Skip to main content

Processing of (personal) data by the entity in charge of the online application process

Privacy Notice 
This data privacy notice, contains information on what personal data MoonLake Immunotherapeutics AG (‘MoonLake‘ ‘we‘ ‘us‘ or ‘our‘) collects, uses and disclose as part of the online application process and what your rights are.

The controller
The controller under data protection law is:
MoonLake Immunotherapeutics AG
Dorfstrasse 29 6300 Zug Switzerland
Commercial register entry number: CHE-433.093.536
Registration Court: Zug, Switzerland

Data Protection Officer:
MyData Trust
Boulevard Initialis 7 / Box 3
7000 Mons, Belgium
Email: moonlake.dpo@mydata-trust.info
Phone: +32 2 896 55 53

The processing of your personal data shall always be in line with the Swiss Federal Act on Data Protection (FADP), and, if applicable, the EU General Data Protection Regulation (GDPR) and UK GDRP (together referred to as, “applicable data protection laws”).
By means of this Privacy Notice, we would like to inform you of the nature, scope, and purpose of the personal data we collect, use and process and which rights you have.
 
Personal data collected as part of the application process
Personal data means any information that relates to an identified or identifiable individual. Personal data includes information such as name, address, telephone number and date of birth, but also data relating to your specific career etc. by reference to which a specific individual can be identified with reasonable effort.

The following types of personal data might be collected, used and transferred during the application process:

Identity and contact data: name (first and last names), e-mail address, postal address, phone number
Job application data: data related to your career, data related to your education
Financial data: previous salary
Technical data: IP address
LinkedIn profile (optional)
Channel through which you found us

Purposes of processing personal data collected from application documents and during the application process
We always process your personal data for a specific purpose and only process the personal data which is relevant to achieve that purpose.
If you apply to us electronically, i.e. using our online form, you transmit personal data that will be processed for the following purposes:
  • to communicate with you;
  • to process your job application;
  • to comply with a legal obligation;
  • for successful candidates, to prepare employment contracts.

Legal basis for processing personal data during the application process

Depending on the purpose of the processing activity the legal basis of the processing of your personal data will be one of the following:

  • necessary for taking steps to enter into or executing a contract with you for the application process;
  • our legal obligation;
  • your consent.
 
Security 
We treat your personal data in a confidential manner and provides for a sufficient and adequate level of protection of your personal data. We have put in place appropriate technical and organizational measures in order to prevent unauthorized access and to ensure a sufficiently high level of security in relation to the inherent risk involved in data processing, to meet regulatory demands and to protect your rights and your data from the moment your data is collected.
Your personal data are contained behind secured networks and are only accessible by a limited number of persons who have special access rights to such systems and are required to keep the information confidential.

Retention period 
 We will keep your personal data for no longer than necessary to fulfill the purposes for which we collected it, including any legal requirements.
Your data will be stored for a period of one year after the application process has been concluded to able to suggest you any other job opportunity that might suit your profile This also includes, for example, applications for apprenticeships or internships.. After this period, some   anonymized data will be kept. The data will only be available to us without any personal identifiable reference, for statistical analysis (for example, share of male and/or female applicants, number of applications per specified period of time etc.).

Disclosure of data to third parties
Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. This database is operated by Personio GmbH, which offers a human resource and applicant management software solution (https://www.personio.com/legal-notice/). Personio, is the data processor under article 28 of the GDPR. In this case, the processing is based on an agreement for the processing of orders between us as the controller and the others as the processors.

Personal data might be shared with other recipients such as MoonLake Immunotherapeutics AG affiliates, the sub-processors for Human Resources for MoonLake and auditors.

All those third parties are subject to a duty of confidentiality under contract or according to their privacy policies.

International Transfers
Sharing your personal data as explained above may involve a transfer of personal data to a country outside the country of your potential future workplace, the European Economic Area (EEA), UK and/or Switzerland. Moonlake is therefore committed to complying with the transfer rules under applicable Data Protection Laws and therefore ensure to:
  • Transfer your data to countries where the data recipient is located that has been recognized as adequate by the European Commission, UK GDPR and/or the Swiss Federal Data Protection and Information Commissioner (FDPIC); or
  • Where a country has not received an adequacy decision, to implement appropriate safeguards, such as the Standard Contractual Clauses ("SCCs").
 You can contact our Data Protection Officer (see contact details above), if you want to have more details or obtain a copy about the mechanism supporting data transfer.
 
Rights of data subjects
According to applicable data protection laws, you have the following rights:
  • Right to Access. You have the right to obtain confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, information related to the processing of data and a copy of the data being processed.
  • Right to Rectification. You have the right to require rectification of inaccurate or incomplete data about you.
  • Right to Erasure (“right to be forgotten”): you have the right to request the deletion of your personal data in the situations set forth by applicable data protection law.
  • Right to object to processing. You have the right to object, on grounds relating to your particular situation, at any time to the processing of your data.
  • Right to Restrict the processing. You have the right to restrict processing of data under certain specified circumstances.
  • Right to Data portability. You have the right to request for the receipt or the transfer to another organization, in a machine-readable form, of your personal data.
  • Right to withdraw consent. When you have given your consent for the processing of your data, you can withdraw it at any time without justification. In that case we will stop processing your data and will delete them, unless we are required to keep it by applicable laws.
Please note that all of these rights are not absolute and will be assessed on a case-by-case basis by our Data Protection Officer.

If you would like to exercise your rights, please let us know by contacting our DPO dpo@moonlaketx.com

You also have the right to lodge a complaint to the Federal Data Protection and Information Commissioner (FDPIC) of Switzerland or with the Data Protection Authority in the Member State of the European Union of your habitual residence, place of work or place of the alleged infringement, or before a court, if you consider that your personal data is not processed in accordance with the applicable data protection laws.

General provision
We reserve the right to adjust this data privacy notice at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the application process or other processes. In this case, the new data privacy notice applies to any later visit of this recruitment platform or any later job application.

In addition to this data privacy notice, please view our general website data privacy notice at Privacy & Cookies Notice – MoonLake (moonlaketx.com).

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.