Privacy notice on the processing of personal data and your rights

under Art. 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC

(the „GDPR„)

In case you are providing your personal data, we as a data controller:

Spaceflow s.r.o., with its registered seat at: Pernerova 676/51, Karlín, 186 00 Praha 8, ID: 05184142, registered by the Commercial Register maintained by the Municipal Court in Prague, File No. C 259630,

would like to inform you about the processing of your personal data and of your rights related to the said processing.

All terms used in Terms of use of the Application [„Terms„; https://spaceflow.io/en/terms], starting with a capital letter, have the same meaning here, in this Privacy notice. For cookies we use a cookie policy on our web pages which pops up.

What are our purpose and legitimate interests for the processing of your personal data?

  1. Selection of potential employees and talents.
  2. Mutual communication.
  3. Promotion of our events and our products.
  4. Targeted communication in social media and product promotion.
  5. Targeted communication through our website and product promotion.
  6. Cooperation with our business partners.

Description of our purpose and legitimate interests:

  1. In case of a vacant position at Spaceflow, we look for the best fit to fill this vacancy. When doing that, we collect the CVs from the applicants directly or from the third persons recommending the potential applicant. After reviewing the CVs of the applicants, we invite them for personal interviews after which we send the follow-up information. In case there is no vacant position at the time or if the applicant has not been successful at the particular job opening, we may, upon consent, store the CVs of these persons to contact them in the future regarding the job opening.
  2. Our philosophy is to be open and transparent at all times. This includes being open to communication from any person interested in Spaceflow and the Application. Additionally, we have also published email, so you can contact them at any time with any question related to our Application and business you may have. However, to ensure such effective, flawless and clear communication, we process some of your personal data (including unstructured personal information – contained in email correspondence). If you send us your personal data based on a web-form on our pages, the processing is wider, therefore based on a consent.
  3. Furthermore, we may process your personal data by taking the photographs and audio-visual recordings, name and surname, email contact which are used for the purpose and legitimate interests of promotion of our events and services (e.g. via our newsletter), and product news with respect to the Application and to help us improve our brand and goodwill by providing you with our newsletters and follow-up marketing materials related to our events and publishing the photographs (where you can appear) and audio-visual recordings on our social media profiles such as LinkedIn and Facebook and via other channels such as our website. In the case you subscribed to our newsletter and you are not our current/past customer, we send you our marketing materials under consent granted by you.
  4. We may also use social media marketing tools such as LinkedIn to process your personal data that you voluntarily submit to us, to the extent: name, surname, position in the company, email contact, for the purpose of promoting under C. or for further contact to support the sale of our products, and online tools like Google Tag Manager, LinkedIn Insight Tag and Facebook Pixel and SDK (social marketing media – like Custom Audiences and Lookalike Audiences).
  5. In order to develop our business, we are looking for new prospective clients, in order to do so – in addition to the points above, our website also uses a third-party service (such as LeadFeeder) to identify potential business partners and collect contact personal data to promote the sale of our products.
  6. If we cooperate with you as our business partner, we need both your personal information to enter into an agreement with you and be with you in a functional business relationship. These personal data will appear on a particular contract and may appear on tax documents, invoices, business cards, in an unstructured form in email (internal) communication and in our CRM systems.
  1. If you send us your CV regarding the specific vacant position, we process your personal data on the basis of the performance of a contractual relationship and your request prior to entering into a contract under Article 6 (1) (b) of GDPR (in case of failure to provide us with the personal data, we cannot enter into a contract with you). If you want us to keep your CV after the recruitment process or without applying for any particular position, we process your personal data on the basis of a consent under Article 6 (1) (a) of GDPR.
  2. If you contact us or any particular employee via email, we process your personal data with respect to such replies on the basis of legitimate interests under Article 6 (1) (f) of GDPR. If you contact us through a web-form on our webpage, we process your personal data for purposes of reply and further send marketing material on the basis of a consent under Article 6 (1) (a) of GDPR.
  3. In case of promoting our events and services provided by us, we process your personal data on the basis of the legitimate interests under Article 6 (1) (f) of GDPR and non-customers based on consent under Article  6 (1) (a) of the GDPR.
  4. In case you send us a filled form with your personal data, we process your personal data on the basis of the legitimate interests under Article 6 (1) (f) of GDPR, if we process your data from Facebook Pixel or Google Analytics is processed on the basis of legitimate interests – Art. 6 (1) (f) of GDPR, with respect to the Custom Audiences and LookAlike Audiences on the basis of consent under Article 6 (1) (a) of GDPR.
  5. In the case you visit our website, we process your personal data on the basis of the legitimate interests under Article 6 (1) (f) of GDPR.
  6. In case of contractual relationship and your request prior to entering into a contract, we process your personal data on the basis of under Article 6 (1) (b) of GDPR (in case of failure to provide us with your personal data, we cannot enter into a contract with you).

What kind of personal data do we process?

  1. Personal data included in the CV (such as name, surname, date of birth, address, email, phone number etc.).
  2. Name, surname, email address and phone number, in case of a web-form it is: email, name, surname, phone number, location.
  3. Name, surname, email address, photograph or/and audio-visual image of yourself.
  4. Name, surname, email address, firm position, business name containing personal name. Information on the data processed in the context of Facebook Insights can be found here and for the purposes of Custom Audiences and creation of LookAlike Audiences can be found here. Facebook: On the use of cookies by Facebook you can find here. You can find general information on how and which data Facebook processes data you can find hereLinkedIn Insight Tag: the data processed are: IP address information, devices, browser properties, timestamp, and events (e.g., page views). Google Analytics are anonymized as described below.
  5. Name, surname, email address, address, details of activities related to a natural person, and web analytics.
  6. Name, middle name, surname, ID No., Tax ID No., registered office, email address and phone number, business name containing your personal name, job title, source of the contact, business category and market.

How long do we store your personal data?

  1. In case of applying for a particular vacant position, we store your personal data until the end of the recruitment process. If you give us your consent to store your CV for future vacant positions, we store it for 3 years.
  2. If you contact us or any employee via email, we store your personal data until you unsubscribe from our contact database, or in case you send us your personal data through the web-form until you withdraw the granted consent.
  3. We store your personal data during the time strictly necessary to achieve the given purpose and for non-customers based on consent for 10 years.
  4. We store your personal data during the time strictly necessary to achieve the given purpose. 
  5. We store your personal data during the time strictly necessary to achieve the given purpose.
  6. We store your personal data for the duration of the contractual relationship and till lapse of tax duty period and time limitation period for defending claims.

As soon as we no longer need your personal data for the processing purposes for which the personal data have been collected, we will delete them unless the statute-barred period applies. Certain details and correspondence may be retained until the time limit for claims, in respect of the pre-contractual or contractual relationship, has expired or in order to comply with regulatory requirements regarding the retention of such personal data.

More about Tags online marketing tools under letter D.

Linkedin Insight Tag: This tag enables LinkedIn ads to our site visitors. The LinkedIn browser cookie is stored in a browser until cookies are deleted or the cookie expires (based on a rolling six-month expiration from the last time your browser loaded the Insight tag). You may also block or delete cookies. LinkedIn does not share personal data with us, it only provides summary reports about the website target group and ad performance. LinkedIn also provides a retargeting service for a website that allows us to use this data to show targeted adverts outside our website without identifying the member. For further information, please go here.

Facebook Pixel and Facebook direct marketing: This technology enables Facebook to identify visitors of our website as a target group for the display of ads (“Facebook Ads”). Accordingly, we use Facebook Pixel to display the Facebook Ads placed by us only to such Facebook users, who have actually shown an interest in our website or who have certain attributes (e.g. interests in certain topics or products as identified based on the visited webpages) that we transmit to Facebook (“Custom Audiences” and for further “Lookalike Audiences”). 

By means of the Facebook Pixel, we would also like to ensure that our Facebook Ads match your potential interests and do not bother you. We can also track the effectiveness of the Facebook Ads by means of Facebook Pixel for purposes of statistics and market research because we can see whether you have been redirected to our website after clicking on a Facebook Ad (“Conversion”). Facebook Pixel is used when our website is retrieved directly from Facebook and it can store so-called cookies on your device. If you sign in to Facebook afterwards or visit Facebook while signed in there, the visit of our online offer will be logged in your profile. 

The data gathered about you are anonymous to us, meaning they do not permit us to identify the users. However, the data is stored and processed by Facebook, so that it is possible to link them to the respective user profile and Facebook can use the data for its own market research and advertising purposes. If we should transmit data to Facebook for purposes of reconciliation, these will be encrypted locally in the browser and then be sent to Facebook via a secure https connection. This is done solely for the purpose of creating a comparison to the data equally encrypted by Facebook. How Facebook Pixel is used for advertising measures can be found out here. You can find more information on the data processing by Facebook here.

Based on Custom Audience we can create within Facebook the Lookalike Audiences and advertise our Product to the Lookalike Audiences which are not known to us. Facebook is the only actor who knows who the Lookalike Audience is and is capable of identifying them. Therefore we are in no position of controller to the Lookalike Audience.

Google Analytics: The information generated by the cookie about your use of our website (e.g. IP address, accesses, navigation flow, duration of the visit, browser and end devices used, language and country) will be transmitted to and stored by Google on its servers in the USA. 

p;

By activation of the IP anonymisation on this website („_anonymizeIp()“ function), your identified IP address, however, will be truncated within Member States of the European Union or in other signatory states of the Treaty on the European Economic Zone. In exceptional cases the complete IP address will only be transmitted into a server of Google in the USA and it will be truncated there. Google will use this information to analyse your use of our website, to compile reports about your website activities for the website operators, and to perform additional services relating to the use of the website and of the internet. Google may also transfer this information to third parties if applicable, provided that such is mandated by law or to the extent, as third parties process these data on account of Google.

By means of browser plug-ins, you can prevent Google from recording the data relating to your use that is generated by cookies. To do so, you can use the following browsers plug-in. If you use the internet with your mobile end device, you can prevent cookies from being recorded – similar as on a desktop device – by clicking the button below for deactivating Google Analytics.

Google Marketing Platform: For the purposes of the Google Marketing Services, your data are pseudonymized for processing. Google does not store and process, for example, your names and email addresses but resorts to cookie-related processing of the data within pseudonymous user profiles. This means that, from Google’s perspective, the advertisements are not managed and displayed for a specifically identifiable person, but for the holder of the cookie, regardless of who the holder of the cookie is. This does not apply if you have given Google express consent to process the data without pseudonymization. Your data collected by Google Marketing Services is transmitted to Google and stored on Google servers in the US.

We can use the „Google Tag Manager“ to incorporate and manage Google analytics and marketing services on our website.

You can find more information about the use of data for marketing purposes by Google on the summary page, the data privacy policy of Google can be retrieved here. If you would like to object to interest-based advertising by Google Marketing Services, you can use the opt-out options provided by Google here.

For a specific type of cookies

Hotjar: We use Hotjar to analyze the use of our website and to continuously improve individual functions and offers as well as the user experience. By statistically evaluating user behaviour we can improve our offer and make it more interesting for you as a user. This is also our legitimate interest in the processing of the below data by Hotjar. 

Hotjar uses cookies, i.e. small text files that are stored locally in the cache of your web browser on your terminal device and which enable an analysis of your use of our website, as well as a so-called tracking code. The cookies used by Hotjar are stored on your terminal for different lengths of time, partly only during your visit, partly 365 days. The information collected in this way is transmitted to Hotjar on a server in Ireland and stored there. The tracking code collects the following information:

Terminal-specific data: (The following information can be collected from your terminal device and the browser): IP address of your device (it is collected and stored in an anonymised format); size of the terminal screen; terminal device type (individual terminal identification features) and browser information; geographic location (country only); Preferred language when displaying the web page;
Log data: Our servers automatically record the information generated when using Hotjar. Among others the following data are recorded: referencing domain; pages visited; geographic location (country only); preferred language when displaying the web page; access date and time of the website pages;

Neither Hotjar nor we will ever use this information to identify individual users or to match it with further data on an individual user. For further details, please see Hotjar’s Privacy Policy. In addition, Hotjar uses various third-party services, e.g. Google Analytics and Optimizely. These services may collect data sent by your browser as part of the website request, such as cookies or your OP request. For information on how Google Analytics and Optimizely collect and use your information, please refer to their Privacy Policy. Using Hotjar, you agree to the processing of the data by the third parties in accordance with their privacy policy.

If you do not want to be recorded by Hotjar, you can disable it by setting the DoNotTrack header in your browser. For more information and more about Hotjar’s data processing, please see here.

With whom do we share your personal data?

For a certain reason, we might provide your personal data to personal data recipients, to perform part of our activities through them (meant outsourced activities). Within our business, we use the following categories of personal data recipients:

Google Ireland Limited (Marketing and Remarketing services, Cloud Service Provider, providing platform as services e.g. environment, computing capabilities, for more information see here, the App runs on the Google Cloud Platform and (E-mailing services out of the App and cloud-storage services, e-mailing services for us), service provider terms are listed here.

  • Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, providing social network and various marketing functionalities (Facebook Pixel, Custom Audiences). The data controller for the processing personal data in the context of using Facebook is Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2. To claim your rights as a data subject and if you have questions relating to data protection, please contact Facebook’s data protection officer directly here.
  •  Message Systems, Inc. d/b/a SparkPost, Delaware, US, (E-mail service – Sparkpost, sending the email from the Application), for more information see this. The Application uses the API of the Sparkpost to send: 1) Addressing message, 2) email address of the addressee 3) content of email. Message Systems, Inc. d/b/a SparkPost is certified under the EU-U.S. Privacy Shield Framework.
  • The Rocket Science Group, LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308 USA (Email service Mailchimp, sending from and out of the Application), contractor who provides us with e-mailing services related to the newsletter); service provider terms are listed here.
  • LinkedIn Ireland Unlimited Company, (contact acquisition from social media marketing service), service provider terms are listed here.
  • Liidio Oy / Leadfeeder (collecting contacts from our webpage), service provider terms are listed here.
  • Hotjar Ltd, Level 2, St Julians Business Center, 3, Elia Zammit Street, St Julians STJ 1000, Malta, Europe, (collecting feedback from users), service provider terms are listed here.
  • CRM software, communication software and project management software which may contain unstructured personal data in order to fulfill the purposes stated above.

We also may be obliged to provide your personal data to public authorities, in particular courts and law enforcement agencies (police and prosecutors) only to the extent necessary and within the limits of the law.

From whom do we get the personal data?

We get personal data from you and in order not to be so vague in explanation, by “you” we mean:

  1. Job applicants for a position with us.
  2. Interviewers and potential business partners.
  3. Participants in events we organize or participate in.
  4. Leads and business partners.
  5. Visitors to our website.
  6. Potential and current business partners or customers and contractors.

Do we use automated individual decision-making?

No, we do not use automated individual decision-making.

Do we transfer your personal data to third countries?

Your personal data is processed within the territory of the Czech Republic and other states of the European Union. Your personal data can be processed by a country outside of European Union if this third country has been confirmed by the European Commission as a country with an adequate level of data protection or if other appropriate data protection safeguards exist (for example, binding corporate privacy rules or EU standard data protection clauses).

Other information:

Personal data may also, in justified cases, be subject to use (processing) for the purpose of dealing with legal matters, including the performance of public authority obligations and monitoring for possible legal protection. Personal data may also be archived for a given public interest, as well as for scientific, historical or statistical research.

What are your rights?

Your rights as a data subject are stated below. Please note that the exact conditions to exercise these rights are set out in detail in Chapter III of GDPR, while in a particular circumstance not all rights may be exercised. You have the following rights:

  • Access to personal data we process about you
  • Rectification of incorrect or inaccurate personal data and add incomplete personal data
  • Restriction, i.e. blocking of processing of your personal data
  • The deletion of personal data in case the purpose absence or unauthorized data processing
  • Submission of an objection to the processing of personal data if you believe that our data processing is not justified
  • Be excluded from automated decision-making
  • Listing of personal data in a structured and machine-readable format or for another controller
  • Revocation of consent to the processing of personal data
  • To lodge a complaint with the supervisory authority

How can you exercise your rights?

Spaceflow s.r.o., registered seat at: Pernerova 676/51, Karlín, 186 00 Praha 8, or
Electronically: hello@spaceflow.cz

We strive to protect your privacy as much as possible and therefore we process your personal data in compliance with GDPR and all other relevant laws. However, if you disagree with the way we handle your personal data, you can exercise your rights via our Data Protection Officer at:

Data Protection Officer’s contact: 

JUDr. Theodor Klán, attorney-at-law

Seat at: Pobřežní 18/16, 186 00 Praha 8,

E-mail: dpo@spaceflow.cz

or you can file a complaint in supervising authority regarding the processing of your personal data. Your local supervisory authority may be found at: https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm

Join the mailing list

Join the Spaceflow community! Get the newest insights & articles on tenant experience and more in your mailbox.

Join the mailing list

Join the Spaceflow community! Get the newest insights & articles on tenant experience and more in your mailbox.

Apply For Job

By clicking the button I agree with the collection and processing of my personal data as described in the Privacy Policy