Privacy Policy Business
1. BRAINSFIRST
1.1.
We are “BrainsFirst”, incorporated in Amsterdam, having offices at MediArena 2, 1114 BC, Amsterdam-Duivendrecht, the Netherlands (“BrainsFirst”). Unless explicitly stated otherwise, we are the ‘controller’ for the processing of Personal Data as detailed in this Privacy Policy Business (“PP Business”). A list of definitions as used in this PP Business are explained in this document and/or can be found in the list of definitions in Appendix I.
2. BRAINSFIRST SERVICES
2.1.
BrainsFirst has developed and now provides a service of providing assessments of cognitive capacities of the brain, such as ‘working memory’ and ‘attention’, by means of various games, to which the results amount to a trustworthy compilation of the cognitive capacities (“Personal Brain Profile” and the full service “Service”).
2.2.
BrainsFirst provides its Services to its Customers in two branches:
2.2.1.
Business – Organisations such as professional services companies, banks, and any company that wishes to hire the right candidate;
2.2.2.
Sports – Organisations that focus on all kinds of sports: cycling, football, etcetera.
2.3.
This PP Business is meant for you if you take part in the Services of BrainsFirst in the Business branch. Should you take part in an assessment regarding Sports, please see the specific privacy policy that applies in that case here.
2.4.
There are two ways for you to make use of the Services of BrainsFirst:
2.4.1.
An organisation that has entered into a contract with BrainsFirst (“Customer”) has a position to fill and wishes to know whether the people that are considered for the position would fit the description of the position. The Customer requests BrainsFirst to assess you and provides your contact details to us to that end. After the Service is conducted, your Personal Brain Profile may be provided to the Customer via a medium as determined by BrainsFirst; In this situation, we refer to you in this PP Business as a “Candidate”;
2.4.2.
You have taken the initiative to be assessed by BrainsFirst yourself. In this situation, we refer to you in this PP Business as a “Private User”.
2.5.
We refer to Candidates and Private Users jointly as “Data Subjects”.
3. SUMMARY OF PROCESSING OF PERSONAL DATA
3.1.
Depending on your activities, BrainsFirst collects and processes the following Personal Data:
3.2.
You are a Data Subject and take part in the Services – When you are taking part in the Services of BrainsFirst as a Data Subject – no matter whether you are a Candidate or a Private User – BrainsFirst is the Controller for the processing of Personal Data. This means that you can direct your questions on the processing of Personal Data to BrainsFirst. More information on this processing can be found in article 4 and article 5 of this PP Business, which articles set out the processing of your General Personal Data and your Sensitive Personal Data respectively.
3.3.
Please note that, if you are a Candidate and thus a Customer has requested you to take part in the Services of BrainsFirst, this Customer may be provided with your Personal Brain Profile (see below for your options in this matter). The Customer will also be provided with an advice of BrainsFirst concerning which Candidates best fit the profile the Customer is looking for, which advice is not available for the Candidate. From the moment on that BrainsFirst has provided the Personal Brain Profile to the Customer, the Customer is Controller and you may contact the Customer for any questions regarding the processing of Personal Data by Customer.
3.4.
You are a visitor to the Website – BrainsFirst exploits various Websites and in doing so, we process certain Personal Data to allow your optimal use of the Websites. More information on this processing can be found in article 6 of this PP Business.
3.5.
The processing as mentioned will be set out in more detail below. Personal Data is stored for the term that is necessary for the purposes as set out in this PP Policy Business, unless laws or legislation obliges us otherwise and unless we have provided a specific retention time below.
4. YOU ARE A DATA SUBJECT AND TAKE PART IN THE SERVICES – GENERAL PERSONAL DATA
4.1.
Personal Data – When you take part in the Services as a Data Subject, BrainsFirst processes the following Personal Data:
4.1.1.
Name, surname, e-mail and further contact details;
4.1.2.
Gender, age, education level (graduation and degreed);
4.1.3.
Communication with BrainsFirst.
Unless stated otherwise, there is no lawful or contractual obligation to provide Personal Data. Unless stated otherwise, the provision of Personal Data is not a condition to enter into an agreement. Not providing Personal Data may, under circumstances, lead to us not being able to enter into an agreement with you or present you to the Customer in the most optimal way.
4.2.
Source – We may collect the Personal Data under 4.1.1 from the Customer. Further Personal Data will be obtained from you. No further or public sources are used, unless explicitly stated otherwise.
4.3.
Purpose – The Personal Data as mentioned in paragraph 4.1 is processed for the following purposes:
4.3.1.
To allow BrainsFirst to offer the Services to the Data Subjects;
4.3.2.
To perform the contract as entered into with the Data Subjects and/or the Customer or in order to take steps at the request of the Data Subjects and/or the Customer prior to entering into a contract;
4.3.3.
To allow BrainsFirst to comply with legal obligations to which BrainsFirst is subject;
4.3.4.
To allow BrainsFirst to develop and market its Services and analyse the use thereof, to promote the Services and BrainsFirst.
4.4.
Legal ground – The legal basis for the processing of Personal Data as mentioned in paragraph 4.1:
4.4.1.
The processing is necessary for the performance of a contract to which the Data Subject is a party or in order to take steps at your request prior to entering into a contract;
4.4.2.
The processing is necessary for compliance with a legal obligation to which BrainsFirst is subject;
4.4.3.
The processing is necessary for the purpose of legitimate interests pursued by BrainsFirst, i.e. the interest to perform its Services, to perform the contracts it has entered into, market the Services of BrainsFirst and the organisation of BrainsFirst, analyse the use of the Services and promote the Services and BrainsFirst, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data, in particular where the Data Subject is a child.
4.5.
Retention – We maintain the following retention times, unless BrainsFirst is required by law to store the Personal Data for a longer period of time:
4.5.1.
Your contact details – This Personal Data is stored for the term of the agreement BrainsFirst has entered into with you or the Customer and for a period of two years after that agreement has ended;
4.5.2.
Payment details – All Personal Data in connection to payments will be stored for the term of the agreement BrainsFirst has entered into with you or the Customer and for up to seven years after the end thereof.
5. YOU ARE A DATA SUBJECT AND TAKE PART IN THE SERVICES – SENSITIVE PERSONAL DATA
5.1.
Personal Data – When you take part in the Services as a Data Subject, BrainsFirst processes the following special categories of Personal Data:
5.1.1.
The results of the Games you play;
5.1.2.
The Personal Brain Profile.
5.2.
Source – The Personal Data as set out in paragraph 5.1 will be obtained from you and by means of the algorithms used in the Services. No further or public sources are used, unless explicitly stated otherwise.
5.3.
Purpose – The Personal Data as mentioned in paragraph 5.1 is processed for the following purposes:
5.3.1.
To allow BrainsFirst to offer the Services to the Data Subjects;
5.3.2.
To perform the contract as entered into with the Data Subjects and/or the Customer or in order to take steps at the request of the Data Subjects and/or the Customer prior to entering into a contract;
5.3.3.
To transfer your Personal Brain Profile to the Customer;
5.3.4.
To allow your participation in the BrainPool (see article 8 of this PP Policy Business).
5.4.
Legal ground – The legal basis for the processing of Personal Data as mentioned in paragraph 5.1:
5.4.1.
Based on your (explicit) consent.
5.5.
Retention – We maintain the following retention times, unless BrainsFirst is required by law to store the Personal Data for a longer period of time:
5.5.1.
Your results of the Games – This Personal Data is stored for the time of the agreement BrainsFirst has entered into with you or the Customer and for a period of one year after that agreement has ended;
5.5.2.
Your Personal Brain Profile – This Personal Data is stored for the time of the agreement BrainsFirst has entered into with you or the Customer and for a period of one year after that agreement has ended;
5.5.3.
BrainPool Personal Data – Should you choose to be included in the BrainPool, we will store your Personal Data for the term that we have agreed that you will be in the BrainPool.
5.6.
Aggregation of Personal Data – BrainsFirst will aggregate the results of the Games to allow analysis of such data and improve our Services. In principle, at this stage and for this purpose, this data cannot be used to identify you with. We may share this data with business partners for industry analysis, demographic analysis and improvement of our Services.
6. YOU VISIT THE WEBSITE
6.1.
Personal Data – When you visit the Website, we collect the following Personal Data:
6.1.1.
Your IP-address and browser language;
6.1.2.
Your browser name, details on the device you use to visit the Website;
6.1.3.
The (details of the) requests you send to the Website;
6.1.4.
Our communication with you.
Unless stated otherwise, there is no lawful or contractual obligation to provide Personal Data. Unless stated otherwise, the provision of Personal Data is not a condition to enter into an agreement. Not providing Personal Data may, under circumstances, lead to us not being able to enter into an agreement with you or present you to the Customer in the most optimal way.
6.2.
Source – We collect this Personal Data automatically and from you. We use no other or public sources, unless explicitly stated otherwise.
6.3.
Purpose – This Personal Data is processed for the following purposes:
6.3.1.
To allow BrainsFirst to offer the Website;
6.3.2.
To allow the optimal and personalised use of the Website;
6.3.3.
To analyse the use of the Website;
6.3.4.
To allow BrainsFirst to develop and market its Services and analyse the use thereof, to promote the Services and BrainsFirst.
6.4.
Legal ground – The legal basis for the processing of Personal Data:
6.4.1.
The processing is necessary for the purposes or legitimate interests pursued by BrainsFirst, i.e. the interest to offer the Website and Services, to perform the contracts it has entered into, market the Website and Services of BrainsFirst and the organisation of BrainsFirst, analyse the use of the Website and Services and promote the Website and Services and BrainsFirst, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of Personal Data, in particular where the Data Subject is a person younger than 16. If you are younger than 16, please see article 11 'younger than 16?'.
6.5.
Cookies and/or similar techniques and consent – When you consent to the use of cookies on the Website via the means as presented to you, the Personal Data as processed for the purpose of placing such cookies will be based on your consent. The Personal Data as collected via cookies and similar techniques is set out in our BrainsFirst Cookie Policy.
6.6.
Retention – We maintain the following retention times, unless BrainsFirst is required by law to store the Personal Data for a longer period of time:
6.6.1.
Details on your use of the Website – This Personal Data is aggregated as soon as possible and stored for a period of five years;
6.6.2.
Your communication with BrainsFirst – This Personal Data is stored for time that we communicate with you and for a period of two years thereafter.
7. PERSONAL BRAIN PROFILE
7.1.
Should you take part in the Services as a Candidate – and thus a Customer has requested your participation in them – your Personal Brain Profile will be shared with the Customer that has requested such after you have provided your consent to this end. Your Personal Brain Profile will not be shared with any other Customers.
7.2.
Should you wish to object to the provision of your Personal Brain Profile to the Customer, please contact us as soon as possible via support@brainsfirst.com.
8. BRAIN POOL
8.1.
After you have taken part in the Services, irrespective of whether a Customer has requested that you take part or you have done so on you own initiative, you may choose to take part in the Brainpool and have your Personal Brain Profile added to the Brainpool. Please note: the Personal Brain Profiles in the BrainPool are stripped of any information that may directly identify you.
8.2.
BrainFirst, after a request of a Customer, analyses and reviews the Personal Brain Profiles in the BrainPool to find a match for the position the Customer has consulted BrainsFirst For.
8.3.
Should your Personal Brain Profile match the request of the Customer, BrainsFirst will invite you to apply for the position Customer has consulted BrainsFirst for. Please note that our identity is not shared with the Customer. You may decide on your own whether to provide more Personal Data to the Customer.
8.4.
Participation in the BrainPool will last for a maximum of two years. You can terminate your participation in the BrainPool at any time. We may ask you to update your personal details. After two years, your Personal Brain Profile will be deleted.
9. RECIPIENTS AND TRANSFER
9.1.
BrainsFirst, in providing the Services, may need to transfer the Personal Data to third parties, referred to as ‘recipients’. The categories of recipients that BrainsFirst shares Personal Data with are:
9.1.1.
Our suppliers, such as not limited to the company that stores the Personal Data on behalf of BrainsFirst, our external IT-supplier, supplier of office supplies, the party that aids BrainsFirst in direct marketing activities, our bookkeeper, accountant, legal advisers and other professional service providers, the parties that assess and maintain (the use of) our websites;
9.1.2.
Customers, where you play the Games on request of such a Customer or where you take part in the BrainPool;
9.1.3.
All recipients that you explicitly or implicitly agree with in the performance of the Services for you or the Customer.
9.2.
BrainsFirst does not transfer Personal Data outside of the European Union or international organisations. Should BrainsFirst transfer Personal Data outside of the European Union or to international organisations, BrainsFirst will determine whether an adequacy decision as stated in the relevant legislation applies and, where such is not the case, transfer will only be conducted if adequate safeguards apply. In that case, a copy of the documents concerned will be available at BrainsFirst.
10. RIGHTS
10.1.
The GDPR, depending on the circumstances, provides you the following rights:
10.1.1.
The right to access to Personal Data;
10.1.2.
The right to rectification of Personal Data;
10.1.3.
The right to request from BrainsFirst the erasure of Personal Data;
10.1.4.
The right to request BrainsFirst whether the processing of the Personal Data may be restricted;
10.1.5.
The right to object to processing;
10.1.6.
The right to data portability;
10.1.7.
Where the processing is based on consent: the right to withdraw such consent at any time, without such withdrawal having effect on the legitimacy of the processing prior to withdrawal;
10.1.8.
The right to lodge a complaint at a supervisory authority, for example the Autoriteit Persoonsgegevens (https://autoriteitpersoonsgegevens.nl/).
10.2.
More specific, you have the right to delete your account with the results of the Games you have played and all other Personal Data at any time. In this case BrainsFirst will delete your name and email. As a result, the connection between your results to the Games and your Personal Data is removed. From that moment on, it is no longer possible for BrainsFirst to provide insights you to anyone, including the Customer. To delete your account, please send a request to support@brainsfirst.com.
10.3.
BrainsFirst does not conduct automated decision-making, including profiling as referred to in articles 22(1) and (4) of the GDPR. It is however possible that the Customer takes a decision about you solely based on the Personal Brain Profile that BrainsFirst has compiled conducting the Services, which decision may affect you.
11. YOUNGER THAN 16?
11.1.
If you are younger than sixteen years, your consent is only lawful to the extent that it is given or authorised by the holder of parental responsibility over you.
12. CYBERSECURITY
12.1.
BrainsFirst works hard to protect your Personal Data. BrainsFirst implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk of the processing of Personal Data, such as but not limited to:
12.1.1.
Personal Data within our Services is encrypted using SSL/AES-256;
12.1.2.
Personal Data is only accessible on a need-to-know basis and via a generated password;
12.1.3.
We oblige our service providers to make use of redundant data storage, comply with ISO 27001 and apply two-step-verification for accessing the Personal Data.
13. AMENDMENTS
13.1.
BrainsFirst may amend this PP Business from time to time. Please consult the Website to review such and always read our most recent PP Business before taking part in the Services.
14. QUESTIONS
14.1.
Should you have any questions, concerns or comments on this PP Business, the processing of Personal Data or the Services of BrainsFirst, please contact support@brainsfirst.com.
APPENDIX I – DEFINITIONS
Candidate
The Data Subject that will be the assessed as part of the Services provided to Customer.
Controller
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
Customer
The legal entity or natural person that has entered or will enter into a contract with BrainsFirst regarding the provision of Services, with the purpose of assessing Candidates.
Data Subject
An identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Games
The brain games that are made available by BrainsFirst to the Candidate as part of the Services for BrainsFirst. The purpose of the Games is to establish the Personal Brain Profile of the Candidate.
GDPR
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data
Personal Brain Profile
The brain profile of a Candidate, derived from the results of the Games.
Personal Data
Any information relating to a Data Subject.
Personal Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
Private User
A Candidate that makes use of the Services of BrainsFirst on its own initiative and without the initial engagement of a Customer.
Processor
A natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller,
Services
All services as provided by BrainsFirst, such as but not limited to assessing Candidates and Private Users in the branches business and sports, providing access to the games and the platform as made available by BrainsFirst, providing reports on Candidates and Private Users and all activities in connection to the foregoing.
Website
The websites that are exploited by BrainsFirst, such as but not limited to www.neurolympics.nl.
Ask your question directly and we'll get back to you in no time!