- Data controller
CodersRank is the data controller, incorporated under the laws of Hungary with the following data:
registration number: 09-10-000582;
registered by: Company Registry Court of Debrecen Regional Court;
seat: 4028 Debrecen, Kassai út 129;
tax number: 26313986-2-09;
represented by: Károly Paczári managing director;
contact data: email@example.com
CodersRank makes efforts to ensure appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures. CodersRank Zrt.’s employees agree to protect the personal data obtained in the course of providing the services and in the course of their work.
- Data processors and data transfer
CodersRank works with the following data processors:
– Google Cloud;
– Microsoft Azure;
– SendGrid (https://sendgrid.com/);
– MailChimp (https://mailchimp.com/);
– Heap Analytics (https://heap.io/)
CodersRank shall not transfer any data to any third person out of the scope of the data processors above except when it is based on the Data Subject’s consent or provision of law.
- The categories of personal data processed; purpose and legal basis of data processing
In order to use the services, the Data Subject shall register on the Website by providing some mandatory personal data as follows: name, email address, GitHub user name, location, job-seeker status; in case of companies the name and email address of the contact persons.
These personal data are necessary for providing the service of the Website. The main aim of the service is to connect the Data Subject and any companies, who recruit professionals and use the service.
CodersRank carries out an assessment and evaluation process on the basis of the private codes and professional skills of the Data Subject. this process focuses on the professional experience and background of the Data Subject, and the result of the process (points and graphs) shall be made by automated means. Such profiling is necessary for the efficient performance of the service provided by CodersRank on the Website, and it is based on the explicit consent (by ticking a checkbox on the registration form) of the Data Subject. For the purpose of profiling CodersRank processes all data provided by the Data Subject during the registration and by using the Profile.
Legal basis: the Data Subject has given consent to the processing of his personal data on the basis of point a) of Section 1 in Article 6 of GDPR.
Following registration, the system creates the Profile of the Data Subject, containing the following data:
- Data Subject’s data provided during and after registration,
- result of the assessment and evaluation process
In the course of registration or any time during the use of the service, the Data Subject shall set his/her profile as private or public.
- Public profile: this profile is available to the companies who recruit professionals and use the service of CodersRank.
- Private profile: this profile is not available to the companies who recruit professionals and use the service of CodersRank
- Additional data
In the course of registration or using the Profile, the Data Subject may upload his professional profile or create an account by adding more personal data as follows: photo, social media links (LinkedIn, GitHub, GitLab, StackOverflow, Twitter, personal website), date of birth, sex, telephone number, languages, expected salary, CV, preference of place of work (region, size), work permit for the territory of EU, technologies applied for work, professional experience, previous places of work, educations, certificates, job-seeker status. The information provided in this way will be also included in the automated profiling process.
Legal basis: the Data Subject has given consent to the processing of his personal data on the basis of point a) of Section 1 in Article 6 of GDPR.
- Newsletter and communication
The Data Subject may provide some personal data in order to be informed on the services or operation of CodersRank, as follows: name, email address, telephone number (Data Subject shall provide one or both of the contact data).
The Data Subject shall clearly agree to accept the data processing related to newsletters or any other marketing purposes (by ticking a checkbox).
Legal basis: the Data Subject has given consent to the processing of his personal data s on the basis of point a) of Section 1 in Article 6 of GDPR.
- Statistical purposes
- Storing period
CodersRank shall store the personal data for no longer than is necessary for the purposes for which the personal data are processed.
If the legal basis of the data processing is the consent of the Data Subject, CodersRank shall process the personal data until the date of withdrawal of consent.
The profile of the Data Subject may be cancelled by him at any time through the Website, without any prior notification. In case of cancellation all data and information provided in the profile shall be cancelled and cannot be restored.
- Data controllers (companies) entitled to access the public profile (data transfer)
The public profile is made available by CodersRank to the companies who use the service of the Website for their own recruiting purpose. These companies can view the Data subject’ public profile and use the contact data in it to get in contact with the certain Data Subject.
Companies using the service of CodersRank can search among Data Subjects having a public profile using a number of search parameters.
- Rights of the Data Subject
- Right of access: the Data Subject shall have the right to obtain from CodersRank confirmation as to whether or not personal data concerning him are being processed, and, where that is the case, access to the personal data and other information according to GDPR. CodersRank shall provide a copy of the personal data undergoing processing.
- Right to rectification: the Data Subject shall have the right to obtain from CodersRank without undue delay the rectification or completion of inaccurate personal data concerning him.
- Right to erasure: the Data Subject shall have the right to obtain from CodersRank the erasure of personal data concerning him without undue delay and CodersRank shall have the obligation to erase personal data without undue delay, according to GDPR.
- Right to restriction of processing: the Data Subject shall have the right to obtain from CodersRank restriction of processing, according to GDPR.
- Right to data portability: the Data Subject shall have the right to receive the personal data concerning him, which he has provided to CodersRank, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from CodersRank to which the personal data have been provided, according to GDPR.
- Right to object: the Data Subject shall have the right to object, on grounds relating to his particular situation, at any time to processing of personal data concerning him which is based on point (e) or (f) of Article 6(1) of GDPR, including profiling based on those provisions. Where personal data are processed for direct marketing purposes, the Data Subject shall have the right to object at any time to processing of personal data concerning him for such marketing, which includes profiling to the extent that it is related to such direct marketing. In the event of the Data Subject’s objection, CodersRank shall abandon the processing of the personal data unless it proves that the data processing is justified by compelling legitimate grounds which override the Data Subject’s interests, rights and freedoms, or are necessary for the establishment, exercise or defence of legal claims.
- Rights regarding profiling: In the case of profiling based on automated data processing by CodersRank, the Data Subject has the right to:
- request human intervention from CodersRank,
- express his/her views on the profiling that concerns him or her,
- file an objection against the data controller’s decision based on automated data processing related to profiling.
- Requests of the data subject
CodersRank shall provide information to the Data Subject on action taken on a request on the rights of the Data Subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. CodersRank shall inform the Data Subject of any such extension within one month of receipt of the request, together with the reasons for the delay. Where the Data Subject makes the request by electronic form means, the information shall be provided by electronic means where possible, unless otherwise requested by the Data Subject.
If CodersRank does not take action on the request of the Data Subject, CodersRank shall inform the Data Subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
Information and any communication and any actions shall be provided free of charge. Where requests from the Data Subject are manifestly unfounded or excessive, in particular because of their repetitive character, CodersRank may either (i) charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested, or (ii) refuse to act on the request. CodersRank shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.
The Data Subject shall have the right to withdraw his consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
- Data security
CodersRank undertakes to ensure the security of data and takes all technical and organisational measures, puts into place the procedural rules that ensure the protection of all collected, stored and processed data, as well as preventing the destruction, unlawful use and unlawful alteration of data. CodersRank also undertakes to call upon each third party to whom data are transferred or transmitted without the Data Subjects’ consent to comply with the data security requirements.
CodersRank shall ensure that no unauthorised persons may access, disclose, transfer, modify or erase the processed data. The processed data may be accessed only by CodersRank and its employees, as well as the data processor employed by them, and CodersRank shall not transfer the data to any third party not authorised to have access to them.
CodersRank shall take every possible effort to ensure data are not accidentally damaged or destroyed. CodersRank requires all its employees taking part in data processing activities to assume the above obligations.
The Data Subject acknowledges and accepts that in case their personal data are provided on the website, full data protection cannot be guaranteed on the internet despite the fact that CodersRank has up-to-date security equipment to prevent any unauthorised access to data or the detection thereof. If data are accessed without authorisation or data are obtained despite our efforts, CodersRank shall not be held liable for the obtaining of data in such a manner or for any unauthorised access to them, or for any damage occurring at the Data Subject as a consequence thereof. In addition, the Data Subject may also supply personal data to third parties who may use them for unlawful purposes and in an unlawful manner.
- Managing and reporting of personal data breaches
All incidents are considered personal data breaches which result in the unauthorised processing or controlling of personal data, in particular unauthorised or accidental access, alteration, disclosure, erasure, loss or destruction of personal data processed, transferred, stored or processed by CodersRank, or in its accidental destruction or damage.
CodersRank is obliged to notify the data protection authority of the personal data breach without undue delay, but no later than 72 hours after the detection of the personal data breach, unless, CodersRank can prove that the personal data breach is unlikely to pose a risk to the rights and freedoms of natural persons. Where such notification cannot be achieved within 72 hours, the reasons for the delay should accompany the notification and information may be provided in phases without undue further delay. The notification to data protection authority includes at least the following information:
- the nature of the personal data breach, the number and categories of data subjects and personal data;
- name and contact information of the data controller;
- the likely consequences arising from the personal data breach;
- the measures taken or planned to manage, rectify or remedy the personal data breach.
CodersRank shall inform the data subjects about the personal data breach via the CodersRank’s website within 72 hours after having become aware of the data breach. The information shall include at least the data specified in this Section.
CodersRank keeps a record of each personal data breach for controlling the measures taken in relation to the occurring incidents and for providing information to the data subjects. The records contain the following data:
- the scope of the affected personal data;
- the range and number of data subjects;
- the date and time of the personal data breach;
- the circumstances and effects of the personal data breach;
- the measures taken for the prevention of the personal data breach.
CodersRank keeps the data contained in the record for 5 years from the detection of a personal data breach.
- Supervisory authority
The Data Subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his habitual residence, place of work or place of the alleged infringement if the Data Subject considers that the processing of personal data relating to him infringes the GDPR. The Data Subject can file his complaint to the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság), with the contact address below:
Address: 1055 Budapest, Falk Miksa utca 9-11.
Postal address: 1363 Budapest, Pf.: 9.
- Judicial remedy
The Data Subject shall have the right to an effective judicial remedy at the relevant court where he considers that his rights under GDPR have been infringed as a result of the processing of his personal data in non-compliance with GDPR.