Skip links

Privacy Policy

Contents

  1. Who We Are
  2. Scope of This Privacy Policy
  3. Key Terms
  4. Confidentiality in Executive Search
  5. Information We Collect and How We Use It
  6. Cookies and Similar Technologies
  7. Legal Bases for Processing
  8. International Data Transfers
  9. Data Retention
  10. Security
  11. Special Category Data; Criminal Conviction Data and Sensitive Personal Information
  12. Minors
  13. Automated Decision-Making and Profiling
  14. Your Privacy Rights (International; Non-United States)
  15. Your Privacy Rights (United States)
  16. Sharing and Disclosure of Personal Data
  17. Changes to This Privacy Policy
  18. Contact Us, Representatives, Data Protection Officer, and Supervisory Authorities
  19. Records of Processing, DPIA / PIPIA, Legitimate Interest Assessment, and Security Documentation
  20. Do Not Track and Global Privacy Control
  21. Specific Provisions for Executive Search — Market Mapping and Anti-Discrimination
  22. Language, Accessibility, and No Discrimination for Exercising Rights

1. Who We Are

Execruit GmbH (“Execruit,” “we,” “us,” or “our”) is a global executive search, recruitment solutions, and leadership advisory firm headquartered at Martinsgasse 20, CH-4051 Basel, Switzerland, registered in the Commercial Register of the Canton of Basel-Stadt under company number CHE-361.972.069. This Execruit Privacy Policy (the “Privacy Policy”) explains how we collect, use, share, and protect personal data in connection with our website at www.execruits.com and our executive search, recruitment solutions, and leadership advisory services (together, the “Services”). We are a Swiss-headquartered firm specialising in the identification, assessment and discreet approach of hard-to-reach, passive executive talent on behalf of our corporate clients in the United States, EMEA, APAC including mainland China.

For all privacy-related questions or to exercise your rights under applicable Data Protection Laws (as defined below), please contact us at privacy@execruits.com or via our website at www.execruits.com.

2. Scope of This Privacy Policy

This Privacy Policy applies wherever we process personal data in connection with the Services, including where we are:

  • Recruiting or evaluating you as a Candidate for a role with a Client, including where we have identified you through market research before we have had direct contact with you;
  • Identifying and presenting Candidates to you as a Client;
  • Engaging with you as a Referee or Source in connection with a Candidate;
  • Retaining you as a Vendor or business partner; or
  • Interacting with you as a visitor to our website.

In this Privacy Policy, “Candidate” means an individual being recruited or evaluated for a role with a Client, including passive or hard-to-reach candidates identified through market research; “Client” means a corporate customer that has retained us to provide Services; “Source” means an individual with market knowledge relevant to a search; “Referee” means a professional reference provided by a Candidate; and “Vendor” means a supplier or business partner.

We act as an independent data controller within the meaning of Article 5(j) nDSG, Article 4(7) EU/UK GDPR for market mapping and search, and as a data processor within the meaning of Article 28 EU/UK GDPR and Article 9 nDSG for Recruitment Process Outsourcing under a Data Processing Agreement. Our Clients become independent controllers upon receipt. Terms such as “controller”, “processor”, “Business”, “Service Provider”, “Sale”, and “Share” have the meanings given in Section 3.

We principally process personal data in accordance with the Swiss Federal Act on Data Protection of 25 September 2020 (“nDSG”) and its Ordinance of 31 August 2022 on Data Protection (“DSV”), and, where applicable, the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“EU GDPR”) and EU GDPR as it forms part of UK law by virtue of European Union (Withdrawal) Act 2018 as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (“UK GDPR”) (the EU GDPR and the UK GDPR are collectively referred to as the “EU/UK GDPR” in this Privacy Policy where the same provision applies under both laws), and Swiss Code of Obligations Article 958f regarding retention. Where we process personal data of individuals located in the United States, we comply with applicable US state privacy laws, including but not limited to the California Consumer Privacy Act Cal. Civ. Code §§1798.100 et seq. as amended by California Privacy Rights Act (“CCPA/CPRA”), Colorado Privacy Act Colo. Rev. Stat. §6-1-1301 et seq. (“CPA”), Connecticut Data Privacy Act Public Act No. 22-15 (“CTDPA”), Montana Consumer Data Privacy Act Mont. Code §30-14-2801 et seq. (“MCDPA”), Oregon Consumer Privacy Act ORS §646A.570 et seq. (“OCDPA”), Texas Data Privacy and Security Act Tex. Bus. & Com. Code §541 et seq. (“TDPSA”), Utah Consumer Privacy Act Utah Code §13-61-101 et seq. (“UCPA”), and Virginia Consumer Data Protection Act Va. Code §59.1-571 et seq. (“VCDPA”)— see Section 15. Where we process personal data in APAC, we comply with Singapore Personal Data Protection Act 2012 (“Singapore PDPA”), Federal Decree Law No. 45 of 2021 on Protection of Personal Data of United Arab Emirates (“UAE PDPL”), Privacy Act 1988 (Cth) of Australia and Australian Privacy Principles (“Australia Privacy Act”), Act on Protection of Personal Information of Japan (“Japan APPI”), and Personal Information Protection Law of People’s Republic of China (“PIPL”).

 

For hard-to-reach and passive talent sourcing, we collect professional data before direct contact based on legitimate interests within the meaning of Article 6(1)(f) EU/UK GDPR and Article 31(1) nDSG, subject to documented Legitimate Interest Assessment and Data Protection Impact Assessment where required under Article 35 EU/UK GDPR, and we provide notice at first contact or within 30 days per Article 14(3)(a) EU/UK GDPR and within reasonable time per Article 17 PIPL. “Data Protection Laws” means the nDSG, DSV, EU/UK GDPR, US State Laws (as defined in Section 15), Singapore PDPA, UAE PDPL, Australia Privacy Act, Japan APPI, and PIPL, as defined above.

3. Key Terms

3.1 Personal Data; Personal Information; Personal Information Under PIPL

Personal Data, Personal Information and Personal Information under Article 4 PIPL means any information relating to an identified or identifiable natural person within the meaning of Article 5(a) nDSG, Article 4(1) EU/UK GDPR, Section 2(1) Singapore PDPA, Article 1 UAE PDPL, Article 4 PIPL, and Cal. Civ. Code §1798.140(o) CCPA/CPRA and Va. Code §59.1-571 VCDPA and other US State Laws, such as name, date of birth, email address, postal address, telephone number, or online identifiers such as an IP address.

3.2 Sensitive Data and Special Category Date Under nDSG, EU/UK GDPR

Sensitive Data and Special Category Data under Article 5(c) nDSG and Article 9(1) EU/UK GDPR means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation, and under nDSG data relating to administrative or criminal proceedings and sanctions and data concerning social assistance measures.

Under CCPA/CPRA Cal. Civ. Code §1798.140(ae) Sensitive Personal Information includes social security number, driver’s licence, financial account with access credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, contents of mail, email, or text, genetic data, biometric data, health data, sex life or sexual orientation.

Under Article 28 PIPL Sensitive Personal Information means personal information that if leaked or illegally used may easily lead to infringement of personal dignity or harm to personal or property safety, including biometrics, religious beliefs, specific identity, medical health, financial accounts, location tracking, and personal information of minors under fourteen (14) years of age. We only process Special Category Data with explicit consent or another applicable legal basis — see Section 11.

3.3 Processing

Any operation performed on personal data, whether or not by automated means, including collection, storage, use, disclosure, and deletion, within the meaning of Article 5(d) nDSG, Article 4(2) EU/UK GDPR, and Article 73 PIPL. Controller, Business, Personal Information Processor means entity determining purposes and means per Article 5(j) nDSG, Article 4(7) EU/UK GDPR, Article 73 PIPL. Processor, Service Provider, Contractor, Entrusted Party means entity processing on behalf of controller per Article 5(k) nDSG, Article 4(8) EU/UK GDPR, Article 21 PIPL. Consent means freely given, specific, informed and unambiguous indication per Article 6(6) nDSG, Article 4(11) EU/UK GDPR, Section 14 Singapore PDPA, Article 14 PIPL, and where PIPL requires separate consent per Articles 29, 39, 56 PIPL. Sale, Share, Targeted Advertising have meanings in Cal. Civ. Code §§1798.140(ad), (ah), 1798.140(bb) and Va. Code §59.1-571.

4. Confidentiality in Executive Search

Confidentiality sits at the centre of how we operate, and this Privacy Policy is intended to describe not only our legal obligations but the discretion our clients and candidates rely on throughout a search:

  • Client search mandates are not disclosed to the market and are shared internally only with the team members directly engaged on that search on a need-to-know basis, pursuant to contractual confidentiality obligations and appropriate security measures.
  • Candidate identities and applications are not disclosed to a Client’s competitors, nor shared with any third party beyond the engaged Client, without the Candidate’s explicit, informed, and freely given consent for that specific mandate, documented in writing via email or signed consent form.
  • Every search we conduct, from initial market mapping through to signed offer, is treated as confidential by default.
  • Where a Candidate requests that their application remains confidential from their current employer, we will honour that request subject to legal disclosure obligations.

Nothing in this section limits your statutory privacy rights under applicable Data Protection Laws, nor our legal obligations under Section 16 to disclose personal data where required by law.

5. Information We Collect and How We Use It

We collect different personal data depending on your relationship with us. This section is organised by role — please refer to the section that applies to you. Because we specialise in hard-to-reach, passive executive talent, we may collect personal data about you even if you have not directly provided it to us, from publicly available professional sources and third-party market Sources, with data minimisation.

 

5.1 If You Are a Candidate

We collect personal data needed to identify, evaluate, and present you for suitable opportunities, even where you have not directly provided it to us because our Services involve identifying hard-to-reach, passive executive talent before direct contact. This includes your name, contact details, education and employment history, professional references, compensation where you voluntarily provide it, and, where relevant and permitted by law, information about your right to work or residency status. Where appropriate and with your explicit, separate consent, we may also collect Special Category Data and Sensitive Personal Information, such as information relevant to a reasonable accommodation request — see Section 11.

 

We use this information to assess your fit for specific roles based on human review, to present your candidacy to Clients with your explicit consent for that specific mandate, conduct reference checks with your knowledge, and, where you have given explicit consent to be included in our talent pool, keep you informed of future opportunities that may be of interest.

 

5.1.1 Categories and Sources: (a) Directly from you when you submit CV, cover letter, application form, interview notes, assessments, work samples, compensation expectations where voluntary, and accommodation needs; (b) From publicly available professional sources such as LinkedIn, employer websites, press releases, industry publications, conference speaker lists, securities filings, and professional association directories — only business-relevant professional information; (c) From third-party market Sources and referrals such as industry Sources and Clients who may suggest you as hard-to-reach talent, we record category of Source and, where permissible, identity of Source, date first identified, and mandate reference, and we do NOT use private investigators or unlawful means; (d) From our own talent pool where you previously consented.

5.1.2 Purposes and Legal Bases: (i) Market mapping of hard-to-reach talent before direct contact: legitimate interests with documented Legitimate Interest Assessment; (ii) Initial confidential approach: legitimate interests and pre-contractual steps; (iii) Presentation to specific Client: explicit consent per mandate, including separate consent for disclosure and cross-border transfer under PIPL where applicable; (iv) Reference checks: legitimate interest and consent; (v) Talent pool: explicit consent; (vi) Legal compliance. See Section 7 for full legal bases.

5.1.3 Notice to Passive Candidates: We provide privacy notice to passive candidates at first communication or within thirty (30) days of first obtaining personal data, whichever is earliest, and in any event before first disclosing your personal data to a Client, and only where you have consented to such disclosure.

5.1.4 No Obligation and Right to Object: There is no statutory or contractual obligation for you as a Candidate to provide your personal data, except where we are required by law for right-to-work verification or where you are already under contract. This information is provided pursuant to applicable Data Protection Laws.

Provision is voluntary, but if not provided then we cannot assess suitability, present candidacy, conduct reference checks, or keep you informed. For passive candidates, you are not required to respond, and non-response will be treated as an objection after ninety (90) days.

For individuals in mainland China, where personal data is marked as required as necessary, non-provision means we cannot achieve that purpose. Where marked optional, non-provision does not affect consideration.

Because we may collect personal data before direct contact, you have the right to object at any time to this processing, including profiling related to such sourcing, on grounds relating to your particular situation under applicable Data Protection Laws. This includes a suppression and do-not-contact list (meaning a limited list of contact details we retain solely to ensure we do not re-contact individuals who have objected).

To exercise your right to object to hard-to-reach sourcing, you may: (a) reply to our initial outreach email with subject “Do Not Contact — Suppression” or click unsubscribe; (b) email us at privacy@execruits.com with subject “Objection to Hard-to-Reach Sourcing”; (c) use LinkedIn InMail; or (d) via our website at www.execruits.com.

Upon receipt of your objection, we will: (i) stop processing for market mapping and outreach within five (5) business days; (ii) delete profile notes and market mapping notes within ninety (90) days, except minimal contact data; (iii) retain only your name, business email address, date of objection, and source of objection on our suppression and do-not-contact list, with restricted access on a need-to-know basis and not used for any other purpose, for five (5) years (for mainland China three (3) years per CAC Measures on Standard Contract, or five (5) years where required to demonstrate compliance with EU/UK GDPR); and (iv) honour withdrawal of consent.

Your objection does not affect the lawfulness of processing before objection. You may also object to talent pool inclusion by emailing privacy@execruits.com with subject “Withdraw Consent — Talent Pool”. If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or Montana, disclosing your personal data as a candidate to a Client as part of our paid executive search mandate for valuable consideration may be considered a sale, share, or targeted advertising under applicable US State Laws. You have the right to opt-out as described in Section 15. For mainland China, you may opt-out by not providing separate consent.

Where processing is based on consent, you may withdraw consent at any time by emailing privacy@execruits.com with subject “Withdraw Consent”, without affecting lawfulness before withdrawal.

5.2 If You Are a Client or a Prospective Client

We collect business contact information for individuals within your organisation involved in a search — such as name, job title, role, business email address, business telephone, business address, and organisation name — to scope, negotiate, and deliver Services, including market mapping, recruitment process outsourcing under a Data Processing Agreement, and leadership advisory. We also collect billing information and communications such as emails, meeting notes, and feedback on Candidates, and commercial information such as search mandate history. Purposes are performance of contract, legitimate interests to manage Client relationship and legal obligation per Article 958f Swiss Code of Obligations. Retention per Section 9. Disclosure is internal need-to-know, processors such as Zone Media OÜ, Calendly LLC, Usercentrics A/S, accounting providers, professional advisors, where required by law.

5.3 If You Are a Referee or Source

If a Candidate identifies you as a professional reference or referee, or if you are approached as a Source, we collect personal data you provide, including name, business contact details, current role and employer, relationship to Candidate, professional assessment such as strengths, leadership style, achievements, areas for development, and verification of employment history. This information is used solely to support the relevant search and to assess suitability for the specific mandate for which the Candidate has consented, and is not disclosed beyond engaged Client team and internal search team on a need-to-know basis without your knowledge and without Candidate consent to presentation, except where required by law or where you explicitly agree to broader disclosure. Retention per Section 9. Notice is provided at first contact.

5.4 If You Are a Vendor or Business Partner

We collect contact and billing information necessary to manage relationships with vendors, suppliers and business partners, such as name, business role, business email, business phone, business address, VAT number, banking details for payment where you provide services, contract details, purchase order numbers, invoices, and communications. Purposes are performance of contract, legitimate interests, and legal obligation per Article 958f Swiss Code of Obligations. Retention per Section 9.

5.5 If You Are Visiting Our Website

5.5.1 Log Data: Each visit is automatically recorded in a server log file, including IP address shortened or truncated where possible, date and time of access, requested URL, data volume, browser type and version, operating system, referring website, and pages accessed. Purpose is security, stability, error diagnosis, and prevention of abuse. Legal basis is legitimate interests in secure and reliable operation. Retention is thirty (30) days unless security incident requires longer, after which logs deleted or anonymised. Recipient is hosting provider Zone Media OÜ, Lõõtsa 2A, 11415 Tallinn, Estonia, acting as processor.

5.5.2 Hosting: Our website is hosted by Zone Media OÜ, Lõõtsa 2A, 11415 Tallinn, Estonia (zone.ee), which processes infrastructure log data as processor under Data Processing Agreement on basis of legitimate interest. Server location is EU.

5.5.3 Content Management System: We use WordPress.org open-source software self-hosted on our servers at Zone Media OÜ and no personal data is transferred to Automattic Inc. for CMS hosting. Where we use WordPress.com hosting, WordPress.com is provided by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA as processor with transfer to US under EU Standard Contractual Clauses 2021/914 and EU-US Data Privacy Framework.

5.5.4 Appointment Booking: We use Calendly, LLC, 271 17th Street NW, Suite 400, Atlanta, GA 30363, USA to simplify scheduling. Information you submit through Calendly is transferred to Calendly as processor and retained until you request deletion or per Calendly’s retention schedule, and by us for twelve (12) months after meeting date then deleted. Legal basis is pre-contractual steps.

5.5.5 Third-Party Content and Services: We use the following third-party services ONLY with your prior consent obtained via our Consent Management Platform Cookiebot by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark:

  • Analytics: Google Analytics 4 (GA4) provided by Google Ireland Ltd. and Google LLC, with IP anonymisation, data retention fourteen (14) months;
  • Tag Management: Google Tag Manager and Google Site Tag (Google LLC);
  • Fonts: Google Fonts (Google LLC) implemented locally, and Font Awesome (Fonticons, Inc.) implemented locally;
  • Remarketing and Conversion Measurement: Google Ads (Google LLC) only with consent up to 540 days. For US, this may constitute a sale/share under applicable US State Laws — see Section 15.

 

5.5.6 Social Media: We maintain a presence on LinkedIn, Facebook, Instagram, and X (formerly Twitter). If you contact or connect with us on any of these platforms, we and the relevant platform operator are joint controllers for Page Insights where applicable, and independent controllers otherwise. For LinkedIn, we are joint controllers for analytics per LinkedIn Page Insights Joint Controller Addendum.

6. Cookies and Similar Technologies

Our website uses cookies and similar technologies to operate correctly and, where you have given prior consent, to analyse site usage, personalise content, and measure effectiveness of advertising. Essential cookies are strictly necessary for the website to function and are used based on our legitimate interests and necessity to provide service. Non-essential cookies such as analytics, functional, and marketing cookies are used only with your prior consent, obtained through Cookiebot.

When you provide or revoke consent, we record your consent status, ID, timestamp, consent state by category, IP address, browser and device information, URL, and the time of your visit as proof of consent, retained for twelve (12) months. You may change or withdraw your consent at any time via cookie icon in the bottom left corner, which does not affect the lawfulness before withdrawal. For US residents, analytics and marketing cookies may constitute sale/share — see Section 15 and use Your Privacy Choices link and Global Privacy Control. For mainland China, non-essential cookies are blocked until separate consent is given via CMP.

For further details, including how to withdraw consent, please refer to our standalone Cookie Policy at [INSERT HYPERLINK TO COOKIE POLICY URL] which is incorporated herein by reference and forms part of this Privacy Policy.

Depending on the nature of the processing, our legal basis is one or more of the following:

  • Consent: You have given your consent within the meaning of Article 6(1)(a) EU/UK GDPR, Article 31(1) nDSG, Articles 13(1) and 14 PIPL separate consent, and where applicable consent under Section 15A Singapore PDPA, Article 5(1)(a) UAE PDPL, and US consent where required for sensitive data under Cal. Civ. Code §1798.121;
  • Contract: Necessary for performance of a contract or pre-contractual steps within the meaning of Article 6(1)(b) EU/UK GDPR, Article 31(1)(b) nDSG, Article 13(3) PIPL;
  • Legal Obligation: Necessary to comply with legal obligation within the meaning of Article 6(1)(c) EU/UK GDPR, Article 31(1) nDSG, Article 13(4) PIPL; or
  • Legitimate Interests: Necessary for our legitimate interests, provided not overridden by your interests or fundamental rights, within the meaning of Article 6(1)(f) EU/UK GDPR, Article 31(1) nDSG, legitimate business purpose under US State Laws, Section 15A(1) Singapore PDPA, Article 5(1)(e) UAE PDPL.

We have conducted a Legitimate Interest Assessment for hard-to-reach sourcing considering nature of data only professional publicly available or limited referral, reasonable expectations, limited impact confidential approach easy opt-out and suppression, safeguards notice within thirty (30) days, suppression list, data minimisation, pseudonymisation, no Special Category inference. Summary available on request at privacy@execruits.com.

8. International Data Transfers

As a global search firm headquartered in Switzerland, personal data will be transferred internationally: From Switzerland to the EU/EEA, United Kingdom, United States, Singapore, United Arab Emirates, Australia, Japan, mainland China, and other jurisdictions; From EU/EEA to Switzerland (Switzerland benefits from EU adequacy decision Commission Decision 2000/518/EC as updated 15 January 2024), United Kingdom, United States, APAC; From United Kingdom to Switzerland, EU/EEA, United States, APAC; From mainland China to Switzerland and other countries outside mainland China, subject to Articles 38-40 PIPL under Chapter III PIPL. Adequacy: Switzerland and United Kingdom adequate under Article 45 EU/UK GDPR; United States does NOT have full adequacy except organisations certified under EU-US Data Privacy Framework; Singapore, UAE, Australia, Japan and mainland China have no adequacy decision. Mechanisms: (a) EU Standard Contractual Clauses Commission Implementing Decision (EU) 2021/914 with Swiss addendum and UK Addendum or UK IDTA; (b) EU-US Data Privacy Framework and UK Extension where certified supplemented by SCCs; (c) For APAC and mainland China, use of SCCs plus supplementary measures including TLS 1.2+ and pseudonymisation, PIPIA per Article 55 PIPL, and separate consent where required.

A list of our current sub-processors is available on request via email to privacy@execruits.com.

9. Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable legal retention periods. We apply storage limitation and data minimisation per applicable Data Protection Laws. As general guidance:

  • Candidate Data: Where you have directly engaged with us, we retain your candidate profile and search records for the duration of an active search and for five (5) years after our last meaningful contact where you have given explicit consent to be included in our talent pool. For purposes of this Privacy Policy, “meaningful contact” means a two-way communication in writing or by meeting where you respond substantively, confirm continued interest, attend an interview, or update your CV or preferences. If you withdraw consent or request deletion, we will delete your data within thirty (30) days, except for minimal contact data retained on our suppression list per Section 5.1.4.
  • Candidate Profiles Presented to a Specific Client: Retained for five (5) years after the presentation date to defend against potential claims.
  • Passive Hard-to-Reach Candidates Who Object or Do Not Respond: Deleted within ninety (90) days of your objection or non-response, with suppression list retained for five (5) years (three (3) years for mainland China per CAC Measures, or five (5) years where required by EU/UK GDPR compliance).
  • Talent Pool With Consent: Five (5) years from our last meaningful contact with you, renewed with each meaningful contact where you confirm continued consent.
  • Market Mapping Data for Candidates Never Contacted: Anonymised or deleted within twelve (12) months.
  • Client Data: Duration plus ten (10) years per Article 958f of the Swiss Code of Obligations for accounting, plus five (5) years for contractual claims.
  • Referee and Source Data: Twenty-four (24) months after search closure, or five (5) years where needed to defend claims.
  • Vendor and Business Partner Data: Duration of the relationship plus ten (10) years per Article 958f.
  • Website Log Data: Thirty (30) days unless security incident requires longer.
  • Cookie Consent Logs: Twelve (12) months as proof of consent.
  • Appointment Booking Data: Twelve (12) months after meeting date and then deleted.
  • Accounting and Tax Records: Ten (10) years per Article 958f.
  • PIPL Transfer and Consent Records: At least three (3) years per Article 24 of the CAC Measures on Standard Contract.
  • Suppression and Do-Not-Contact Lists: Five (5) years with restricted access on a need-to-know basis and not used for any other purpose, three (3) years for mainland China per CAC Measures on Standard Contract, or five (5) years where required to demonstrate compliance with EU/UK GDPR — per Section 5.1.4.

Once the applicable purpose or retention period has ended, the corresponding personal data is deleted, anonymised, or archived with restricted access on a need-to-know basis or securely deleted. For purposes of Cal. Civ. Code §1798.100(c), each retention period above is reasonably necessary for the disclosed purpose for which the personal information was collected, plus legal obligations. For mainland China, retention is limited to the minimum necessary to achieve the purpose per Article 19 PIPL and within the scope of your consent. Where you withdraw consent per Article 15 PIPL, we will delete or anonymise your personal information within fifteen (15) business days, except for suppression data and records we are legally required to retain per Article 24 and Article 47 PIPL.

10. Security

Our website uses TLS 1.2+ or higher encryption to protect data in transit. We also use encryption at rest where feasible, including AES-256 encryption for databases containing Candidate data.

We implement appropriate technical and organisational measures, including access controls on a need-to-know basis, to ensure a level of security appropriate to the risk, per Articles 8 nDSG, Article 7 DSV, Article 32 EU/UK GDPR, reasonable security procedures and practices appropriate to nature of personal information per Cal. Civ. Code §1798.81.5 and applicable Data Protection Laws.

These measures include: role-based access controls (RBAC) on need-to-know basis; multi-factor authentication (MFA); pseudonymisation and anonymisation where possible; regular security patching; secure encrypted backups; logging and monitoring with intrusion detection; contractual obligations for processors per applicable Data Protection Laws; employee confidentiality agreements and training; and physical security measures for our office at Martinsgasse 20, CH-4051 Basel, Switzerland.

No method of transmission over the internet or method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authorities and the affected individuals as required by applicable law, for example:

  • Switzerland: Where required under Article 24 nDSG and Article 22 DSV, we will notify the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern, within seventy-two (72) hours of becoming aware of the breach where the breach is likely to result in a high risk to your personality or fundamental rights.
  • EU/EEA: Where the EU GDPR applies, we will notify the relevant EU supervisory authority within seventy-two (72) hours per Article 33 EU GDPR, and we will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms per Article 34 EU GDPR.
  • United Kingdom: Where the UK GDPR applies, we will notify the Information Commissioner’s Office (ICO) within seventy-two (72) hours per Article 33 UK GDPR, and we will notify affected individuals without undue delay where high risk per Article 34 UK GDPR.
  • Singapore: Where the Singapore PDPA applies and the breach is a notifiable data breach per Part 6A of the Singapore PDPA (where it is likely to result in significant harm or is of significant scale), we will notify the Personal Data Protection Commission (PDPC) and affected individuals as required per Section 26B and Section 26D PDPA within three (3) calendar days where feasible.
  • Mainland China: Where the PIPL applies, we will immediately take remedial measures per Article 57 PIPL and notify the relevant PRC authorities, including the Cyberspace Administration of China (CAC) and relevant sector regulators, and notify affected individuals per Articles 57 and 58 PIPL and the CAC Measures on Data Breach Reporting, including the nature of the breach, cause, categories of personal information affected, impact, remedial measures taken, and contact details.

We maintain a personal data breach register documenting facts, effects, and remedial actions.

11. Special Category Data; Criminal Conviction Data and Sensitive Personal Information

We do not actively seek Special Category Data within the meaning of Article 5(c) nDSG, Article 9(1) EU/UK GDPR, or Sensitive Personal Information within the meaning of Article 28 PIPL or Cal. Civ. Code §1798.140(ae).

Special Category Data includes personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for uniquely identifying a natural person, data concerning health, or sex life or sexual orientation. Under nDSG, it also includes data relating to administrative or criminal proceedings and sanctions and data concerning social assistance measures. Under CCPA/CPRA, Sensitive Personal Information includes social security number, driver’s licence, financial account with access credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, contents of mail, email, or text messages, genetic data, biometric data, health data, and data concerning sex life or sexual orientation. Under Article 28 PIPL, Sensitive Personal Information means personal information that, if leaked or illegally used, may easily lead to infringement of personal dignity or harm to personal or property safety, including biometrics, religious beliefs, specific identity, medical health, financial accounts, location tracking, and personal information of minors under fourteen (14) years of age.

We only process Special Category Data and Sensitive Personal Information where it is specifically required in connection with the Services and where we have obtained your explicit, separate consent for that specific purpose, or another legal basis applies, such as where necessary for employment law obligations where authorised, or where you have manifestly made information public.

In hard-to-reach sourcing, we may inadvertently encounter information that could be Special Category Data from a public profile, such as a political office held. We do not infer or record such information unless you have explicitly made it public for professional purposes and it is relevant to role, and even then only with explicit consent. We train researchers not to record diversity characteristics unless voluntarily self-disclosed with explicit consent.

Data concerning right-to-work and immigration status is not Special Category Data but is treated as sensitive and processed only where permitted by applicable immigration law and where necessary to comply with legal obligations.

Data concerning criminal convictions and administrative or criminal proceedings and sanctions per Article 10 EU/UK GDPR and Article 5(c) nDSG is not processed unless permitted by applicable law, relevant to a role requiring background checks, and processed with explicit consent and appropriate safeguards where lawful.

12. Minors

Our Services are directed at professionals aged eighteen (18) and over and at organisations, not at children. We do not knowingly collect personal data from minors.

We do not knowingly collect personal data from individuals under eighteen (18) years of age. Where a higher age of consent applies under applicable US State Laws, such as the opt-in consent requirement for sale or share of personal information of individuals under sixteen (16) years of age under Cal. Civ. Code §1798.120(c), we do not knowingly collect personal data from individuals under sixteen (16) years of age. Under Article 28 PIPL, personal information of minors under fourteen (14) years of age in mainland China is Sensitive Personal Information, and we do not process such information without verifiable parental consent per Article 31 PIPL.

If we become aware that we have inadvertently collected personal data from a minor without appropriate consent, we will delete that data within thirty (30) days, unless legally required to retain longer for safety or legal reasons. If you believe we have collected personal data from a minor, please contact us using the methods in Section 18 with subject “Minor Data Deletion Request”.

13. Automated Decision-Making and Profiling

We do not make decisions about you based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you, per applicable Data Protection Laws.

All assessments of Candidate suitability for executive roles involve human review. We may use limited automated tools for operational purposes that do not produce legal effects, such as spam filtering, virus scanning, and keyword searching within our talent pool database to prioritise outreach order based on professional experience, seniority, industry, function, and location against Client mandate criteria.

Where we use automated tools for search ranking or prioritisation, logic is keyword matching and filtering, significance is to prioritise outreach order for human review, and you may request explanation of logic, request human intervention, and object to or refuse decision made solely by automated means by contacting us per Section 18 with subject “Automated Decision-Making Explanation Request”.

We do not use automated decision-making to infer Special Category Data or Sensitive Personal Information without explicit consent.

14. Your Privacy Rights (International; Non-United States)

14.1 Switzerland / EU / UK / Singapore / Australia / Japan / Mainland China

Subject to conditions and exceptions under applicable Data Protection Laws, you may have the following rights:

  • Right to be Informed: You have the right to be informed about how we process your personal data. This Privacy Policy is intended to provide that information.
  • Right of Access: You have the right to request information about the personal data we hold about you and to obtain a copy.
  • Right to Correction: You have the right to request correction of inaccurate or incomplete personal data.
  • Right to Object: You have the right to object to certain processing based on legitimate interests, including objecting to executive search and market mapping, profiling, and on grounds relating to your particular situation. See Section 5.1.4 for suppression within five (5) business days.
  • Right to Deletion: You have the right to request deletion of your personal data per applicable Data Protection Laws.
  • Right to Restriction: You have the right to request restriction of processing where you contest accuracy, processing is unlawful but you oppose erasure, we no longer need data but you need it for legal claims, or you have objected pending verification.
  • Right to Data Portability: You have the right to request data portability to receive personal data you provided in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
  • Right to Withdraw Consent: You have the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. For mainland China, you may withdraw separate consents individually.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority. See Section 18.
  • Right Not to be Subject to Solely Automated Decision-Making: You have the right not be subject to a decision based solely on automated processing that produces legal effects. See Section 13.

To exercise any of these rights, please use the contact us at privacy@execruits.com or via our website at www.execruits.com with subject “Privacy Rights Request”. We will verify your identity by requesting at least your email address and one other identifier and, where sensitive data is involved, a redacted government ID. We will respond as soon as reasonably possible and, in any event, within the timeframe required by applicable law: thirty (30) days per Article 25(3) nDSG and Article 19(1) DSV; one (1) month per Article 12(3) EU/UK GDPR, extendable by two (2) months where complex; forty-five (45) days per Cal. Civ. Code §1798.130(a)(2) for US residents extendable by forty-five (45) days; thirty (30) days per Section 21(3) Singapore PDPA; and fifteen (15) business days internal SLA per Article 50 PIPL guidance for mainland China. If we are unable to fulfil a request, we will explain why, subject to confidentiality owed to Sources.

14.2 Other International Jurisdictions

In addition to jurisdictions expressly listed, we may process personal data of individuals located in other countries where we identify executive talent or where Clients are located. Where we process personal data in such other jurisdictions, we will comply with applicable laws and will honour substantially similar rights where required by applicable law. This Section 14 shall be interpreted to provide at least the minimum rights required under the applicable Data Protection Laws for residents of that jurisdiction.

To exercise rights in any other jurisdiction, you may contact us per Section 18 with subject line “Privacy Rights Request — [Jurisdiction]”. We will respond within timeframe required by applicable law, or within thirty (30) days where no specific timeframe applies.

15. Your Privacy Rights (United States)

This Section 15 provides additional disclosures and rights for residents of the United States under applicable comprehensive US state privacy laws, including as of the Effective Date of this Privacy Policy, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), Cal. Civ. Code §§1798.100 et seq., the Virginia Consumer Data Protection Act (“VCDPA”), Va. Code §59.1-571 et seq., the Colorado Privacy Act (“CPA”), Colo. Rev. Stat. §6-1-1301 et seq., the Connecticut Data Privacy Act (“CTDPA”), Public Act No. 22-15, the Utah Consumer Privacy Act (“UCPA”), Utah Code §13-61-101 et seq., the Texas Data Privacy and Security Act (“TDPSA”), Tex. Bus. & Com. Code §541 et seq., the Oregon Consumer Privacy Act (“OCDPA”), ORS §646A.570 et seq., the Montana Consumer Data Privacy Act (“MCDPA”), Mont. Code §30-14-2801 et seq., and other US state comprehensive privacy laws that have been enacted as of the Effective Date or that become effective during the term of this Privacy Policy, together with their implementing regulations, as amended from time to time (collectively, “US State Laws”).

15.1 Controller and Applicability

Execruit GmbH, Martinsgasse 20, CH-4051 Basel, Switzerland, is a Business and Controller within the meaning of CCPA/CPRA Cal. Civ. Code §1798.140(c) and (j) and VCDPA Va. Code §59.1-571 and similar definitions under other US State Laws. This Section 15 supplements the rest of our Privacy Policy and applies only to personal information that is subject to US State Laws. Where there is a conflict between this Section 15 and the rest of the Privacy Policy for US residents, this Section 15 prevails for US personal information.

15.2 Categories Collected in the Last 12 Months

Per Cal. Civ. Code §1798.130(a)(5)(B), we have collected:

(a) Identifiers: name, email, telephone, IP address, Calendly ID, cookie ID. Sources: Directly from you, publicly available professional sources, referrals and market Sources. Purpose: Executive search including market mapping. Retention: Per Section 9. Disclosed to: Clients only with explicit consent, processors such as Zone Media OÜ, Calendly LLC, Google LLC only with consent, Usercentrics A/S, Automattic Inc. where applicable, professional advisors. Sold or Shared: Yes. Disclosing candidate Identifiers and Professional Data to a Client as part of paid search mandate for valuable consideration may be considered sale per Cal. Civ. Code §1798.140(ad) or share per §1798.140(ah).

(b) Personal Information per §1798.80(e): name, signature, telephone, postal address, education, employment history. Same sources, purposes, retention, disclosure, sale/share as (a).

(c) Protected Classification: age, date of birth where voluntary, accommodation needs where explicit separate consent. Disclosed to: Client only with explicit separate consent. Sold/Shared: No.

(d) Commercial Information: meeting bookings and mandate history. Disclosed to: Calendly, LLC. Sold/Shared: No.

(e) Internet or Other Electronic Network Activity: log data, cookie IDs, analytics, advertising IDs. Disclosed to: Google LLC only with consent. Sold/Shared: Yes.

(f) Professional or Employment-Related Information: CV, work history, qualifications, achievements, assessments, compensation where voluntary, reference notes. Disclosed to: Clients only with explicit consent. Sold/Shared: Yes.

(g) Sensitive Personal Information per §1798.140(ae): precise geolocation where voluntary, accommodation data, right-to-work data, financial account information where provided as vendor. Disclosed to: Clients only with explicit separate consent and processors need-to-know. Sold/Shared: No.

(h) Inferences: search fit and suitability assessments. Disclosed to: Client only with explicit consent. Sold/Shared: No. We do not collect Social Security numbers, driver’s licence numbers, state ID numbers, financial account numbers with access credentials, biometric data, or contents of mail, email, or text messages beyond described.

15.3 Sources

Directly from you; publicly available professional sources; referrals and market Sources; Clients; existing talent pool where consented; and automatically from your device.

15.4 Retention Justification

Per Cal. Civ. Code §1798.100(c), each retention period in Section 9 is reasonably necessary for disclosed purpose, plus legal obligations such as ten (10) years per Article 958f Swiss Code of Obligations, five (5) years to defend claims, thirty (30) days for website security, twelve (12) months for consent proof, and three (3) years for PIPL transfer records.

15.5 Sale, Share, and Targeted Advertising and Opt-Out

We do not sell personal information for money in traditional sense. However, under broad definition of sale per Cal. Civ. Code §1798.140(ad) and share per §1798.140(ah) for cross-context “behavioral” advertising and targeted advertising under applicable US State Laws, disclosing candidate personal information to a Client as part of paid executive search mandate for valuable consideration may be considered sale, share, or targeted advertising.

You have right to opt-out of sale, share, targeted advertising and profiling in furtherance of decisions that produce legal or similarly significant effects under applicable US State Laws. Methods:

(a) Your Privacy Choices Link in footer with opt-out icon per Cal. Civ. Code §1798.135(a)(1) and Cal. Code Regs. Title 11 §7004;

(b) Email privacy@execruits.com subject “Do Not Sell or Share My Personal Information”;

(c) Global Privacy Control at https://globalprivacycontrol.org per Cal. Code Regs. Title 11 §7025(c);

(d) Cookie icon to reject analytics/marketing cookies;

(e)  via our website at www.execruits.com.

We do not have actual knowledge that we sell or share personal information of individuals under sixteen (16).

15.6 Notice at Collection

Per Cal. Civ. Code §1798.100(b), at or before collection we provide notice of categories per Section 15.2, purposes per Section 5 and 7, retention per Section 9, whether sold/shared per Section 15.2, and retention justification per Section 15.4.

15.7 Your US Privacy Rights — How to Exercise

Subject to exceptions under Cal. Civ. Code §1798.145 and similar provisions in other US State Laws, you have the following rights:

(a) Right to Know and Access: Under CCPA/CPRA and other applicable US State Laws, you have right to know categories, sources, purposes, third parties, and specific pieces of personal information.

(b) Right to Delete: Under CCPA/CPRA and other applicable US State Laws, you have right to request deletion, subject to exceptions such as legal obligations.

(c) Right to Correct: Under CCPA/CPRA and other applicable US State Laws, you have right to request correction.

(d) Right to Opt-Out of Sale, Share, Targeted Advertising, and Profiling: Under CCPA/CPRA and other applicable US State Laws, you have right to opt-out. See Section 15.5.

(e) Right to Limit Use and Disclosure of Sensitive Personal Information: Per Cal. Civ. Code §1798.121, you have right to limit use to permitted purposes. We only use sensitive personal information for permitted purposes.

(f) Right to Non-Discrimination: Under CCPA/CPRA and other applicable US State Laws, we will not discriminate against you for exercising rights, except where permitted.

(g) Right to Appeal: Under applicable US State Laws, you have right to appeal denial. See Section 15.9.

To submit a US privacy rights request, please contact us at privacy@execruits.com with subject line “US Privacy Rights Request — [Know/Delete/Correct/Opt-Out]” or via our website at www.execruits.com.

We verify identity per Cal. Civ. Code §1798.132 by matching at least email address and one other identifier, and where sensitive data involved, redacted government ID. We will not require you to create account. Authorised Agent: You may designate an “authorized agent” per Cal. Civ. Code §1798.145 by providing signed permission and proof of registration where business entity, plus verification of your identity directly unless you provided power of attorney per California Probate Code. Response Timing: Forty-five (45) days per Cal. Civ. Code §1798.130(a)(2), extendable by additional forty-five (45) days where reasonably necessary with notice, and sixty (60) days for Colorado appeal.

15.8 Non-Discrimination and Financial Incentives

We will not discriminate for exercising rights under applicable US State Laws. We do not offer financial incentives per Cal. Civ. Code §1798.125(b). If we offer an incentive “program” in future, we will provide notice and obtain opt-in consent.

15.9 Right to Appeal and State Attorney General Contacts

If we deny your US privacy rights request, you have right to appeal under applicable US State Laws. To appeal, email privacy@execruits.com with subject line “Appeal — US Privacy Rights Request” within forty-five (45) days of denial. We will respond within forty-five (45) days, sixty (60) days for Colorado, with written explanation.

If appeal denied, you may contact your State Attorney General:

15.10 Shine the Light

Per California Shine the Light law, Cal. Civ. Code §1798.83, California residents who have established business relationship with us may request once per calendar year information about personal information we disclosed to third parties for their direct marketing purposes in preceding calendar year, if any. To make request, email privacy@execruits.com with subject line “Shine the Light Request”. We will respond within thirty (30) days. We do not currently disclose personal information to third parties for their own direct marketing purposes without consent per Section 16.

15.11 Anti-Discrimination Compliance

Our executive search services comply with Title VII of Civil Rights Act of 1964, 42 U.S.C. §2000e et seq., Age Discrimination in Employment Act, 29 U.S.C. §621 et seq., Americans with Disabilities Act, 42 U.S.C. §12101 et seq., Genetic Information Nondiscrimination Act, and applicable US state and local anti-discrimination laws such as California Fair Employment and Housing Act, Cal. Gov. Code §12900 et seq. We do not accept Client instructions that would require unlawful discrimination per Section 21.

15.12 De-Identified Data

Per Cal. Civ. Code §1798.140(m), where we maintain de-identified data, we will not attempt to re-identify it and will contractually require recipients not to attempt to re-identify and to maintain de-identification.

15.13 Catch-All for Other US States and Future US State Privacy Laws

In addition to US State Laws expressly listed, we will honour privacy rights required under other comprehensive US state privacy laws that have been enacted as of Effective Date or that become effective after Effective Date, including Iowa, Indiana, Tennessee, Delaware, New Jersey, Nebraska, New Hampshire, Minnesota, Maryland, Rhode Island, Wisconsin, Kentucky, and similar laws. Where a US state law provides rights substantially similar to those described in Sections 15.7 and 15.9, we will provide such rights to residents of that state as required, using same methods described in Section 15.7. We will not discriminate against you for exercising rights under any US State Law. This Section 15 shall be interpreted to provide at least the minimum rights required under the applicable US State Law for residents of that state.

16. Sharing and Disclosure of Personal Data

We do not sell personal data for money in the traditional sense. However, as explained in Section 15, under the broad definition of sale and share under CCPA/CPRA, disclosing candidate Identifiers and Professional Data to a Client as part of a paid search mandate for valuable consideration may be considered a sale or share. You may opt-out as described in Section 15.

We disclose Personal Data only as described in this Privacy Policy and as follows:

(a) Clients: We disclose candidate data to Clients only with the Candidate’s prior explicit consent for that specific mandate. For individuals located in mainland China, we obtain separate consent for disclosure and for cross-border transfer. Upon receipt, the Client becomes an independent controller, or separate Personal Information Processor under PIPL, and is responsible for its own compliance.

(b) Service Providers, Processors, and Entrusted Parties: We disclose personal data to our service providers who process personal data on our behalf under a Data Processing Agreement or Entrustment Agreement that meets requirements under applicable Data Protection Laws. These providers include: hosting provider Zone Media OÜ, Lõõtsa 2A, 11415 Tallinn, Estonia; IT support and maintenance providers under contract; content management system provider WordPress.org self-hosted or, where applicable, Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA; appointment booking provider Calendly LLC, 271 17th Street NW, Suite 400, Atlanta, GA 30363, USA; consent management provider Cookiebot by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark; analytics and advertising provider Google Ireland Ltd. and Google LLC, only where you have consented; professional advisors including legal and accounting advisors; and our PIPL representative for mainland China per Section 18.1. A current list of processors and entrusted parties is available on request at privacy@execruits.com.

(c) Legal and Compliance: We may disclose personal data where required by law, court order, subpoena, or regulatory request, where necessary to protect our rights, prevent fraud, enforce our terms, in connection with legal proceedings, or to comply with legal obligations under applicable law, including to comply with obligations under PIPL for mainland China.

(d) Corporate Transactions: We may disclose personal data in connection with a merger, acquisition, reorganisation, or sale of assets, subject to appropriate confidentiality obligations. Where such transaction occurs, we will notify you as required by applicable law.

We do not disclose personal data to third parties for their own direct marketing purposes without your consent.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology or in applicable law.

We will post the updated version on our Website with a new “Effective Date” and “Last Updated” date at the top. For material changes, we will notify you via website banner and, where we have your email address and applicable law requires, via email at least thirty (30) days before the effective date. Where the change affects processing based on consent, we will seek fresh consent, including separate consent under PIPL where material change affects consented purpose.

We encourage you to review this Privacy Policy periodically. Your continued use of Services after the Effective Date constitutes acceptance of the updated Privacy Policy, except where processing is based on consent, in which case we will seek fresh consent as described in Section 17 above, subject to your right to withdraw consent where applicable.

18. Contact Us and Supervisory Authorities

18.1 Contact Methods

If you have questions about this Privacy Policy or wish to exercise your rights under applicable Data Protection Laws, please contact us at privacy@execruits.com, or via our website at www.execruits.com, or write to us at Execruit GmbH, Martinsgasse 20, CH-4051 Basel, Switzerland.

All requests will be verified per applicable verification procedures (email plus at least one other identifier, government ID where sensitive), and we respond within statutory timelines: nDSG thirty (30) days per Article 25(3) nDSG and Article 19 DSV; EU GDPR one (1) month per Article 12(3) EU GDPR extendable two (2) months; UK GDPR one (1) month per Article 12(3) UK GDPR extendable two (2) months; US forty-five (45) days per Cal. Civ. Code §1798.130(a)(2) etc. extendable forty-five (45) days; Singapore PDPA thirty (30) days per Section 21(3) PDPA; PIPL fifteen (15) business days internal SLA.

18.2 Right to Lodge Complaint

You have the right to lodge a complaint with a supervisory authority:

  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern, Switzerland, Tel: +41 58 462 43 95, www.edoeb.admin.ch, per Article 49 nDSG.
  • EU/EEA: Your local supervisory authority where you habitually reside, work, or where infringement occurred. List at https://edpb.europa.eu/about-edpb/about-edpb/members_en per Article 77 EU GDPR.
  • United Kingdom: Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, UK, Tel: 0303 123 1113, www.ico.org.uk, per Article 77 UK GDPR and Section 165 UK DPA 2018.
  • United States: No federal data protection authority; you may contact your State Attorney General as listed in Section 15.9 or on your State Attorney General’s website.
  • Singapore: Personal Data Protection Commission (PDPC), 10 Pasir Panjang Road, #03-01, Mapletree Business City, Singapore 117438.
  • UAE: UAE Data Office.
  • Australia: Office of the Australian Information Commissioner (OAIC).
  • Japan: Personal Information Protection Commission (PPC).
  • Mainland China: Cyberspace Administration of China (CAC).

19. Records of Processing, DPIA / PIPIA, Legitimate Interest Assessment, and Security Documentation

19.1 Records of Processing Activities (ROPA)

We maintain records of processing activities per Article 12 nDSG, Article 30(1) EU/UK GDPR, Section 24 Singapore PDPA, and Articles 24 and 55 PIPL, containing: name and contact details of controller and representatives and DPO, purposes of processing, categories of data subjects and personal data, categories of recipients including foreign recipients, cross-border transfers with destination countries and safeguards, retention periods, general description of technical and organisational security measures, and, where processing is based on legitimate interests, a description of those legitimate interests and reference to the applicable Legitimate Interest Assessment.

19.2 DPIA and PIPIA

Because we conduct large-scale market mapping and sourcing of passive candidates, including Sensitive Personal Information and cross-border transfer from mainland China, we conduct: (a) Data Protection Impact Assessment (DPIA) under Article 35 EU GDPR and UK GDPR and Article 8 nDSG where processing likely to result in high risk; (b) Personal Information Protection Impact Assessment (PIPIA) under Article 55 PIPL before processing Sensitive Personal Information, using automated decision-making, entrusting processing, disclosing to other processors, transferring outside mainland China, and for other processing that has significant impact.

Safeguards for hard-to-reach sourcing, documented in DPIA/PIPIA and LIA register, include: (a) Data minimisation: Only professional data relevant to executive roles collected initially; (b) Confidentiality: Source identities kept confidential unless Source consents; (c) Transparency: Notice within thirty (30) days and PIPL notice before processing/disclosure/transfer; (d) Opt-out suppression: Immediate honouring, suppression list restricted access; (e) No sensitive inferences.

20. Do Not Track and Global Privacy Control

20.1 Do Not Track (DNT)

Our Website does not currently respond to Do Not Track signals sent by browsers (DNT header) due to lack of industry standard for interpretation per Cal. Civ. Code §22575(b)(5). We rely on consent management via Cookiebot CMP per Section 6.

20.2 Global Privacy Control (GPC)

We honour Global Privacy Control (GPC) signal as described in Section 15.5. For PIPL, we rely on explicit consent signals via CMP.

21. Specific Provisions for Executive Search — Market Mapping and Anti-Discrimination

21.1 No Employment Decisions

We do not make employment decisions; our Clients do. We provide assessment and advisory services, but final hiring decisions are made by Clients as independent controllers.

21.2 Anti-Discrimination

We do not accept instructions from Clients that would require unlawful discrimination under Swiss law (Gender Equality Act, Disability Discrimination Act), EU law (Racial Equality Directive 2000/43/EC, Employment Equality Directive 2000/78/EC), UK Equality Act 2010, Title VII of Civil Rights Act of 1964, ADEA, ADA, GINA, and applicable US state and local anti-discrimination laws (e.g., California Fair Employment and Housing Act), and mainland China anti-discrimination provisions (Employment Promotion Law, etc.). Where we become aware of a Client instruction that would require unlawful discrimination, we will not act on it and will inform the Client of its obligations. This list is not exhaustive and we comply with all applicable anti-discrimination laws in the jurisdictions where we operate.

21.3 Source Confidentiality

Where market Sources request confidentiality, we protect their identity subject to legal disclosure obligations. We do not disclose the identity of a Source to a Candidate or Client without the Source’s explicit consent, except where required by law.

21.4 No Deception

When we approach Candidates, including passive / hard-to-reach candidates, we identify ourselves as Execruit GmbH and explain purpose of contact and source categories without deception or misrepresentation.

22. Language, Accessibility, and No Discrimination for Exercising Rights

22.1 Language

This Privacy Policy is written in English. Where required by Article 17 PIPL to provide Chinese version for individuals in mainland China, we provide Chinese translation; in case of conflict, Chinese version prevails for PIPL matters. Where required by local law in EU/EEA Member States to provide local language, local language version prevails for that jurisdiction for EU GDPR matters. English version prevails for Swiss nDSG and UK GDPR matters unless applicable law requires otherwise. In case of conflict between translations, the version in the language required by applicable law for that jurisdiction prevails for that jurisdiction.

22.2 Accessibility

If you need this Privacy Policy in an alternative format due to disability, visual impairment, or other accessibility needs, please contact privacy@execruits.com and we will provide accessible format (e.g., large print, audio) per Equality Act 2010 and ADA reasonable accommodation.

22.3 No Discrimination for Exercising Rights

We will not discriminate against you for exercising privacy rights under applicable Data Protection Laws, including by denying Services, charging different prices or rates, or providing different quality of Services, except where permitted by law.