Lever’s Privacy Notice
Effective as of 15 May 2019
Lever is committed to protecting your privacy. This Privacy Notice informs you how Lever collects, uses, secures and shares your information (“Personal Data”, as defined under the applicable law) collected by us when you interact with us in the following ways (“Interactions”):
- Visit our websites that display or link to this Privacy Notice;
- Visit our branded social media pages;
- Visit our offices;
- Receive communications from us, including invitations, resources, materials, emails, phone calls, texts or fax;
- Register for, attend or take part in our events, webinars or contests; or
- Ask questions about the recruiting software we provide (“Service”).
If you are a Lever customer that uses the Service, please review the Service’s Privacy Notice. Personal Data does not include information that has been anonymized or aggregated so the information cannot be traced to a specific individual. If you do not feel comfortable with any part of this Privacy Notice, please cease your Interactions with us.
Please note that our website may include links to other organizations’ websites whose privacy practices may differ from those of Lever. If you submit Personal Data to any of those sites, your information is governed by their privacy notices. We encourage you to carefully read the privacy notices of any website you visit.
1. Changes to Our Privacy Notice
This Privacy Notice may change from time to time. If we make a change to this Privacy Notice that we believe materially affects how we process your Personal Data, we will provide notice of such change on our website. By continuing your Interactions after those changes become effective, you accept the provisions of our revised Privacy Notice.
In addition, we may provide you with “just-in-time” disclosures or additional information about the data collection, use and sharing practices. These notices may provide more information about our privacy practices, or provide you with additional choices about how we process your Personal Data. The notices and information are subject to this Privacy Notice unless specifically indicated otherwise in the notice.
2. The Information We Collect and Store
Except as described in this Privacy Notice, Lever will not give, sell, rent or loan any Personal Data to any third party. We may collect and process the following Personal Data in connection with our Interactions with you:
- Personal Data You Voluntarily Provide. We will collect Personal Data when you voluntarily provide it to us (including to our service providers or other parties who collect it on our behalf). For example, we collect Personal Data when you request information about our Service, subscribe to marketing communications, complete surveys, or sign up for a Lever event or webinar. We may also collect Personal Data from you offline, such as when you attend one of our events, or during phone calls with sales representatives. The Personal Data we collect may include contact information (such as your name, address, telephone number or email address), professional information (such as your job title, department or job role), and contact preferences. We also collect information you choose to provide to us when requesting information or completing any “free text: boxes in our forms (for example, for event sign-up), or the nature of your request or communication.
- Log Data. When you use the Service, we automatically record information from your device, its software, and your activity using the Service (“Log Data”). This may include the device’s Internet Protocol (“IP”) address, browser type, the web page visited before you came to our website, information you search for on our website, locale preferences, identification numbers associated with your devices, your mobile carrier, date and time stamps associated with transactions, system configuration information, metadata concerning your Files, and other interactions with the Service. We may use your IP address to identify the general geographic area from which you are accessing the website. While an IP address may reveal your ISP or geographic area, we cannot determine your identity solely based upon your IP address.
- Location Data. We may collect geolocation and proximity of your device if location services are enabled on your device ((e.g., GPS-based functionality on mobile devices used to access our website), and may use that information to customize the Interactions with location-based information and features. If you access our website through a mobile device and you do not want your device to provide us with location-tracking information, you can disable the GPS or other location-tracking functions on your device, provided your device allows you to do this.
3. Third Party Sources of Information
We collect information about you from the following third-party sources:
- Third-Party Services. You may choose to register events sponsored by our partners where we will share your information with our marketing partners. To engage in marketing activities, we may collect Personal Data disclosed by you on message boards, chat features, blogs and other services or platforms to which you are able to post information and materials (including third party services and platforms). We process such information to better understand you, to maintain and improve the accuracy of the information we store about you, and to better promote or optimize our Interactions with you, including providing information about our Service.
4. How We Use Personal Data
Your Personal Data may be used for the following purposes:
- Respond to Requests.We may process your Personal Data when you contact us, such as with questions, concerns, feedback, disputes or issues, to respond to your request or provide information requested by you. We share this information with third parties upon your request, or our service providers or partners to the extent necessary to facilitate the Interactions. Without your Personal Data, we cannot respond to you or ensure your continued use and enjoyment of the website.
- Ensure the Security of the Service.We are committed to ensuring your safety and continued enjoyment of our website. To do so, we may process your Personal Data to help monitor, prevent and detect fraud, enhance security, monitor and verify identity or access, and combat spam or other malware or security risks. combat spam, malware, malicious activities or security risks; improve and enforce our security measures; and to monitor the security of our website.
- Facilitate and Evaluate Use of the Online Properties. We may use your Personal Data to provide you with the online services, to facilitate your use of the online services (such as facilitating navigation and the login process, preserving information between sessions and enhancing security), to improve quality, to evaluate page response rates and determine content.
- Improve the Accuracy of our Records. We may use the Personal Data we receive from you or third parties to better understand you and/or maintain and improve the accuracy of the records we hold about you.
- Post Testimonials. We may use Personal Data to post testimonials on our website. Prior to posting a testimonial, we will obtain your consent to use your name and testimonial. You can request your testimonial be updated or deleted at any time by sending a request with your name, testimonial location and contact information.
- Marketing: We may use information we obtain from you, your interactions with Lever and our website, and from third party sources to provide you with marketing and promotional communications, to deliver targeted and relevant advertising and marketing to you, to determine the effectiveness of our marketing and promotional campaigns, to better understand you and your preferences, and to position and promote our Services. Our marketing will be conducted in accordance with your advertising / marketing preferences and as permitted by applicable law.
- Quality Control and Training. Lever may use or access Personal Data for the purposes of quality control related to the website and staff training.
- Conferences and Events. Lever and our partners may use Personal Data to communicate with you about our events or our partner events. After the event, Lever may contact you about the event and related products and services, and may share information about your attendance with your company and our conference sponsors and partners, where legally permitted to do so. If a partner or conference sponsor directly requests your Personal Data at their conference booths or presentations, your Personal Data will be handled in accordance with their privacy practices. We recommend that you review the privacy practices of such partners and sponsors.
- Provide Online Communities and Blogs: We may use Personal Data and other information disclosed by you on our message boards, chat features, blogs and other services or platforms to which you are able to post information and materials for the purposes of providing you and our customers with a forum to discuss our Services, responding to your request, providing you with support, improving our website or any other purposes set forth in this Privacy Notice. Any information that is disclosed in those forums becomes public information and may therefore appear in public ways, such as through search engines or other publicly available platforms, and may be “crawled” or searched by third parties. It could also be read, collected or used by other users to send you unsolicited messages. Please do not post any information that you do not want to reveal to the public at large.
- Other Legitimate Business Purposes. We may use your Personal Data when it is necessary for other legitimate purposes such as protecting Lever’s confidential and proprietary information.
If, in the future, we use your Personal Data in any way that is not described in this Privacy Notice, we will disclose this to you. At that time, you can choose not to allow us to use your Personal Data for any purpose that is incompatible with the purposes for which we originally collected it or subsequently obtained your consent. If you choose to limit the ways we can use your Personal Data, some or all of the website may not be available to you, and we may not be able to interact with you.
5. Information Sharing and Disclosure
We only disclose your Personal Data to those who really need access to perform their tasks and third parties who have a legitimate purpose for accessing it. We may share Personal Data with third parties in the following situations:
- Service Providers, Business Partners and Others.We may share your Personal Data with third parties, such as vendors, consultants, agents and other service providers who work on our behalf. Examples include vendors and service providers who provide assistance with marketing, billing, processing credit card payments, data analysis and insight, technical support and customer service. Unless described in this Privacy Notice, we do not share, sell, rent, or trade any of your Personal Data with third parties for their own promotional purposes.
- Compliance with Laws and Law Enforcement Requests; Protection of Lever’s Rights.We may use or disclose Personal Data stored in your Lever account and other Personal Data about you to third parties when we have a good faith belief that disclosure is reasonably necessary to: (a) comply with a law, regulation or legal requests including to meet national security or law enforcement requirements; (b) protect the safety of any person from death or serious bodily injury; (c) prevent fraud or abuse of Lever or its user, or (d) protect Lever’s property rights.
- Vital Interests: We may disclose information when we believe it necessary to protect the vital interests of any person.
- Business Transfers. If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction, but we will notify you (for example, via email and/or a prominent notice on our website) of any change in control or use of your Personal Data, or if either become subject to a different Privacy Notice. We will also notify you of choices you may have regarding the information.
- With Your Consent: We may disclose your Personal Data for any purpose with your consent.
6. Marketing Opt Out and Choice
If you sign up to receive marketing or informational announcements from us, such emails will include the capability to opt-out of receiving such e-mails in the future. Marketing and informational announcements include any communications to you that are only based on advertising or promoting products and services. Transactional communications about an Interaction, or our Services are not considered “marketing” or “informational” communications.
7. Transfer of Personal Data
If you Interact with us or provide your Personal Data to us, your Personal Data may be transferred to, processed and maintained on servers or databases located outside of the country or jurisdiction where you are located. Such countries or jurisdictions may have data protection laws that are less protective than the laws of the jurisdiction in which you reside. If you do not want your Personal Data transferred to or processed or maintained outside of the country or jurisdiction where you are located, you should not use this website, our resources, or the Services.
If you are located in the European Economic Area (“EEA”), the United Kingdom or Switzerland, we comply with applicable laws to provide an adequate level of data protection for the transfer of your Personal Data to the US. Lever is certified under the EU-U.S. and the Swiss-U.S. Privacy Shield Framework and adheres to the Privacy Shield Principles. For more, see Section 16 below.
Where applicable law requires us to ensure that an international data transfer is governed by a data transfer mechanism, we use one or more of the following mechanisms: EU Standard Contractual Clauses with a data recipient outside the EEA, verification that the recipient has implemented Binding Corporate Rules, or verification that the recipient adheres to the EU-US and Swiss-US Privacy Shield Framework.
The security of your Personal Data is important to us. We employ appropriate technical and organizational measures to ensure a level of security that is appropriate for our Interactions with you. We follow generally accepted standards to protect the Personal Data submitted to us, both during transmission and once we receive it. No method of electronic transmission or storage is 100% secure, however. Therefore, we cannot guarantee its absolute security. If you have any questions about security on our website, you can contact us at email@example.com.
9. Accessing or Updating Your Personal Data
If you would like to correct or update the Personal Data you provided to us in relation to our Interactions with you or in connection with our Service, please contact firstname.lastname@example.org. We will use responsible efforts to respond to your inquiry as soon as practicable. When updating your Personal Data, we may ask you to verify your identity before we can act on your requests.
Individuals located in the European Economic Area, Switzerland, or the United Kingdom during data collection, or that are California residents should refer to the relevant sections below for more information about their access, correction and other rights in relation to their Personal Data.
10. Data Retention
We may retain and use your Personal Data as necessary to comply with our legal obligations, or resolve disputes. Consistent with these requirements, we will try to delete your Personal Data within the time limits imposed by applicable law, if any upon request. When we have no justifiable business need to process your Personal Data, we will either delete or anonymize it, or, if this is not possible (for example, because your Personal Data has been stored in backup archives), then we will securely store your Personal Data and isolate it from any further processing until deletion is possible.
While retention requirements can vary by country, we generally apply the retention periods noted below.
- Marketing. We store Personal Data used for marketing purposes indefinitely until you unsubscribe. Once you unsubscribe from marketing communications, we add your contact information to our suppression list to ensure we respect your unsubscribe request.
- Telephone Records. As required by applicable law, we will inform you that a call will be recorded before doing so. Any telephone calls with you may be kept for a period of up to six years.
11. Our Policy Toward Children
Our website and Services are not directed to persons under 18. We do not knowingly collect Personal Data from children under 18. Any individuals under the age of 18 must have consent to Interact with us or use the Services from their parent or guardian. If a parent or guardian becomes aware that his or her child has provided us with Personal Data without their consent, he or she should contact us at email@example.com. If we become aware that a child under 18 has provided us with Personal Data, we will take steps to delete such information from our files.
12. California Privacy Rights
A business subject to California Civil Code section 1798.83 is required to disclose to its California customers, upon request, the identity of any third parties to whom the business has disclosed Personal Data information within the previous calendar year, along with the type of Personal Data disclosed, for the third parties’ direct marketing purposes. Please note that under California law, businesses are only required to respond to a customer request once during any calendar year. If you are a California resident and would like to make either type of request described above, please contact us at firstname.lastname@example.org.
13. Additional Rights for Individuals in the EEA, UK or Switzerland
This section only applies to Interactions with individuals who are in the European Economic Area, United Kingdom or Switzerland (collectively, the “Designated Countries”) at the time of data collection.
We may ask you to identify which country you are in when you Interact with us, or we may rely on your IP address to identify which country you are located in. When we rely on your IP address, we cannot apply the terms of this section to any individual that masks or otherwise hides their location information from us so as not to appear located in the Designated Countries. If any terms in this section conflict with other terms contained in this Notice, the terms in this section shall apply Designated Countries users.
Lever is a data controller with regard to any Personal Data collected from users pursuant to an Interaction. A “data controller” is an entity that determines the purposes and the manner in which the Personal Data is processed. Any third parties that handle your Personal Data in accordance with our instructions are our service providers and are “data processors.” You are a “user.” Users are individuals providing Personal Data to us via an Interaction, such as signing up for our newsletter(s), or otherwise accessing or using our resources that we provide.
Marketing. We will only contact individuals located in the Designated Countries by electronic means (including email or SMS) based on our legitimate interests, as permitted by applicable law, or the individual’s consent. To the extent we can rely on legitimate interest under the applicable law, we will only send you information about our Services and other materials that are similar to those which were the subject of a previous Interaction with you. If you do not want us to use your Personal Data in this way please go to the email settings for your account to opt out, click an unsubscribe link in your emails, or contact us at email@example.com. You can object to direct marketing at any time and free of charge
Additional Privacy Rights. We provide you with the rights described below when you Interact with us. We may limit these privacy rights requests (a) where denial of access is required or authorized by law, (b) when granting access would have a negative impact on others’ privacy, (c) to protect our rights and properties, or (d) where the request is frivolous or burdensome. If you would like to exercise your rights under applicable law, please contact us at firstname.lastname@example.org. We may seek to verify your identity when we receive your privacy rights request to ensure the security of your Personal Data.
- Right to withdraw consent.For any consent-based processing of your Personal Data, you have the right to withdraw your consent. A withdrawal of consent will not affect the lawfulness of our processing or the processing of any third parties based on consent before your withdrawal.
- Right of access/right of portability.You may have the right to access the Personal Data that we hold about you, and in some limited circumstances, have the Personal Data provided to you so that you can provide that Personal Data to another controller.
- Right to rectification. You may request to correct any of your Personal Data in our files.
- Right to erasure. In certain circumstances, you may have a right to the erasure of your Personal Data that we hold on you.
- Right to restriction.You have the right to request that we restrict our processing of your Personal Data win certain circumstances.
- Right to object to processing.You have the right to object to our processing at any time and as permitted by applicable law if we process your Personal Data on the legal bases of: consent; contract; or legitimate interests. We may continue to process your Personal Data if it is necessary for the defense of legal claims, or for any other exceptions permitted by applicable law.
- Notification to third parties.When we fulfill your individual rights requests for correct (or rectification), erasure or restriction of processing, we will notify third parties also handling the relevant Personal Data unless this proves impossible or involves disproportionate effort. Upon your request, we will identify such third parties.
- Right to Lodge Complaint. In compliance with the Privacy Shield Principles, we commit to resolve complaints about our collection or use of your Personal Data. European Union and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact Lever at email@example.com.
If you have questions, or would like to exercise any of the above rights you may reach our Data Protection Officer (“DPO”) at firstname.lastname@example.org or our EU member representative VeraSafe by using this contact form: https://www.verasafe.com/privacy-services/contact-article-27-representative or via telephone at: +420 228 881 031.
The EU-U.S. and Swiss-U.S. Privacy Shield Frameworks. Lever complies with the EU-U.S. and the Swiss-U.S. Privacy Shield Frameworks as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of Personal Data transferred from the European Union and Switzerland to the United States. Lever has certified to the Department of Commerce that it adheres to the Privacy Shield Principles. The Federal Trade Commission has jurisdiction over Lever’s compliance with the Privacy Shield.
If there is any conflict between the terms in this Privacy Notice and the Privacy Shield Principles, the Privacy Shield Principles shall govern. In the context of an onward transfer, Lever has responsibility for the processing of Personal Data it receives under the Privacy Shield and subsequently transfers to a third party acting as an agent on its behalf. To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/.
If you are a European data subject with an unresolved complaint or dispute arising under the requirements of the Privacy Shield Framework, we agree to refer your complaint under the Framework to an independent dispute resolution mechanism. Our independent dispute resolution mechanism is the International Centre for Dispute Resolution (“ICDR”), operated by the American Arbitration Association (“AAA”). For more information and to file a complaint, you may contact the International Centre for Dispute Resolution by phone at +1.212.484.4181, or by visiting the website http://go.adr.org/privacyshield.html,
Please note that if your complaint is not resolved through these channels, under limited circumstances, a binding arbitration option may be available before a Privacy Shield Panel. You also have a right to lodge a complaint with a competent supervisory authority situated in a Designated State of your habitual residence, place of work, or place of alleged infringement.
Legal Bases for Processing Personal Data. Our legal bases for collecting and using the Personal Data described above will depend on the type of Personal Data collected, the specific context in which we collect it and the purposes for which it is used. We rely on the following legal bases under the European Union’s General Data Protection Regulation in processing your Personal Data.
Section & Purposes of Processing
Legal Basis for Processing
5(a) Respond to Requests
6(a) Service Providers, Business Partners and Others
Processing is based on our contract obligations or to take steps at the request of the individual prior to entering into a contract.
5(c) Facilitate and Evaluate Use of the Website
5(d) Improve the Accuracy of our Records
5(f) Personalize your Experience
5(h) Quality Control and Training
5(i) Conferences and Events
5(j) Provide Online Communications and Blogs
5(k) Other Legitimate Purposes
Processing is based on our legitimate interest to better understand you, to maintain and improve the accuracy of the information we store about you, and to better promote or optimize our Services.
5(e) Post Testimonials
6(e) With Your Consent
Processing is based on your consent.
5(b) Ensure the Security of the Service
6(b) Compliance with Laws and Law Enforcement Requests; Protection of Lever’s Rights
6(c) Vital Interests
6(d) Business Transfers
Processing is necessary for compliance with our legal obligations, the public interest, or in your vital interests.
14. Contacting Us
If you have any questions or complaints about this Privacy Notice, please contact Lever’s DPO at email@example.com or send physical mail to:
155 5th Street, 6th Floor
San Francisco, California 94103
Attention: Lever DPO