Skip to main content

Processing of (personal) data by the entity in charge of the online application process

Privacy Policy for Recruitment Using Personio

RAW iGaming Ltd, a leading iGaming company, is committed to protecting your personal data during the recruitment process. This Privacy Policy outlines how we, as the Data Controller, handle your data using Personio’s recruitment platform.

The service for handling recruitments and simplifying the hiring process (the "Service") is powered by Personio on behalf of RAW iGaming Ltd ("Controller," “we,” “us,” etc.). It is important that the persons using the Service ("Users”) feel safe with, and are informed about, how we handle Users' personal data in the recruitment process. We strive to maintain the highest possible standard regarding the protection of personal data. We process, manage, use, and protect Users' Personal Data in accordance with this Privacy Policy ("Privacy Policy").

1. General

We are the controller in accordance with current privacy legislations. The Users’ personal data is processed with the purpose of managing and facilitating recruitment of employees to our business.

2. Collection of Personal Data

We are responsible for the processing of the personal data that the Users contribute to the Service, or for the personal data that we in other ways collect with regards to the Service.

When and How We Collect Personal Data

We collect personal data about Users from Users when Users:

  • Make an application through the Service or otherwise, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn; and
  • Use the Service to connect with our staff, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn.
  • Provide identifiable data in the chat (provided through the website that uses the Service) and such data is of relevance to the application procedure.

We collect data from third parties, such as Facebook, LinkedIn, and through other public sources. This is referred to as “Sourcing” and may be manually performed by our employees or automatically in the Service.

In some cases, existing employees can make recommendations about potential applicants. Such employees will add personal data about such potential applicants. In the cases where this is made, the potential applicant is considered a User in the context of this Privacy Policy and will be informed about the processing.

The Types of Personal Data Collected and Processed

The categories of personal data that can be collected through the Service can be used to identify natural persons from names, e-mails, pictures and videos, information from Facebook and LinkedIn accounts, answers to questions asked through the recruiting, titles, education, and other information that the User or others have provided through the Service. For certain roles, we may collect special categories of personal data for background checks, with your explicit consent (GDPR Article 9(2)(a)) or as required by law (GDPR Article 9(2)(b)). Only data that is relevant for the recruitment process is collected and processed.

Purpose and Lawfulness of Processing

The purpose of collecting and processing personal data is to manage recruitment, including evaluating applications and selecting candidates for employment. The lawfulness of this processing is primarily based on the necessity to take steps at the request of the data subject prior to entering into a contract (GDPR Article 6(1)(b)). For certain activities, such as conducting aggregated analytics, we rely on our legitimate interest to simplify and facilitate recruitment (GDPR Article 6(1)(f)), provided this does not override the data subject’s rights. Where consent is required (e.g., for sourcing data from third-party platforms), we process data based on the User’s explicit consent (GDPR Article 6(1)(a)).

Personal data that is processed with the purpose of aggregated analysis or market research is always made unidentifiable. Such personal data cannot be used to identify a certain User. Thus, such data is not considered personal data.

The Consent of the Data Subject

The User consents to the processing of its personal data with the purpose of Controller’s handling recruiting. The User consents that personal data is collected through the Service, when Users:

  • Make an application through the Service, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn, and that Controller may use external sourcing tools to add additional information; and
  • When they use the Service to connect to Controller’s recruitment department, adding personal data about themselves either personally or by using a third-party source such as Facebook or LinkedIn.

The User also consents to the Controller collecting publicly available information about the User and compiling them for use in recruitment purposes.

The User consents to the personal data being collected in accordance with the above a) and b) will be processed according to the below sections Storage and Transfers and How Long the Personal Data Will Be Processed.

The User has the right to withdraw his or her consent at any time, by contacting Controller using the contact details listed under section 9. Using this right may, however, mean that the User cannot apply for a specific job or otherwise use the Service.

Storage and Transfers

Personal data collected through the Service is stored and processed inside the EU/EEA or in third countries recognized by the European Commission as providing an adequate level of protection. For transfers to other third countries, we ensure appropriate safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission, to protect the rights of data subjects. To obtain documentation regarding these safeguards, contact us using the contact details listed in section 9.

How Long the Personal Data Will Be Processed

Personal data collected through the Service is stored and processed for the duration of the recruitment process and for up to 6 months or 12 months (if the recruitment process is for the United Kingdom) thereafter to address feedback, disputes, or legal requirements.

3. Users’ Rights

Users have the right to request information about the personal data that is processed by us, by notifying in writing, us using the contact details below under section 9 below. Users have the right to one (1) copy of the processed personal data which belongs to them without any charge. For further demanded copies, Controller has a right to charge a reasonable fee on the basis of the administrative costs for such demand.

Users have the right to, if necessary, rectification of inaccurate personal data concerning that User, via a written request, using the contact details in section 9 below.

The User has the right to demand deletion or restriction of processing, and the right to object to processing based on legitimate interest under certain circumstances.

The User has the right to revoke any consent to processing that has been given by the User to Controller. Using this right may, however, mean that the User cannot apply for a specific job or otherwise use the Service.

The User has under certain circumstances a right to data portability, which means a right to get the personal data and transfer these to another controller as long as this does not negatively affect the rights and freedoms of others.

User has the right to lodge a complaint to the supervisory authority regarding the processing of personal data relating to him or her, if the User considers that the processing of personal data infringes the legal framework of privacy law.

4. Security

We prioritize personal integrity and therefore work actively so that the personal data of the Users are processed with utmost care. We take the measures that can be reasonably expected to make sure that the personal data of Users and others are processed safely and in accordance to this Privacy Policy and the GDPR regulation.

However, transfers of information over the internet and mobile networks can never occur without any risk, so all transfers are made on the own risk of the person transferring the data. It is important that Users also take responsibility to ensure that their data is protected. It is the responsibility of the User that their login information is kept secret.

5. Transfer of Personal Data to Third Party

We will not sell or otherwise transfer Users’ personal data to third parties.

We may transfer Users’ Personal Data to:

  • Our contractors and sub-contractors, acting as our Processors and Sub-Processors in accordance with our instructions, for the provision of the Service;
  • Authorities or legal advisors in case criminal or improper behaviour is suspected; and
  • Authorities, legal advisors, or other actors, if required by us according to law or authority’s injunction.

We will only transfer Users’ personal data to third parties that we have confidence in. We carefully choose partners to ensure that the User’s personal data is processed in accordance to current privacy legislations. We cooperate with the following categories of processors of personal data: Personio, who supplies the Service, server and hosting companies, e-mail reference companies, video processing companies, information-sourcing companies, analytical service companies, and other companies with regards to supplying the Service.




6. Aggregated Data (Non-Identifiable Personal Data)

We may share aggregated data to third parties. The aggregated data has in such instances been compiled from information that has been collected through the Service and can, for example, consist of statistics of internet traffic or the geological location for the use of the Service. The aggregated data does not contain any information that can be used to identify individual persons and is thus not personal data.

7. Cookies

When Users use the Service, information about the usage may be stored as cookies. Cookies are passive text files that are stored in the internet browser on the User’s device, such as computer, mobile phone, or tablet, when using the Service. We use cookies to improve the User’s usage of the Service and to gather information about, for example, statistics about the usage of the Service. This is done to secure, maintain, and improve the Service. The information that is collected through the cookies can in some instances be personal data and is, in such instances, regulated by our Cookie Policy.

Users can at any time disable the use of cookies by changing the local settings in their devices. Disabling of cookies can affect the experience of the Service, for example disabling some functions in the Service.

8. Changes

We have the right to, at any time, make changes or additions to the Privacy Policy. The latest version of the Privacy Policy will always be available through the Service. A new version is considered communicated to the Users when the User has either received an email informing the User of the new version (using the e-mail stated by the User in connection to the use of the Service) or when the User is otherwise informed of the new Privacy Policy.

9. Contact

For questions, further information about our handling of personal data, or for contact with us in other matters, please use the below stated contact details: privacy@rawgroup.com

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.