APPLICANTS PRIVACY NOTICE
August 2020

SEPHORA COSMETICS ROMANIA S.A., legal entity constituted according to the Romanian legislation, whose registered office is 165 Splaiul Unirii, 7th floor, TN2 Offices, Bucharest registered in the Commercial Register to the Registry Agency with J40/9300/2000, e-mail: recruitment@sephora.ro [(hereinafter ’Sephora’, ’we’ or ‘our’), attaches great importance to the protection of personal data relating to its applicants (hereinafter ’you’) and acts as data controller of your personal data.

Sephora respects your concerns relating to the protection of your privacy and your personal data. This Applicants Privacy Notice (hereinafter referred to as the “The Privacy Notice”) describes how we use information about you collected when you apply to join Sephora.

This Privacy Notice contains information regarding the nature and the use we make of your personal data, as well as your rights relating to this use.

This Privacy Notice is therefore an important resource for you, helping to ensure that you have a positive and confident experience of Sephora’s handling of your personal data and enabling us to provide accurate and complete answers to any questions you may have and to take account of your wishes in this area.

In order to ensure the protection of your personal data, Sephora has decided to designate a person responsible with data protection (hereinafter ‘ DPR ’), with effect from the 25th of May 2018, namely Mrs. Daniela Drogeanu, who may be contacted at the following address : privacy@sephora.ro. In addition, at Sephora Group level, the person responsible with data protection is Mrs. Bruchet Caroline (hereinafter ‘DPO’).

Changes to the Privacy Notice

We may occasionally modify the terms of this Privacy Notice. In such an event, we shall highlight the change by updating the date indicated at the beginning of this document, which is permanently available for consultation through your applicant space (www.jobs.sephora.com) or any other communication resource related to the Sephora recruitment process. We encourage you to check the Applicant Privacy Notice on a regular basis, in order to stay up-to-date with the procedures implemented by Sephora for processing your personal data, as well as the methods by which you can send us inquiries regarding our use of the data.

Why do we collect your personal data? What is the legal basis and what are the purposes of the data collection?

Sephora collects and processes your personal data for purposes related to human resources, in accordance with the Romanian labour legislation, in order to carry out the employment process and future working relationships in good conditions, as follows:

Under the performance of a contract you are a party to or to take steps to conclude a contract at your request, for the following purposes:             

Management of your application for employment. Your personal data are processed in order to carry out the necessary steps at your request, before the conclusion of a contract, in order to conclude it.

(ii) Management of the job offers for which you may be suited;

Under the necessity of fulfilling our legal obligations, for the following purposes:

(i) for the purpose of fulfilling the legal obligations regarding the archiving of documents and information;

(ii) for the purpose of fulfilling the legal obligations regarding reporting and information to authorities and/or institutions, or other public bodies, in case the disclosure of personal data is required, according to the applicable law;

(iii) for the purpose of taking the necessary security measures according to the applicable regulations regarding the safeguarding and protection of the objectives, assets, values ​​and people, and the risk analyses carried out (such as monitoring and managing the access inside the Sephora stores; or the video surveillance inside the Sephora stores)

(iv) for the purpose of complying with any laws, regulations or practices applicable to Sephora;

Based on the legitimate interests of Sephora, for the following purposes:

          

(i) for the purpose of carrying out studies and statistics, more precisely the compilation of statistics on Sephora employment opportunities. The processing of your personal data for this purpose is necessary to protect our legitimate interest to continuously improve our recruitment practices.

(ii) for the purpose of complying with internal rules and regulations, codes of good practice applicable to Sephora, or to its clients and/or partners;

(iii) for the purpose of exercising and/or safeguarding Sephora's contractual or legal rights and interests, for example in order to protect ourselves in the event of a dispute.

for the purpose of taking the necessary security measures according to the applicable regulations regarding the safeguarding and protection of the objectives, assets, values and people, and the risk analyses carried out (such as monitoring and managing the access inside Sephora or the video surveillance inside  Sephora ). 

In this case, we make sure that we consider the potential impact that the processing of personal data based on this legal basis may have on you. If we find that your fundamental rights exceed our legitimate interest, we will not use your personal data on this legal basis and we may request your consent to continue the processing.

 What type of personal data do we process?

We only process data that is strictly necessary for the purposes described in paragraph 1.

We collect your personal data when you send your curriculum vitae and other documents attached to it, either online or in paper form, or when you apply for employment by indirect means, for example via an agency or recruitment firm, and generally throughout the Sephora recruitment process. For your information there follows a list of the categories of your personal data that we may process, depending on the purposes to be achieved by this processing:

Data relating to your civil status and identity, or contact data, such as: surname and forename, address, e-mail, telephone number, birth date;

Data relating to your educational and professional background, such as : training, professional experience, references, distinctions, certifications;

Data relating to your application (such as the source of recommendation, the application status, the approval of the offer, etc.) and your professional expectations ;

Results of professional evaluations and/or tests ;

Information about your right to work (in the EU or in the country of application );

Public information about your profile on social media platforms (such as LinkedIn, etc.);

Login to the recruitment platform (such as user ID, login data, etc.);

Data on employee history within Sephora or other employers;

Data contained in video images, in the situations in which the interview takes place in the premises of the Sephora  stores;

Other data required to be processed in the context of a recruitment / employment / internship process or in the context of a future employment or collaboration report or that you voluntarily provide us through the CV or documents attached to it.

The information we collect that are required in order to process your application are marked with an asterisk on the forms presented for you to complete on our online recruitment platform. If you do not fill in these mandatory fields, we shall be unable to process your application. In the case of other forms of application, if Sephora is unable to identify the information required in order to process your application, Sephora reserves the right to re-contact you in order to collect the missing information.

Personal data processed through video surveillance systems

The video surveillance systems (cameras) are mainly located in the common areas and spaces through which access is made within the premises, being located in places where they are necessary to ensure the security of the incidents, positioned towards the entrances and exits of the supervised spaces (halls, access stairs, gates and access doors), towards the cash registers, etc. in order to identify the unauthorized persons and for the purpose of physical security and protection of the values and of the people in the unit, including the protection of the values ​​held by you, according to the applicable legal provisions.

 

Surveillance cameras are also placed in Sephora stores, for the purpose of preventing and investigating inappropriate incidents or behaviours, or for preventing and investigating attempted theft or fraud within the stores in question or for special events organized by Sephora.

 

Sephora operates video surveillance systems located in all Sephora stores representing points of business of the company. 

4.         Who can access your personal data ?

Within Sephora, your personal data are only accessible to authorized individuals who need to use them in order to carry out their respective duties and who use them exclusively to carry out these duties.

More specifically:

 Employees in Sephora’s HR department ;

 Senior employees expressly designated with attributions in the recruitment process;

 Employees in Sephora’s recruitment department;

 Employees in Sephora’s IT department, for the purpose of ensuring the technical security and for maintenance.

Sephora does not transfer your personal information to other parties, except when:

- disclosure is necessary in the context of the existing or expected  relationships between you and Sephora, including whether disclosure is necessary for the proper processing of your application or for the proper functioning and management of the recruitment activities within Sephora, the Sephora Group and the LVMH Group, or  

 -we have your agreement in this regard, or  

- Sephora must comply with the obligations imposed by the legislation in force regarding the transmission of data to authorities, agencies, public bodies, or other third parties to which the disclosure of personal data is required.      

Thus, your data may be disclosed to the following persons or entities:

HR Departments of the Sephora Group and/or the LVMH Group responsible for international careers and talent management;

proxies, partners or service providers that work for Sephora and provide Sephora operational services, such as telecommunications, IT, security, data processing, storage, archiving, recruitment and human resources management or other services;

For example, to:

HR Nouveau, in order to provide operational services of recruitment , personnel selection and related verifications; 

service providers that make the recruitment platform and applications available in the workplace. They process your personal data only on our behalf and based on our written instructions.      

for purposes connected to computer systems maintenance, your personal data may be available to employees of certain external IT services providers. These employees will only be able to access your data in order to ensure the security and perform maintenance activities of the information systems. They will fulfil their duties in accordance with Sephora instructions and fully respecting the personal data related legislation.      

Professional advisers, such as experts, accountants, auditors or lawyers.

5.   Where are your personal data processed and stored?

Your personal data are processed, first and foremost, in the European Union , being protected in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance).

As a rule, if necessary according to the above purposes, we transfer data only to countries in the European Union or the European Economic Area. However, as Sephora is part of an international group, in the processing of your personal data for the purposes described in article 2 above, your personal data, mainly your identification and contact details such as name, first name, position, e-mail or telephone can be transferred to organizations within the Sephora Group or the LVMH Group and to external service providers involved in the Sephora recruitment processes, which can be located outside the European Union and more specifically in the following countries: Monaco, Turkey, Serbia, Switzerland, Russia, Kuwait, Saudi Arabia, United Arab Emirates, Qatar, Bahrain, China, Singapore, Hong Kong, Thailand, Malaysia, Indonesia, New Zealand, Australia, India, Philippines, Brazil, Canada and the United States of America, to organizations within the LVMH Group (parent company and subsidiaries) and to external service providers.

 

Given the fact that some of these countries do not ensure an adequate level of protection of personal data, similar to the one within the European Union, Sephora will ensure the protection of your personal data in accordance with the applicable regulations.

These protection measures are supported by:

- the legislation in force in the country of the beneficiary that is considered equivalent to the protection offered within the European Union, if any;

- the mandatory corporate rules (BCR) applicable across all LVMH Group entities;

- contracts concluded with external service providers containing the standard clauses published by the European Commission.

6.   How long do we store your personal data for?

Sephora stores your personal data for the time required to comply with the obligations assumed, respectively for a period equal to the period established by the legal requirements for storing information applicable in our field, the legislation on archiving, as well as other applicable regulations and/or specific provisions , for example:

no more than 1 (one) year from the moment of receiving the CVs, for the data inserted in the CVs, or from the completion  time of the recruitment process, for the data collected during a recruitment process that has not resulted in the recruitment of the candidate, as the case may be;      

according to the applicable legal provisions and depending on the duration of the closed individual work contract, for the data collected during a recruitment process that resulted in the recruitment of the candidate;

video recordings made for security purposes in the context of the time spent in our premises are kept for a maximum period of 30 days, except for cases expressly regulated by law or in duly justified cases.

if Sephora processes your data based on Sephora's legitimate interest, for the duration of the legitimate interest, but not longer than 1 (one) year after the last interaction you had with us.   

At the end of these periods, your personal data is erased or archived, depending on our legal obligations.

7. How is the security of your personal data guaranteed?

Your personal data are protected by technical and organizational measures that comply with the legal provisions and the regulated conditions at the Romanian and European level, and that ensure their security and confidentiality.

 

In particular, Sephora uses protection technologies, such as encryption, authentication and security incident detection, to protect your data processed by the company.

Sephora obtains the written commitment of its service providers and subcontractors to guarantee and implement sufficient security measures that ensure the protection of personal data entrusted to them for processing in accordance with the legal requirements regarding the protection of personal data.

8. Your rights

As specified in the legal provisions applicable in this area, you have the following rights:

8.1 The right to access data relating to you

You have the right to obtain from us a confirmation that personal data relating to you are processed or not, and if so, to access your personal data and relevant information regarding them, such as: processing purposes; the categories of data targeted; the recipients or categories of recipients to whom data have been or are to be disclosed, especially recipients from third countries or international organizations; where possible, the period for which the data are expected to be stored or, if this is not possible, the criteria used to determine this period; or, in case the data is not collected from yourself, any available information regarding their source.

8.2 You have the right to request the rectification of the data, if applicable.

You have the right to obtain from Sephora the rectification of inaccurate personal data concerning you. If you submit a correction request, it must be accompanied by the proof that the data is incorrect. 

Taking into account purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

8.3. You have the right, within certain limits, to erase your data.

You have the right to withdraw your consent on which the processing is based, in case the processing is carried out on the basis of your consent.

You have the right, within certain limits, to request from Sephora the erasure of your personal data , without undue delay, where one of the following grounds applies:

- the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;

 

- you exercise the right to object, on grounds relating to your particular situation, regarding the processing based on the legitimate interest of the Company, including profiling based on those provisions and there are no overriding legitimate grounds for the processing;

- you exercise the right to object at any time when personal data are processed for direct marketing purposes, including profiling, to the extent that it is related to such direct marketing;

- the personal data have been unlawfully processed;

 

- the personal data have to be erased for compliance with a legal obligation to which the Company is subject;

In some instances the law provides for certain limitations in regards of exercising this right, for example, by exception, data can not be erased immediately and  Sephora may refuse the erasure request, if:

   - there is a legal, administrative or judicial obligation that contradicts this request.         

- processing is necessary for the establishment, exercise or defence of legal claims by the Company or for exercising the right to freedom of expression and information.         

8.4. Right to restriction of processing

You have the right to request the restriction of processing where one of the following applies:

you contest the accuracy of the personal data – the restriction will apply for a period enabling the Company to verify the accuracy of the personal data; or

the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead; or

The Company no longer needs the personal data for the purposes of the processing, and you require them for the establishment, exercise or defence of legal claims;

You have objected, on grounds relating to your particular situation, regarding the processing based on the legitimate interest of the Company, including profiling based on those provisions - the restriction will apply for a period enabling the Company to verify whether the legitimate grounds of the controller override those of the data subject.

Where processing has been restricted as per the above, such personal data shall, with the exception of storage, only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of public interest.

8.5 You have the right to data portability

You have the right to request a copy of your personal data which you have provided directly, in a structured, commonly used and machine-readable format.

8.6 Furthermore, you have the right to issue advance instructions regarding the use or disposal of your personal data after your death.

8.7 You have the right to object

You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on the legitimate interest of Sephora. Also, in case the processing is carried out on the basis of your consent, you have the right to withdraw your consent for the processing of your personal data at any time, without being prejudiced in any way.

We invite you to exercise these rights by writing to the following address: recruitment@sephora.ro or by using our contact data specified above. Sephora will provide you with information on the actions taken following a request within one month of receiving the request. According to the applicable legislation, this period can be extended by two months if necessary, taking into account the complexities and the number of applications.

8.8 You have the right to make a complaint

You have the right to make a complaint at any time at The National Supervisory Authority For Personal Data Processing, 28-30 G-ral Gheorghe Magheru Bld., District 1, post code 010336

Bucharest, Romania if you consider that your rights as a data subject were violated. However, we suggest that you first send any information to the person in charge of data protection, so that we can answer your questions and find together solutions that solve the problems you encounter.