The present Privacy Policy (hereinafter referred to as the “Policy”) describes the procedures implemented by Brainy OÜ, a legal entity incorporated under the laws of the Republic of Estonia, registry code 16546221 (hereinafter referred to as the “Brainy Agency” on the processing of personal data of Data subjects using or interested in recruiting services of Brainy Agency (hereinafter referred to as the “Services”) available via the website with the URL https://brainyagency.com/ (hereinafter referred to as the “Website”).

This Policy shall also apply in connection with the Terms of Use for Recruiting Agency of Brainy (hereinafter referred to as the “Terms for Recruiting Agency”). In case of any contradictions between the Policy and the Terms for Recruiting Agency related to personal data processing, the Policy shall prevail.

The terms and definitions provided by the Terms for Recruiting Agency shall apply to this Policy unless their application does not contradict the provisions of the Policy.

The Policy is enacted in accordance with the Personal Data Protection Act of the Republic of Estonia and the General Data Protection Regulation No. 2016/679 (GDPR) adopted by the European Parliament and the Council on 27 April 2016. In case of any contradictions between this Policy and GDPR or the Personal Data Protection Act, GDPR or the Personal Data Protection Act shall prevail. In case of any contradictions between GDPR and the Personal Data Protection Act, GDPR shall prevail.

All the terms and definitions provided by GDPR shall apply to this Policy unless their application does not contradict the terms or definitions of the Policy.

If Brainy Agency processes the personal data of a data subject who is not a resident of the European Union, and the processing of personal data of such data subject is governed by the laws and regulations of other jurisdictions, including, but not limited to California Consumer Privacy Act (CCPA) and Children’s Online Privacy Protection Act and Rule enacted by the Federal Trade Commission (COPPA), such laws and regulations shall apply to the extent that their application does not violate GDPR and laws and regulations of the Republic of Estonia.

The following terms and definitions shall apply to the Policy:

“Controller” means Brainy Agency.

“Data subject” means a natural person who is either:

(a) a Customer of Brainy Agency as defined in the Terms for Recruiting Agency or

(b) a natural person who visits the Website or otherwise expresses interest in the Services of Brainy Agency

"Employer” means an Employer as defined in the Terms for Recruiting Agency.

“Recruiter” means Recruiter as defined in the Terms for Recruiting Agency.

“Processor” means a natural person or a legal entity that is either:

(a) engaged in the provision of the Services and processes personal data of Data subjects for the purpose of providing the Services (including Recruiters of Brainy Agency) or

(b) engaged in the processing of personal data of Data subjects under the contract concluded with Brainy Agency.

“Services” means Services offered by Brainy Agency under the Terms for Recruiting Agency..

“Third party” means a natural person or a legal entity that either:

(a) provides Brainy Agency with personal data of the Data subject on the lawful basis provided by Article 6 GDPR or

(b) receives personal data of the Data subject from Brainy Agency for purposes not related to the processing of personal data under this Policy (including Employers defined in the Terms for Recruiting Agency)

“Usage data” means personal data about the Data subject’s activities on the Internet collected automatically either through the use of the Services or from the Services infrastructure itself. The Usage data is anonymous and cannot be attributed to a particular person.

Brainy Agency processes the personal data of Data subjects under this Policy in accordance with the following principles:

(1) The processing of personal data is performed only in accordance with this Policy and the applicable legislation

(2) The processing of personal data is performed only for achieving the purposes specified in the Policy

(3) Brainy Agency processes only personal data that is correct and up-to-date and retained only for such time as may be necessary for achieving the purposes of processing provided by the Policy.

CONTENT

  1. Lawfulness of Personal Data Processing
  2. Personal Data Processed
  3. Purposes of Personal Data Processing
  4. Data Subjects and Privacy of Children
  5. Controller and Processor
  6. Third Parties and Business Use of Personal Data
  7. Cookies and Similar Technologies
  8. Brainy Agency and Social Network
  9. Rights of Data Subject
  10. Security of Personal Data
  11. Storage of Personal Data
  12. International transfer of Personal Data
  13. Changes to the Privacy Policy
  14. Contact information of Brainy Agency

1. LAWFULNESS OF PERSONAL DATA PROCESSING

1.1. By visiting, using, or/and exploring the Website, the Data subject provides Brainy Agency with the consent to the processing of personal data of the Data subject provided in paras.2.1.13-2.1.14 of the Policy.

1.2. By accepting the Terms for Recruiting Agency in accordance with para.1.1 of the Terms for Recruiting Agency, the Data subject provides Brainy Agency with the consent to the processing of personal data of the Data subject provided in paras.2.1.1-2.1.6, paras.2.1.8-2.1.12, and para.2.1.16 of the Policy.

1.3. If the Customer is a legal entity which concluded the contract with Brainy Agency on the provision of the Services under the Terms for Online Courses for Data subjects who are natural persons, Brainy Agency has the right to process personal data of such a Customer and the representatives and employees of such a Customer provided in paras.2.1.1-2.1.7 of the Policy under Article 6 paragraph 1 point (a) GDPR. 

1.4. Even if the Customer who is a natural person does not provide explicit consent to the processing of his or her personal data, but uses the Services of Brainy Agency or requests Brainy Agency to provide the Services, Brainy Agency has the right to process personal data of such a Customer provided in paras.2.1.1-2.1.12 of the Policy for the purposes related to the provision of the Services under the Terms for Recruiting Agency (Article 6 paragraph 1 point (b) GDPR).

1.5. If a Data subject provides Brainy Agency with personal data provided in para.2.1.16 of the Policy, the Data subject provides Brainy Agency with consent to the processing of such personal data for the purposes prescribed by this Policy. In this case, the exact purpose of personal data processing depends on the nature of the personal data provided by the Data subject. This paragraph of the Policy applies even if the Data subject is not a Customer of IT Talent under the Terms for Recruiting Agency.

1.6. If a Data subject provides Brainy Agency with personal data prescribed by para.8.2 of the Policy, the Data subject provides Brainy Agency with consent to the processing of such personal data for the purposes provided in para.8.3 of the Policy.

1.7. If a Data subject makes publicly available personal data provided in para.8.4 of the Policy, the Data subject provides Brainy Agency with consent to the processing of such personal data for the purposes prescribed by para.8.4 of the Policy.

1.8. If a Data subject refuses to give consent to the processing of personal data, and there are no other legal grounds for processing provided by Article 6 GDPR, Brainy Agency has the right to refuse the provision of the Services or restrict access to the Data subject to the Website if the provision of the Services or provision of access to the Website is impossible without processing of such personal data.

2. PERSONAL DATA PROCESSED

2.1. Under this Policy, Brainy Agency has the right to process the following personal data of Data subjects:

2.1.1. First and last name of the Data subject.

2.1.2. Personal identification code of the Data subject (if the Data subject is a citizen or resident of the Republic of Estonia), or ID/passport number or Tax ID number of the Data subject (if the Data subject is not a citizen or resident of the Republic of Estonia).

2.1.3. Email address of the Data subject and/or the contact details of the Data Subject in a social network or messenger (e.g., Telegram, Skype etc.).

2.1.4. Phone number of the Data subject.

2.1.5. Address of residence of the Data subject.

2.1.6. Information about the profession or qualification, the level of education, the work experience, and professional interests of the Data subject.

2.1.7. Customer’s Content as defined in the Terms for Recruiting Agency and open (public) profiles of the Customer in social networks and messengers if the Customer uses the Services under the Terms for Recruiting Agency or requests the provision of the Services under the Terms for Recruiting Agency, subject to the rules of Section 8 of this Policy.

2.1.8. Data on the subject’s history of previous employment and the reasons for their termination.

2.1.9. Data subject’s career path, namely, the information about the employment positions held by the Data subject and the periods during which each position was held.

2.1.10. Information about the Data subject’s personal characteristics and hobbies.

2.1.11. Information about the Data Subject is available through public state or/and municipal registers.

2.1.12. Cookies and technically similar data are defined in Section 7 of this Policy.

2.1.13. Usage data, including, but not limited to Internet Protocol address of the Data subject’s computer or telephone (e.g., IP address), browser type, browser version, the pages of the Website that the Data subject visits, the time and date of the visit of the Website, the time spent by the Data subject on the pages of the Website, unique device identifiers, and other diagnostic data.

2.1.14. Personal data lawfully provided to Brainy Agency by the Third parties.

2.2. Personal data not provided in para.2.1 of the Policy may be processed only under the prior consent of the Data Subject or under other grounds of processing provided by Article 6 paragraph 1 point (c)-(f) GDPR.

2.3. Brainy Agency does not and will not process any special categories of personal data provided by Article 9 GDPR (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs etc.). If Brainy Agency finds out that Brainy Agency or Brainy Agency’s Processor has processed any personal data provided by Article 9 GDPR, Brainy Agency will immediately delete such personal data and will take reasonable measures to prevent the processing of such personal data in future.

3. PURPOSES OF PERSONAL DATA PROCESSING

3.1. Brainy Agency has the right to process the personal data of Data subjects provided in paras.2.1.1-2.1.12 of the Policy for the following purposes:

3.1.1. Provision of the Services under the Terms for Recruiting Agency.

3.1.2. Resolving disputes with the Customers in accordance with Section 12 of the Terms for Recruiting Agency.

3.1.3. Resolving challenges of Recruiters and Employers in accordance with Section 3 of the Terms for Recruiting Agency.

3.1.4. Improving the quality of the Services provided under the Terms for Recruiting Agency.

3.2. Brainy Agency has the right to process the personal data of Data subjects provided in paras.2.1.13-2.1.14 of the Policy for the following purposes:

3.2.1. Statistical and analytical purposes.

3.2.2. Improving the Data subject’s experience related to the use of the Website.

3.2.3. Improving the work of the Website.

3.2.4. Changing the functionality of the Website to attract more Customers to the Services.

3.2.5. Providing the Customer with all the functionality of the Website necessary for the provision of the Services.

3.2.6. Providing technical support for the Website.

3.2.7. Analyzing the interaction of Data subjects with the Website for amending the contents and the structure of the Website and other Internet resources used by Brainy Agency for providing the Services.

3.2.8. Analyzing the interaction of Data subjects with the Website for creating and launching marketing and ad campaigns on the Internet.

3.2.9. Resolving disputes with Data subjects.

3.3. Brainy Agency has the right to process the personal data of Data subjects provided in para.2.1 of the Policy for marketing and advertising purposes, which includes direct advertising (such as email newsletters, and bulk emailing) and the creation of context advertisements.

3.4. Depending on the nature of personal data, Brainy Agency has the right to process the personal data of Data subjects provided in para.2.1.16 of the Policy for the purposes provided in paras.3.1-3.3 of the Policy.

3.5. Depending on the nature of personal data, Brainy Agency has the right to process the personal data of Data subjects provided in para.2.1.15 of the Policy for the purposes provided in para.6.1 of the Policy.

4. DATA SUBJECTS AND PRIVACY OF CHILDREN

4.1. The Services of Brainy Agency are not aimed at natural persons who are under 16 (sixteen) years of age. Brainy Agency does not provide Services to Customers who are under 16 (sixteen) years of age and does not knowingly process the personal data of other Data subjects who are under 16 (sixteen) years of age. Brainy Agency takes all reasonable technical and organizational measures to prevent the processing of personal data of Data subjects who are under 16 (sixteen) years of age.

4.2. If Brainy Agency has doubts regarding the age of the Customer, Brainy Agency has the right to request the Customer to verify the Customer’s age. If the Customer refuses to verify the Customer’s age or if Brainy Agency finds out that the Customer is less than 16 (sixteen) years of age, Brainy Agency immediately terminates the Terms for Recruiting Agency with the Customer (depending on the type of the provided Services), deletes all the personal data associated with such Customer in accordance with this Policy, and restricts access of the Customer to the Services.

4.3. If a Data subject who is not a Customer and who is under 16 (sixteen) years of age provides Brainy Agency with any personal data prescribed by paras.2.1.1-2.1.12 or para.2.1.16 of the Policy, Brainy Agency will immediately delete such personal data and take reasonable measures preventing the processing of such personal data in future.

4.4. If a Third party provides Brainy Agency with personal data in accordance with para.2.1.15 of the Policy, and Brainy Agency figures out that such personal data belongs to a Data subject who is under 16 (sixteen) years of age, Brainy Agency will immediately delete such personal data and take reasonable measures preventing the processing of such personal data in future. Brainy Agency also has the right to terminate the contract with such a Third party under which the Third party provided Brainy agency with personal data.

4.5. If the Website or other technical tools used by Brainy Agency process personal data provided in paras.2.1.13-2.1.14 of the Policy, and Brainy Agency figures out that the processed personal data belongs to a Data subject who is under 16 (sixteen) years of age, Brainy Agency will take all the reasonable steps to extract and delete such personal data.

4.6. If a person who is a holder of parental responsibility over the Data subject that is under 16 (sixteen) years of age contacts Brainy Agency and presents evidence that Brainy Agency unknowingly processes personal data of such a Data subject, Brainy Agency will immediately delete such personal data and take reasonable measures preventing the processing of such personal data in future. If such holder of parental responsibility notifies Brainy Agency that Brainy Agency unknowingly processes personal data provided in paras.2.1.13-2.1.14 of the Policy, Brainy Agency will make all the reasonable steps to extract and delete such personal data and to prevent the processing of such personal data in future.

5. CONTROLLER AND PROCESSOR

5.1. Under this Policy, Brainy Agency is the Controller as defined by Article 4 paragraph 7 GDPR. The Controller determines the purposes and means of the processing of personal data of Data subjects and engages Processors in the processing of personal data under this Policy.

5.2. The Controller processes the personal data of Data subjects directly by itself or through engaged Processors. The Processors process the personal data of Data subjects on behalf of the Controller as defined in Article 4 paragraph 8 of GDPR. All the Processors act under the contracts concluded with the Controller or Controller’s Subsidiary under the direct authorization of the Controller. The Controller observes the compliance of the Processors with the GDPR and other applicable personal data legislation.

5.3. Under this Policy, the Controller has the right to engage the following categories of Processors in the processing of personal data of Data subjects:

5.3.1. Recruiters providing recruiting Services under the Terms for Recruiting Agency. Such Recruiters may only process personal data that directly relates to the provision of the Services under the Terms for Recruiting Agency, including personal data provided by para.2.1.16 of the Policy.

5.3.2. Other employees and/or contractors of Brainy Agency that are natural persons who directly participate in the provision of the Services under the Terms for Recruiting Agency. Such employees and contractors may only process personal data that directly relates to the provision of the Services under the Terms for Recruiting Agency, including personal data provided by para.2.1.16 of the Policy.

5.3.3. Processors that provide technical support to the Website and other Internet resources used by Brainy Agency for the provision of the Services.

5.3.4. Processors that provide Brainy Agency with web and other technical solutions aimed at the provision of the Services and/or increasing the quality of the Services.

5.3.5. Processors that assist Brainy Agency with processing personal data provided by paras.2.1.13-2.1.14 of the Policy.

5.3.6. Processors that assist Brainy Agency with analyzing and using personal data provided by paras.2.1.13-2.1.14 of the Policy for advertising and marketing purposes (such as Google Analytics, Meta for Business etc.).

5.3.7. Processors that assist Brainy Agency with resolving disputes with Data subjects.

5.3.8. Processors that ensure the security of the Website and other Internet resources used by Brainy Agency for the provision of the Services and processing of personal data of Data subjects.

5.4. By providing consent to the processing of personal data under this Policy, the Customer agrees that the Recruiters of Brainy Agency providing the Services may reside outside EEA and may receive and process personal data of the Customer on behalf of Brainy Agency outside EEA for the purpose of providing the Services under the Terms for Recruiting Agency.

5.5. By providing consent to the processing of personal data under this Policy, the Data Subject agrees that the Processors prescribed by para.5.3.9 of the Policy may reside outside EEA and may receive and process personal data of the Data subject outside EEA for the purposes provided in para.3.1.2, para.3.1.4, and para.3.2.9 of the Policy.

5.6. By providing consent to the processing of personal data under this Policy, the Data Subject agrees that other Processors listed in this Section of the Policy may reside outside EEA and may receive and/or process personal data of Data subjects outside EEA for the purposes provided in the Policy and in accordance with the rules and procedures established by the Policy and GDPR.

6. THIRD PARTIES AND BUSINESS USE OF PERSONAL DATA

6.1. Brainy Agency may receive personal data provided by para.2.1.15 of the Policy from Third parties for achieving the purposes provided in paras.3.2.1-3.2.8 and para.3.3 of the Policy. Such Third parties do not participate in the processing of personal data under the Policy. The following categories of Third parties may provide Brainy Agency with the personal data of Data subjects for the purposes prescribed by this paragraph of the Policy:

6.1.1. Natural persons and legal entities conducting collection and/or analysis of Usage data described in para.2.1.14 of the Policy.

6.1.2. Business partners, contractors, and subcontractors of Brainy Agency assisting Brainy Agency with the provision of the Services under the Terms for Recruiting Agency or participating in other business projects of Brainy Agency indirectly related or unrelated to the provision of the Services.

6.2. Brainy Agency refuses to receive personal data from a Third party if such personal data was illegally obtained by such a Third party. If Brainy Agency finds out that the Third party illegally obtained the personal data of a Data Subject, Brainy Agency will immediately delete such personal data and take reasonable measures to prevent the processing of such personal data in future. Brainy Agency also has the right to terminate the contract with such a Third party under which the Third party provided Brainy Agency with illegally obtained personal data.

6.3. Brainy Agency may provide personal data of Data subjects to the following categories of Third parties:

6.3.1. Business partners, contractors, and subcontractors of Brainy Agency assisting Brainy Agency with providing the Services under the Terms for Recruiting Agency or performing other business projects of Brainy Agency indirectly related or unrelated to the provision of the Services. Such business partners, contractors, and subcontractors may use the personal data of Data subjects exclusively for the following purposes:

(a) Analysis of personal data for the purpose of improving the Services and other services offered by Brainy Agency.

(b) Organizing the provision of the Services or performance of other business projects of Brainy Agency.

(c) Improving the design or functionality of the Website.

(d) Assisting Brainy Agency with launching and administering marketing and ad campaigns.

(e) Promoting the Services of Brainy Agency among current or potential Customers.

6.3.2. Employers as defined in the Terms for Recruiting Agency. Brainy Agency has the right to provide such Employers with any personal data of the Customer provided in paras.2.1.1-2.1.12 and para.2.1.16 of the Policy if the Customer uses the Services of Brainy Agency under the Terms for Recruiting Agency. Brainy Agency has the right to transfer to the Employers the personal data of such Customer for the following purposes:

(a) Evaluating the Customer as the potential employee of the Employer.

(b) Conducting job interviews with the Customer as the potential employee of the Employer.

(c) Providing the Customer with test tasks aimed at evaluating the qualification and professional experience of the Customer, as well as checking the test tasks completed by the Customer.

(d) Conducting internal investigations of the Employer aimed at preventing any conflicts of interest in respect of the Customer as the potential employee and identifying the existence of any legal grounds for refusing to hire the Customer as the employee of the Employer.

(e) Conducting negotiations with the Customer on the terms of the employment contract between the Employer and the Customer.

(f) Hiring the Customer as the employee of the Employer if the Employer makes the decision that the Customer should be the employee of the Employer, and the Customer accepts the job offer of the Employer.

6.3.3. Potential or current investors of Brainy Agency interested in investing in the business activities of Brainy Agency. Such Third parties may receive the personal data of Data subjects exclusively for the purpose of evaluating the business activities of Brainy Agency to make the decision on investing in the business of Brainy Agency. The disclosure of Data subjects’ personal data to such Third parties is strictly limited to the purpose of personal data disclosure and performed under the non-disclosure agreement signed with the potential or current investor of Brainy Agency. Generally, Brainy Agency does not disclose to such Third parties the personal data provided in paras.2.1.1-2.1.12 of the Policy.

6.3.4. Competent courts, supervising authorities, or other governmental or municipal authorities of the Republic of Estonia or other jurisdictions. The disclosure of Data subjects’ personal data to such Third parties is performed only under the legal request of such a Third party that cannot be overridden or if the disclosure is performed under the grounds provided by Article 6 paragraph 1 point (c)-(f) GDPR.

6.4. Brainy Agency may disclose personal data of Data subjects to other categories of Third parties not listed in para.6.3 of the Policy if the disclosure is performed under the legal grounds provided by GDPR or applicable laws of the Republic of Estonia or other jurisdictions.

6.5. Brainy Agency does not and will not sell any personal data of Data subjects to any Third parties or to any other natural persons or legal entities. Brainy Agency has never sold any personal data of Data subjects within the preceding 12 (twelve) calendar months.

6.6. The Website of Brainy Agency may include URL links of the websites and other Internet resources of Third parties and other natural and legal persons. Brainy Agency does not control or govern neither the contents of such websites or Internet resources nor the rules of personal data processing applicable to such websites or Internet resources. It is fully the Data subject’s responsibility to carefully use the websites and the Internet resources the URLs to which are provided on the Website. Brainy Agency does not post URLs of websites or other Internet resources that violate applicable laws.

7. COOKIES AND SIMILAR TECHNOLOGIES

7.1. Cookies or cookie files are small text files located in browser directories that may include an anonymous unique identifier. Generally, there are two types of cookies – a session cookie and a persistent cookie. A session cookie is used to make it easier for a person to navigate a website and expires when a person closes the browser. A persistent cookie remains on the hard drive of a person’s device for an extended period of time. Cookies cannot be used to run programs or deliver viruses to a person’s computer. Cookies are uniquely assigned to a person’s device and can only be read by a web server in the domain that issued the cookie to a person’s device. To learn more about cookies please follow the link: https://en.wikipedia.org/wiki/HTTP_cookie.

7.2. Brainy Agency may use both session cookies and persistent cookies to help Data subjects navigate through the Website and the Services and efficiently perform the functions of the Website. Particularly, the following kinds of cookies may be used by Brainy Agency in accordance with this Policy:

7.2.1. Session Cookies. Brainy Agency may use Session Cookies to operate the Services provided via the Website.

7.2.2. Preference Cookies. Brainy Agency may use Preference Cookies to remember preferences and various settings of the Data subject using the Website.

7.2.3. Security Cookies. Brainy Agency may use Security Cookies for making safe use of the Website.

7.3. By use of cookies, Brainy Agency may automatically collect information about the online activity of the Data subject on the Website. Such information may include:

7.3.1. The information about the web pages of the Website visited by the Data subject.

7.3.2. The URL links clicked by the Data subject on the Website.

7.3.3. The searches made by the Data subject via the Website.

7.4. The Data Subject has the right to accept or decline cookies by using the browser settings. However, if the Data subject declines cookies, the Data subject may not be able to use the full range of functions provided by the Website of Brainy Agency.

7.5. Brainy Agency may also use other technologies for processing personal data provided in para.7.3 of the Policy, including the following:

7.5.1. Web beacons. Web beacons (also known as clear gifs, pixel tags, or web bugs) are tiny graphics with a unique identifier, similar in functions to cookies, and used to track the online movements of website users. Unlike cookies, which are stored on a user’s device, web beacons are embedded invisibly on the web pages of the website or in an email, and the size of such web beacons is about the size of the period at the end of the sentence.

7.5.2. Tracking URLs. A tracking URL is a standard link that has parameters attached to it for the purpose of tracking and analytics. A tracking URL has a unique identifier that allows to identify the source of the website’s traffic (e.g., the location from which the Internet users visit the website or the search engine used by the visitors for clicking the URL of the website).

7.6. Brainy Agency may also use web beacons and tracking URLs prescribed by para.7.5 of the Policy in marketing emails of Brainy Agency (including marketing bulk emailing) and in online advertisements of Brainy Agency posted on third-party websites.

8. IT TALENT AND SOCIAL NETWORKS

8.1. In order to promote information about Brainy Agency, its Services, and the Website, Brainy Agency may create accounts in social networks and messengers, including LinkedIn, Facebook, Instagram, WhatsApp, and Telegram.

8.2. In order to interact with Brainy Agency, Data subjects may follow the accounts of Brainy Agency in social networks and the channels of Brainy Agency in messengers. Data subjects may like posts and comments of Brainy Agency and leave comments, reviews, or reactions under the posts and messages of Brainy Agency in social networks and messengers. Data subjects may also send messages to accounts of Brainy Agency in social networks and messengers.

8.3. The data prescribed by para.8.2 of the Policy is considered as personal data of Data subjects provided in para.2.1.16 of the Policy. Such personal data of Data subjects, depending on the nature of the processed data, may be used by Brainy Agency for the purposes provided by para.3.1, paras.3.2.1-3.2.3, paras.3.2.7-3.2.8, and para.3.3 of the Policy.

8.4. In addition to the personal data provided in para.8.2 of the Policy Brainy Agency may also analyze the profile information of the Data subject published by the Data subject on his or her account in a social network or messenger, subject that such analysis does not violate applicable terms and policies of social networks and messengers. The analysis is performed only in manual mode without the use of any automated decision-making. Such analysis may be performed for achieving the purposes provided in paras.3.2.7-3.2.8 and para.3.3 of the Policy.

8.5. The rules of para.8.4 of the Policy do not apply to the processing of open (public) profiles of the Customers in social networks and messengers provided by para.2.1.8 of the Policy. The processing of such personal data of the Customers may be performed by Brainy Agency for achieving the purposes provided in para.3.1 and para.3.3 of the Policy. The processing is performed only in manual mode without the use of any automated decision-making.

9. RIGHTS OF DATA SUBJECT

9.1. Each Data Subject has the following rights:

9.1.1. Right of access: the Data Subject is entitled to receive from Brainy Agency the information about personal data that is processed by Brainy Agency, the purposes of personal data processing, the categories of personal data recipients, the period of personal data storage, and the information about the transfer of personal data to other jurisdictions.

9.1.2. Right to lodge a complaint with a supervisory authority: the Data Subject is entitled to file a complaint against Brainy Agency with a supervising authority of the Data subject’s habitual residence or place of work or with a supervising authority located in a place of a possible infringement or with a supervising authority of Brainy Agency’s residence which supervises the compliance of Brainy Agency with personal data legislation.

9.1.3. Right to rectification: the Data Subject is entitled to rectification of inaccurate data about the Data subject.

9.1.4. Right to erasure: the Data Subject is entitled to erasure the personal data of the Data subject.

9.1.5. Right to restriction of processing: the Data Subject is entitled to restrict the processing of personal data under the grounds provided for in Article 18 GDPR.

9.1.6. Right to data portability: the Data Subject is entitled to receive personal data about the Data subject in a structured, commonly used, and machine-readable format and transmit such data to another controller.

9.1.7. Right to object: the Data Subject is entitled to object to personal data processing on the grounds relating to a particular situation (for example, if Brainy Agency processes personal data for marketing purposes).

9.1.8. Right not to be subject to a decision based solely on automated processing, including profiling.

9.1.9. Right to file a request or complaint with Brainy Agency acting as the Controller. The such right also includes the right of the Data subject to use judicial remedies against Brainy Agency in a country of Brainy Agency’s or Data subject’s residence under Article 79 GDPR and the right to use judicial remedies against the supervisory authority in a country where the supervisory authority is established (Article 78 GDPR).

9.1.10. Right to withdraw Data subject’s consent to personal data processing.

9.1.11. Right to prohibit sale or resale of Data subject’s personal data.

9.2. If the Data Subject is intending to use one of the rights provided for in para.9.1 of the Policy, the Data subject shall send a mail or an email to Brainy Agency by using the contact details of Brainy Agency provided for in Section 14 of the Policy. If the Data subject desires to lodge a complaint with a supervisory authority against Brainy Agency or use judicial remedies against Brainy Agency or the supervisory authority, the Data subject shall follow the procedures provided by Articles 77-79 GDPR and by the legislation of the country in which the Data subject is planning to lodge a complaint or use judicial remedies.

9.3. If the Data subject requests Brainy Agency to erasure the Data subject’s personal data, objects to the processing of the Data subject’s personal data, exercises the right to data portability, or withdraws the consent to personal data processing, Brainy Agency has the right to refuse provision of the Services or/and terminate the Terms if the provision of the Services is impossible without processing of Data subject’s personal data. In this case, Brainy Agency also has the right to restrict access of the Data subject to the Website if the provision of access to the Website or particular parts of the Website is impossible without processing of the Data subject’s personal data under the Policy.

10. SECURITY OF PERSONAL DATA

10.1. Brainy Agency takes all the reasonable measures to protect the Data subject’s personal data from unauthorized access by third parties, as well as against loss, misuse, alteration, or destruction of personal data, including the following:

10.1.1. The Data subject’s session on the Website goes through the secure SSL connection during the Website browsing.

10.1.2. Only authorized personnel of Brainy Agency have access to the personal data of Data subjects, and these employees and contractors are required to treat this information as confidential.

10.1.3. The Data subject’s personal data is stored on the servers of Brainy Agency and protected by authentication.

10.2. The existing security measures will be reviewed from time to time in accordance with new legislation and technical innovations.

11. STORAGE OF PERSONAL DATA

11.1. Brainy Agency stores the personal data of Data subjects only for the period that is necessary for achieving the purposes of processing provided by Section 3 of this Policy.

11.2. Brainy Agency stores the personal data of the Customers provided in paras.2.1.1-2.1.12 and para.2.1.16 of the Policy for the period of use of the Services by the Customers. If the Customer stops using the Services of Brainy Agency, Brainy Agency has the right to store personal data of such Customer for the period not exceeding 5 (five) years after the Customer stops using the Services. The provided five-year term does not apply if the Customer starts using the Services again before the expiration of the five-year term.

11.3. Brainy Agency stores the personal data of Data subjects provided in para.2.1.15 of the Policy for the period necessary for achieving the purposes of processing provided by Section 3 of the Policy.

11.4. Brainy Agency stores the personal data of Data subjects provided in paras.2.1.13-2.1.14 of the Policy for the period necessary for achieving the purposes of processing provided by para.3.2 and para.3.3 of the Policy.

11.5. Brainy Agency will periodically review the stored personal data provided in para.11.4 and para.11.5 of the Policy. Based on the nature of personal data and the purposes of the processing, Brainy Agency will periodically delete out-of-date personal data that is not necessary for achieving the purposes of processing provided by Section 3 of the Policy.

11.6. Brainy Agency does not store any personal data provided in Section 8 of this Policy.

11.7. If personal data of the Customer using the Services under the Terms for Recruiting Agency is transferred to the Employer in accordance with para.6.3.2 of the Policy, Brainy Agency will take all the reasonable measures to ensure that such Employer does not store personal data of the Customer beyond the reasonable period necessary for achieving the purposes of personal data processing provided in para.6.3.2 of the Policy. However, Brainy Agency does not control the activities of the Employers in any way and cannot guarantee to the Customer that the respective Employer will delete the personal data of the Customer after achieving the purposes of personal data processing.

11.8. Brainy Agency will continue storing the personal data of a Data subject if deletion of such personal data is restricted or prohibited by the Money Laundering and Terrorist Financing Prevention Act of the Republic of Estonia or by other applicable laws and regulations.

12. INTERNATIONAL TRANSFER OF PERSONAL DATA

12.1. Brainy Agency stores the personal data of Data subjects only on the servers located in the Republic of Estonia or/and other countries of EEA (European Economic Area which includes the countries of the European Union plus Iceland, Liechtenstein, and Norway).

12.2. If Brainy Agency takes the organizational decision to store the personal data of Data subjects outside EEA, Brainy Agency will first choose servers located in the countries in respect of which the European Commission made the decision that such countries provide an adequate level of data protection (Article 45 GDPR). Particularly, Brainy Agency may choose such jurisdictions as Switzerland, the United Kingdom, Andorra, Israel, New Zealand. To see the full list of jurisdictions outside EEA that provide an adequate level of data protection please visit the following web-page of the European Commission: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en.

12.3. If it is not possible for Brainy Agency to store the personal data of Data subjects on the servers located in EEA or jurisdictions provided in para.12.2 of the Policy, Brainy Agency will transfer personal data of Data subject to other jurisdictions subject to appropriate safeguards provided in Article 46 GDPR.

12.4. If for some reason it is not possible for Brainy Agency to transfer personal data in accordance with paras.12.1-12.3 of the Policy, Brainy Agency will transfer Data subject’s personal data only subject to the provisions of Article 49 GDPR which provide derogations for specific situations.

Particularly, if a Data subject is a natural person using the Services under the Terms for Recruiting Agency, and it is necessary to transfer the personal data of such natural person outside EEA for the provision of the Services under the Terms for Recruiting Agency, Brainy Agency will perform such a transfer without the prior written consent of the Customer (Article 49 paragraph 1 point (b) and point (c) GDPR).

The same rule will also apply if the Recruiter of Brainy Agency providing the Services under the Terms for Recruiting Agency resides outside EEA, and it is necessary to transfer the personal data of the Customer using the Services of Brainy Agency under the Terms for Recruiting Agency to such HR Specialist for the purpose of providing the Services under the Terms for Recruiting Agency.

Brainy Agency also has the right to transfer the personal data of the Customer using the Services under the Terms for Recruiting Agency to the Employer, if the Employer is located outside EEA, and it is necessary to transfer personal data of the Customer to such Employer for the purpose of providing the Customer with the Services under the Terms for Recruiting Agency. If there are several Employers that may be interested in the Customer as a potential employee of the Employer, IT Talent will take all the reasonable measures to give priority to the Employers located in EEA.

Brainy Agency may also transfer the personal data of the Data subject outside the jurisdictions provided by paras.12.1-12.2 of the Policy if there are legal grounds for transfer provided by Article 49 paragraph 1 point (d)-(g) GDPR.

12.5. If Brainy Agency needs to transfer the personal data of the Data subject outside the jurisdictions provided in paras.12.1-12.2 of the Policy, and the only legal ground for such a transfer is the Data subject’s consent to transfer (Article 49 paragraph 1 point (a) GDPR), Brainy Agency will only perform the transfer after receiving the consent of the Data subject to the proposed transfer of personal data. Such consent may only be obtained from the Data subject after Brainy Agency informs the Data subject about the possible risks of such a transfer caused by the absence of an adequacy decision provided by para.12.2 of the Policy and appropriate safeguards provided by para.12.3 of the Policy. If the Data subject does not provide consent to the transfer of personal data, Brainy Agency may refuse the provision of the Services to such a Data subject or restrict access of the Data subject to the Website if the provision of the Services or provision of access to the Website is impossible without the Data subject’s consent to the international transfer of personal data.

13. CHANGES TO THE PRIVACY POLICY

13.1. Brainy agency shall periodically review this Policy for compliance with applicable data protection laws and will provide the Policy with amendments as Brainy Agency deems necessary. The amendments will be posted on the Website in the form of the updated Policy and will be in effect from the date of publication. The publication of the updated version of the Policy amounts to notification of Data subjects about the changes. Data subjects shall periodically review the Website for amendments in the Policy.

14. CONTACTING IT TALENT

Brainy OÜ

A legal entity incorporated under the laws of the Republic of Estonia

Registration number: 16546221

UID/VAT number: EE102520721

Address: Harju maakond, Tallinn, Kesklinna linnaosa, Vesivärava tn 50-201, 10152 Estonia

Email: [email protected]

Phone: +3725060627