erasure: You also have the right to request the erasure of your personal data or to restrict processing in accordance with the data protection laws.
Right of data portability: You have the right to request a copy of your personal data in electronic format and to transmit that personal data to another data controller.
Right to withdraw consent: You have the right to withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
Contact us
If you apply or get referred for a job at any of our company locations in the UK or Lithuania, the respective company overseeing that location is responsible for supporting the hiring process. Contact details of the relevant entities are below.
Flo Health UK Limited (United Kingdom)
Address: 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom
Flo Health LTU UAB (Lithuania)
Address: Saltoniškių st. 2-1, 08126 Vilnius, The Republic of Lithuania
We only process your personal information in compliance with this Policy and in accordance with the relevant data protection laws. If, however, you wish to raise a complaint regarding the processing of your personal data or are unsatisfied with how we have handled your information, please email our data protection officer at dpo@flo.health.
You can also complain to your local data protection authority or other local regulatory body responsible for ensuring protection of your rights relating to the handling of personal data. Without prejudicing your rights, we would appreciate it if, in such cases, you would contact us first to resolve the issue together.
If you have any questions regarding this Policy or your privacy, please email us at hr@flo.health, or you can email Flo’s data protection officer at dpo@flo.health.