BioCatch Ltd.

Global Job Candidate Privacy Notice


Last Updated: August, 2023

Last Updated: August 2023

This Global Job Candidate Privacy Notice (“Notice”) describes what personal information we – BioCatch Ltd. and our affiliates (together, “BioCatch,” “we”, “our” or “us”) – collect and process on our job candidates and applicants (“Candidates” or “you”) with respect to our application and recruitment process, why we collect it and how we use it. It also describes how Candidates may exercise their rights to such information held with us.

We strongly urge you to read this Notice and make sure that you fully understand and agree to it. If you do not agree to this Notice, please avoid providing us with your personal information.

You are not legally required to provide us with any personal information, but without it we may not be able to process your application.

        1. What information do we collect and how do we collect it?

Throughout the application and recruitment process, you may provide us (or we may otherwise have access to) personal information about you, such as your identifying information, contact details, resume/CV, work-related information, social media activity, etc. We may collect this information directly from you, as you provide it voluntarily through your application and candidacy review process, or from other sources such as recruitment agencies, background check services (as applicable and subject to applicable law), public information or your references. We refer to such information as “Personal Information.”

In some regions, we may also require you to submit sensitive data relating to your ethnicity, gender, and whether you have a disability, to ensure our compliance with our legal obligations under applicable law when processing your application. We may also collect sensitive data about your prior criminal convictions and offences and credit rating and/or history as part of our background checks for specific roles if permitted or required by law. To the extent legally required, we will obtain your explicit consent prior to any such collection and use.

     2. For what purposes do we use your Personal Information?

We use your Personal Information as part of the application and recruitment process for the following purposes and in reliance on the lawful bases detailed below:

Purpose Lawful Basis for Processing

To assess our Candidates’ skills, qualifications and overall to verify, consider and process their application and candidacy for any of our positions, and to communicate with them regarding such processes

Contractual Necessity

Legitimate Interests

Consent (where applicable)

To contact you about other suitable roles within BioCatch in the future

Legitimate Interests

Consent (where applicable)

To maintain our internal records of recruitment and candidate applications

▪ Legal Obligations

Contractual Necessity

Legitimate Interests

To create your personnel file, if onboarded

 

To comply with applicable legislation and industry codes

 

To manage risk and enhance our security and anti-fraud measures

 

To create aggregated statistical or inferred data regarding our Candidates 

Legitimate Interests

To further develop and improve our recruitment and onboarding processes

 

To protect the rights and interests of BioCatch

 

Should we wish to conduct any additional activities that may require the use of your Personal Information, we will notify you in advance, and if required by applicable law, request your prior specific consent.

If you reside in a territory governed by privacy laws under which “consent” is the only or most appropriate legal basis for the processing of Personal Information as described herein, your application means that you have had the opportunity to read and that you accept this Notice and will be deemed as your consent to the processing of your Personal Information for all purposes detailed in this Notice. If you wish to revoke such consent, you may do so at any time by contacting us at dpo@biocatch.com.

  1. Where do we store your Personal Information?

Your Personal Information will be maintained, processed and stored by BioCatch and our Service Providers (as defined in Section 6 below) in the applied position’s location(s), in relevant BioCatch offices worldwide (including, without limitation, in the European Union (EU), United Kingdom (UK), Israel, Brazil and the United States), and other jurisdictions as necessary for the proper handling of your candidacy.

While privacy laws may vary between jurisdictions, BioCatch and Service Providers processing Personal

Information on our behalf are each committed to protecting Personal Information in accordance with this Notice, customary industry standards, and such appropriate lawful mechanisms and contractual terms requiring adequate data protection, regardless of any lesser legal requirements that may apply in the jurisdiction to which such Personal Information is transferred.

To the extent we transfer Candidates’ Personal Information originating in the European Economic Area (EEA), UK, or Switzerland to countries that have not been recognized as offering an adequate level of data protection by the relevant competent authority, we rely on appropriate contractual undertakings and data transfer mechanisms as established under applicable law, such as the standard contractual clauses adopted in the EU (available here), the UK (available here). If we transfer Candidates’ Personal Information originating from the EEA to Israel or the UK, and if we transfer such data originating from the UK to Israel or the EEA, we rely on the respective adequacy findings of the EU and the UK regarding the level of data protection offered by Israel, the UK, and the EEA.

  1. How do we secure your Personal Information?

BioCatch will take appropriate measures to protect Personal Information that are consistent with applicable privacy and data security laws and regulations, including requiring service providers to use appropriate measures to protect the confidentiality and security of Personal Information. Please be aware that regardless of the measures we take and the efforts we make, we cannot and do not guarantee the absolute protection and security of any personal data stored with us.

  1. For how long may we keep your Personal Information?

BioCatch will process your Personal Information for carrying out the purposes described in this Notice. BioCatch will retain Personal Information for the period necessary to fulfill the purposes outlined in this Notice unless a longer retention period is required or permitted by law. The criteria used to determine the retention periods relate to the nature, scope, context and purposes of processing. For example, we may retain Personal Information even after the applied position has been filled or closed so we can reconsider Candidates for other positions and opportunities at BioCatch in the future. We may also retain Personal Information to use as reference for future applications submitted by such Candidate. Where a Candidate is hired, we may retain Personal Information for additional employment and business purposes. We may also retain Personal Information as reasonably necessary to comply with our legal and contractual obligations, to resolve disputes, prevent fraud and abuse, enforce and perform under our agreements or otherwise protect our legitimate interests.

  1. Who may have access to your Personal Information?
    • Service Providers: Third-parties whose services and solutions complement, facilitate and enhance the processing of your application and our recruitment process. These include any recruitment firms or individuals that have referred you to us (or vice versa), candidate evaluation centers, recruitment software providers, background checks providers (where applicable), reference providers, data and cybersecurity services, web analytics, and our business, legal, compliance and financial advisors. Such Service Providers may receive or otherwise have limited access to Personal Information, depending on each of their particular roles and purposes in facilitating and enhancing our recruitment process, and may only use it for such purposes.
    • Public and Governmental Authorities: Entities that regulate or have jurisdiction over BioCatch such as regulatory authorities, law enforcement, public bodies, and judicial bodies. We may disclose or otherwise allow access to Personal Information pursuant to a legal request, such as a subpoena, search warrant or court order, or in compliance with applicable laws, with or without notice to you, if we have a good faith belief that we are legally required to do so, or that disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, fraud or other wrongdoing. We may also share your Personal Information with others, with or without notice to you, if we believe in good faith that this will help protect the rights, property or personal safety of BioCatch, any of our customers or personnel, or any member of the general public, including yourself or other applicants.
    • BioCatch Group of Companies: Due to the global nature of BioCatch operations, we disclose Personal Information to personnel and departments throughout BioCatch to fulfill the purposes described in this Notice. This may include transferring Personal Information to other countries. For example, if you are located in the European Union (EU) or the United Kingdom (UK), we transfer your Personal Information to countries located outside of the EU or the UK. For more information on transfers, please see Section 3 above. Access to Personal Information within BioCatch will be limited to those who have a need to know the information for the purposes described in this Notice, including potential managers and their designees, executive management and personnel in HR, IT, Compliance, Legal, Finance and Accounting and Internal Audit.
    • Corporate Transactions: Should BioCatch undergo any change in control or other corporate-type transactions, including by means of merger, acquisition or purchase of all or part of its assets or sales of equity, your Personal Information may be shared with the parties involved in such event.
  2. How can you exercise your rights?

If you wish to exercise your rights under any applicable law (including, but not limited to, the EU or UK General Data Protection Regulation (GDPR), Israeli Privacy Protection Laws, or the California Consumer Privacy Act (CCPA)) such as, to the extent applicable – the right to know/access to (specific pieces of Personal Information collected; categories of Personal Information collected; categories of sources from whom the Personal Information was collected; purpose of collecting Personal Information; categories of third parties to whom we have disclosed Personal Information), to request rectification or erasure of your Personal Information held with BioCatch, to port such Personal Information, or to restrict or object to such Personal Information’s processing or any similar rights afforded to data subjects under the laws that apply to you – please contact us at dpo@biocatch.com. We will respond to your request consistent with applicable law. Please note, however, that certain Personal Information may be exempt from requests pursuant to applicable data protection laws or other laws and regulations.

Please note that we may require additional information, including certain Personal Information, in order to authenticate and process your request. Such additional information, along with any communications and records related to your request, may then be retained by us for legal purposes (e.g., as proof of the identity of the person submitting the request or proof of request response), in accordance with Section 5 above.

Additionally, you have a right to lodge a complaint with a competent data protection authority, such as the supervisory authority in the EU Member State of your habitual residence, place of work, or of the alleged GDPR infringement, the UK’s Information Commissioner’s Office, or your State’s Attorney General (as relevant).

  1. S. State Privacy Laws

This policy describes the categories of Personal Information we may collect and the sources of such information (Section 1), and our retention (Section 5) and deletion (Section 7) practices, currently and in the preceding 12 months. We also included information about how we may process your information, which includes processing for “business purposes” under the CCPA as amended (Section 2), and other applicable US State privacy laws. We do not sell or share your Personal Information for the intents and purposes of the CCPA. We do not currently use or disclose sensitive Personal Information outside of the purposes allowed by the CCPA. We may disclose Personal Information to other parties or allow them to collect Personal

Information from us as described above (Section 6) if those parties are authorized Service Providers, or if you direct us to disclose your Personal Information. You may also designate an authorized agent, in writing or through a power of attorney, to request to exercise your privacy rights on your behalf where applicable law provides you that right. The authorized agent may then submit a request on your behalf to exercise these rights by emailing us at dpo@biocatch.com.

  1. Cookies and tracking technologies

If you apply to one of our positions via our website (or that of a Service Provider) please note the use of certain monitoring and tracking technologies, such as “cookies” or similar technologies. These technologies are used to maintain, provide and improve our processes and operations on an ongoing basis, and in order to provide a better experience to our website visitors and Candidates. For example, these technologies enable us to better secure our website and services and detect abnormal behaviors, to identify technical issues, and to monitor and improve the overall performance of our services and processes. To learn more about our cookies practices, please visit our website privacy policy or, where applicable, the privacy policies of our Service Providers.

  1. Will this Notice be updated?

We may update this notice to reflect changes in our privacy practices. If we make any changes that we deem as "material", we will update this page prior to the change becoming effective.

  1. Data Protection Officer Contact Information and Complaints

If you have any comments or questions regarding our Personal Information practices or your privacy, or if you have any concerns regarding your Personal Information held with us, or if you wish to make a complaint about how your Personal Information is being processed by BioCatch, you can contact our Data Protection Officer (DPO) at dpo@biocatch.com.  

Inquiries regarding our EU or UK privacy practices may be sent by e-mail to dpo@biocatch.com or you may contact our designated EU or UK representatives via mail as follows: to make an EU inquiry, please visit the following page: https://prighter.com/q/16916575803. UK inquiries may be sent to: BioCatch (Emea) Limited, 4th Floor, St. James House St. James Square, Cheltenham, GL50 3PR, England. 

Actionable Behavioral Insights Start Here

Request a Demo