- Solutions
- Products
- Community
- Resources
- Company
Contents
How We Obtain Your Personal Data
How We Share Your Personal Data
Legal Basis for Processing Personal Data
Security and Data Breach Notification
Cookies and Similar Technologies
How We Treat Do Not Track Signals
Effective Date: September 16, 2024
Please note, this Privacy Notice is available at www.icims.com and its related domains and subdomains, including, but not limited to, www.icims.com/en-gb/ (each the “Website” as applicable). iCIMS maintains other privacy notices to address specific use cases applicable to iCIMS, which are available at the following locations:
The purpose of this notice is to give you a better understanding of who we are and our practices with respect to your personal data.
Read more +
iCIMS, Inc. and its subsidiaries, iCIMS International, LLC, TextRecruit, Inc., Opening HR Limited, EasyRecrue S.A.S., Altru Labs, Inc., Candidate ID Ltd, and SkillSurvey, Inc. (collectively, “iCIMS,” “we,” or “us”), respects the privacy of its job applicants and individuals interested in potential employment opportunities with iCIMS (“you”), and we are committed to protecting their personal data. To that end, we have put together this Talent Acquisition Privacy Notice (“Privacy Notice”) to give you a better understanding of who we are and our practices with respect to the collection, use, disclosure, and retention of personal data obtained in connection with applying for a job at iCIMS and iCIMS’ recruitment process.
For purposes of this Privacy Notice:
Please take the time to read this Privacy Notice and the related statements in their entirety to ensure you are fully informed. If you have any questions or concerns about our processing of your personal data, please contact us by using the contact details under the “Contact Information” heading below.
iCIMS complies with your local privacy laws.
Read more +
This Privacy Notice is a general guide on how iCIMS processes your personal data. As such, you should be aware that data protection and privacy laws can vary in different jurisdictions where iCIMS operates. iCIMS’ policy is to comply with applicable laws, including requirements in certain countries that iCIMS notify individuals in that country of its personal data practices, and in some cases, obtain consent to those practices.
Where applicable laws are stricter than the practices described in this Privacy Notice, iCIMS has adopted specific privacy practices in those locations to satisfy those stricter requirements.
iCIMS collects your personal data as you apply to a job at iCIMS, including the following data:
iCIMS collects your personal data in a variety of ways, including through:
As further described below, we collect personal data from you in connection with your job application with iCIMS and iCIMS’ recruitment and onboarding processes, which includes the following:
iCIMS may collect this information in a variety of ways, including from application forms, CVs or résumés, identity documents, third parties (such as for references or background checks, or from recruiters), or through interviews or other forms of assessment.
If we ask you to provide any other personal data not described above, then the personal data we will ask you to provide, and the reasons why we ask you to provide it, will be made clear to you at the point we collect it. If we ask you to provide personal data that we consider to be mandatory for us to administer your relationship with us, we will inform you of such at the time of collection. In addition, we will also inform you of the consequences for not providing us with the mandatory personal data.
iCIMS uses your personal data as part of the recruitment process, including to:
Our processing of personal data includes automated methods of processing, including machine learning, artificial intelligence, and generative intelligence capabilities.
iCIMS uses your personal data for the purposes of carrying out its job application, recruitment, and onboarding processes. Such uses include:
Our processing of Personal Data for the purposes described in this Talent Acquisition Privacy Notice also includes the use of automated methods of processing, including machine learning, artificial intelligence, and generative intelligence capabilities. to analyze your Personal Data, determine trends, or create AI-generated responses or other content. When you interact with the chatbot in hiring software, we may also store the transcript for the purposes described in this Talent Acquisition Privacy Notice.
If you are offered and accept employment with iCIMS, the personal data collected during the job application, recruitment, and onboarding processes may become part of your employment record.
If we need to process your personal data for an incompatible purpose not discussed in this Privacy Notice, we will provide notice to you and, if required by law, seek your consent. We may process your personal data without your knowledge or consent only where required by applicable law.
iCIMS does not sell your personal data.
We may share your personal data with those who need access to perform their duties, including:
iCIMS takes care to allow your personal data to be accessed only by those who need such access to perform their tasks and duties, and to third parties who have a legitimate purpose for processing or accessing it. As such, we may share your personal data as described in this Privacy Notice to the following categories of recipients:
Please note that we do not sell (as defined in applicable data protection and privacy laws) your personal data (and will not sell it without providing any required notices and/or opt-in/opt-out rights).
Our legal basis for processing your personal data vary based on the data and the context. However, we normally process your personal data according to the following legal bases:
If you are a resident of the “EEA” or the UK, our legal basis for collecting and using the personal data described above will depend on the personal data concerned and the context in which we collect it. However, we will normally collect and/or process your personal data pursuant to one or more of the following legal bases:
If we ask you to provide personal data to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and let you know whether the provision of your personal data is mandatory or not (as well as the possible consequences if you do not provide it). Similarly, if we collect and use your personal data in reliance on our legitimate interests (or those of a third party) that are not listed above, we will make clear to you at the relevant time what those legitimate interests are. If you have questions about or need further information concerning the legal basis on which we collect and use your personal data, please contact us using the contact details provided in the “Contact Information” section below.
iCIMS transfers personal data to other countries in accordance with applicable privacy laws. For transfers outside of the EEA or UK, iCIMS will implement appropriate safeguards to protect your personal data, including Standard Contractual Clauses.
Read more +
iCIMS or its appointed service providers or contractors may collect, use, process, store and disclose your personal data outside of your home jurisdiction, including in the U.S., and in some cases, other countries, for the purposes described in this Privacy Notice. These countries may have data protection and privacy laws that are different than the laws of your home country. iCIMS only transfers personal data to another country in accordance with applicable data protection and privacy laws, provided there are legally adequate protections in place for the personal data. A list of iCIMS’ global offices is available here.
If your personal data is processed within the EEA or UK, and for onward transfers of personal data to iCIMS’ appointed service providers or contractors, iCIMS and its appointed service providers or contractors, will protect your personal data (as defined in the European Union’s (“EU”) General Data Protection Regulation (“GDPR”)) when it is transferred outside of the EEA or UK by:
If you require further information about our international transfers of personal data, please contact us by using the contact details under the “Contact Information” heading below.
iCIMS complies with the EU-U.S. Data Privacy Framework (DPF) and the UK Extension.
iCIMS is committed to maintaining its DPF certification and will honor its obligation to comply with the DPF Principles. EEA and UK individuals with inquiries or complaints regarding our privacy practices should first contact iCIMS as provided in the “Contact Information” heading below.
iCIMS, Inc. and certain of its subsidiaries listed here comply with the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”) and the UK Extension to the EU-U.S. DPF as set forth by the U.S. Department of Commerce. iCIMS has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (“EU-U.S. DPF Principles”) with regard to the processing of personal data received from the EEA in reliance on the EU-U.S. DPF and from the UK (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. If there is any conflict between the terms in this Privacy Notice and the EU-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (“DPF”) program, and to view our certification, please visit https://www.dataprivacyframework.gov .
iCIMS is responsible for the processing of personal data it receives, under the DPF and subsequently transfers to a third party acting as an agent on its behalf. iCIMS complies with the DPF Principles for all onward transfers of personal data from the EEA and UK, including the onward transfer liability provisions.
Although iCIMS also relies on Standard Contractual Clauses or other lawful transfer mechanisms approved by the European Commission (or other relevant governmental authority) to transfer personal data from the EEA and UK, iCIMS is committed to maintaining its DPF certification and will honor its obligation to comply with the DPF Principles.
The Federal Trade Commission has jurisdiction over iCIMS’ compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. In certain circumstances, iCIMS may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
EEA and UK individuals with inquiries or complaints regarding our privacy practices should first contact iCIMS as provided in the “Contact Information” section below. In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, iCIMS commits to cooperate and comply with the advice of the panel established by the EU data protection authorities (“DPAs”) and the UK Information Commissioner’s Office (“ICO”) and the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) and the Gibraltar Regulatory Authority (GRA) with regard to unresolved complaints concerning our handling of human resources data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF in the context of the employment relationship.
For complaints regarding DPF compliance not resolved by any of the other DPF mechanisms, you have the possibility, under certain conditions, to invoke binding arbitration. Further information can be found on the official DPF website.
iCIMS maintains appropriate safeguards to protect personal data from accidental, unlawful, or unauthorized access. Our personnel and service providers are required to keep personal data confidential and secure.
iCIMS has a dedicated team responsible for monitoring and responding to security events.
Read more +
iCIMS maintains appropriate technical and organizational measures, including, but not limited to, reasonably designed administrative, physical, and technical safeguards, designed to protect the personal data obtained as discussed in this Privacy Notice from accidental or unlawful destruction, loss, alteration, unauthorized disclosure and access. iCIMS personnel, service providers, and contractors with access to personal data collected as discussed in this Privacy Notice are required to keep such personal data confidential and secure. iCIMS has a dedicated team responsible for monitoring and responding to security events, and it notifies applicable parties of security or privacy incidents and data breaches in accordance with its incident response procedures and applicable law.
We will retain your data for as long as is needed to fulfill the purpose, after which we will either delete or anonymize it.
We reserve the right to use anonymous data for any legitimate business purpose without further notice to you or your consent.
Read more +
Unless a longer retention period is required by law, we will retain your personal data for as long as is needed to fulfill the purposes outlined in this Privacy Notice or for as long as we have a legitimate business interest that is not outweighed by your data protection interests or fundamental rights and freedoms. When we have no ongoing legitimate business need to process your personal data, we will either delete or anonymize it or, if this is not possible (e.g., because your personal data has been stored in backup archives), then we will securely store your personal data and isolate it from any further processing until deletion is possible. As such, we reserve the right to use such anonymous data for any legitimate business purpose without further notice to you or your consent.
For information about the cookies and other tracking technologies used by our Website and how to manage your settings for these cookies and technologies, please see our Cookie Notice.
To exercise any of your privacy rights such as the right to access or delete your personal data, please contact us by using the contact details under the “Contact Information” heading below.
If you are a California resident, please see our Privacy Notice for California Residents for additional disclosures and information.
Read more +
Certain jurisdictions may provide you with privacy rights under applicable data protection or privacy law regarding your personal data. In particular, you may have the right to:
These rights may be limited, for example, if fulfilling your request would reveal personal data about another individual, or if you ask us to delete personal data which we are required by law to keep or which we need to defend claims against us.
If you are a California resident, please see our Privacy Notice for California Residents for additional disclosures and information about the personal data we have collected about you over the last 12 months and rights you may have regarding your personal data.
If you do not wish to receive our email marketing communication for promotional purposes, you may opt‑out by clicking on the “unsubscribe” or “opt‑out” link in the marketing e‑mails we send you.
If we process your personal data in reliance upon your consent, you can contact us at any time to withdraw your consent.
To exercise any of these rights, please contact us by using the contact details under the “Contact Information” heading below.
We will respond to such requests in accordance with the requirements of applicable data protection laws. Please note that in order to fulfil your request, we may need you to provide certain personal data to verify your identity. Depending upon applicable data protection and privacy law, individuals may also designate an authorized agent to exercise these rights on their behalf.
We do not currently commit to respond to browser “do not track” signals.
Read more +
Various browsers (i.e., Internet Explorer, Chrome, Firefox, Edge, etc.) allow a “do not track” (DNT) setting, which sends a signal to websites visited by an individual about their browser DNT setting. At this time, there is no general agreement on how companies, like iCIMS, should interpret DNT signals. Therefore, we do not currently commit to respond to DNT signals. We will continue to monitor developments around DNT browser technology and the implementation of a standard.
This notice does not apply to any external or third-party links.
Read more +
This Website may link to websites that are not owned or controlled by iCIMS. As such, this Privacy Notice does not apply to personal data collected on any third‑party site or by any third‑party application that may link to or be accessible from the Website. This Privacy Notice does not apply to personal data collected by Subscribers, our business partners, and other third parties or third‑party applications or services, even if this personal data is collected using our Website or at events.
This website is not intended for anyone under the age of 18.
Read more +
The Website is not directed to or intended to be used by anyone under the age of 18. We do not knowingly collect personal data from anyone under the age of 18. If you are under 18, please do not attempt to fill out our forms or send any personal data about yourself to us. If we learn that we have collected personal data from a child under age 18, we will delete that personal data promptly.
Please check this notice periodically to stay informed about any updates.
Read more +
iCIMS reserves the right to update or change this Privacy Notice from time to time. If we make material changes to this Privacy Notice, we will post it to our Website home page prior to or at the time of the change becoming effective. We ask that you review the Privacy Notice periodically to stay informed about any updates or changes that we may have made.
You can see when this Privacy Notice was last updated by checking the “Effective Date” displayed at the top of this Privacy Notice.
To ask questions or comment about this Privacy Notice and our privacy practices or if you need to update, change, or remove your personal data or exercise any other rights,
Via Webportal: Click here
Via Email: privacy@icims.com
Via Mail: iCIMS, Inc., Attn: Privacy, Legal Department, 101 Crawfords Corner Road, Suite 3-100, Holmdel, NJ 07733 USA