Privacy Policy — UTS Group Poland sp. z o.o.
Controller: UTS Group Poland sp. z o.o.
Registered address: Aleje Jerozolimskie 109/70, 02-011 Warsaw, Poland
KRS: 0001190687 · NIP (Tax ID): 7011274414 · REGON: 542536940
Contact: contact@utsgroup.io · postal mail to the registered address
UTS Group Poland sp. z o.o. (“we”, “UTS Group Poland”) provides recruitment and talent advisory services. This Privacy Policy explains how we process personal data of candidates, clients, suppliers, and users of our online services, in accordance with Regulation (EU) 2016/679 (“GDPR”) and Polish data-protection laws.
1) Whose data we process
- Job candidates: identification and contact details; education, qualifications, employment history, skills, preferences, salary expectations; interview notes, assessments, and correspondence.
- Client and prospective client contacts (B2B): name, role, professional contact details, communication history.
- Suppliers/contractors: representative details, professional contact data, invoicing data.
- Website users: technical data (logs, IP/identifiers), cookies/analytics data, and form submissions (e.g., “Apply”, “Contact us”).
We do not request special-category data (e.g., health, beliefs). If you voluntarily include such data, we will restrict/erase it unless processing is legally permitted.
2) Sources of data
- Directly from you (CV/application, email, phone, interviews, events).
- Recruitment portals/ATS tools, referrals, job fairs—within those platforms’ terms.
- Public professional sources (e.g., LinkedIn) to the extent necessary for recruitment.
3) Purposes and legal bases
- Recruitment for a specific role – to assess and present your candidacy at your request:
GDPR Art. 6(1)(b) (steps prior to a contract) and Art. 6(1)(f) (our legitimate interest: selecting candidates and servicing client vacancies). - Talent pool / future vacancies – only with your consent: Art. 6(1)(a).
- Client relationship management, business development (B2B) – Art. 6(1)(f) (maintaining/expanding business relationships).
- Contracting and performance with clients/suppliers – Art. 6(1)(b) and compliance/record-keeping: Art. 6(1)(c).
- Defence of claims, security, audits, reporting – Art. 6(1)(f).
- Marketing of our own services (e.g., newsletters, salary guides) – Art. 6(1)(f); where telecom/anti-spam laws require it, we will obtain Art. 6(1)(a) consent.
- Website operation & cookies – necessary cookies under Art. 6(1)(f); analytics/marketing cookies only with Art. 6(1)(a) consent via the cookie banner.
We do not make decisions producing legal effects solely by automated means. We may use ATS tools for initial filtering, but final decisions are made by consultants.
4) Disclosures (recipients)
- Our clients (potential employers) when we present your candidacy for an agreed role—upon such transfer, the client acts as an independent controller.
- Trusted processors under data-processing agreements: hosting/ATS providers, communications and productivity tools, background-check or testing vendors where applicable, professional advisors, auditors.
- Public authorities and courts where required by law.
5) International transfers
If any processor or group IT system is located outside the EEA, we implement GDPR transfer safeguards (e.g., Standard Contractual Clauses, risk assessments, and additional technical/organizational measures). Details of current safeguards are available on request.
6) Retention periods
- Specific-role recruitment: for the duration of the process and generally up to 12 months after closure (limitation/defence of claims).
- Talent pool / future roles (consent): up to 24 months or until consent is withdrawn.
- Contracts and finance (clients/suppliers): for the contract term and statutory periods (e.g., tax/accounting).
- Website logs/cookies: per cookie type and consent settings shown in our cookie banner.
We will delete or anonymize data after the retention period or if you successfully object (where applicable).
7) Your rights
You have the rights of access, rectification, erasure, restriction, portability, and objection (including to direct marketing), as well as the right to withdraw consent at any time (without affecting prior lawful processing).
You also have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO/UODO) in Poland.
How to exercise your rights: contact us at contact@utsgroup.io or by post (see address). We may verify identity and will respond within one month (extendable per GDPR where complex).
8) Candidate presentations to clients
Before introducing you to a client, we will inform you of the role and client (unless confidentiality applies) and share only data necessary for recruitment. Clients become independent controllers of your data; please refer to their privacy notices for further details.
9) Security
We apply appropriate technical and organizational measures, including access controls, encryption in transit/at rest where feasible, vendor due diligence, secure development and backup practices, and staff training. We review these controls periodically.
10) Minors
Our services are not directed to persons under 16. If we learn that we have collected data from a child, we will delete it.
11) Cookies (summary)
- Necessary cookies: enable core site functionality (legal basis: legitimate interests).
- Analytics/marketing cookies: only with your consent, managed through our cookie banner/Consent Management Platform (CMP).
12) Changes to this Policy
We may update this Policy from time to time. The latest version will be posted at https://utsgroup.io/privacy-policy with the effective date. Material changes may be notified by email or on-site notice.
13) Contact
Controller: UTS Group Poland sp. z o.o.
Aleje Jerozolimskie 109/70, 02-011 Warsaw, Poland (KRS 0001190687, NIP 7011274414, REGON 542536940)
Email: contact@utsgroup.io