1. Scope & Applicability
This policy applies to all users (candidates, employers, visitors) worldwide, with regional provisions for:
- GDPR (EU/EEA/UK)
- CCPA/CPRA (California)
- PIPEDA (Canada)
- LGPD (Brazil)
- PDPA (Singapore/Thailand)
- Other jurisdictions where we operate
2. Data Controller Information
Global HQ: Singapore
Data Protection Officer:
DPO Contact Email | Phone
Regional Representatives:
- EU: Article 27 GDPR Rep
- UK: UK Representative
3. Data Collection Matrix
| Data Type | Purpose | Legal Basis (GDPR) | Retention Period |
|---|---|---|---|
| Candidate profile data | Job matching | Performance of contract | 3 yrs inactivity |
| Employer contact info | Service delivery | Legitimate interest | 5 yrs post-contract |
| Payment data | Transaction processing | Legal obligation | 7 yrs (tax compliance) |
| Cookie/usage data | Analytics & improvements | Consent (non-essential) | 26 months |
4. Cross-Border Data Transfers
We implement:
- EU SCCs (Standard Contractual Clauses)
- UK IDTA (International Data Transfer Agreement)
- APEC CBPR certifications for Asia-Pacific
- Localized storage options where required (e.g., China)
5. User Rights by Region
| Right | GDPR | CCPA | Other Regions | How to Exercise |
|---|---|---|---|---|
| Access | ✓ | ✓ | Varies | Privacy Portal |
| Deletion | ✓ | ✓ | ✓ (where applicable) | Email request |
| Opt-out of sales | N/A | ✓ | Brazil/LGPD | Preference Center |
| Data portability | ✓ | ✓ | Limited | Download tool |
6. Special Provisions
- EU/UK: Explicit consent for profiling
- California: Shine the Light Law disclosures
- Saudi Arabia: Data localization requirements
- China: PIPL-compliant consent mechanisms
7. Security Measures
- ISO 27001 certification
- Annual penetration testing
- Role-based access controls
- Breach notification protocols meeting:
- 72hrs (GDPR)
- 45 days (CCPA)
- Local timelines
8. Policy Updates
- 30-day notice for material changes
- Version archive available upon request
- Jurisdiction-specific changelogs
Implementation Checklist
- Geo-Adaptive Disclosures
- IP-based policy snippets
- Language-localized versions
- Consent Management
- Cookie banner with IAB TCF 2.0 (EU)
- “Do Not Sell” toggle (California)
- Contact Matrix
“`markdown Region Privacy Questions Data Requests Americas privacy-us@co.1twh.com dsar-us@co.1twh.com EMEA privacy-eu@co.1twh.com dsar-eu@co.1twh.com APAC privacy-apac@co.1twh.com dsar-apac@co.1twh.com “` - Compliance Proof
- Maintain Records of Processing Activities (ROPA)
- DPIA for high-risk processing
