Keter Group BV and its affiliates, as listed in Appendix A of this notice (“Keter”, “we”, “us”, “our” or the “Company”) is committed to protecting the personal information that is shared with us as part of our recruitment processes and respects the privacy of its employment candidates (“you” or “Data Subjects”).
This privacy notice (the “Privacy Notice”) explains the types of information we collect from you, that we receive about you or that you may provide in the course of our recruitment processes. We are transparent about our practices regarding the information we collect, use, maintain and process and describe our practices in this Privacy Notice. Please read the following carefully to understand our practices regarding your personal data and how we will treat it. Please note that we reserve the right to update this Privacy Notice at any time. If you have any questions about this Privacy Notice, please contact our Data Protection Officer at [email protected].
For the purposes of the EU and UK General Data Protection Regulation (together, the “GDPR”) and other applicable privacy laws, the applicable Keter entity managing your recruitment process, as listed in Appendix A of this Privacy Notice, is the data controller (“Controller”) in relation to the personal data of our employment candidates. Please note that we maintain a separate privacy notice regarding our employees.
Summary: we collect various categories of personal data as part of our recruitment process, both from you and from other sources.
Sources of personal data
When you apply to a position at our company, you provide us with your personal data. Please note that, in most cases, we receive the information directly from you (such as through our website, mail or email), or record data in interview records. references or background check companies. This information is necessary for our recruitment and hiring purposes. You are under no obligation to provide us with your data during our recruitment process. However, if you do not provide us with this data, we will not be able to assess you as a candidate and advance your recruitment process.
Personal data that We Collect and Process
Job applicant data includes personal data such as your name, contact information, any personal data contained in your resume (c.v.) and job application, email correspondence, information from references, employment history, education information, job interview notes, your responses to any assessment, .
Summary: we process personal data in order to evaluate your employment suitability and comply with legal obligations.
We collect and process your personal data for the following purposes:
We process your personal data on the following legal bases:
Summary: we share personal data with our service providers and group companies, and authorities where required.
We transfer personal data to:
Third Parties. We may share your personal data with the following categories of recipients:
In addition, we will disclose your personal data to third parties if some or all of our companies or assets are acquired by a third party including by way of a merger, share acquisition, asset purchase or any similar transaction, in which case personal data will be one of the transferred assets. Likewise, we may transfer personal data to third parties to assert or protect our rights.
For avoidance of doubt, Keter may transfer and disclose non-personal data to third parties at its own discretion.
Summary: we store your personal data across multiple locations globally
We store your personal data on servers owned or controlled by Keter, or processed by third parties on behalf of Keter (see the following section regarding international transfers).
Summary: we transfer personal data internationally with appropriate safeguards in place.
Personal dataWhere your personal data is transferred outside of the EEA or UK, we will take all steps reasonably necessary to ensure that your Data is subject to appropriate safeguards, including entering into contracts that require the recipients to adhere to data protection standards that are considered satisfactory under EU or UK law and other applicable laws, and that it is treated securely and in accordance with this Privacy Notice. Transfers from the EEA or UK to countries recognized as adequate by the EU and UK are based on such adequacy decisions. Transfers from the EEA to the USA are made based on the Standard Contractual Clauses published by the EU Commission. Transfers from the UK to the USA are made based on the UK’s International Data Transfer Addendum to the EU Commission Standard Contractual Clauses. For more information about these safeguards, please contact us as set forth below.
We transfer personal data to locations outside of the EEA and UK in order to:
Summary: we retain personal data according to our data retention policy, as required to meet our obligations, protect our rights, and manage our business.
Keter will retain personal data it processes only for as long as required in our view, to operate our recruitment operations, and as necessary to comply with our legal and other obligations, to resolve disputes and to enforce agreements. We will also retain personal data to meet any audit, compliance and business best-practices. Some data may also be retained on our third-party service providers’ servers until deleted in accordance with their privacy policy and their retention policy, and in our backups until overwritten.
Generally, we retain recruitment data for up to 6 months after the end of the relevant recruitment process. After this period, we will securely destroy your data in accordance with our data retention policy. If we wish to retain your data on file for a longer time period for the purpose of follow-up regarding future vacancies, we will do so only based on your explicit consent. Please note that if your application for employment is successful, personal data gathered during the recruitment process will be transferred to your personnel file, and its use and retention will be governed by our employee privacy notice.
Summary: we take data security very seriously, invest in security systems, and train our staff. In the event of a breach, we will notify you as required by law.
We take great care in implementing, enforcing and maintaining the security of the personal data we process. Keter implements, enforces and maintains security measures, technologies and policies to prevent the unauthorized or accidental access to or destruction, loss, modification, use or disclosure of personal data. We likewise take steps to monitor compliance of such policies on an ongoing basis.
Note however, that no data security measures are perfect or impenetrable, and we cannot guarantee that unauthorized access, leaks, viruses and other data security breaches will never occur.
Within Keter, we endeavor to limit access to personal data to those of our personnel who: (i) require access in order for Keter to fulfill the purposes of the data processing, and (ii) have been appropriately and periodically trained with respect to the requirements applicable to the processing, care and handling of the personal data, and (iii) are under confidentiality obligations as may be required under applicable law.
Keter shall act in accordance with its policies and with applicable law to promptly notify the relevant authorities and data subjects in the event that any personal data processed by Keter is lost, stolen, or where there has been any unauthorized access to it, all in accordance with applicable law and on the instructions of qualified authority. Keter shall promptly take reasonable remedial measures.
Summary: You have various data subject rights, such as rights to access, erase, and correct personal data, and information rights. We will respect any lawful request to exercise those rights.
Data subjects in certain jurisdictions, such as in the EU and UK, have rights under the GDPR or other applicable laws in certain circumstances and with certain exceptions, including:
Please note that these rights only apply in certain circumstances, and may be limited by law and subject to exceptions. For example, where fulfilling your request would adversely affect other individuals or our trade secrets or intellectual property, where there are overriding public interests or where we are required by law to retain your personal data. In addition, data subject rights cannot be exercised in a manner inconsistent with the rights of Keter employees and staff or third-party rights. As such, job references, reviews, internal notes and assessments, documents and notes including proprietary information or forms of intellectual property, cannot be accessed or erased or rectified by data subjects. In addition, these rights may not be exercisable where they relate to data that is not in a structured form, for example emails, or where other exemptions apply.
To exercise any of your rights, you can contact our Data Protection Officer at [email protected]. We will respond to requests to exercise these rights without undue delay as required by applicable laws. Note that Keter may have to undertake a process to identify a data subject exercising their rights. Keter may keep details of such rights exercised for its own compliance and audit requirements. Please note that personal data may be either deleted or retained in an aggregated manner without being linked to any identifiers or personal data, depending on technical commercial capability. Such information may continue to be used by Keter.
Data subjects in the EU, UK and other jurisdictions have the right to lodge a complaint, with a data protection supervisory authority in the place of their habitual residence. If the supervisory authority fails to deal with a complaint, you may have the right to an effective judicial remedy.
We do not knowingly collect or solicit information or data from or about children under the age of 16 without parental consent, or knowingly allow children under the age of 16 to submit an employment application. If you are under 16, do not send any information about yourself to us. If we learn that we have collected or have been sent personal data from a child under the age of 16 without appropriate permissions, we will delete that personal data as soon as reasonably practicable without any liability to Keter. If you believe that we might have collected or been sent information from a minor under the age of 16, please contact us at: [email protected], as soon as possible.
Keter aims to process only adequate, accurate and relevant data limited to the needs and purposes for which it is gathered. It also aims to store data for the time period necessary to fulfill the purpose for which the data is gathered. Keter only collects recruitment data in connection with a specific lawful purpose and only processes data in accordance with this Privacy Notice. Our policies and practices are constantly evolving and improving, and we invite any suggestions for improvements, questions, complaints or comments concerning this Privacy Notice, you are welcome to contact us (details below) and we will make an effort to reply within a reasonable timeframe.
Keter’s Data Protection Officer (DPO) may be contacted at: [email protected].
The details of the European Keter entities are listed in Appendix A below.
* * * * *
Last Revised: November 14, 2024
Copyright ©2025 Keter Group. All rights reserved.