Data protection
DATA PRIVACY POLICY (Obermeyer Middle East)
Obermeyer Middle East
Al Bustan Office, Level 2
P.O. Box 130783, Abu Dhabi, UAE
OME-Operations@obermeyer-ae.com
This privacy policy is aligned with Obermeyer Group’s Data Privacy Statement and is issued in accordance with Articles 13 and 14 of the EU-DA General Data Protection Regulation and UAE Federal Decree Law No. 45/2021 – Protection of Personal Data
Obermeyer Middle East is accordingly committed to protecting user privacy and ensuring that the personal information / details “Defined as information that can be used to identify individuals, such as names, postal addresses, or email addresses” obtained from the website is handled securely and in compliance with applicable data protection regulations.
The preceding statement accordingly emphasizes the following OME’s obligations.
- Protection of Personal Details: The website stresses the importance of safeguarding personal information and assures users that they can navigate the website without the need to disclose personal details.
- Non-Evaluation of Information: The website states that no personal evaluation of the information occurs when users access the site.
- Voluntary Provision of Information: Users are informed that any personal details they provide on the website are voluntary.
- Secure Transmission: Any personal details provided on forms are transmitted securely in encrypted form to prevent unauthorized access by third parties.
- Use of SSL Process: The SSL (Secure Sockets Layer) process is employed to ensure secure transmission of personal information.
The forthcoming explains how the website intends to provide users, through the next sections, with information about the types of data it collects, how it processes that data, and what rights users have regarding their data.
Use of Cookies and Other Technologies
The website uses cookies and possibly other technologies to enhance the user experience and improve the website's functionality.
- Essential vs. Non-Essential Cookies - Some of the cookies used are essential for the website to function properly, while others are non-essential and are used to improve the website and enhance the user experience.
- IP addresses Personal Data - Acknowledging that personal data, such as IP addresses, may be processed. It specifically mentions that this data could be used for purposes such as personalized ads and content, as well as ad and content measurement.
- Option to Manage Preferences / Change Cookie Settings - Users are informed that they can revoke or adjust their cookie preferences at any time. This refers to a cookie consent management tool or settings form where users can manage their preferences regarding the use of cookies and other tracking technologies.
Log Files for Internal System and Statistical Reasons
The logging practices employed by OME’s website for internal system management and statistical purposes are broken down into the following key points
- Data Recorded in Log Files - When someone accesses the website, whether it's a person or an automated system, various general data and information are recorded. Examples of recorded data include:
- Types and versions of browsers used.
- Operating systems of accessing systems.
- Referrers, i.e., the website from which another system accessed the website.
- Sub-websites activated on the accessed website.
- Date and time of access.
- Anonymized IP addresses.
- Other similar data to avert dangers such as cyber-attacks.
- Purpose of Data Collection - The information collected is not used to draw conclusions about individuals. Instead, it serves various purposes as follows:
- Providing website content correctly and optimizing it.
- Ensuring the lasting functional capability of IT systems and website technology.
- Providing information to law enforcement agencies in case of cyber-attacks.
- Statistical Evaluation - The anonymized data and information stored in server log files are statistically evaluated. The evaluation aims to increase data protection and data security within the facility. Ultimately, the goal is to ensure an optimum level of protection for the personal data processed by the website.
- Separation of Anonymous Data and Personal Details - It's mentioned that the anonymous data in server log files is stored separately from personal details provided by individuals.
Overall, these key points demonstrate the website's commitment to data protection and security while utilizing logged information for internal management and statistical analysis purposes.
Google Analytics
This section outlines the usage of Google Analytics, specifically Google Analytics 4 (GA4), on the website, including details on data processing, scope, recipients of data, storage duration, legal basis, and options for opting out. The breakdown is as follows:
- Google Analytics 4 (GA4)
- Google Analytics, a web analysis service provided by Google LLC, is used on the website.
- GA4 activates IP address anonymization by default, shortening IP addresses within the EU/EEA and only transmitting full IP addresses to Google servers in the USA in exceptional cases.
- Google states that the transmitted IP addresses will not be merged with other Google data.
- Scope of Processing
- Google Analytics uses cookies to analyze website usage, recording user behavior as "events" during website visits.
- Examples of recorded events include pageviews, first website visit, session start, click path, interactions with the website, scroll events, clicks on external links, internal search queries, interactions with videos, file downloads, ads viewed/clicked, and language settings.
- Additionally, information such as approximate location, shortened IP address, technical details about browsers and end devices, internet service provider, and referrer URL are recorded.
- Recipients of Data
Recipients of the data include Google Ireland Limited, Google LLC, and Alphabet Inc
- Storage Duration
- Data linked to cookies is automatically deleted after two (2) months.
- Data whose retention period has been reached is automatically deleted once a month.
- Legal Basis
The legal basis for this data processing is user consent under Art. 6 Para.1 p.1 lit.a GDPR and Art. 49a GDPR and UAE Federal Decree Law No. 45/2021.
- Google Analytics Opt-out
- Users can opt out of Google Analytics tracking for the website by clicking a provided link, which places an opt-out cookie on their device.
- Deleting cookies in the browser requires clicking the opt-out link again.
This breakdown provides a detailed overview of the Google Analytics implementation on the website, including data processing practices, user options for opt-out, and the legal basis for data processing.
Webserver Logfiles
The following approaches demonstrate our commitment to data privacy and responsible data handling practices.
- Unmasked IP Addresses for Seven (7) Days - During the initial period of seven days, IP addresses are kept unmasked. This allows OME to analyze and detect any faults or errors in their systems. It provides a window for troubleshooting and identifying potential issues that may arise from user interactions.
- Introduction of IP Masking - After the initial seven (7)-day period, IP masking is introduced. IP masking involves replacing parts of the IP address with a generic identifier, such as replacing the last octet of the IP address with zeroes. This helps anonymize the IP address while still allowing for some level of analysis and tracking, such as identifying geographic regions or patterns of traffic.
- Deletion of Masked IP Addresses after 30 Days - Following the initial seven (7)-day unmasked period and the subsequent IP masking phase, we delete the masked IP addresses after a total retention period of 30 days. This ensures that we retain IP address data only for a reasonable period necessary to fulfill its purposes, such as system maintenance, security, or analytics.
Job Applications and Situations Vacant Subscription
We ensure compliance with data privacy regulations and maintain transparency in handling personal details for Job Applications and Situations Vacant subscriptions, the procedure of handling the personal details is outlined and enumerated below:
Job Applications:
- Data Collection - Personal details including name, nationality, date of birth, address, contact details, qualifications, curriculum vitae, testimonials, supporting documents, covering letter, degrees, certificates, application photo, email address (as a username for accessing the applications portal), user language, and consent to remaining in the Obermeyer Talent Pool.
- Application Process
- Purpose of Processing
- To initiate employment relationships and conduct application and applicant management procedures.
- Obtain consent for sending information about job vacancies
- Legal Basis for Processing - Processing is based on the applicant's consent.
- Recipients of Data
- Applications are forwarded to the HR department for appraisal.
- Managers of technical departments with vacancies may be granted access to applications as needed.
- Duration of Storage
- Data is stored throughout the application process and, if consent is given, in the Talent Pool until revoked or up to three (3) to six (6) months if no longer consent is given.
- Compliance with additional legal storage periods and necessity for legal claim application is considered.
Automatic Decision-Making and/or Profiling
This section provides information on the process of utilizing the automated means to serve as a reliable prescreening tool that assist in making final decisions. It is important to note that Article 22, Paras. 1 and 4 of EU General Data Protection Regulation (GDPR) and UAE Federal Decree Law No. 45/2021 – Protection of Personal Data, specifically addresses automated preliminary filtering, screening and profiling.
Profiling involves the automated processing of personal data to establish a preliminary evaluation of certain aspects related to individuals, such as their behavior, preferences, or interests.
We confirm that automated analysis does not constitute the only mean of evaluating the personal data. Processing and making final decisions or assessments about individuals relies on and includes human involvement. Accordingly, we rely on human judgment and discretion rather than fully automated processes when making final decisions, determinations or assessments that could significantly affect individuals.
Technical and Organizational Security Measures
Technical measures may include encryption, access controls, firewalls, and intrusion detection systems, while organizational measures involve policies, procedures, and employee training to ensure data security.
These measures are explained in the paragraphs below:
- Protection vs. Manipulation, Loss, Destruction, and Unauthorized Access - Personal data are safeguarded against various threats, including accidental or deliberate manipulation, loss, destruction, or unauthorized access. This involves implementing controls and safeguards to prevent, detect, and mitigate security incidents.
- Security Measures for External Services - When using external services or third-party providers that handle personal data, we ensure that appropriate security measures are in place to protect the data. This may involve conducting due diligence on service providers, establishing contractual agreements, and monitoring compliance with security standards.
- Encryption of Personal Data during Transmission - Personal data are encrypted during transmission to prevent interception or unauthorized access. We employ Transport Layer Security (TLS) protocols, Secure Sockets Layer (SSL) certificates, and other encryption mechanisms to help secure data as it travels over networks.
Procedure on Handling Business Cards
We handle the exchange of business cards ethically and in compliance with data privacy laws while fostering professional relationships.
The subsequent summary outlines the procedure:
- Exchange of Business Cards - We exchange business cards with individuals during networking or professional interactions.
- Communication of Personal Details - When exchanging cards, we provide personal contact details such as phone number and/or email address.
- Purpose of Contact Details – We clearly communicate that the contact details will be used solely for the purpose of staying in touch and fostering professional relationships.
- Information About Services Provided - We use the opportunity to share information about the products or services our company offers.
- Data Retention Policy - We inform the recipient that if they don't utilize our services or products, we will retain their contact details for five (5) years.
- Data Deletion - After five (5) years, if no services or products are sourced from our company, we delete the contact details from our database.
- Compliance with Data Privacy Regulations - We ensure that our procedure aligns with relevant data privacy regulations, such as the EU GDPR (General Data Protection Regulation) or UAE Federal Decree Law No. 45/2021 – Protection of Personal Data.
- Transparency and Consent - We are transparent about our data retention policy and obtain consent from individuals before storing their contact details.
- Opt-out Option - We provide individuals with an option to opt-out of further communication or data retention if they choose to do so.
Rights Granted to Individuals
The information below outlines the rights granted to individuals as data subjects under the EU’s General Data Protection Regulation (GDPR) and UAE’s Federal Decree Law No. 45/2021 – Protection of Personal Data.
- Revocation of Consent - You have the right to revoke your consent to the processing of your personal data at any time if the processing is based on your consent.
- Information - You have the right to obtain confirmation from the data controller whether your personal data is being processed and, if so, to receive information about the processing activities.
- Correction - You have the right to request the correction of inaccurate personal data concerning you, and the data controller must rectify it without undue delay.
- Deletion - You may have the right to request the deletion of your personal data, also known as the "right to be forgotten," under certain circumstances.
- Restriction of Processing - You may have the right to request the restriction of the processing of your personal data in certain situations.
- Objection to Processing - You have the right to object to the processing of your personal data, including profiling, for reasons related to your particular situation.
- Consequences of Failure to Provide Data - You are not obligated to provide personal data, but failure to do so may result in the inability to process your inquiry or operate a customer account, depending on the circumstances.
- Right to Data Portability - You have the right to receive the personal data you provided to the data controller in a structured, commonly used, and machine-readable format, and you have the right to transmit that data to another controller.
- Right to Lodge a Complaint with a Supervisory Authority - You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the EU’s General Data Protection Regulation (GDPR) and/or UAE’s Federal Decree Law No. 45/2021 – Protection of Personal Data.