This Privacy Notice (together with any other documents referred to herein) sets out the basis on which the personal data collected from you, or that you provide to HackTheBox, will be processed by HackTheBox in connection with HackTheBox’s recruitment processes. Please read the following carefully to understand HackTheBox’s views and practices regarding your personal data and how HackTheBox will treat it.
For the purpose of the General Data Protection Regulation (“GDPR”) ”) and the version of the GDPR retained in UK law (the “UK GDPR”) the Data Controller is:
For UK candidates employees: Hack The Box Ltd., a company incorporated in England and Wales with registered number 10826193 whose registered office address is 38 Walton road, Folkestone, Kent CT18 5QS.
For Greece candidates employees: HackTheBox SMPC, a single member private company incorporated in Greece with company number 149655201000 whose registered office address is Ippokratous 53, Elliniko, Attiki, 16777.
HackTheBox uses Workable, an online application provided by Workable Software Limited, to assist with the recruitment process. Workable processes personal data as a data processor on behalf of HackTheBox and only in accordance with HackTheBox’s instructions.
This notice explains how HackTheBox processes your personal data in respect of the recruitment process.
You should note that when you apply via an application, function, online service provider such application or provider may retain and process your personal data and you should be informed of their privacy practices via their privacy notice.
Information that you provide when you apply for a role.
This includes information provided through an online job site, via email, in person at interviews and/or by any other method. In particular, HackTheBox process personal details such as name, email address, address, telephone number, date of birth, qualifications, experience, information relating to your employment history, skills experience that you provide to HackTheBox, as well as your video in case you conduct your interview using the Video Interview feature.
If you contact HackTheBox, a record of that correspondence may be kept.
A record of your progress through any hiring process that we may conduct.
Information We Collect From Other Sources
Workable provides HackTheBox with the facility to link the data you provide to HackTheBox, with other publicly available information about you that you have published on the Internet – this may include sources such as LinkedIn and other social media profiles.
We may receive your personal data from a third party who recommends you as a candidate for a specific job opening or for our business more generally.
Personal data within the recruitment process will be used for the assessment of your application and, if an employment relationship is established, also for the execution of the employment relationship.
When information is obtained from your public profile on professional social networks, such as LinkedIn, we base this processing on HackTheBox’s legitimate interest to build a decision base in order to establish an employment relationship with you.
Furthermore, your personal data may be processed where this is necessary to defend ourselves against legal claims arising from the application process that are brought against us.
When your consent is requested the lawful basis shall be your consent which you can freely withdraw at any time by contacting HackTheBox.
We use information held about you in the following ways:
Your information is shared to Workable, who processes such information according to the law.
Where you have applied to a job opening through another service provider, we may disclose data similar to the Disposition Data defined above to such service provider. The service provider shall be the data controller of this data and shall therefore be responsible for complying with all applicable law in respect of the use of that data following its transfer by Us.
We take appropriate measures to ensure that all personal data is kept secure including security measures to prevent personal data from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal data to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where We are legally required to do so.
Unfortunately, the transmission of information via the internet is not completely secure. Although We will do Our best to protect your personal data, We cannot guarantee the security of your data transmitted through any online means, therefore any transmission remains at your own risk.
Your personal data are processed and stored at Workable Services.
Furthermore your data may be transferred to, and stored at, a destination outside the UK or the European Economic Area ("EEA"). It may also be processed by HackTheBox staff operating outside the UK or the EEA.
Subject to any legal or regulatory obligations, we will hold all the data for two (2) years, unless you delete or request the deletion of your personal data earlier.
Under the General Data Protection Regulation and the UK GDPR, you have a number of important rights free of charge. In summary, those include rights to:
You may exercise any of the above rights either by the user interface or by submitting a written request to the email: [email protected]. In order to process your request you must provide enough information to identify you. Response to such a request can be expected within one (1) month following reception of a properly identifiable request.
We hope that by contacting HackTheBox at [email protected] any query or concern you raise about your personal data will be resolved.
Nevertheless you have the right to complain to the competent Data Protection Authority.
For UK candidates employees: The supervisory authority in the UK is the Information Commissioner who may be contacted at https://ico.org.uk/make-a-complaint or telephone: 0303 123 1113.
For Greece candidates employees: The supervisory authority in Greece is the Hellenic DPA who may be contacted at https://www.dpa.gr/en/individuals/complaint-to-the-hellenic-dpa or telephone: +30-210 6475600
If you want to receive notifications about changes in our
Terms & Policies, subscribe here.