COMPANY PRIVACY NOTICE
Company Name: Propono (‘the Company’)
Company Contact Details: Sharon McDonagh (Data Protection Lead) – admin@propono.co.uk
Date Updated: 20th January 2024
This Privacy Policy governs the manner in which Propono, a talent acquisition license subscription platform, collects, uses, maintains, and discloses information collected from users (hereinafter referred to as "you" or "users") of the Propono platform (hereinafter referred to as the "Platform"). This Privacy Policy applies to the Platform and all products and services offered by Propono.
i. Data Security
Propono is hosted by a Tier 1 ISO (International Organization for Standardization) certified provider that adheres to industry-leading security standards. The hosting provider maintains a long list of internationally recognized certifications and accreditations, including ISO 27001 for information security, ISO 9001 for quality management systems, ISO 27017 for cloud security, ISO 27018 for cloud privacy, SOC 1, SOC 2, and SOC 3, PCI Level 1, The Crown Commercial Service (CCS), and multiple Microsoft accreditations. Regular security and performance tests are conducted to ensure the smooth operation of the service.
Data Storage:
Any information collected and processed by Propono is stored in the following locations:
- On our secure CRM (Chameleoni)
- On our portal, which showcases an anonymised, pertinent snapshot of your skills and experience – this snapshot contains no identifiable information and is accessed by clients who possess a unique username and password. You can withdraw your information from the talent portal at any point by emailing admin@propono.co.uk
- In our emails (which can be accessed via our laptops and mobile phones only)
- In files on our server (which can be accessed via our laptops only)
- Our emails and files are securely stored on a server hosted by Microsoft Office 365, which follows ISO 27001, 27018, and 27017 standards for information security. Access to the server is limited to authorized Propono staff members, each of whom possesses a unique username and password.
- To ensure further protection, the following measures are implemented:
- All laptops used by Propono staff members are password protected.
- An additional username and password are required to access emails and files on the laptops.
- All mobile phones used by Propono staff members are password protected.
- An additional username and password are required to access emails on the mobile phones.
Our website:
You can send us your personal information via the ‘Contact Us’ page on our website:
- Cookies: www.propono.co.uk (Our site) does not use cookies
- Our website contains links to Third Party sites. We recommend reading the privacy statements upon visiting these websites as we are not responsible for the information that is submitted/collected by these third parties.
CRM Security:
Our Customer Relationship Management (CRM) system, Chameleoni, is hosted by a Tier 1 ISO certified provider that maintains industry-leading security measures. The hosting provider possesses internationally recognized certifications and accreditations, including ISO 27001 for information security, ISO 9001 for quality management systems, ISO 27017 for cloud security, ISO 27018 for cloud privacy, SOC 1, SOC 2, and SOC 3, PCI Level 1, The Crown Commercial Service (CCS), and multiple Microsoft accreditations. Regular security and performance tests are conducted to ensure the smooth operation of the service.
ii. General Data Protection Regulation (GDPR) Compliance
- Propono is committed to protecting your personal data and complying with the requirements of the General Data Protection Regulation (GDPR). We ensure that all personal data collected and processed through the Platform is done so lawfully, transparently, and securely.
- By using the Propono Platform and providing us with your personal information, you acknowledge and consent to the collection, use, and disclosure of your information as described in this Privacy Policy.
- Please note that we may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. We encourage you to periodically review this Privacy Policy to stay informed about how we collect, use, and protect your information.
- Propono employs strict access controls and limitations to ensure that only authorized personnel have access to user data.
- In the event of a data breach, Propono has procedures in place to promptly respond, mitigate the impact, and notify affected users as required by applicable laws and regulations.
- Propono retains user data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy or as required by law.
- Users have the right to access, update, and delete their personal information stored on the Propono platform.
- Please be aware that you have the following data protection rights - users can exercise these rights by contacting Propono's customer support at admin@propono.co.uk
- The right to be informed about the personal data the Company processes on you;
- The right of access to the personal data the Company processes on you;
- The right to rectification of your personal data;
- The right to erasure of your personal data in certain circumstances;
- The right to restrict processing of your personal data;
- The right to data portability in certain circumstances;
- The right to object to the processing of your personal data that was based on a public or legitimate interest;
- The right not to be subjected to automated decision making and profiling; and
- The right to withdraw consent at any time.
- Propono does not sell, trade, or rent user information to third parties for marketing purposes.
- Propono may share user information with trusted third-party service providers who assist us in operating our business, conducting activities on our behalf, or providing services to users. These third-party providers are bound by strict confidentiality agreements and are only authorized to use the information for the specified purposes.
- Propono may disclose user information if required by law, regulation, legal process, or governmental request.
- The Propono platform may contain links to third-party websites or services. Propono is not responsible for the privacy practices or content of these third-party sites. We encourage users to read the privacy policies of any third-party sites they visit.
- Propono takes reasonable steps to protect the privacy and security of user information. However, no data transmission over the internet or electronic storage system can be guaranteed to be 100% secure. Therefore, while we strive to use commercially acceptable means to protect user information, we cannot guarantee its absolute security.
- If users have any questions, concerns, or complaints regarding their privacy or this Privacy Policy, they can contact Propono's privacy officer at admin@propono.co.uk
iii. Legal Basis for Processing Personal Information
Propono relies on the legal basis of legitimate interest for the processing of personal information. We consider it necessary to process personal data to provide our talent acquisition services and facilitate work finding opportunities for our users. This includes matching job seekers with relevant employment opportunities, maintaining our talent portal, and facilitating communication between users and potential employers.
We conduct a careful assessment to ensure that our legitimate interests are not overridden by the rights and freedoms of individuals whose data we process. We strive to strike a balance between our legitimate interests and the privacy rights of our users.
Propono respects and upholds the privacy rights of individuals and ensures that the processing of personal information is fair, transparent, and conducted in accordance with applicable data protection laws and regulations.
iv. Data Retention
Propono retains user data only for as long as necessary to fulfill the purposes for which it was collected and processed or as required by applicable laws and regulations. The specific retention periods may vary depending on the nature of the information and the legal requirements.
Regarding the storage locations mentioned:
- On our secure CRM (Chameleoni): User data stored on our CRM is retained for as long as you maintain an active account with Propono. If you decide to close your account, your data will be securely deleted within a reasonable timeframe, unless retention is required by law or for legitimate business purposes.
- On our portal (talent portal): The snapshot of your skills and experience showcased on the talent portal is anonymized and does not contain any identifiable information. You have the right to request the withdrawal of your information from the talent portal at any time by sending an email to admin@propono.co.uk. Upon receipt of such a request, we will promptly remove the relevant snapshot from the talent portal.
- In our emails: Emails containing user data are stored on our server via Microsoft Office 365. The retention period for emails may vary based on the specific email content and legal requirements. We regularly review and delete unnecessary emails to ensure that personal data is not retained longer than necessary.
- In files on our server: Files containing user data are stored on our server and can only be accessed via our laptops. The retention period for files is determined by the nature of the information and legal requirements. We implement data management practices to regularly review and securely delete unnecessary files.
It's important to note that while we take reasonable measures to protect your data, Propono cannot guarantee the absolute security of any information transmitted or stored. Users are encouraged to take appropriate steps to safeguard their personal information and maintain the confidentiality of their account credentials.
v. Privacy Policy Updates
At Propono, we regularly review and update our privacy policy to ensure it accurately reflects our data handling practices and any changes in applicable laws and regulations. We strive to provide you with the most recent and up-to-date information regarding the collection, use, and protection of your personal data.
To stay informed about any updates or modifications to our privacy policy, we encourage you to periodically visit our website at http://www.propono.co.uk/privacy-policy. The most recent version of the privacy policy will be available on the website, allowing you to review any changes that may affect your rights and obligations.
By continuing to use the Propono platform and our services after any modifications to this privacy policy, you acknowledge and agree to be bound by the updated terms.
If you have any questions or concerns about our privacy policy or the updates made to it, please contact our privacy officer at admin@propono.co.uk