Skip to main content

Processing of (personal) data by the entity in charge of the online application process

1. General information 

This data privacy statement applies to personal data collected in the context of our recruitment and hiring processes. It explains how we collect, use, and handle your personal data when you apply for or are considered for a position with us.
This privacy policy applies to all recruitment and application channels through which we may receive or process candidate data. This includes, but is not limited to, applications submitted via our careers website, email, online forms, professional networks (e.g., LinkedIn), referrals, university job portals, and any other platforms or sources.
It also applies in cases where we proactively approach potential candidates (e.g., via professional networks) and, following an initial interaction, process their personal data where permitted by applicable law, including creating a candidate profile or application record in our systems.

2. The controller 

The controller under data protection law is: 
  • Aily Labs GmbH 
  • Müllerstraße 27, 80469, München 
  • Commercial register entry number: HRB 257335 
  • Registration Court: Amtsgericht München 
  • Contact (Data Protection Officer)Privacy@ailylabs.com 

3. Personal Data Processed

Personal data means any information relating to an identified or identifiable natural person. This includes, for example, your name, contact details, and information about your professional background and qualifications that can be used to identify you, directly or indirectly.
As part of the application process, we may process the following categories of data:
  • First and last name
  • Email address
  • Phone number
  • CV/resume and professional experience
  • Education history
  • Cover letter (if provided)
  • LinkedIn profile or other professional links (optional)
  • Source of application (e.g., job portal, referral, direct sourcing)
  • Communication data (emails, messages, interview notes)
  • Any additional information you voluntarily provide
You may also upload documents (e.g., CV, cover letter, references), which may include additional personal data such as date of birth or address.

4. Purpose and Legal Basis of Processing

We process your personal data, regardless of the channel through which it was collected, for the purpose of managing the application process and assessing your suitability for employment, including taking steps prior to entering into an employment contract.
Your data is processed primarily on the basis of Article 6(1)(b) GDPR (performance of pre-contractual measures) and, where applicable, Article 6(1)(f) GDPR (legitimate interests in conducting an efficient recruitment process). Our legitimate interests include identifying and recruiting suitable candidates and managing our hiring processes efficiently.
Access to your data is restricted to authorized HR personnel and employees involved in the recruitment process.
By submitting an application or otherwise engaging with us in the context of a potential employment opportunity, you express your interest in employment with us and acknowledge the processing of your personal data for the purposes of the recruitment process as described in this privacy policy.
In cases where your data is provided through third parties (e.g., referrals) or where we proactively approach you, we will process your personal data only where a valid legal basis applies, including where processing is necessary for pre-contractual steps, based on our legitimate interests, or on the basis of your consent where required.
We do not make hiring decisions based solely on automated processing, including profiling, within the meaning of Article 22 GDPR.

5. Retention Period

Your personal data will generally be stored for 6 months after the conclusion of the application process.
This retention period allows us to comply with legal obligations and to defend against potential legal claims. After this period, your data will be deleted or anonymized. In case of anonymization, the data will only be retained in aggregated form without any personal reference (e.g., for statistical purposes).
If you consent to being included in our Talent Pool, we may retain and process your data for an additional period of up to 6 months after the conclusion of the application process for the purpose of considering you for future relevant opportunities.
If you accept an offer of employment, your data will be retained for the duration of your employment in accordance with applicable employee data policies.

6. Disclosure of Data to Third Parties

Data transmitted as part of your application will be transferred using encryption and stored in systems used to support our recruitment process. These include applicant tracking systems and communication and collaboration tools.
In particular, we use Personio GmbH as our applicant tracking system provider (https://www.personio.com/legal-notice/). In addition, we may use communication tools (e.g., email and video conferencing solutions) to conduct interviews and document the recruitment process.
These service providers act as data processors on our behalf under Article 28 GDPR and are bound by appropriate data processing agreements.
Where personal data is transferred to countries outside the European Economic Area, appropriate safeguards are implemented in accordance with applicable data protection laws, such as the use of Standard Contractual Clauses approved by the European Commission.

7. Your Rights

Under the GDPR, you have the following rights, subject to applicable conditions:
  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
If processing is based on your consent, you may withdraw it at any time (Art. 7(3) GDPR).
To exercise your rights, please contact our Data Protection Officer at the details above.
You also have the right to lodge a complaint with a supervisory data protection authority if you believe that the processing of your personal data violates applicable data protection law.

8. Updates to this Privacy Policy

We reserve the right to update this privacy policy at any time to reflect legal requirements or changes in our recruitment process. The version published on our careers page applies at the time of your application.

-----

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.