Subject matter of processing: The provision of employee reference and background checking services to You as further set out in the Terms and Conditions.
Duration of processing: For the term of the Agreement and thereafter for any periods permitted under the Agreement.
Nature and Purpose of Processing: Zinc will Process the types Personal Data set out below in order to arrange background and reference checks for Your Candidates.
Personal Data Categories: Identity data (which may include the following Special Categories of Personal Data: biometric data for the purpose of uniquely identifying a natural person)), contact data, background check status data, qualification data, employment history data, sanctions data (which may include criminal offence data), financial data and usage data.
Data Subject Types:
- Your employees, contractors or workers.
- Candidates seeking to work with You (whether that work is paid, voluntary or otherwise).
- Referees providing employment references for applicable Candidates.
- Other third parties upon Your or applicable Candidate’s requests.
Location of data processing
16/18 rue Gaillon, 75002 Paris, France.
Supporting international criminal record checks
First floor, Chiltern House, Sigford Rd, Marsh Barton, Exeter, EX2 8NL
Supporting criminal record checks in England and Wales
3 Finsbury Ave, London EC2M 2PA
Red Lion Buildings, Cock Ln, London, EC1A 9BU
27 Old Gloucester Street, London, WC1N 3AX
Employment verification checks
Building Two, Number One Ballsbridge, Dublin 4, Ballsbridge, Dublin
Distributed cloud database for storage or data
Riverside Building, 6th Floor, The County Hall, Belvedere Rd, London, SE1 7PB
CDN and edge computing infrastructure
101 6th Ave, New York, NY 10013, United States
Cloud servers to process the application
15 Bonhill Street, LONDON, EC2A 4DN
API driven Communication service
112 E Pecan St. #1135, San Antonio, TX 78205
Email communication service.
Limited One Park Place, Upper Hatch Street Dublin 2 Ireland
9th Floor, 107 Cheapside, United Kingdom.
Invoicing and card payment rails
Bellevue, 10800 NE 8th St #700, Washington, United States
Identity Access Management platform
Amazon Web Services, Inc.
410 Terry Avenue North, Seattle, WA 98109-5210, U.S.A.
Distributed cloud database for storage or data
Location of data processing
5 New Street Square, London, England, EC4A 3TW
Receiving contact data to trigger background checks and returning report links
125 Mission Street, San Francisco, CA94103
EU or US services chosen by client
Receiving contact data to trigger background checks and returning report links
95 - 97 Kifsias Ave, 15125, Marousi
EU or US services chosen by client
Receiving contact data to trigger background checks and returning report links
New York City, 18 West 18th Street, 11th Floor, New York, NY 1001
EU or US services chosen by client
Receiving contact data to trigger background checks and returning report links
4th Floor, National House, 60 - 66 Wardour St, London, W1F 0TA
Receiving contact data to trigger background checks and returning report links
225 Bush Street, Suite 300, San Francisco, CA 94104
Receiving contact data to trigger background checks and returning report links
Ajax Way, Methil Docks, Leven, Fife, KY8 3RS
Receiving contact data to trigger background checks and returning report links
109 South 5th Street, Brooklyn, New York
EU or US services chosen by client
Receiving contact data to trigger background checks and returning report links
Skelbaekgade 4, 4. Tv. 1717 Copenhagen V Denmark.
Receiving contact data to trigger background checks and returning report links
49 Geary Street, Suite 411, San Francisco, CA 94108, United States
United States by client choice
Receiving contact data to trigger background checks and returning report links
3rd Floor, Johnson Building, 77 Hatton Garden, London, EC1N 89S
Receiving contact data to trigger background checks and returning report links
7th Floor, 1 Finsbury Avenue, EC2M 2PF
Receiving contact data to trigger background checks and returning report links
c/o Factory Works Gmbh, Lohmühlenstraße, 65, 12435, Berlin
In support of Workday only
Physical Access Control: Zinc takes measures to prevent unauthorised persons from entering the premises in which data processing systems are stored and with which personal data are processed.
Technical Access Control: Zinc takes technical measures to prevent data processing systems from being used by unauthorised persons. These include authentication when accessing computers or systems using a user ID and password, as well as setting up firewalls.
Personnel Access Control: Zinc ensures that only authorised personnel can access Personal Data and that said data cannot be copied, changed or deleted without authorisation during processing and use and after saving. When granting access rights to Zinc personnel working on Your project, Zinc follows the principle of least privilege to ensure Your data are accessed only by personnel that need the access in order to provide the Zinc Services as ordered by You.
Vulnerability & Penetration testing. In order to prevent any unauthorised attacks to our platform, Zinc maintains relationships with vulnerability and penetration testing service providers. Through penetration testing Zinc can identify and resolve foreseeable attacks and possible abuse scenarios and thus prevent them.
(B) Organisational Measures
DPO: Zinc has a designated Data Protection Officer (DPO) as well as a Legal Counsel and IT professionals, to monitor and ensure compliance with GDPR and local laws.
Personnel training: Zinc organises regular and obligatory company wide security training on top of our security training delivered during onboarding. Relevant personnel are required to sign NDAs where appropriate. During the course of engagement with Zinc, all personnel follow guidelines to ensure confidentiality, professional and ethical standards necessary to guarantee effective data protection.
Remote Working Policy: Zinc personnel must act in compliance with further measures such as the remote working policy, device secure setup and security awareness, strong passwords policy, two factor authentication process, etc.
Transfer Control: Zinc prevents personal data from being read, copied, changed or deleted in an unauthorised way during electronic transmission, transport or storage on data media through firewalls and encryption.
Input control: Zinc ensures that it can be subsequently checked whether and by whom personal data have been entered, changed or deleted. This includes logging, user identification.
Availability control; Zinc ensures that personal data are protected against accidental destruction or loss. This includes the usual fire protection measures and overvoltage protection, backup concept, virus protection, clean coding.
Separation control: Zinc ensures that personal data collected for different purposes are to be processed separately. This includes separate accounts and encryption methods.
Data Encryption: Reference data is encrypted in transit and at rest. All data is encrypted in transit. Authentication is added to every candidate background check report, single sign on login and two factor authentication is available.
TLS: Transport Layer Security (TLS) security protocol is used for communication within the app and web tracking.
Additional Technical Measures: Firewalls, logging, malware protection, vulnerability scans and other control mechanisms are in place to provide further technical security.
(D) Security Development practices
Zinc has the further following practices in place to ensure the security of the application:
1. Clean coding and least privilege access granting for Zinc IT developers.
2. Monitoring traffic – Internal network traffic is systematically checked for any suspicious behaviour.
3. Vulnerability Management – Zinc conducts web scans and scans for potential threats.
4. Incident Management - Zinc has a well-defined incident management process for security events, including reporting, prioritisation based on urgency, escalation and mitigation.
5. Business Continuity – Zinc reviews all business-critical functions.
6. Quality assurance – Zinc tests all new features before implementing them to the application.
(E) Further measures to protect Customer Data
Infrastructure. Zinc relies upon acknowledged hosting providers in the field, that (i) enable a multi-tenant, geographically distributed environment and a high availability infrastructure, (ii) comply with all data protection obligations as stipulated in applicable Data Protection Laws.
Control of Processors: Zinc ensures that personal data processed by Processors are processed in accordance with the instructions of Zinc. This includes control rights and data processing contracts according to the GDPR.
External review: Zinc is subject to external reviews to test, evaluate and confirm that the security measures are up-to-date, effective and functional.
Zinc currently maintains the following certifications:
ISO 27001
Tier 1 with the Independent Commissioners Office
Cyber Essentials
UK Digital Identity Certification Scheme
Zinc reserves the right to replace any security measures with an equivalent or enhanced alternative at any time during the term of the Agreement that ensure equal data security and measures in compliance with state of the art security standards applicable in the field.