This notice explains how Bonzer processes your personal data when you apply for a job, send an open application, or join our talent pool.
Who is responsible
The data controller is the Bonzer company that is hiring for the position — the company in the country where the job is based:
- Denmark: Bonzer ApS, CVR 38848267, Farvergade 2-4, 1463 København K
- Sweden: Bonzer AB, org.nr 559293-5919, Gamla Brogatan 32, Stockholm
- Norway: Bonzer AS, org.nr 927 399 059, Stortorvet 7 (c/o Spaces), 0155 Oslo
An open application is handled by the company for the market whose website you applied on (Bonzer ApS for bonzer.io), and passed to the company that hires if a relevant position opens. Questions about your data: [email protected]. We have not appointed a data protection officer, as we are not required to; our data protection contact can be reached at the same address.
What we process
- Data you give us: name, email, phone, location, LinkedIn profile, CV, cover letter, other attachments and your answers to the application questions.
- Data from the process: our notes, interview evaluations and ratings, and the emails we exchange with you.
- Data from others: references — only people you have given us, and only with your agreement. If we find you ourselves (e.g. on LinkedIn), we save your name, contact details and public professional profile and tell you within 30 days.
Please don't send sensitive information (e.g. health, religion, trade-union membership, sexual orientation) or national identity numbers — we don't need them to assess your application.
Why we process it and our legal basis
- To assess your application and run the recruitment process — steps taken at your request before an employment contract (GDPR Art. 6(1)(b)) and our legitimate interest in finding the right person for the role (Art. 6(1)(f)).
- Talent pool — only with your separate, explicit consent (Art. 6(1)(a)). You can withdraw it at any time; withdrawal doesn't affect processing before it.
- Legal claims — if needed, to establish or defend a legal claim, e.g. a discrimination complaint (Art. 6(1)(f)).
Giving us your data is voluntary, and you are not legally or contractually required to. But we can't consider your application without the information marked as required.
We don't use automated decision-making or profiling. People read and decide on every application.
Who has access
Only the people involved in the recruitment: the hiring manager and interviewers for the role, recruitment/HR and management — including colleagues in other Bonzer companies in Denmark, Sweden and Norway where the recruitment is shared.
Our suppliers process data on our behalf under data processing agreements: Vercel (website and app hosting), Neon (database, EU – Frankfurt), Cloudflare (file storage, EU) and Resend (email). Some of these are US companies; where data may be transferred outside the EU/EEA, the transfer is covered by the EU–US Data Privacy Framework and/or the EU Commission's standard contractual clauses. We never sell your data or share it for marketing.
How long we keep it
- Not hired: we delete your application and all related data 6 months after the recruitment process ends, so we can answer questions and handle any legal claims.
- Talent pool: 24 months from your consent. We ask you before it expires whether you want to stay; if you don't renew, we delete your data.
- Hired: the relevant data moves to your personnel file and is covered by our employee privacy notice.
- If a legal claim is raised, we keep the relevant data until it is resolved.
- Deleted data disappears from our encrypted backups within 30 days.
Your rights
You have the right to access your data, to have it corrected or deleted, to restrict or object to our processing, to receive your data in a portable format, and to withdraw consent at any time. You can see, download or delete your data yourself using the link in our emails, or write to [email protected].
You can complain to the data protection authority in the country of the company that is hiring: Datatilsynet in Denmark (www.datatilsynet.dk), Integritetsskyddsmyndigheten (IMY) in Sweden (www.imy.se) or Datatilsynet in Norway (www.datatilsynet.no) — or to the authority where you live or work.