RAINBOW AU PAIRS LIMITED
The wording in this document reflects the requirements of the General Data Protection Regulation (GDPR), which will come into effect in the UK on 25 May 2018.
Click on Table of Contents links to see relevant section of the Terms and Conditions
1. ABOUT US - RAINBOW AU PAIRS LIMITED
Rainbow Au Pairs Limited (“We”, “Us”, “Our”, “Rainbow Au Pairs”)is a company registered in England and Wales with the company registration number 06808082 and having its registered office at Gallipot Hill House, Gallipot Hill, Hartfield East Sussex TN7 4AH.
Data controller: Rainbow Au Pairs Limited, Gallipot Hill House, Gallipot Hill, Hartfield East Sussex TN7 4AH Data protection officer: Mrs Cynthia Cary 01342 776151
As part of any recruitment process, the Agency collects and processes personal data relating to families. The Agency is committed to being transparent about how it collects and uses that data and to meeting its data protection obligations.
2. WHAT INFORMATION DOES THE AGENCY COLLECT?
The Agency collects a broad range of information about the family. This includes:
• your name, address and contact details, including email address and telephone number;
• details of your requirements;
• information about your child/children, their ages and special needs (if relevant)
• equal opportunities monitoring information, including information about your ethnic origin, sexual orientation, health and religion or belief.
The Agency collects this information in a variety of ways. For example, data might be contained in application forms, obtained from your passport or other identity documents, or collected through interviews or other forms of assessment.
The Agency will also collect personal data about you from third parties, such as references, information from background check providers and information from criminal records checks.
Data will be stored in a range of different places, including on your application record, in HR management systems and on other IT systems (including email).
3. WHY DOES THE AGENCY PROCESS PERSONAL DATA?
The Agency needs to process data to take steps at your request prior to entering into a contract with you. It also needs to process your data to enter into a contract with you.
In some cases, the Agency needs to process data to ensure that it is complying with its legal obligations. For example, it is required to check a successful applicant's eligibility to live in the UK before any placement is made.
The Agency has a legitimate interest in processing personal data during the recruitment process and for keeping records of the process. Processing data from families allows the Agency to manage the recruitment process, assess and confirm a family’s suitability to take on an au pair and decide who would be a suitable au pair for you and keep you informed of available candidates as they arise and keep you informed of the services offered by us.
The Agency may also need to process data from families to respond to and defend against legal claims.
Where the Agency relies on legitimate interests as a reason for processing data, it has considered whether or not those interests are overridden by the rights and freedoms of families and has concluded that they are not.
The Agency processes health information if it needs to make reasonable adjustments to the recruitment process for families who have a family member who may have a disability.
For some roles, the Agency is obliged to seek information about criminal convictions and offences. Where the Agency seeks this information, it does so because it is necessary for it to carry out its obligations and exercise specific rights in relation to employment.
The Agency will not use your data for any purpose other than the recruitment exercise for which you have contracted with is for.
If we do not find you an au pair, the Agency will keep your personal data on file in case there are future au pairs for which you may be suited. The Agency will ask for your consent before it keeps your data for this purpose and you are free to withdraw your consent at any time.
4. WHO HAS ACCESS TO THE DATA?
Your information will be shared internally for the purposes of the recruitment exercise. Your information will also be shared with our 3rd party partner au pair agencies in EU countries and non EU countries, au pairs, and IT staff if access to the data is necessary for the performance of their roles. Personal data shall not be transferred to a country or territory outside the EEA unless that country or territory ensures an adequate level of protection or the appropriate safeguards are in place for your rights and freedoms.
The Agency will then share your data with referees to provide references for you, background check providers to obtain necessary background checks and the Disclosure and Barring Service to obtain necessary criminal records checks.
Your data may be transferred outside the European Economic Area (EEA) to our partner agencies for the purpose of finding a suitable au pair.
When transferring personal data to third countries or international organisations outside of the EU, our Agency will ensure that an adequate level protection has been established as follows:
• That the country (or industry sector within that country) of the recipient is on the EU approved list of countries as set out in the Official Journal of the European Union;
• That the country of the recipient has adequate data protection controls by virtue of legal or self-regulatory regime;
• We have a contract in place, which uses either existing or approved data protection clauses to ensure adequate protection;
• We are making the transfer under approved binding corporate rules;
• We are relying on an exemption as set out in clause 6.8 of the Data Protection Policy
• We are relying on approved codes of conduct or certification mechanisms, together with binding and enforceable commitments in the third country or international organisation to apply the appropriate safeguards in relation to data subject rights.
5. HOW DOES THE AGENCY PROTECT DATA?
The Agency takes the security of your data seriously. It has internal policies and controls in place to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and is not accessed except by our employees in the proper performance of their duties.
Rainbow Au Pairs adopt a clear desk policy particularly in relation to personal data.
Protection of data is done via a bespoke back office system that provides the right levels of security. The solutions include cloud storage and backing up all data on an external hard drive which is compliant with EU regulations.
6. FOR HOW LONG DOES THE AGENCY KEEP DATA?
If your application for a match is unsuccessful, the Agency will hold your data on file for 12 months after the end of the relevant recruitment process. If you agree to allow the Agency to keep your personal data on file, the Agency will hold your data on file for a further 12 months for consideration for future placement opportunities. At the end of that period, your data is deleted or destroyed.
If your application to be a client is successful, personal data gathered during the recruitment process will be transferred to your client file and retained during the time that you have an au pair matched by us. The periods for which your data will be held will be provided to you in a new privacy notice.
As a data subject, you have a number of rights. You can:
• access and obtain a copy of your data on request;
• require the Agency to change incorrect or incomplete data;
• require the Agency to delete or stop processing your data, for example where the data is no longer necessary for the purposes of processing;
• object to the processing of your data where the Agency is relying on its legitimate interests as the legal ground for processing; and ask the Agency to stop processing data for a period if data is inaccurate or there is a dispute about whether or not your interests override the Agency's legitimate grounds for processing data.
If you would like to exercise any of these rights, please contact Cynthia Cary of Gallipot Hill House Gallipot Hill Hartfield East Sussex TN7 4AH.
If you believe that the Agency has not complied with your data protection rights, you can complain to the Information Commissioner.
What if you do not provide personal data?
You are under no statutory or contractual obligation to provide data to the Agency during the recruitment process. However, if you do not provide the information, the Agency may not be able to process your application properly or at all.
Recruitment processes are not based solely on automated decision-making.
7. COOKIES AND IP ADDRESSES
7.2 You may block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of our Website.
7.3 Please note that when you visit our site, we may also log your IP address, a unique identifier for your computer or other access device.
9. CONTACT DETAILS
Rainbow Au Pairs Limited Gallipot Hill House Gallipot Hill Hartfield East Sussex TN7 4AH