SonarSource Candidate Privacy Notice
This Candidate Privacy Notice (“Candidate Notice”) explains what personal information we collect about you during the application and recruitment process for employment with SonarSource, as well as the purposes for which we collect and use that information. We are committed to protecting your personal data and being transparent about our data handling practices. This Candidate Notice also outlines your rights and choices regarding your information.
In this Candidate Notice, “personal data” and “personal information” refer to information that can identify you directly or indirectly, but do not include anonymous or aggregated data. Throughout this Candidate Notice, we refer to such information as “Candidate Data”.
We encourage you to read this Candidate Notice carefully. If you have questions or concerns, please contact us using the details provided at the end of this Candidate Notice.
What Information We Collect
We collect Candidate Data about you in connection to career opportunities with us.
Categories of Candidate Data we may collect about you may include:
- Contact and Identification Information: Full name, pronouns, address, email
address, phone number, and related contact details. - National Identifiers: Citizenship status, residency status, and work permit status.
- Professional and Educational Information: CV/resume, cover letter, work history, educational background and achievements, professional qualifications, skills, and references.
- Application Data: Desired salary, notice period, eligibility to work, willingness to relocate, preferred work arrangements, and other job-related preferences.
- Referral and Source Information: How you heard about the position, including referral sources and recruitment agencies.
- Diversity and Inclusion Data (optional): Gender, ethnicity, disability status, or other protected characteristics, collected for diversity and inclusion reporting, with your explicit consent. Providing this information is entirely voluntary.
- Sensitive Information (optional): Health and medical conditions, trade union membership, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, or other special categories of personal data, collected only where permitted by law and with your explicit consent. Providing this information is entirely voluntary and will only be used for specific purposes permitted by law.
- Interview and Assessment Information: Notes and feedback from interviews, results of skills tests, assessments, or exercises.
- Publicly Available Information: Information from publicly available sources, such as LinkedIn profiles or other professional networking sites.
- Background Check Data (for successful applicants): Criminal records, employment verification (including references), and educational background, collected in accordance with local laws.
How We Collect Your Candidate Data
We collect Candidate Data about you through the following methods:
- Directly from You: Information you provide when you complete an application form, submit your CV or resume, participate in interviews or assessments, or communicate with our hiring team.
- From Third Parties: Information received from recruitment agencies, job boards (such as LinkedIn, Meetup, or Indeed), individuals who refer you for a position, professional references you provide, and background check providers (where permitted by law), and specialist recruitment technology providers that help us identify and connect with potential candidates.
- From Public Sources: Information obtained from publicly available professional platforms to supplement your application data.
- Automatically Collected Information: Data such as IP address, device identifiers, and website usage information collected when you visit and use our websites. For more information and opt-out options regarding our use of cookies and similar technologies, please see our Cookie Policy.
How We Use Your Candidate Data
We use your Candidate Data solely for recruitment and hiring purposes, including to:
- Process your job application and assess your suitability for employment with SonarSource.
- Communicate with you regarding your application, the recruitment process, and other potential opportunities.
- Proactively identify and contact you about relevant career opportunities, including inviting you to join our talent pool or informing you of future opportunities that may match your profile.
- Arrange and conduct interviews and assessments.
- Verify your information, including your professional qualifications and references.
- Conduct background checks for successful applicants, as required by law or company policy.
- Maintain accurate records of our recruitment process.
- Comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
- Analyze and improve our hiring process to ensure it is fair, effective, and inclusive.
- Protect our legal rights and maintain the security and integrity of our facilities, equipment, websites, and other electronic platforms.
Who We Disclose Your Candidate Data To
We may disclose your Candidate Data to the following parties, and only when necessary for the recruitment process:
- Our Hiring Team: Your information will be disclosed with the hiring manager, interviewers, and other individuals involved in the recruitment process for the specific role to which you have applied.
- Affiliates: Where relevant, your information may be disclosed with SonarSource affiliates or group companies involved in the hiring process.
- Service Providers: We may engage third-party service providers to support our recruitment efforts, such as applicant tracking systems (ATS), assessment platforms, candidate sourcing tools, or background check services. These providers are bound by confidentiality obligations and are only permitted to use your data to perform services on our behalf.
- Legal and Regulatory Authorities: We may be required to disclose your information to comply with legal obligations, court orders, or governmental requests, or as necessary to establish, exercise, or defend legal claims, or to protect the rights, safety, or security of SonarSource, our candidates, or others.
- With Your Consent: We may disclose your information with third parties at your request or with your explicit consent (for example, when contacting your references).
Candidate Data Retention
We retain your Candidate Data only as long as necessary for recruitment purposes, to consider you for future opportunities, to comply with legal obligations, or as otherwise permitted by law. Generally, this means we keep your data for up to two years after the recruitment process concludes. With your explicit consent, we may retain your data for up to three years to inform you of future opportunities.
If you are hired, your data will be transferred to your employee file and managed under our Internal Employee Privacy Policy.
You may request deletion of your Candidate Data at any time by contacting us at internal.secgov@sonarsource.com. We will process your request in accordance with applicable data protection laws.
International Data Transfers
SonarSource is organized as a corporate group. Our parent holding company is based in the United States, while SonarSource Sàrl in Switzerland is our principal operating entity and primarily responsible for processing Candidate Data. We operate internationally, with offices and affiliates in the European Union, United Kingdom, Switzerland, Japan, Singapore, United Arab Emirates, and the United States.
As part of our recruitment process, your Candidate Data may be stored and processed in these countries and other locations where SonarSource Sàrl, its affiliates, or authorized service providers operate. For example, our hiring team is distributed globally, and we may transfer your Candidate Data to team members in different countries to manage your recruitment process.
Where Candidate Data is transferred outside the European Economic Area (EEA), United Kingdom, or Switzerland to countries without an adequate level of data protection, we implement appropriate safeguards, such as Standard Contractual Clauses (SCCs), UK International Data Transfer Agreements (IDTAs), and Swiss Addenda, as required by law.
Legal Bases for Candidates Located in the EEA, UK, or Switzerland
If you are located in the EEA, UK, or Switzerland, we process your Candidate Data only where
permitted by law. Our legal bases include:
- Administering a contract or taking steps at your request before entering into a contract;
- Pursuing our legitimate interests (such as assessing your suitability, evaluating our recruitment processes, protecting our legal rights and interests);
- Your consent for specific purposes (such as demographic surveys); or
- Compliance with legal obligations (such as required background checks).
- Where the lawful basis is consent, you may withdraw your consent at any time though this will not affect processing already carried out. You also have the right to object to processing based on our legitimate interests.
Your Privacy Rights
Depending on applicable law, you may have certain rights regarding your Candidate Data.
These may include the right to:
- Request access to the Candidate Data we hold about you;
- Request correction of inaccurate or outdated data;
- Request deletion of your Candidate Data;
- Object to or restrict certain types of processing; and
- Request a copy of your Candidate Data in a portable format.
Please note that we may be legally permitted or required to retain certain information (for example, for record-keeping or compliance purposes).
If you wish to withdraw your application or no longer wish to be considered for a position, you may contact your recruiter or email us at hiring@sonarsource.com at any time.
To exercise your rights, please contact us at internal.secgov@sonarsource.com. We may need to verify your identity, which could require additional information (such as the email address used during your application). If you believe we have not adequately addressed your privacy concerns, you may have the right to contact a data protection authority where you live, work, or believe your rights have been infringed.
California Mandatory Disclosures
This section applies only to California residents and supplements the information provided elsewhere in this Candidate Notice.
Categories of Personal Information Collected
In the past 12 months, we have collected the categories of personal information described in the “What Information We Collect” section, which may include:
- Identifiers and contact details (e.g., name, email address, mailing address, phone number).
- National identifiers (e.g., citizenship or work permit status).
- Professional and educational information (e.g., CV/resume, work history, education, qualifications).
- Application data (e.g., desired salary, notice period, job preferences).
- Referral and source information.
- Diversity and inclusion data (where provided voluntarily and with consent).
- Sensitive information (where provided voluntarily and with consent, and only as permitted by law).
- Interview and assessment information.
- Publicly available information (e.g., LinkedIn profile).
- Background check data (where applicable and permitted by law)
We collect this information directly from you, from third parties (such as recruitment agencies or references), and from publicly available sources, as outlined in “What Information We Collect.”
Business or Commercial Purposes for Collection
We use personal information for the purposes described in “How We Use Your Candidate Data” section, including evaluating your application, communicating with you, conducting interviews and assessments, verifying information, complying with legal obligations, and supporting diversity and inclusion initiatives.
Disclosure of Personal Information
In the past 12 months, we have disclosed the categories of personal information listed above for business purposes to service providers and third parties who assist us in the recruitment process (such as recruitment agencies, background check providers, and assessment platforms), as described in “Who We Disclose Your Candidate Data To” section.
Sharing and Sale of Personal Information
SonarSource does not “sell” or “share” candidate personal information as those terms are defined under California law. We do not use candidate personal information for cross-context behavioral advertising, nor do we sell candidate data to third parties. We also do not “sell” or “share” the personal information of known minors under 16 years of age.
Your Rights and Choices
California residents have the following rights regarding their personal information, subject to certain limitations:
- The right to know what personal information we collect, use, disclose, and retain
- The right to request access to your personal information;
- The right to request deletion of your personal information;
- The right to correct inaccurate personal information;
- The right to limit the use and disclosure of sensitive personal information (where applicable); and
- The right not to be discriminated against for exercising your privacy rights.
To exercise your rights, please contact us at internal.secgov@sonarsource.com. We may need to verify your identity before processing your request. You may also authorize an agent to exercise your rights on your behalf. If you use an authorized agent, the agent may contact us at internal.secgov@sonarsource.com. We may require you to confirm your identity and your authorization of the agent.
If you have questions or concerns about your privacy rights, you may also contact the California Attorney General or your local data protection authority. You will not be discriminated against for exercising any of your privacy rights under California law.
Retention of Personal Information
We retain your personal information as described in the “Candidate Data Retention” section of this Candidate Notice, typically for up to two years after the recruitment process concludes, unless a longer or shorter period is required or permitted by law.
Updates to this Candidate Notice
SonarSource may update this Candidate Notice from time to time to reflect changes in our data handling practices, legal requirements, or recruitment processes. The effective date will be indicated at the bottom of this page. We encourage you to review this Candidate Notice periodically to stay informed about how we protect and use your Candidate Data.
Contact Us
If you have any questions or concerns regarding our data practices or this Candidate Notice, or if you would like to exercise any of your privacy rights, please contact us at internal.secgov@sonarsource.com. Please include your country and/or state of residence to help us respond appropriately.
If you are located in the United States, you may also contact us at +1 737 263 2279.
You may opt out of certain data processing activities or withdraw your consent at any time, where applicable, by contacting us through the methods listed above.