Candidate Privacy Policy
CANDIDATE PRIVACY NOTICE FORM
With this notice, as required by current legislation on the protection of personal data (Art. 13 of the General Data Protection Regulation, hereinafter also GDPR), BKT Europe Srl (hereinafter also the "Data Controller" or "Company") provides job seekers ("data subjects") with information relating to the processing of their data.
WHO IS THE CONTROLLER AND HOW TO CONTACT THEM
The Data Controller is BKT Europe Srl, in the person of its pro tempore legal representative, with registered office in Viale Bianca Maria 25, 20122 Milan, and operational headquarters in Viale della Repubblica 133, 20831 Seregno (MB), VAT number 05404270968. The Company can be contacted through the email address [email protected]
WHAT DATA IS PROCESSED
The data to be processed is identification and resume data provided by the data subject using the form on the website and the file upload system that is made available. The collection will only cover common data. Therefore, the candidate must not indicate sensitive personal data – such as data suitable for revealing racial and ethnic origin, religious, philosophical or other beliefs, political opinions, membership in parties, trade unions, associations or organizations of a religious, philosophical, political or trade union nature, as well as personal data suitable for revealing state of health and sex life – which, if provided, will be in any case deleted.
WHAT ARE THE PURPOSES AND LEGAL BASES OF PROCESSING?
The data provided by the data subject is processed only for the purpose of evaluating the application.
More specifically, the data is used to:
examine the data subject's application form;
proceed with the verification of hiring conditions and/or the start of a collaboration.
The legal basis for the processing of the data that is collected is the execution of pre-contractual measures, preparatory to the establishment of employment or a working relationship.
Should it be necessary, the data may also be used given the Controller's legitimate interest in undertaking defensive initiatives or enforcing or defending a right in court.
WHO CAN SEE THE DATA?
The data will be processed by employees of the Controller who are authorized to process it.
The data may be known by theParent Company based in India as an independent data controller in view of the legitimate interest of the data controller to collaborate with the other companies of the group in the case of open positions and the advantage that the data subject can derive from the contact aimed at evaluating the proposed application.
The data can be seen by the competent Authorities in cases of specific requests which the Controller is required by law to comply with, by consultants or by companies which provide IT supply and assistance services, by the Parent company for the email service, by the provider used to manage the form and by consultants to manage disputes and for legal assistance in the case of any disputes which make their involvement necessary.
Please note that some of the indicated subjects act as data processors and that communication to those who operate as independent controllers is carried out since required by legal obligations or is necessary to fulfil the obligations arising from the contractual relationship or the legitimate interest of the Controller in maintaining the security of the IT systems with maintenance work by competent personnel and in adopting defensive initiatives through legal consultants.
The data subject may request a detailed list of data recipients from the Data Controller, to the extent to which they can be identified specifically.
Communication is in any case limited to the sole categories of data the transmission of which is necessary to undertake the activities and purposes pursued.
HOW ARE DATA MANAGED?
The data collected is processed with IT instruments and on paper, in compliance with the security obligations prescribed by the law in force to prevent the loss of data, illegal or incorrect use and unauthorized access.
Storage period
The data shall be retained by the Data Controller for the time necessary to fulfill the requirements for candidate selection and evaluation and, in any event, no longer than one year from its collection, unless an employment and/or working relationship is established.
There is no prejudice to any defensive needs for which the data can be kept also beyond the indicated deadlines.
Transferring data abroad
The data will be transferred outside the European Union and the European Economic Area (India) in the absence of adequacy decisions from the EU Commission, but the transfer will be assisted by appropriate safeguards; In particular, standard contractual clauses will be used with additional contractual measures.
WHAT HAPPENS IF THE DATA IS NOT PROVIDED?
The provision of data is optional and is left to the will of the candidate who decides to submit his/her CV and application. Failure to provide the data will make it impossible to verify the conditions for recruitment and/or the start of a working relationship and, therefore, the possible establishment of a relationship with the Data Controller.
WHAT ARE THE DATA SUBJECT'S RIGHTS?
The law recognizes the data subject's right to ask the Processing Controller for access to the personal data and its rectification or cancellation or limitation of the processing regarding them or to object to its processing, as well as the right to data portability.
The data subject may assert their rights at any time, without formalities, by contacting the Processing Controller by email at [email protected].
Details are provided below of the rights recognized by the applicable law on the protection of personal data.
The right of access, i.e. the right to obtain from the processing controller the confirmation that data processing is or is not taking place which regards them and, if so, to obtain access to personal data and to the following information: a) the purposes of the processing; b) the categories of personal data concerned; c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations; d) where possible, the envisaged period for storing the personal data, or, if not possible, the criteria used to determine such period; e) the existence of the right to request from the Controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject, or to object to such processing; f) the right to lodge a complaint with a supervisory authority; g) where the personal data are not collected from the Data Subject, any available information as to their source; h) the existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the Data Subject. Where personal data are transferred to a third country or to an international organization, the Data Subject will have the right to be informed of the appropriate safeguards in place relating to the transfer.
The right of rectification, i.e. the right to obtain from the processing controller the rectification of inexact personal data regarding them without unjustified delay. Taking account of the purposes of processing, the Data Subject has the right to make any incomplete personal data complete, also by providing an additional statement.
The right to erasure (right to be forgotten), i.e., the right to obtain from the controller the erasure of personal data concerning him or her without undue delay where: a) the personal data are no longer required for the purposes for which they were collected or otherwise processed; b) the Data Subject withdraws the consent on which the processing is based, and where there is no other legal ground for processing; c) the Data Subject objects to processing and there are no overriding legitimate grounds for processing, or the Data Subject objects to processing; d) the personal data have been unlawfully processed; e) the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the Controller is subject; f) the personal data have been collected in relation to the offer of information society services to minors. The request for erasure cannot, however, be accepted if processing is required: a) to exercise the right to freedom of expression and information; b) to fulfill a legal obligation which requires processing as envisaged by the law of the European Union or of the Member State to which the Controller is subject or to execute a task undertaken in the public interest or in the exercise of public powers with which the Controller is invested; c) for reasons of public interest in the public health sector; d) for the purposes of archiving in the public interest, scientific or historic research or statistical purposes, to the extent to which cancellation risks making impossible or seriously compromising the task of achieving the goals of such processing; or e) for verifying, exercising, or defending a right in the courts.
The right to restriction of processing, i.e., the right to obtain from the controller restriction of processing where one of the following applies: a) the accuracy of the personal data is contested by the Data Subject, for the period required by the Controller to verify the accuracy of the personal data; b) processing is unlawful, and the Data Subject opposes the erasure of the personal data and requests the restriction of their use instead; c) the Controller no longer needs the personal data for the purposes of processing, but they are required by the Data Subject for the establishment, exercise, or defense of legal claims; d) the Data Subject has objected to processing because it is required for the performance of a task carried out in the public interest or in connection with the exercise of official authority vested in the Controller or for pursuing the legitimate interests of the Controller or a third party, pending verification as to whether the legitimate grounds of the Controller override those of the Data Subject.
The right to data portability, i.e., the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where the processing is based on consent or a contract, and the processing is carried out by automated means. This right will not affect the right to cancellation.
Please note, in particular, the right to object, i.e., the data subject's right to object at any time, on grounds relating to their particular situation, to the processing of their personal data as required for the performance of a task carried out in the public interest or in connection with the exercise of the official authority vested in the controller or for the furtherance of the legitimate interests of the Data Controller or of a third party. Should the personal data be processed for direct marketing purposes, the Data Subject has the right to oppose at any time the processing of the personal data regarding them undertaken for these purposes, including profiling, to the extent this is connected to such direct marketing.
Based on the provisions of art. 22 of the GDPR, then, the data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, unless the decision a) is necessary for the conclusion or signing of a contract between the data subject and a processing controller; b) is authorized by Union or Member State law that the processing controller must observe, which also specifies appropriate measures to protect the rights, freedoms and legitimate interests of the data subject; c) is based on the explicit consent of the data subject.
The data subject is then informed that, if they believe that the processing of their personal data is in violation of the provisions of the GDPR, they have the right to lodge a complaint with the Supervisory Authority (Article 77 of the Regulation) or to take legal action (Article 79 of the Regulation).
This privacy policy was last updated on 20 February 2026