Candidate Privacy Notice

Scope and Overview

Seven Bridges Genomics Inc. is committed to protecting the privacy and security of your personal data. This Privacy Notice, effective July 20, 2020, describes how Seven Bridges Genomics Inc. and its subsidiaries and affiliates (collectively, “Seven Bridges”, “we,” or “us”) collect and process personal data about you during the application and recruitment process. This Privacy Notice applies to job applicants only, including candidates who directly apply for a job and candidates sourced through other means (e.g. professional recruiting services). This privacy notice applies to all job applicants, regardless of location.

This Privacy Notice describes the categories of personal data that we collect, how we use your personal data, how we secure your personal data, when we may disclose your personal data to third parties, and when we may transfer your personal data outside of your home jurisdiction. This Privacy Notice also describes your rights regarding the personal data that we hold about you including how you can access, correct, and request erasure of your personal data.

We will only process your personal data in accordance with this Privacy Notice unless otherwise required by applicable law. We take steps to ensure that the personal data that we collect about you is adequate, relevant, not excessive, and processed for limited purposes.

Collection of Personal Data

For purposes of this Privacy Notice, personal data means any information about an identifiable individual collected in connection with the recruitment process. Seven Bridges may collect personal data directly from you, as a job applicant, or may receive personal data from third parties, for example, in connection with a reference check, subject to your consent where required by law. Personal data excludes anonymized or de-identified data not associated with a particular individual. We may collect, store, and process the following categories of personal data, in connection with our recruiting activities:

  • Personal contact details such as name, title, addresses, telephone numbers, and personal email addresses.
  • Work history, education information and other relevant experience including information contained in a resume, CV, cover letter, or job application.
  • Information collected during phone screenings and interviews.
  • Details regarding the type of employment sought, desired salary, willingness to relocate, job preferences, and other information related to compensation and benefits.

The personal data listed in this notice is mandatory in connection with our recruiting activities. Failure to provide or allow us to process mandatory personal data may affect our ability to accomplish the purposes stated in this Privacy Notice. 

Use of Personal Data

Seven Bridges takes appropriate measures to ensure that all processing of your personal data by us, or our service providers, is lawful. We only process your personal data where applicable law permits or requires it in connection with carrying out our application and recruitment process, to take steps necessary to enter into an employment contract with you, where the processing is necessary to comply with a legal obligation that applies to us, for our legitimate interests or the legitimate interests of third parties, or with your consent if applicable law requires consent. We may process your personal data for the following legitimate business purposes:

  • Identifying and evaluating job applicants, including assessing skills, qualifications, and interests for the purposes of determining suitability for the position for which you have applied.
  • Verifying your information and carrying out employment, background, and reference checks, where applicable, subject to your consent where required by applicable law.
  • Communicating with you about the recruitment process and your application.
  • Keeping records related to our hiring processes, for only as long as described below.
  • Creating and submitting reports as required by applicable laws or regulations.
  • To comply with our legal, regulatory, or other corporate governance requirements.
  • Analyzing and improving our application and recruitment process.

In addition to using your personal data for the position for which you have applied, we may retain and use your personal data to inform you about and consider you for other positions that may be appropriate for you with your consent. 

We may also analyze your personal data or aggregated, anonymized data to improve our recruitment and hiring processes and improve our ability to attract successful candidates.

You will not be subject to hiring decisions based solely on automated data processing without your prior consent.

Collection and Use of Special Categories of Personal Data

Certain special categories of personal data (e.g. race or ethnic origin, ethnicity, health information, trade union membership, sexual orientation and other categories as prescribed by law) may be considered sensitive under the laws of your jurisdiction. We do not seek to obtain and will not collect such data about a candidate unless permitted to do so by applicable laws (e.g. US equal opportunity monitoring).

Data Sharing

We will only disclose your personal data to third parties where required by law or to our employees, contractors, designated agents, or third-party service providers who require such information to assist us with administering the recruitment process. We may use third-party service providers for various purposes, including, but not limited to, obtaining employment verification and data storage or hosting. These third-party service providers may be located outside of the country in which you live or the country where the position you have applied for is located.

We require all our third-party service providers, by written contract, to implement appropriate security measures to protect your personal data consistent with our policies and any data security obligations applicable to us. We do not permit our third-party service providers to process your personal data for their own purposes. We only permit them to process your personal data for specified purposes in accordance with our instructions.

We may also disclose your personal data for the following additional purposes where permitted or required by applicable law:

  • To comply with legal obligations or valid legal processes such as search warrants, subpoenas, or court orders. When we disclose your personal data to comply with a legal obligation or legal process, we will take reasonable steps to ensure that we only disclose the minimum personal data necessary for the specific purpose and circumstances.
  • To protect the rights and property of Seven Bridges.
  • During emergency situations or where necessary to protect the safety of persons.
  • Where the personal data is publicly available.
  • If a business transfer or change in ownership occurs and the disclosure is necessary to complete the transaction. In these circumstances, we will limit data sharing to what is absolutely necessary, and we will anonymize the data where possible.

Cross-Border Data Transfers

Where permitted by applicable law, we may transfer the personal data we collect about you to the United States and other jurisdictions that may not be deemed to provide the same level of data protection as your home country for the purposes set out in this Privacy Notice. If you are located in the EU, Seven Bridges ensures that your personal data is protected by using appropriate legal mechanisms including contracts or wording approved by the European Commission, or, in the case of US-based parties, working with companies that are Privacy Shield certified.

Data Security

We have implemented appropriate physical, technical, and organizational security measures designed to secure your personal data against accidental loss and unauthorized access, use, alteration, or disclosure. In addition, we limit access to personal data to those employees, agents, contractors, and other third parties that have a legitimate business need for such access. 

Data Retention

Except as otherwise permitted or required by applicable law or regulation, we will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, but in no event longer than two (2) years or for as long as reasonably required to satisfy any legal, accounting, or reporting requirements, or as necessary to resolve disputes. 

Under some circumstances we may anonymize your personal data so that it can no longer be associated with you. We reserve the right to use such anonymized and de-identified data for any legitimate business purpose without further notice to you or your consent.

If you are offered and accept employment with Seven Bridges, the personal data we collected during the application and recruitment process will become part of your employment record, and we may use it in connection with your employment consistent with our employee personal data policies. If you do not become an employee, or, once you are no longer an employee of Seven Bridges, we will retain and securely destroy your personal data in accordance with this Privacy Notice and applicable laws and regulations.

Rights of Access, Correction, Erasure, and Objection

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during the recruitment process. By law you may have the right to request access to, correct, and erase the personal data that we hold about you, or object to the processing of your personal data under certain circumstances. You may also have the right to request that we transfer your personal data to another party. If you want to review, verify, correct, or request erasure of your personal data, object to the processing of your personal data, or request that we transfer a copy of your personal data to another party, please contact us at dpo@sevenbridges.com. Any such communication must be in writing.

We may request specific information from you to help us confirm your identity and your right to access, and to provide you with the personal data that we hold about you or make your requested changes. Applicable law may allow or require us to refuse to provide you with access to some or all of the personal data that we hold about you, or we may have destroyed, erased, or made your personal data anonymous in accordance with our record retention obligations and practices. If we cannot provide you with access to your personal data, we will inform you of the reasons why, subject to any legal or regulatory restrictions.

Changes to This Privacy Notice

We reserve the right to update this Privacy Notice at any time, and we will provide you with a new Privacy Notice by posting it to this page, so please check back periodically. In some cases we may also notify you via email or other mechanisms.

Contact Us

If you have any questions about our processing of your personal data or would like to make an access or other request, please contact us at dpo@sevenbridges.com. If you are unsatisfied with our response to any issues that you raise, you may have the right to make a complaint with the data protection authority in your jurisdiction by contacting the applicable data protection authority.