Privacy Notice for Candidates
Last updated: 01/07/2025
This Privacy Notice explains how Sumsub companies (collectively, “Sumsub”, the “Company”, or “we”) process personal data of candidates or other individuals who apply to an open position with us, whom we contact for recruitment purposes, or who undergo an interview or assessment with us (“Candidate(s)”).
As used in this Notice, “personal data” means any information that relates to, identifies, or reasonably could be used to identify an individual, directly or indirectly.
This Privacy Notice does NOT apply to:
- Personal data that Sumsub processes about you if you interact with Sumsub websites, products, our branded social media pages as a user, and other non-career websites which we operate (collectively, our “Services”), or other ways you may interact with Sumsub as a user of our products and services. In such cases, the privacy notice posted on the Services you interact with will apply; or
- Personal data that Sumsub processes about you if you are already an employee with and/or provide services to Sumsub (currently or formerly), which is subject to our separate Staff Privacy Notice.
If you are offered and you accept a role at Sumsub, the Candidate personal data collected during the recruiting process will be governed by the Sumsub Staff Privacy Notice, a copy of which will be provided when you are onboarded.
1. General
Depending on the Sumsub company you are in contact with or applying to, the data controller of your personal data is either of the following companies:
- UK: Sum and Substance Ltd (reg. 09688671);
- Germany: Sumsub GmbH (reg. HRB 204951 B);
- Cyprus: Sumsub Tech Limited (reg. HE 424752), Sumsub Ltd (reg. HE 405087), Raritex Trade Ltd (reg. HE 369578);
- USA, Delaware: Sumsub Inc. (reg. 6366081);
- UAE: Sumsub Technology LLC (reg. 2014604);
- Singapore: Sumsub APAC Pte. Ltd. (red. 202345939C);
- Brazil: Sumsub Brazil LTDA (CNPJ 59.949.822/0001-66).
2. Collection of personal data
The categories of personal data we may collect from includes:
- Identification details (such as your name, contact information, and location);
- Professional background (including job titles, employment history, skills, qualifications, and education);
- Public profile information (such as details from your LinkedIn or other publicly accessible professional profiles);
- Recruitment-related data (such as your CV, cover letter);
- Identity verification data (biometric information);
- Technical data (such as IP address, browser type and version, time zone setting and location, operating system and platform).
We collect most of the data from you directly. We may, however, also collect personal data about you from third parties, such as:
- Job portal or recruitment agency;
- Electronic vacancy applications;
- Public Internet sources;
- Sumsub employees providing a referral.
3. Purposes of processing
When you apply or are contacted by us regarding open positions at Sumsub, we process your personal data for recruitment purposes, which may include:
- Communications with you;
- Verification of your information;
- Identity verification;
- Assessment of your application and suitability for entering into a contractual relationship with Sumsub;
- Compliance with applicable laws, legal processes, or enforceable government request;
- Notifying you of future job offerings where we you have provided your consent;
- Carrying out background checks as appropriate and in accordance with applicable law.
4. Lawfulness of data processing
We will process your personal data based on one or more of the following legal bases:
Contract. We may process your personal data when we assess your suitability for the role and when we have the intention to enter into a contract with you.
Legitimate interest. We may process your personal data to pursue our legitimate interests, such as:
- assessing your suitability for a role;
- verifying the information you provide;
- managing and improving our recruitment processes; or
- defending from legal claims.
Legal obligation. We may be obliged to process some of your personal data to comply with applicable laws, e.g., to conduct checks for eligibility to work, as required under immigration laws.
Consent. We may process certain personal data based on your consent, e.g., where you are passing Liveness checks and we collect your biometric data.
5. Disclosure of personal data
Your personal data may be shared with our group companies where necessary to process your application.
We may also share your personal data with service providers (“Data Processors”) that help us with the recruitment process, such as, e.g., recruitment agencies (to manage and coordinate the hiring process), background check providers, IT and software vendors (e.g., applicant tracking systems).
We may also share your personal data for the following additional purposes where permitted or required by applicable law:
- to comply with legal obligations or valid legal processes such as search warrants, subpoenas, or court orders. When we disclose your personal data to comply with a legal obligation or legal process, we will take reasonable steps to ensure that we only disclose the minimum personal data necessary for the specific purpose and circumstances.
- where it is necessary for the purpose of, or in connection with, any legal proceedings (including prospective legal proceedings), for the purpose of obtaining legal advice, or if it is otherwise necessary for the purpose of establishing, exercising, or defending legal rights.
As a group of companies operating internationally, we may need to transfer your personal data outside of the country or region where you reside to process your application. This may involve transferring your personal data to countries which do not have equivalent data protection or privacy laws to those which apply in your own country. We may also need to transfer your personal data to third party service providers located in other countries. Regardless of where your personal data is transferred, we shall put in place appropriate safeguards to ensure that your personal data is treated securely and in accordance with applicable law. For individuals in the EEA, UK and Brazil, this usually means entering into Standard Contractual Clauses with recipients of your data who are located in countries which are not recognised as having adequate data protection laws.
To ensure transparency and compliance with applicable data protection legislation, Sumsub provides below the details of the countries outside the EU where personal data may be transferred and the corresponding safeguards applied.
- United Kingdom: EU Adequacy Decision for the UK, Brussels, 28 June 2021
- United States of America: Appropriate safeguards pursuant to article 46 of the EU GDPR and the UK GDPR: the Standard Contractual Clauses; or Adequate level of protection pursuant to article 45 of the EU GDPR: EU–US Data Privacy Framework.
- United Arab Emirates: Appropriate safeguards pursuant to article 46 of the EU GDPR and the UK GDPR: the Standard Contractual Clauses.
- Singapore: Appropriate safeguards pursuant to article 46 of the EU GDPR and the UK GDPR: the Standard Contractual Clauses.
- Brazil: Appropriate safeguards pursuant to article 46 of the EU GDPR and the UK GDPR: the Standard Contractual Clauses.
6. Personal data retention
Your personal data will be stored in accordance with applicable laws and kept as long as needed to carry out the purposes described in this privacy notice (or as otherwise required by applicable law). If you are successful with your application, your personal data will be kept in accordance with our Staff Privacy Notice. If you are unsuccessful with your application, your personal data will be kept for the duration of the application process, plus a reasonable period of time after confirmation that your application was unsuccessful to allow us to record the reasons for our decision in relation to your application (including so that we can exercise, establish, or defend any legal claims).
Where you provide consent for it, we also retain your personal data for up to 24 months to consider you for other suitable openings within Sumsub in the future. After this period, we will ask you to provide us with new consent if you want to stay in our pool of candidates.
Notwithstanding anything to the contrary, the biometric data collected during the identity verification process is deleted immediately after the verification.
7. Automated decision-making
Our decisions about candidates are not determined by automated processes.
8. Your rights
Subject to applicable laws in your location, you may have certain rights in relation to your personal data, including the right to:
- access a copy of the personal data which we hold about you by completing this form;
- ask us to correct your personal data if you think it's wrong;
- ask us to delete your personal data in certain circumstances by completing this form;
- object to us processing your personal data on the basis of our legitimate interests or another lawful basis in certain circumstances;
- ask us to restrict how we use your personal data in certain circumstances;
- ask us to transfer personal data to you or another company in a structured, commonly used, machine-readable format in certain circumstances;
- withdraw your consent (in cases in which we process personal data based on your consent).
Please note that not all of these rights are absolute and we may not be required to comply with your request where exemptions apply under applicable data protection laws.
You can exercise your privacy rights by contacting us at privacy@sumsub.com or by using the forms provided above.
You also have a right to complain to your local data protection authority or other local regulatory body responsible for ensuring protection of your data privacy rights. We would appreciate it if, in such cases, you would contact Sumsub first to resolve the problem together.
9. Changes
Sumsub reserves the right to make amendments to this Notice at any time and for any reason. Any amendments will be effective immediately upon us posting the updated Privacy Notice on our website. Users of our website waive the right to receive specific notice about such amendments. You are invited to review this Privacy Notice at any time to stay informed about updates.
10. Contact
If you have any questions regarding this privacy notice, please email us at privacy@sumsub.com.