Effective as of June 30, 2020

Candidate Privacy Notice

We are pleased that you are interested in us and that you wish to apply or have already applied for a position with Contentful.

This notice applies to personal data of applicants applying for positions with Contentful (whether Contentful Inc. or Contentful GmbH). The data controller according to European Union General Data Protection Regulation (“GDPR”) Art. 4(7) is

  • Contentful Inc. for positions in North America and
  • Contentful GmbH for positions elsewhere in the world.

The California Consumer Privacy Act (“CCPA”) includes concepts similar to GDPR: for example “business” is similar to “data controller”. For simplicity, when we talk about Contentful being a “data controller”, we also mean that Contentful is a “business” in the sense of CCPA.

For questions concerning our processing of your personal data please reach out to the recruiter handling your application or contact us through the contact details in the Contact Information section.

This notice explains:

  • What personal data we process
  • The purpose and legal basis of processing
  • With whom we share your data
  • How long we keep your data
  • Your rights related to our processing of your data and how we protect your data
  • We can change our data processing practices and this notice
  • Where to address your questions or complaints

The personal data we process

We process the following personal data related to you:

Information that you provide to us:

  • Identifiers – such as your name, email address, contact details, telephone number.
  • Location information such as your address.
  • Professional or employment information – such as your resume/CV, certifications, and qualifications.
  • Education information – such as your school or university, your degree and grades earned, your major, and your graduation date.
  • Protected classifications/special categories of data – such as ethnicity, national origin, any disabilities you may have, marital status, gender identity and expression, citizenship or citizenship status, and military or veteran status which we may receive directly from you if you fill out a voluntary equal employment opportunity questionnaire. Such data is aggregated and not retained in a manner which identifies a specific candidate.
  • Information from a background check (if any) we have obtained from you.
  • CCTV recordings made in our premises if you visit us at our premises.

Information that we receive from third party sources:

  • We may receive your identifiers, location information, professional or employment information and/or education information from sources such as professional and other networks (such as LinkedIn Corporation, 1000 W. Maude Ave. Sunnyvale, California 94085, U.S.A. or Stack Overflow/Stack Exchange, Inc. 110 William Street, Floor 28, New York, New York 10038, U.S.A.) or from recruitment agencies to the extent you have shared such information in those networks or with such agencies and when we “source” candidates through such channels. Both LinkedIn and Stack Overflow are Privacy Shield certified and so committed to complying with the European Union’s data protection regulations. Their certifications are available, respectively, here: https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active https://www.privacyshield.gov/participant?id=a2zt0000000CbWGAA0&status=Active
  • Feedback from referees we may have contacted, subject to your permission, as part of our recruitment process.
  • Subject to your permission, background information from third parties as part of a background check, if any.

You are not required to provide your personal data during the application process. However, if you do not provide the information, we may not be able to process your application properly or at all.

What categories of data do we process for what purpose and on what legal basis (where GDPR and/or German Federal Data Protection Law apply)

  • To process your application, we may process your identifiers, professional, employment and/or education information.
    • The legal basis for this processing is Art. 6(1)(b) GDPR in conjunction with Section 26(1) of the German Federal Data Protection Act (“BDSG”)
  • To communicate with you about your application and respond to questions you may have about the application process, we process your identifiers, professional, employment and/or education information related to you and the specific communications with you.
    • The legal basis for this processing is Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG
  • To conduct reference checks, we process your identifiers, professional or employment information, and education information.
    • The legal basis for this processing is Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG
  • To assess your suitability for the position for which you have applied, we may process your identifiers, location, professional or employment information and/or education information.
    • The legal basis for this processing is Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG
  • Where permitted by local law, to monitor compliance with equal opportunities and non-discrimination policies, as well as for complying with our health, safety, and occupational health obligations, we process your protected classifications/special categories of data.
    • The legal basis for this processing is Art. 6(1)(c) GDPR. To the extent we process special categories of data, we rely on the additional legal basis of Art. 9(2)(h) GDPR in conjunction with Section 22(1)(1)(b) BDSG
  • To assess your working capacity, we process your protected classifications/special categories of data.
    • The legal basis for this processing is Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG. To the extent we process special category data, we rely on the additional legal basis of Art. 9(2)(h) GDPR in conjunction with Section 22(1)(1)(b) BDSG.
  • For carrying out the obligations and exercising specific rights of the data controller or of the data subject in the field of employment and social security and social protection law.
    • The legal basis for this processing is Art. 6(1)(b) GDPR in conjunction with Section 26(1) BDSG. To the extent we process special category data, we rely on the additional legal basis of Art. 9(2)(b) GDPR in conjunction with Section 26(3) BDSG.
  • To respond to legal processes such as subpoenas, to pursue legal rights, defend litigation, or comply with requests of government or public authorities, we may process your identifiers, protected classifications/special category data, professional or employment information to the extent it is relevant to such legal purposes.
    • The legal basis for this processing is Art. 6(1)(c) and Art. 6(1)(f) GDPR. In such cases, our legitimate interest is in asserting or defending claims.

You have the right at any time to object, on grounds relating to your particular situation, to processing of your personal data where the processing is based on Art. 6(1)(f) GDPR.

The “recipients” of your personal data/with whom we share your personal data

  • Our employees in the HR department, recruitment coordinators, interview panelists, and department heads and hiring managers to whom your position would report will generally receive your work and education history and your application.
  • External recruitment agencies or consultants who will generally receive your identifiers, your work and education history and your application. Because the recruitment agencies are subject to change, please contact us (contact details below) to learn which agencies, if any, we are using in connection with your application.
  • Applicant software service provider (currently Greenhouse Software Inc. 18 West 18th Street, 11th Fl. New York, New York 10011, U.S.A.) who will generally receive your entire application and messages that we exchange with you via that platform, such as invitations to interviews. Greenhouse Software Inc. is certified under Privacy Shield, the US-EU data protection agreement, and is so committed to complying with the European Union’s data protection regulations (https://www.privacyshield.gov/participant?id=a2zt00000004U1KAAU&status=Active)
  • If the interview takes place using Contentful video conferencing tools, your data will be transferred to Zoom Video Communication, Inc. Such data includes: identifiers (such as name, email address, optional profile photo), content (such as voice and video calls, chat messages, files, whiteboards and other information shared in the video conferencing service), metadata related to the meeting and telephony or other connectivity data (such as meeting topic, start and end time, participant IP addresses, device/hardware information, phone number). Zoom is certified under Privacy Shield, the US-EU data protection agreement, and is so committed to complying with the European Union’s data protection regulations https://www.privacyshield.gov/participant?id=a2zt0000000TNkCAAW&status=Active
  • If you provide us with your LinkedIn profile, for example in the application form via Greenhouse, we will receive your LinkedIn profile and LinkedIn will learn that you applied for a position at Contentful. LinkedIn Corporation is certified under Privacy Shield, the US-EU data protection agreement, and is so committed to complying with the European Union’s data protection regulations https://www.privacyshield.gov/participant?id=a2zt0000000L0UZAA0&status=Active
  • Subject to your permission, referees who will receive identifiers such as your name and employment and/or education information such as reference to the common former or current employer you may have or other such commonality between you and your referee.
  • To the extent engaged in the recruitment process, recruiting software and service providers such as Codility Limited in the U.K. (for conducting coding reviews) that will receive identifiers such as your contact details, coding samples and employment information/inferences such as related assessments, or GEM Software, Inc. in the U.S.A. (currently used as an email campaign software) that will receive identifiers such as your contact details and employment information such as email messages that we will send to you. GEM Software, Inc. is certified under Privacy Shield, the US-EU data protection agreement, and is so committed to complying with the European Union’s data protection regulations (https://www.privacyshield.gov/participant?id=a2zt0000000PLfJAAW&status=Active)
  • Contentful uses technologies such as cookies on the Contentful website. Cookie and similar data is shared with third parties in accordance with our cookie and privacy notices available on our website via contentful.com/legal

We have concluded what’s known as a data processing agreement with all external persons involved in the process. The data processing agreements ensure that data processing is carried out lawfully. Our own employees have committed to confidentiality and privacy obligations to keep your personal data safe.

Data that we have shared in the past 12 months

Depending on whether you have already applied for a position with Contentful, at what stage your application process is, what type of position you have applied for and if you have visited our website, where we use cookies and similar technologies, we have shared your data for the purposes of processing your application with the applicable third parties listed above. For example, if you have visited our website and applied for a software developer position, we would have shared your data with third parties according to our website cookie and privacy notices (available on contentful.com/legal), Greenhouse (please see above) and the appropriate employees referred to above. If your application proceeded further, we may have shared your data with Codility (please see above) and, subject to your permission, referees. You can reach out to us by contacting our recruitment team member handling your application or by using the contact details provided below to request a detailed overview of your application and data.

The period for which your personal data will be stored

In the event of a rejection, candidate data will be deleted after 6 months unless it is apparent that the data will be needed for legal reasons, such as for legal claims. In such cases the legal basis for this processing is Art. 6(1)(f) GDPR and our legitimate interest is in asserting or defending claims. If you are offered a job in the context of the application process, the data will be transferred to our HR information system which is currently Bamboo HR LLC, 335 South 560 West, Lindon, Utah 84042, U.S.A. Bamboo HR is Privacy Shield certified and so committed to complying with the European Union’s data protection regulations. Their certification is available here: https://www.privacyshield.gov/participant?id=a2zt0000000GnsZAAS&status=Active

If your application is successful, the information will form part of your employment file and we will be entitled to process it for all relevant purposes in connection with your employment and as indicated in our Privacy Notice to Employees which you will receive at the time of concluding your employment agreement.

Your rights and how we protect your data

If our processing of your personal data is subject to the GDPR, you have the following rights under the GDPR:

  • Right of access: You can request information in accordance with Art. 15 GDPR about your personal data that we process.
  • Right to rectification or erasure: If the information concerning you is not correct, you can request correction in accordance with Art. 16 GDPR. If your data is incomplete, you may request that it be completed. You can request the deletion of your personal data in accordance with Art. 17 GDPR.
  • Right to restriction of processing: In accordance with Art. 18 GDPR, you have the right to request restriction of processing your personal data.
  • Right to withdraw your consent: If you have given your consent for processing, you have a right to revoke your consent according to Art. 7.3 GDPR.
  • Right to data portability: You have the right to receive the personal data concerning you that you have provided to us in a structured, common and machine-readable format as well as the right to transfer this data to another data controller, if the conditions of Art. 20.1(a), (b) GDPR are met.
  • You have the right to file a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR).
  • Right to object to processing: You have the right to object at any time to processing of your personal data in accordance with Art. 21(2) GDPR (processing for direct marketing purposes). In accordance with Art. 21(1) GDPR, you also have the right at any time to object, for reasons arising from your particular situation, to processing carried out on the basis of Art. 6(1)(e) or (f) GDPR. In this latter case we will not process your data unless we can demonstrate compelling legitimate reasons to do so which outweigh your interests, rights and freedoms, or if the processing is for purposes of establishing, asserting, exercising or defending against legal claims.

All Contentful employees are committed to confidentiality and protection of personal data. We apply strict security practices across our business, including regularly training our employees. We regularly assess the security of our suppliers and partners and ensure that they are contractually committed to appropriate privacy and security measures. For more information about information security at Contentful, please see here: https://www.contentful.com/legal/de/2017-01-31/security/

For more information on processing your personal data by Contentful, please contact your Contentful recruiter via the contact details provided in the relevant job description or use the contact details provided below.

Other useful information

Do Not Track

We do not currently support Do Not Track (“DNT”) on our website contentful.com. Please review the privacy practices of other websites such as job portals where you may view and apply for open positions with Contentful. DNT is a preference you can set in your web browser to inform websites that you do not want to be tracked. You can enable or disable DNT by visiting the preferences or settings page of your web browser. For further details, visit https://www.eff.org/issues/do-not-track.

Changes to our data processing practices and this notice

This notice may be updated and changed from time to time. We will post the new notice on this page and/or in the job ads that we post on our career website or other job boards and will indicate the date it goes into effect. If the changes allow us to use personal data in ways that are different from the ways specified at the time the information was originally collected, our website will contain a special notice about the changes and, if required by law, will prompt you for your consent for certain changes. Each version of this notice will be identified by its effective date, which you can find at the bottom of this notice.

Contact information; Where to address your questions or complaints

If you would like to view or update the information we have collected about you, please contact the recruiter handling your application or contact us via:

Contentful, Inc. 101 Montgomery Street, Suite 1900, San Francisco, CA 94104, U.S.A.

Contentful GmbH, Ritterstr. 12-14, 10969 Berlin, Germany

You can also contact us at legal@contentful.com or privacy@contentful.com

If you have any questions about data protection and processing of your personal data by Contentful, you can also contact our data protection officer: Contentful GmbH/Data Protection Officer, Ritterstraße 12-14, 10969 Berlin, Germany and by email: privacy@contentful.com.

add-circle remove subtract-circle