DimeRepublic is committed to full compliance with the General Data Protection Regulation (GDPR) (EU Regulation 2016/679). This page outlines our GDPR compliance framework, our commitments to protecting personal data, and your rights regarding the processing of your personal data. We take our obligations under GDPR seriously and have implemented comprehensive policies, procedures, and technical measures to ensure compliance.
1. Our Commitment
DimeRepublic is dedicated to protecting the privacy and security of personal data in accordance with GDPR. Our commitment includes:
- Implementing and maintaining a comprehensive data protection program that covers all aspects of GDPR compliance, including data mapping, privacy impact assessments, and records of processing activities.
- Processing personal data lawfully, fairly, and in a transparent manner, ensuring that data subjects are informed about how their data is collected, used, and protected.
- Collecting and processing only the minimum amount of personal data necessary for the specified purpose (data minimization).
- Maintaining accurate and up-to-date personal data and providing mechanisms for data subjects to correct inaccuracies.
- Storing personal data only for as long as necessary and securely deleting or anonymizing it when no longer required.
- Implementing appropriate technical and organizational security measures to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
- Ensuring that all employees, contractors, and sub-processors who handle personal data are trained on data protection obligations and are contractually bound to comply with GDPR.
2. Data Controller and Data Processor
Under GDPR, DimeRepublic acts as both a Data Controller and a Data Processor depending on the context of the processing activities:
- Data Controller: When we collect and process personal data for our own organizational purposes, such as managing our website, marketing communications, business development, human resources, and general business operations. As a Controller, we are responsible for determining the purposes and means of processing and for complying with all Controller obligations under GDPR.
- Data Processor: When we process personal data on behalf of our clients in connection with our services (e.g., talent acquisition, payroll management, performance monitoring). In such cases, our clients are the Data Controllers, and we act under their documented instructions. Our obligations as a Processor are set forth in our Data Processing Agreement.
3. Lawful Basis for Processing
Under GDPR Article 6, we process personal data only under one or more of the following lawful bases. We identify and document the appropriate lawful basis before processing personal data and ensure that data subjects are informed of the basis relied upon.
- Consent (Article 6(1)(a)): The data subject has given clear, informed, and unambiguous consent for the processing of their personal data for a specific purpose. We rely on consent for activities such as sending marketing communications, placing non-essential cookies, and processing special category data where applicable. Consent can be withdrawn at any time, and we make it as easy to withdraw as to give consent.
- Contractual Necessity (Article 6(1)(b)): Processing is necessary for the performance of a contract with the data subject or to take steps at the data subject's request before entering into a contract. We rely on this basis for processing data to deliver our services, manage placements, process payments, and fulfill our contractual obligations to clients and candidates.
- Legal Obligation (Article 6(1)(c)): Processing is necessary for compliance with a legal obligation to which we are subject. We rely on this basis for retaining financial records for tax purposes, responding to lawful requests from public authorities, and complying with employment and labor laws.
- Vital Interests (Article 6(1)(d)): Processing is necessary to protect the vital interests of the data subject or another natural person. We may rely on this basis in emergency situations where processing is necessary to prevent serious harm.
- Public Interest (Article 6(1)(e)): Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This basis is not typically relied upon in our commercial operations.
- Legitimate Interests (Article 6(1)(f)): Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. We rely on this basis for activities such as website analytics, network security, fraud prevention, direct marketing to existing clients, and general business improvement. We conduct Legitimate Interest Assessments (LIAs) to balance our interests against data subjects' rights.
4. Data Subject Rights
Under GDPR, individuals have the following eight rights regarding their personal data. We are committed to facilitating the exercise of these rights and responding to all valid requests within the timeframes required by law.
- 1. Right to be Informed (Articles 13-14): You have the right to be informed about the collection and use of your personal data. This includes the purposes of processing, the categories of data involved, the lawful basis for processing, the retention period, and your rights. We provide this information through this page, our Privacy Policy, and at the point of data collection.
- 2. Right of Access (Article 15): You have the right to obtain confirmation from us as to whether we are processing your personal data and, if so, to request a copy of that data along with supplementary information about how it is being processed. We will respond to access requests within 30 days and provide the information free of charge, unless the request is manifestly unfounded or excessive.
- 3. Right to Rectification (Article 16): You have the right to request the correction of inaccurate personal data concerning you and to have incomplete personal data completed. We will make the requested corrections promptly and notify any recipients of the data about the rectification.
- 4. Right to Erasure (Article 17) - "Right to be Forgotten": You have the right to request the deletion of your personal data under certain circumstances, including when the data is no longer necessary for the purpose it was collected, when you withdraw consent, when you object and there are no overriding legitimate grounds, when the data has been unlawfully processed, or when erasure is required for legal compliance.
- 5. Right to Restrict Processing (Article 18): You have the right to request the restriction of processing of your personal data under certain conditions, such as when you contest the accuracy of the data (for a period enabling us to verify accuracy), when processing is unlawful but you oppose erasure and request restriction instead, when we no longer need the data but you require it for legal claims, or when you have objected to processing pending verification of whether our legitimate grounds override yours.
- 6. Right to Data Portability (Article 20): You have the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format (such as CSV or JSON) and to transmit that data to another controller without hindrance. This right applies only to data processed based on consent or contract and carried out by automated means.
- 7. Right to Object (Article 21): You have the right to object, on grounds relating to your particular situation, to processing of your personal data based on legitimate interests or public interest. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. You also have the absolute right to object to processing for direct marketing purposes at any time.
- 8. Rights Related to Automated Decision-Making (Article 22): You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. DimeRepublic does not currently engage in automated decision-making that produces legal effects, but if we do in the future, we will ensure appropriate safeguards are in place, including the right to obtain human intervention.
To exercise any of these rights, please submit a request to contact@dimerepublic.com. We will acknowledge receipt within 5 business days and respond substantively within 30 days. In the case of complex or high-volume requests, we may extend the response period by an additional 60 days, but we will inform you of any such extension within the initial 30-day period.
5. Data Protection Officer
DimeRepublic has appointed a Data Protection Officer (DPO) in accordance with GDPR Article 37. The DPO is responsible for overseeing our data protection strategy, monitoring compliance with GDPR, advising on data protection impact assessments, and acting as a point of contact for data subjects and supervisory authorities. The DPO can be contacted as follows:
The DPO operates independently and reports directly to senior management. The DPO is involved in all data protection matters and has access to all necessary resources to fulfill their duties.
6. International Transfers
When personal data of individuals in the European Economic Area (EEA) is transferred to countries outside the EEA that have not been deemed adequate by the European Commission (including the United States, Pakistan, and India), DimeRepublic ensures that appropriate safeguards are in place to protect the data. The safeguards we implement include:
- Standard Contractual Clauses (SCCs): We have adopted the European Commission's Standard Contractual Clauses (2021 version) as the primary transfer mechanism for international data transfers. We enter into SCCs with our sub-processors and partners to ensure an equivalent level of data protection.
- Transfer Impact Assessments (TIAs): We conduct TIAs for all restricted transfers to assess the level of data protection in the recipient country and implement supplementary measures where necessary to address any gaps.
- Supplementary Measures: Where required, we implement additional technical, contractual, and organizational measures to ensure an essentially equivalent level of protection, including encryption, pseudonymization, and strict access controls.
- Data Processing Agreements: We execute comprehensive DPAs with all recipients of personal data that incorporate the SCCs and impose GDPR-compliant data protection obligations.
7. Data Breach Procedures
DimeRepublic has implemented robust procedures to detect, investigate, contain, and report personal data breaches in accordance with GDPR Articles 33 and 34. Our breach response procedures include the following steps:
- Detection and Assessment: Upon becoming aware of a potential breach, our incident response team immediately assesses the nature, scope, and likely impact of the breach. We determine whether a personal data breach has occurred and whether it poses a risk to the rights and freedoms of natural persons.
- Containment and Remediation: We take immediate steps to contain the breach and prevent further unauthorized access or loss of data. This may include isolating affected systems, revoking compromised access credentials, and applying security patches.
- Notification to Supervisory Authority (Article 33): If the breach is likely to result in a risk to the rights and freedoms of individuals, we notify the relevant supervisory authority within 72 hours of becoming aware of the breach. The notification includes: (a) a description of the nature of the breach; (b) the categories and approximate number of data subjects and records affected; (c) the likely consequences; and (d) the measures taken or proposed to address the breach.
- Communication to Data Subjects (Article 34): If the breach is likely to result in a high risk to the rights and freedoms of individuals, we communicate the breach to affected data subjects without undue delay, providing clear and understandable information about the nature of the breach, its potential consequences, and the steps taken to mitigate it.
- Documentation: We maintain a detailed record of every breach, including the facts surrounding the breach, its effects, and the remedial actions taken, as required by GDPR Article 33(5).
8. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, in accordance with the data minimization principle (GDPR Article 5(1)(c)) and storage limitation principle (Article 5(1)(e)). Our specific retention periods are as follows:
- Client Data: Retained for the duration of the service agreement plus five years for legal and tax compliance purposes.
- Candidate Data: Retained for two years from the date of collection or last engagement to facilitate future placement opportunities, unless earlier deletion is requested.
- Website Usage Data: Retained in anonymized form for analytics purposes for up to 26 months.
- Financial Records: Retained for seven years as required by tax and accounting regulations.
- Marketing Data: Retained until the data subject opts out, with deletion within 30 days of opt-out.
- Communication Records: Retained for three years from the last communication.
When the retention period expires, personal data is securely deleted or anonymized using industry-standard methods to prevent unauthorized access or reconstruction.
9. Complaints
If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. We encourage you to first contact our DPO so that we can attempt to resolve your concerns directly. However, you are not required to exhaust our internal processes before filing a complaint with a supervisory authority.
10. Our EU Representative
In accordance with GDPR Article 27, DimeRepublic has appointed an EU representative who can be contacted on matters related to the processing of personal data of individuals in the EEA. Our EU representative is: DimeRepublic EU Ltd, The Work Station, 15-17 Pembroke Row, Dublin 2, D02 KH59, Ireland. Email: contact@dimerepublic.com.
11. Changes to This Page
We may update this GDPR Compliance page from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. Material changes will be notified through our website or by email. We encourage you to review this page periodically to stay informed about our GDPR compliance program.
12. Contact
For GDPR-related inquiries, to exercise your data subject rights, or to contact our DPO, please use the following channels: