
provider or payment service provider). The Controller uses only processors that provide sufficient
guarantees of implementing appropriate technical and organisational measures so that processing meets
the requirements of the GDPR Regulation and protects the rights of data subjects.
2. Personal data may be transferred by the Controller to a third country. In such a case, the Controller
ensures that the transfer will be made to a country providing an adequate level of protection in
accordance with the GDPR Regulation, or, in the case of other countries, on the basis of standard data
protection clauses. The Controller ensures that the data subject may obtain a copy of their data. The
Controller transfers collected personal data only where and to the extent necessary to achieve a specific
processing purpose consistent with this Privacy Policy.
3. The Controller does not transfer data in every case or to all recipients or categories of recipients indicated
in this Privacy Policy. The Controller transfers data only where this is necessary to achieve a specific
purpose of personal data processing and only to the extent necessary to achieve that purpose.
4. Personal data of Service Recipients of the Web Application may be transferred to the following recipients
or categories of recipients:
a. entities handling electronic or card payments – where a Service Recipient purchases paid
Electronic Services in the Web Application and uses an electronic or card payment, the Controller
discloses the collected personal data of the Service Recipient to the selected entity handling such
payments in the Application on behalf of the Controller, to the extent necessary to process the
payment made by the Service Recipient.
b. service providers supplying the Controller with technical, IT and organisational solutions enabling
the Controller to conduct its business, including operating the Web Application and providing
Electronic Services through it (in particular, providers of computer software used to operate the
Web Application, email and hosting providers, and providers of business-management software
and technical support for the Controller) – the Controller discloses the collected personal data of
the Service Recipient to the selected provider acting on its behalf only where and to the extent
necessary to achieve a specific processing purpose consistent with this Privacy Policy.
c. providers of accounting, legal and advisory services supporting the Controller in accounting, legal
or advisory matters (in particular an accounting office, law firm or debt collection company) – the
Controller discloses the collected personal data of the Service Recipient to the selected provider
acting on its behalf only where and to the extent necessary to achieve a specific processing
purpose consistent with this Privacy Policy.
d. other Service Recipients of the Application – to the extent resulting from the Profile visibility
level selected by the Service Recipient (privacy settings) or from the functionality of the
Application, in particular the ratings and evaluation system, ranking system, private messages
and chat. In such a case, the Service Recipient (Employer or Candidate) becomes a controller,
independent of the Controller, of the personal data obtained from other Service Recipients and is
required to comply independently with the resulting legal obligations;
e. third parties without an Account in the Application – only where a Service Recipient (Candidate)
has selected a public visibility level for their Profile, or an Employer has shared a link to the
Candidate’s Profile with third parties and the Candidate has selected a setting allowing access to
the Profile without logging in. The scope of the data disclosed is limited to content entered by the
Candidate in their Profile;
f. public authorities and law-enforcement authorities – data may be disclosed only in cases
provided for by generally applicable law or on the basis of decisions of competent authorities for
the purposes of proceedings conducted by them.
5) PROFILING IN THE WEB APPLICATION
1. The GDPR Regulation requires the Controller to provide information about automated decision-making,
including profiling referred to in Article 22(1) and (4) of the GDPR Regulation, and – at least in those cases
– meaningful information about the logic involved, as well as the significance and envisaged consequences
of such processing for the data subject. With this in mind, the Controller provides information on possible
profiling in this section of the Privacy Policy.