Privacy policy
This is the inSymmetry International privacy policy (GDPR notice), as published at insymmetry-international.com. It applies to data collected through this page, including the assessment.
Cookies and tracking on this page
DRAFT — this section is not part of the inSymmetry policy published at insymmetry-international.com. It was written for this assessment page, which is the only place these cookies are set, and needs inSymmetry’s legal review before launch.
Nothing below is set until you choose. The advertising cookies load only if you select “Accept”; if you select “Reject” they are never requested. You can change your choice at any time through Cookie settings in the page footer, and we ask again every six months.
Necessary — always set
● is-cookie-consent (stored by this page, kept 6 months) — remembers whether you accepted or rejected, so we do not ask on every visit. It holds only your choice and the date.
● is-countdown-deadline (stored by this page, erased when you close the tab) — keeps the intake countdown showing the same time as you move through the assessment.
Advertising — only if you accept
● Meta pixel (set by Meta Platforms Ireland, up to 3 months) — tells us how many people who saw our advertising went on to take the assessment, and lets us show it to similar audiences. Meta acts as a joint controller for this measurement.
● LinkedIn Insight Tag (set by LinkedIn Ireland, up to 6 months) — the same measurement for our LinkedIn advertising.
Neither receives your assessment answers, your score or your email address. Those go only to inSymmetry International and to our email provider, as described in the policy below.
Other third parties
● This page loads its typeface from Google Fonts and its animation library from the jsDelivr CDN. Neither sets a cookie, but both receive your IP address as a technical necessity of delivering the file.
For everything else — what we do with the assessment itself, your rights, and how to contact us — the inSymmetry International policy follows.
1. INTRODUCTORY NOTES
This policy is provided by DIKEMAR HR PARTNERS LIMITED (HE383655) Prodromou & Zinonos Kitieos 2 Palceview House 2064 Nicosia, Cyprus.
DIKEMAR HR PARTNERS LIMITED is running the “inSymmetry International” Program (“The Program”) in Cyprus and abroad, and for the purposes of this Policy, is acting as a “Data Controller” of the Personal Data (“PD”) that is being processed.
The security of your Personal Data is our priority.
Therefore, in those instances, different provisions of the General Data Protection Regulation (GDPR) (EU) 679/2016 apply, with which we comply.
The basic definitions of the terms used in this Policy are explained in section (10) below.
This Policy may be amended or updated from time to time to reflect changes in our practices in relation to the processing of Personal Data or changes in applicable law.
We encourage you to carefully review this Policy. In the event of any changes that may be made to the provisions of this Policy, we will keep you accordingly informed, as set forth below.
If you have any comments or questions regarding any of the information in this Policy or any other matter related to the Data processing by DIKEMAR HR PARTNERS LIMITED, please contact our company at:
join@inSymmetry-international.com
Personal Data Collection Points: We may collect personal information about you, such as your full name, address, contact information (email, telephone number), job title, industry, LinkedIn profile, etc. Examples of sources from which we collect Personal Data include:
● We may obtain your Personal Data directly from you (e.g. from our website when you contact us in “registration” or “contact form”, by email or telephone or by any other means)
● We may collect and share testimonials from participants in The Program, on the website, social media, informative materials (brochure) and events, including photographs and/or videos
● We may collect Personal Data that you choose to share on other platforms, including social media (e.g. we may collect information from your social media profiles as long as you have set them as public information on those mediums)
● We may collect personal information about you through a proprietary questionnaire collecting information about the participants in The Program, professional and personal characteristics, personalities, etc
● We may, with your prior written consent, carry out data confirmation checks that you disclose to us
We may also collect and process, when managing invoices/payments, financial information, such as tax IDs, invoicing address, contact details and bank accounts
Personal Data Generation: We can also generate Personal Data for you, such as files from the interviews you participated in. These Personal Data help us provide our services and manage our legitimate business interests in pursuit of our statutory purpose.
Personal Data Categories: The categories of Personal Data that we may process are as follows:
Personal details: name (s), gender, date of birth/age, citizenship, photo, marital status, job title, employer, department, details of wages and benefits
Contact details: home address, work address, home phone number, work phone number, personal mobile phone number, personal email address, work email address and social media profile details
Legal basis for the processing of Personal Data (“Processing”): When processing personal data for the purposes set out in this Policy, we may rely on one or more of the following legal bases:
● We have obtained your prior explicit consent to “Process” the data (this legal basis is used only in relation to “Processing” which is completely optional – not to be used in cases where the Processing is legally necessary or mandated in any other way)
● “Processing” is necessary for the performance of any contract that you may enter into with us
● “Processing” is mandated by applicable law
● “Processing” is necessary to protect the vital interests of any individual, or
● We have a legitimate interest in performing the “Processing”, which does not in any way violate any of your interests, fundamental rights, or freedoms
Whenever we rely on this legal basis, our legitimate interests are as follows:
● our legitimate interest in managing and carrying out our business activities
● our legitimate interest in promoting our business and
● our legitimate interest in providing services to our Customers
Processing of special categories of Personal Data (‘sensitive data’): We do not seek to collect or otherwise process special categories of Personal Data, except where:
● “Processing” is required or permitted by applicable law
● “Processing” is necessary for the investigation or prevention of criminal acts
● “Processing” is necessary for the constitution, exercise or defense of legal rights
● We have obtained, in accordance with applicable law, your prior explicit consent before processing sensitive Personal Data (as mentioned above); this legal basis is used only in relation to “Processing” which is completely optional, not to be used in cases where the Processing is legally necessary or mandated in any other way.
Purposes for which we may process Personal Data:
In view of the foregoing, the purposes for which we may process Personal Data in accordance with applicable law include
Communication and briefing: communicating with you by any means (including email, telephone, text message, social media, in-person contact) regarding issues about your participation in The Program
Communication, management and processing of invoices, payments and accounting of financial data (invoices, contract documents)
Profiling: In pursuit of our statutory purposes, we use and process the information we collect with the consent of the data subjects to produce ratings, which are inter alia related to the suitability of the candidates to participate in The Program.
We hereby declare that we do not perform automated processing of Personal Data of the Data subjects, and respectively we do not use automated decision-making processes that produce legal effects that affect or substantially influence the Data subjects and result in the refusal of the provision of goods or services or in unjustified discrimination.
3. DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES
We may disclose Personal Data to other members of our Network for legitimate business purposes (including the provision of services to you) in accordance with applicable law.
In addition, we may disclose personal data to:
● legal and regulatory authorities, upon request, or for the purpose of reporting any actual or suspected breach of applicable law or regulation
● judicial authority, in so far as it is necessary for the exercise or defense of our legal rights
● any party involved in the prevention, investigation, detection or prosecution of criminal offenses or the enforcement of criminal penalties, including the protection and prevention of threats to public security
In case we employ a third-party partner or company for the processing of Personal Data, we will ensure that the necessary Data processing agreements are signed or that specific guarantees regarding the transfer of Personal Data are being provided, by applying to their agreements, standard contractual clauses which will subject them to the following binding contractual obligations:
1. restriction of Personal Data processing in accordance with our prior written instructions
2. use of measures to safeguard the privacy and security of Personal Data
3. availability to perform compliance audits on the above conditions
4. PERSONAL DATA TRANFERS. COUNTRIES HAVING ACCESS TO YOUR PERSONAL DATA
Our servers, storing and keeping your information secure, are located in the European Economic Area. However, due to the international nature of our business, we may require to transfer Personal Data to other entities on our Network and to third parties, who are located in other countries. Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
• We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see European Commission: Adequacy of the protection of personal data in non-EU countries.
• Where we use certain service providers, we may use specific contracts approved by the European Commission ,which give personal data the same protection it has in Europe.
5. SECURITY OF PERSONAL DATA
We apply appropriate technical and organizational security measures to protect Personal Data from accidental or unlawful destruction, loss, tampering, unauthorized disclosure, unauthorized access and other unlawful or unauthorized forms of processing, in accordance with applicable law.
For your part, you are responsible for ensuring that the Personal Data you have provided us with have been securely transmitted.
In addition, we shall take steps to ensure that any individual acting under the supervision of the Data controller having access to Personal Data, will only process such data under the instructions of the Data controller and will limit access to your personal information to authorized employees.
Indicative security measures applied by us are as follows:
A. Organizational Measures
1. Employee management process – assignment of roles to all individuals involved in Data processing activities
2. Information system management
3. Employee training on the protection of Personal Data, information provided to all employees regarding the company’s policies/processes
4. Monitoring of Data Processors
5. Setting up a deletion/destruction of Data process
6. Monitoring of Data breach incidents
7. Monitoring of controls/security measures
B. Technical Measures
1. Access controls
2. Backup Data process
3. Modification of workstations
4. User log files, security incident logs
5. Communications security
6. Management and protection of portable Data storage assets
7. Software and applications safeguards
8. Management of amendment controls
C. Environmental Security Measures
1. Physical access controls
2. Environmental security – protection from natural disasters
3. Document exposure to threats
4. Protection of portable Data storage assets
6. ACCURACY OF PERSONAL DATA
We will ensure that the Personal Data that we process are accurate and, where necessary, updated. For our part, we take every reasonable measure to ensure that:
● The personal data we process are accurate and, where necessary, up to date
● In case any of the Personal Data we process are inaccurate (taking into account the purposes for which they are processed), we will proceed without undue delay to their deletion or correction. From time to time, we may ask you to confirm the accuracy of your Personal Data.
7. DATA MINIMIZATION
We are applying all reasonable measures to ensure that the Personal Data that we process are limited to that necessary for the processing purposes related to this Policy.
8. DATA RETENTION
The Data retention period depends on the legal basis of processing, as set out in detail below:
● In case the legal basis for processing is the exercise of legitimate interest, the processing of Personal Data is carried out for as long as it is considered necessary for the fulfillment of the intended statutory purpose (in this instance 5 years, a Data retention period deemed sufficient for the company’s intended purposes as laid out in this policy) and until such time the limitation period of any related claims has expired (article 6 of GDPR)
● In case the Personal Data of participants are provided under their own consent, we shall retain their Data until the consent granted by the data subject has been withdrawn. In case the consent is withdrawn for any valid reason, we shall retain them for as long as it is required until the limitation period of any related claims expires (article 6 of GDPR)
● In case the lawful basis for processing is the performance of the contract, we shall retain your Data for as long as you retain the contractual relationship with us in hard copy and in electronic form, or we shall retain them for as long as it is required until the limitation period of any related claims expires (Article 6 of GDPR)
● In case where the processing of the Personal Data is based on a legal obligation (Article 6 of GDPR), the Data retention period is set in accordance with the pertinent legislation and the limitation period for any inspections that may be performed by competent authorities.
9. RIGHTS OF THE DATA SUBJECTS
Pursuant to applicable law, your rights in relation to the processing of your Personal Data include the following:
Right to information: the Data controller is obliged to provide the Data subject with a range of information, including the identity and contact details of the controller, DPO contact details assuming his appointment is mandatory and set by the company, the purpose and the legal basis of the processing, the recipients of the Data disclosed and any transfers thereof, the length of time the Data is retained, the rights of the subject (Articles 12, 13, 14 of GDPR).
● Right of access: the Data subject has the right to know whether Personal Data are being processed or not, as well as to have access to information for the purpose of processing, the categories of Personal Data, the recipients of the data disclosed, the data retention period, the rights of the subject, and profile development (Article 15 of GDPR)
● Right of rectification: the subject has the right to ask the controller to rectify or supplement their Personal data without undue delay (Article 16 of GDPR)
● Right to erasure (“right to be forgotten”): the Data subject has the right to request from the controller to delete the Personal Data without undue delay when one of the reasons referred to in the Regulation occurs (e.g. data is no longer necessary for the purpose originally processed, the subject withdraws his consent or opposes the treatment and there is no other legal basis for processing where the processing is unlawful (Article 17 of GDPR)
● Right to restriction of processing: the Data subject has the right to pinpoint stored Personal Data in order to request the limitation of their processing in the future when one of the reasons stated in the regulation (e.g. whenever the accuracy of data is questioned or when the processing is unlawful and a Data subject is opposed to it, Article 18 of GDPR)
● Right to data portability: the Data subject has the right to receive Personal Data in a structured, commonly used and machine-readable format and to transmit it to another Data controller (Article 20 of GDPR)
● Right of opposition: the Data subject has the right to object at any time and for reasons related to his / her status, in the processing of their Personal Data (Article 21 of GDPR)
● The Data subject has the right not to incur a decision made solely on the basis of automated processing, including profiling process which produces legal effects concerning them or similarly significantly affects them (Article 22 of GDPR).
In case you exercise any of the above rights, we will take all appropriate measures available for the satisfaction of your request within thirty (30) days following the confirmed receipt of the relevant request. We may either inform you of the acceptance of your request or, on any objective grounds, that hinder the processing of your request related to the exercise of your rights under GDPR.
In case, however, the aforementioned rights are exercised excessively and without good cause, thus causing us administrative burden, we may charge you with the cost related to the exercise of the respective right.
In addition, you have the right to contact the Cypriot Data Protection Authority, which may receive written complaints as per its protocol at its offices at 15 Kypranoros Street, PC. 1061, Nicosia or via email (
join@inSymmetry-international.com
) according to the instructions listed on their webpage.
10. DEFINITIONS
“Data subject”
refers to the individual to whom the data relates and whose identity is known or can be ascertained, directly or indirectly, in particular on the basis of an identity number or one or more of the specific physical characteristics of the entity; biological, mental, economic, cultural, political or social
“Data Protection Authority”
is an independent public authority that has the legal authority to oversee compliance with applicable data protection laws
“Personal Data”
means any information relating to a natural person on the basis of which it is identified, as well as any other information through which his or her identity can be directly or indirectly verified (e.g. name, surname, ID, Tax Identification Number, Social Security Number, telephone, email). Special categories of Personal Data are data revealing racial or ethnic origin, political beliefs, religious or philosophical beliefs, participation in trade unions, as well as genetic data, biometrics and health, sex data or the sexual orientation of the natural person. Examples of Personal Data we may process are provided in Section (2) above
“Data processing”
means any operation or series of operations performed with or without the use of automated means, on Personal Data or Personal Data sets, such as the collection, registration, organization, structure, storage, adjustment or alteration, retrieval, retrieval of information, use, disclosure, dissemination or any other form of disposal, association or combination, restriction, deletion or destruction
“Data controller”
means the natural or legal person, public authority, agency or other entity which, alone or in combination with others, determines the purposes and manner of processing Personal Data
“Data processor”
means the natural or legal person, public authority, service or other body which processes Personal Data on behalf of the Data controller
“Special categories of Personal Data”
Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, physical or psychological condition, sexual orientation, any performed or alleged criminal action or sentence, information deemed to be sensitive in accordance with applicable law
“Source”
means any person who provides any opinion or viewpoint on the attributes of any candidate or participant for any purpose, including but not limited to the fitness of a candidate or participant for a particular role
“Third party”
means any natural or legal person, public authority, agency or body, with the exception of the Data subject, processor and persons who, under the direct supervision of the Data controller or processor, are authorized to process Personal Data
“Data subject’s consent”
means any indication of a free, specific, explicit and fully informed will, with which the Data subject indicates that he/she agrees, by declaration or by a clear affirmative action, to the processing of Personal Data which relate to it. This consent is normally required, except for the exceptions set out in the Regulation
“Personal Data breach”
means a breach of security that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access to Personal Data transmitted, stored or otherwise processed