Privacy Statement
For job applicants and employees of the Lapithus Group ("Lapithus")
Lapithus' commitment to your privacy
Lapithus is committed to protecting and respecting your privacy rights. This privacy statement ("Statement") tells you about the use that Lapithus will make of the personal information we hold about you, how we will collect certain personal information, under what circumstances we may share or otherwise use the information and who we may disclose it to.
What personal data do we collect about you?
We will collect, store, and use the following categories of personal information about you:
•Personal contact details such as name, title, addresses, telephone numbers, and personalemail addresses.•Date of birth.
•Gender.
•Marital status and dependants.
•Next of kin and emergency contact information.
•Social Security Number, National Insurance number, Personal Public Service number,Matricule (as applicable).
•Bank account details, payroll records and tax status information.
•Salary, annual leave, pension and benefits information, to include season ticket loans.
•Start date.
•Location of employment or workplace.
•Recruitment information (including copies of right to work documentation, references andother information included in a CV or cover letter (to include qualification information/testresults where required) as part of the application process, interview information.
•Employment records (including job titles, work history, holidays taken, working hours, skillsinformation, any work-related injury, training records, travel planner and professionalmemberships).
•Family leave information.
•Remuneration records and history.
•Performance information.
•Investigatory, disciplinary and grievance information.
•CCTV footage and other information obtained through electronic means such as swipe cardrecords.
•Information about your use of our information and communications systems.
•Information on termination of employment/worker/freelancing relationship.
We may also collect, store and use the following "special categories" of more sensitive personal information:
•Information about your health, including any medical conditions, health and sickness recordsand information provided for income protection schemes.•Information about criminal convictions and offences, where relevant to your role.
•Information about your race or ethnicity, religious beliefs, sexual orientation and politicalopinions.
•Trade union membership (if applicable).
How is your personal information collected?
We collect personal information about employees, workers and freelancers through the application and recruitment process, either directly from candidates or sometimes from an employment agency or background check provider. We may sometimes collect additional information from third parties including former employers, credit reference agencies or other background check agencies. We will continue to collect additional personal information in the course of job-related activities throughout the period of you working for us as described above.
Why do we ask for this information?
All of the information you provide during the recruitment process will only be used for the purpose of progressing your application, or to fulfil legal or regulatory requirements if necessary. We will use the contact details you provide to us to contact you to progress your application. We will use the other information you provide to assess your suitability for the role you have applied for. We will also retain your name and CV on file for future vacancies, unless you ask us not to.
In the event that you are offered and accept a role with Lapithus, the information we collect about you will be used for the purposes of administering and maintaining personnel records (including but not limited to information relevant to induction, on-boarding and leaver processes); planning, paying and reviewing your salary, other remuneration and benefits; assessments of your performance or conduct including performance appraisals and reviews and for disciplinary, grievance and whistleblowing procedure purposes; planning, delivering or arranging training courses related to your role and/or continued professional development, including providing information to external training providers; maintaining sickness and other absence records; maintaining health and safety records and ensuring a safe working environment; taking decisions on your fitness to work and complying with obligations under the Equality Act 2010; providing references and information to future employers and other third parties; providing information to relevant external authorities for tax, social security and other purposes as legally required; equal opportunities monitoring; monitoring IT usage and building access; allowing and removing access to data systems; providing information to any future purchasers of Lapithus or parts of its business, including but not limited to due diligence purposes; and planning or reviewing options, in relation to the operation or management of Lapithus.
What is the legal basis for processing your data?
We need all the categories of information in the list above primarily to allow us to perform our contract with you and to enable us to comply with legal obligations. In some cases, we may use your personal information to pursue legitimate interests of our own or those of third parties, provided your interests and fundamental rights do not override those interests. The situations in which we will process your personal information are listed below. We have indicated the purpose or purposes for which we are processing or will process your personal information, as well as indicating which categories of data are involved.
•Making a decision about your recruitment or appointment.•Determining the terms on which you work for us.
•Checking you are legally entitled to work in the applicable jurisdiction.
•Paying you and, if you are an employee, deducting tax and National Insurance contributions.
•Providing the benefits due to you.
•Liaising with your pension provider and ensuring legal obligations to pay pension contributions in the UK are met.
•Administering the contract we have entered into with you.
•Business management and planning, including accounting, auditing and succession.
•Conducting performance reviews, managing performance and determining performancerequirements.
•Making decisions about pay reviews and remuneration generally.
•Assessing qualifications/skills for a particular job or task, including decisions aboutpromotions.
•Gathering evidence for possible investigation meetings or grievance/disciplinary hearings.
•Making decisions about your continued employment or engagement.
•Dealing with family leave matters.
•Contacting you or other family members where required in our working relationship.
•Making arrangements for the termination of our working relationship.
•Education, training and development requirements.
•Dealing with legal disputes involving you, or other employees, workers and freelancers,including accidents at work.
•Ascertaining your fitness to work.
•Managing sickness absence to include reference to income protection schemes whereappropriate.
•Complying with health and safety obligations.
•To prevent fraud.
•To monitor your use of our information and communication systems to ensure compliancewith our IT policies.
•To ensure network, information and building security, including preventing unauthorisedaccess to our buildings, computer and electronic communications systems and preventingmalicious software distribution.
•To conduct data analytics studies to review and better understand employee retention andattrition rates.
•Equal opportunities monitoring.
Some of the above grounds for processing will overlap and there may be several grounds which justify our use of your personal information.
If you fail to provide certain information when requested, we may not be able to perform the contract we have entered into with you (such as paying you or providing a benefit), or we may be prevented from complying with our legal obligations (such as to ensure the health and safety of our workers).
We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
We will use your sensitive personal information in the following ways:
•We will use information relating to leaves of absence, which may include sickness absence or family related leaves, to comply with employment and other laws, and for managing HR processes such as administering Sick Pay and Sick Leave schemes, managing absence, administering Maternity Leave and related pay schemes•We will use information about your physical or mental health, or disability status, to ensure your health and safety in the workplace and to assess your fitness to work, to provide appropriate workplace adjustments, to monitor and manage sickness absence and to administer benefits.
•We may use information about your race or national or ethnic origin, religious, philosophical or moral beliefs, or your sexual life or sexual orientation, to ensure meaningful equal opportunity monitoring and reporting.
•Where applicable, we will use trade union membership information to pay trade union premiums, register the status of a protected employee and to comply with employment law obligations.
•Managing Human Resources processes such as administering Sick Pay and Sick Leave schemes, managing absence, administering Maternity Leave and related pay schemes
•Managing a safe environment and ensuring fitness for work
•Managing obligations under Equal Opportunities legislation
•Provision of occupational health and wellbeing services to individuals
What will we do with the information you provide to us?
As required by data protection legislation, Lapithus has security procedures regarding the storage and disclosure of personal data. In the course of your application process or employment with us, Lapithus may engage third parties such as background screening companies, payroll providers, performance management software providers, employee benefits providers (such as healthcare, pension, employee assistance, flu vaccinations etc.), employment lawyers, tax advisors, training providers and occupational health providers. Lapithus may disclose your personal data to these third parties in connection with services provided by them. We will share your personal information with such third parties where required by law, where it is necessary to administer the working relationship with you or where we have another legitimate interest in doing so. For a full list of specific providers, please contact Human Resources.
At all times, Lapithus will ensure that the personal data is processed in accordance with our instructions and in circumstances which require the recipient to observe industry standard security measures in respect of personal data. Lapithus may also be under a duty to disclose or share your personal data in order to comply with a legal or regulatory obligation, where such disclosure is required by the relevant tax authority (e.g. HMRC), regulatory bodies (such as the Financial Conduct Authority (FCA) or the Central Bank of Ireland (CBI)), the police or a court of competent jurisdiction. Lapithus will not disclose or transfer personal data about you to third parties for the purposes of marketing.
The personal data that we collect about you may be transferred to, and stored at, one or more countries outside the European Economic Area (“EEA”). It may also be processed by staff operating outside the EEA who work for Lapithus or for our third parties. In such cases, Lapithus will take appropriate steps to ensure an adequate level of data protection in the country of the recipient as required under the EU General Data Protection Regulation and as described in this Statement. If Lapithus cannot ensure such an adequate level of data protection, your personal data will only be transferred outside the EEA if you have given your prior consent to such transfer.
How long is the information retained for?
If you are successful in your application to join Lapithus, the information you provide during the application process will be retained by us as part of your employee file for the duration of your employment, plus an additional length of time depending on the type of information, following the end of your employment. See Schedule 1 of the HR Data Protection Policy for retention periods. If you are unsuccessful at any stage of the process, the information you have provided until that point will be retained for no more than one year.
Information generated throughout the assessment process, for example interview notes, is retained by us for no more than one year. Equal opportunities monitoring information is retained for one year.
Your rights under the EU General Data Protection Regulation
You have the right to access personal data we hold about you and to request rectification or erasure of such personal data, or to request its transfer. Full details are held within the HR Data Protection Policy. You may address your requests to Lapithus' Data Protection Officer whose details are provided at the end of this document.
Changes to this Statement
Lapithus reserve the right to change this Statement and any other relevant policies or procedures at any time without notice to you. Any changes we may make to this Statement in the future will be posted on Lapithus' Intranet and you are advised to regularly check and review the Statement to ensure you understand how we may be processing your personal data. Any changes Lapithus may make to this Statement (which will, unless otherwise indicated, apply to any personal data already obtained by Lapithus before the changes were made) will be effective from the date on which those changes have been posted on this page. Where appropriate, Lapithus may also notify you of any changes made by e-mail.
Complaints or queries
For the purposes of the data protection legislation, Lapithus is the data controller. If you have any questions on the Statement, please contact:
Head of Human Resources
Claire Bridges - cbridges@lapithus.com