- Startseite
- Applicant Privacy Notice
Applicant Privacy Notice
This privacy notice (the “Privacy Notice”) informs you about how Sunday Natural Products GmbH (“Sunday Natural”, “we”, “us”, “our”) collects and processes your personal data as a candidate (“you” or “candidate”) for recruiting purposes.
1. Identity and Contact Details of the Controller
The controller responsible for the processing of your personal data within the meaning of the European Data Protection Regulation (Regulation (EU) 2016/679) (the “GDPR”) is:
Sunday Natural Products GmbH
Potsdamer Str. 83
10785 Berlin, Germany
Email: [email protected]
2. Contact Details of the Data Protection Officer
We have appointed an external Data Protection Officer, which you can reach at
Händlerbund Rechtsanwaltsgesellschaft mbH
Kohlgartenstraße 11-13
04315 Leipzig, Germany
Email: [email protected]
3. Types of Personal Data Processed
We process personal data in connection with your application, which typically includes the following:
- Contact and identification data: Name, date of birth, contact details (e.g. address, phone number, email address), gender, nationality, age, etc.
- Qualification data: CV (resumé), cover letter, certificates, references, records of professional experiences, work authorization, language skills, etc.
- Assessment data: Notes from interviews, results of work samples, personality / skill assessments, etc.
- Professional online data: URLs to LinkedIn or other professional online profiles.
- Recruitment and communication data: We process information related to your specific candidacy and our communication with you. This includes:
-
-
- Application source: Details on how your job application reached us (e.g. via recruitment agency, internal referral, job board, etc.).
- Recruitment communication: Your email correspondence and interactions with our team.
- Employment preferences: Information regarding your availability (e.g. start date, notice periods, etc.), your expectations regarding salary, working hours, work location, etc.
- Application source: Details on how your job application reached us (e.g. via recruitment agency, internal referral, job board, etc.).
-
- Special categories of data: We do not request special categories of personal data in the meaning of Art. 9(1) GDPR, and process such data only if you choose to provide us with the data on a voluntary basis. Special categories of personal data may include information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, information about health, sex life or sexual orientation.
- Device and technical information: IP address, device and browser data, connection method, metadata (e.g. when you logged into the platform), etc.
If you submit your candidacy by email or online, then you are the main source of the personal data. Your personal data can also originate from other sources, such as LinkedIn profiles, recruitment agencies, headhunters, and referrals.
4. Purpose and Legal Bases for the Processing of Personal Data
In the table below we inform you about:
- For what purpose we will use your personal data for,
- Which types of personal data we use for the respective purpose,
- Based on which legal basis we are processing the personal data for the purpose.
|
Processing purpose. |
Type of personal data used for the purpose.
See section 3 for more details on the different types of personal data. |
Legal basis for the processing according to the GDPR. |
|
Evaluating job candidates and deciding on the establishment of an employment agreement. |
|
The processing is necessary for pre-contractual measures(Art. 6(1)(b) GDPR and § 26(1) of the German Data Protection Act(Bundesdatenschutzgesetz-BDSG)) If your application includes special categories of personal data (e.g. from materials you choose to provide to support your candidacy), our processing of such data takes place on your explicit consent(Art. 9(2)(a) GDPR). |
|
Inclusion in our talent pool to contact you for future roles. |
|
The processing is based on your consent (Art. 6(1)(a)GDPR). If your application includes special categories of personal data (e.g. from materials you choose to provide to support your candidacy), our processing of such data takes place on your explicit consent (Art. 9(2)(a) GDPR). |
|
Contacting you for candidacy status and interviews. |
|
The processing is necessary for pre-contractual measures (Art. 6(1)(b) GDPR and §26(1) BDSG) |
|
Scheduling meetings and interviews. |
|
The processing is necessary for pre-contractual measures (Art. 6(1)(b) GDPR and §26(1) BDSG) |
|
Anonymizing your personal data in order to create hiring statistics and reports. |
|
The processing is based on a balancing of interests (Article 6(1)(f) GDPR). When balancing interests, Sunday Natural has determined that we have a legitimate interest in anonymising your personal data for analytical statistics and reporting purposes. We ensure that the particular processing this entails is necessary to achieve the purpose in question, and that our interest outweighs your right not to have your data processed for this purpose. If your application includes special categories of personal data (e.g. from materials you choose to provide to support your candidacy), our processing of such data takes place on your explicit consent(Art. 9(2)(a) GDPR). By anonymising information concerning you, we also ensure that we use personal data to the lesser extent possible. |
|
Protecting us from legal claims and safeguarding Sunday Natural’s legal rights. |
In the event of a dispute, Sunday Natural may also collect other types of personal data concerning you if we need them to exercise our rights.
|
The processing is based on a balancing of interests (Article 6(1)(f) GDPR). When balancing interests, Sunday Natural has determined that we have a legitimate interest in being able to protect ourselves from legal claims. We ensure that the processing this entails is necessary to achieve the purpose of the processing, and that our interest outweighs your right not to have your data processed for this purpose. Special categories of personal data, if necessary to establish, exercise or defend legal claims, are processed based on your explicit consent (Article 9(2)(f)GDPR). |
|
Ensuring network and information security of the application platform. |
|
The processing is based on a balancing of interests (Article 6(1)(f) GDPR). When balancing interests, Sunday Natural has determined that we have a legitimate interest in being able to ensure network and information security. We ensure that the processing this entails is necessary to achieve the purpose of the processing, and that our interest outweighs your right not to have your data processed for this purpose. |
|
Preventing fraudulent activity on or through our application platform. |
|
The processing is based on a balancing of interests (Article 6(1)(f) GDPR). When balancing interests, Sunday Natural has determined that we have a legitimate interest in being able to prevent fraudulent activities. We ensure that the processing this entails is necessary to achieve the purpose of the processing, and that our interest outweighs your right not to have your data processed for this purpose. |
5. Recipients of Your Personal Data
When we share your personal data, we ensure that the recipient processes it in accordance with this notice, such as by entering into data transfer agreements or data processor agreements with the recipients. Those agreements include all reasonable contractual, legal, technical and organizational measures to ensure that your information is processed with an adequate level of protection and in accordance with applicable law.
We share your personal data with the following recipients:
5.1. Service providers and subcontractors
Service providers and subcontractors are companies that only have the right to collect, store, and process personal data on our behalf for the purposes of our recruitment processes and conduct business operations, i.e. data processors. Examples of such service providers and subcontractors are recruiting and applicant tracking platform providers, as well as software and data storage providers. For the technical administration of our recruitment process, we use the platform of Ashby, Inc., which includes the AI-supported functionalities. The privacy notice of Ashby, Inc. is available here.
Sunday Natural needs access to specialized services and technical tools from other companies to provide a professional and secure recruitment process. Sunday Natural has a legitimate interest in being able to access these services and functionalities to manage our business and recruitment effectively (Article 6(1)(f) GDPR). We ensure that this processing is necessary to pursue that interest, and balanced against your interests. You may object to this processing at any time based on your particular circumstances. See Section 8 for more information about your rights.
5.2. Sunday Natural group companies
We may share your personal data with other entities within the Sunday Natural group if this is necessary for the recruitment process. This occurs, for example, if a position involves cross-departmental responsibilities, if hiring managers from affiliated companies are involved in the selection process, or if we use centralized administrative and HR services provided by a group entity.
Sunday Natural has a legitimate interest in accessing these services and functionalities to manage your application effectively (Article 6(1)(f) GDPR). We ensure that this processing is necessary to pursue that interest, and balanced against your interests. You may object to this processing at any time based on your particular circumstances. See Section 8 for more information about your rights.
5.3. Recruitment agencies and referral sources
If your job application was submitted to Sunday Natural by a third party (such as a professional recruiting agency or through an internal employee referral) we may share limited information regarding the status of your application with that source. We share this information to provide necessary feedback to our recruitment partners and to manage our internal incentive programs, such as our employee referral bonus scheme. We ensure that only the minimum information required for these administrative purposes is shared. This typically includes your name, and your current recruitment status.
This processing is based on our legitimate interest in maintaining effective partnerships with agencies and rewarding employees who contribute to our growth (Art. 6(1)(f) GDPR). We ensure that this processing is necessary to pursue that interest, and balanced against your interests. You may object to this processing at any time based on your particular circumstances. See Section 8 for more information about your rights.
5.4. Public authorities
We may disclose your personal data to regulatory authorities, courts, or law enforcement agencies, if we are legally required to do so or if it is necessary to protect our rights. We share personal data to comply with legal discovery requirements, responding to mandatory government requests, or defending Sunday Natural in legal disputes.
To the extent we are required by law to provide information to an authority, this processing is based on compliance with a legal obligation (Art. 6(1)(c) GDPR).
To the extent the disclosure is necessary to establish, exercise, or defend legal claims, this processing is based on legitimate interest (Art. 6(1)(f) GDPR). We ensure that this processing is necessary to pursue that interest, and balanced against your interests. You may object to this processing at any time based on your particular circumstances. See Section 8 for more information about your rights.
5.5. Business transfers and corporate restructuring
In the event of a change in our corporate structure, such as a merger, acquisition by another company, or a sale of all or a portion of our assets, your personal data may be shared with the involved third parties (e.g. potential buyers and their professional advisors) to conduct necessary due diligence and ensure the continuity of our recruitment processes and business operations during a transition.
This processing is based on our legitimate interest in evaluating and carrying out such corporate transactions (Art. 6(1)(f) GDPR). We ensure that this processing is necessary to pursue that interest, and balanced against your interests. You may object to this processing at any time based on your particular circumstances. See Section 8 for more information about your rights.
6. International Data Transfers
To manage our recruitment processes and conduct business operations, Sunday Natural may transfer your personal data to recipients outside of the European Economic Area (“EEA”). This typically occurs when our service providers store or process data in third countries.
In this case we always ensure that your personal data still receives a high level of protection in accordance with the requirements under GDPR, regardless of where it is processed. Appropriate safeguards to achieve this include, but are not limited to:
- Adequacy Decisions: If the European Commission has decided that the country outside of the EEA to which your personal data are transferred has an adequate level of protection, which corresponds to the level of protection afforded by the GDPR. This means, for example, that the personal data is still protected from unauthorized disclosure, and that you may still exercise your rights in regards to your personal data.
- Standard Contractual Clauses (SCCs): The European Commission’s SCCs have been entered into between Sunday Natural and the recipient of the personal data outside the EEA. This means that the recipient guarantees that the level of protection for your personal data afforded by the GDPR still applies, and that your rights are still protected. In these cases, we also assess whether there are laws in the recipient country that affect the protection of your personal data. Where necessary, we take technical and organizational measures so that your data remain protected during the transfer to the relevant country outside the EEA.
- EU-US Data Privacy Framework: The EU-US Data Privacy Framework is an opt-in certification scheme for US companies, administered by the US Department of Commerce. This EU-US Data Privacy Framework includes a set of enforceable principles and requirements that must be certified to by the US company, ensuring that your personal data is still being sufficiently protected.
If you would like more information about the specific safeguards applied to your data transfer, please contact us using the details provided in Section 1 . You can also find more information on the European Commission’s website.
7. Data Retention
We only store your personal data for as long as necessary to evaluate your application or to fulfill our legal obligations. Our standard retention periods are as follows:
- If your application is unsuccessful: We typically retain your data for 6 months after the recruitment process ends. We do this based on our legitimate interest to protect ourselves against potential legal claims (e.g. under the German General Act on Equal Treatment (Allgemeines Gleichbehandlungsgesetz - AGG))
- If you join our talent pool: If you have given us your consent to stay in touch for future roles, we will keep your data for two (2) years after the recruitment process ends. You can withdraw this consent at any time; if you do, we will remove your profile from the talent pool immediately
- If you are hired: Your application documents will be transferred to your personnel file and kept for the duration of your employment and for an adequate period afterwards, in accordance with our internal employee privacy policy.
What happens after these periods?
Once the retention period expires, we are legally required to either delete your personal data or anonymize it. If we anonymize it, all personal identifiers are removed so you can no longer be identified. We use this “metadata” only for internal statistical analysis, for example, to track the number of applications we receive over time or to monitor our diversity goals.
8. Your Data Protection Rights as a Data Subject
We want to make sure you stay informed and in control of your data. As an applicant, you have several rights under the GDPR regarding your personal data. You can read more about these rights and how to exercise them below.
- Right to have personal data deleted (“Right to be forgotten”). You have the right to request us to delete your personal data in certain situations. For example, if we no longer need the personal data for the recruitment process, or if we process your personal data based on your consent and you revoke such consent.
Please note that Sunday Natural may be unable to delete your data if we have a valid legal reason to keep it. For example, where the processing of the personal data is still necessary for the purpose for which the data was collected, when Sunday Natural’s interest to process the personal data overrides your interest in having them deleted, or if we have a legal obligation to keep it. - Right to be informed. You have the right to be informed of how we process your personal data. We do this through this Privacy Notice.
- Right to receive access to your personal data (“data subject access”). You have the right to know if Sunday Natural processes personal data about you, and to receive a copy (so-called “data extract”) of such data. Through the data extract you will receive information about what personal data Sunday Natural holds about you and how we process it.
- Right to access, and request a transfer, of your personal data to another recipient (“data portability”). In certain cases, you have the right to receive a copy of the personal data you provided to us in a structured, commonly used, and machine-readable format. This allows you to easily move or “port” your information to another organization if you wish. This right applies specifically to data that we process (i) based on the consent you gave us (e.g., for our talent pool), or (ii) to fulfill a contract or take pre-contractual steps (e.g. your actual job application).
- Right to rectification. You have the right to request that we rectify inaccurate information or complete information about you that you consider is inaccurate or incomplete.
- Right to restrict processing. If you believe that your personal data is inaccurate, that our processing is unlawful or that we do not need the information for a specific purpose, you have the right to request that we restrict the processing of such personal data. You also have the possibility to request that we stop processing your personal data while we assess your request. If you object to our processing per your right described directly below, you may also request us to restrict processing of that personal data while we make our assessment.
- Right to object against our processing of your personal data. You have the right to object to processing of your personal data when we rely on our legitimate interest (Article 6(1)(f) GDPR) as a legal basis. If you object, please provide us with information regarding your specific situation. We will then stop processing your personal data, unless we can demonstrate compelling legitimate grounds that override your interests, or if we need the data to establish, exercise, or defend legal claims.
- Right to object to an automated decision that significantly affects you. You have the right to object to an automated decision made by Sunday Natural if the decision produces legal effects or significantly affects you in a similar way. Please note that Sunday Natural does not carry out automated decision-making or profiling for its recruitment purposes.
- Right to withdraw your consent. As described in Section 9 below, where we process your personal data based on your consent or explicit consent, you have the right to revoke that consent at any time. When you revoke your consent we will stop processing your data for such purposes.
- Right to lodge a complaint. If you have concerns about how we handle your personal data, we encourage you to contact us first so we can address them. You also have the right to lodge a formal complaint with the data protection supervisory authority. The supervisory authority responsible for Sunday Natural is the Berlin Commissioner for Data Protection and Freedom of Information:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Friedrichstr. 219
10969 Berlin
Tel.: +49 (0)30 13889-0
Fax: +49 (0)30 2155050
E-Mail: [email protected]
Additionally, you may file a complaint with the national data protection authority in your country of residence. You can find a complete list of European authorities and their contact details here.
9. Withdrawal of Consent
When Sunday Natural uses your personal data based on your consent or explicit consent, you can withdraw such consent at any time. You can do this by sending an email to [email protected] or via the contact information you find in Section 1 of this Privacy Notice. We will then delete the information (or stop using it for the purpose consent is relied on).
Please note that if you withdraw your consent for including your data in our talent pool, we will no longer be able to consider you for future vacancies outside of the specific position for which you originally applied.
10. Automated Decision-Making
No automated decision-making is involved in our recruiting process.
We may use specialized software tools that may include artificial intelligence (AI) and machine learning (ML) components to assist in the initial screening of employment applications. These AI/ML tools assess applications against the characteristics and qualifications relevant to the respective job requisition. These tools are designed to help identify potentially qualified candidates, but they do not make any automated hiring decisions. The AI/ML-generated assessments are one of several factors considered in the hiring process. Our human recruiters thoroughly evaluate your skills and qualifications to determine your suitability for the respective role. AI/ML tools will never reject your application automatically or make a final hiring decision on its own.
11. Cookies
When you visit our job board, our service provider Ashby, Inc. uses cookies to automatically collect device and technical information required to display the website securely and stably. This information includes IP address, date and time of access, browser type, and operating system, connection method and device identifiers, activity timestamps and interactions with the recruitment platform.
This data is processed to ensure the security of our application process, prevent fraudulent applications (e.g., bot activity), and optimize the functionality of our recruitment platform. The legal basis for this processing is our legitimate interest (Art. 6(1)(f) GDPR) in maintaining a secure and functional online presence. We ensure that the processing this entails is necessary to achieve the purpose of the processing, and that our interest outweighs your right not to have your data processed for this purpose.
12. Updates to this Privacy Notice
We are committed to continuously optimizing our recruitment processes to ensure a professional and efficient candidate experience. This may involve updates to our recruitment workflows or the implementation of new administrative tools. Should such improvements require formal notification or consent under applicable law, we will inform you accordingly or provide the opportunity to grant your consent.
As our recruitment procedures may evolve over time, we encourage you to review this privacy notice periodically during your application journey to stay informed about how we handle your personal data.
Last updated: 15.04.2026