You have an old version of the software. The website may not work properly. Please update your system to view the page with all available features.
light
dark

Privacy and Cookie Policy

Privacy Policy for TTMS Nordic

We process your personal data in accordance with this privacy policy, which describes how we collect, protect, and use your data when you are a customer of ours, subscribe to our newsletter, sign up or search for assignments, or visit our website.

1. Data Controller

- Company Name: TTMS Nordic A/S

- CVR Number (Company Reg. No.): DK10138256

- Address: Kirkebjerg Allé 84, DK - 2605 Brøndby

- E-mail: consulting@ttmsnordic.dk

- Telephone: +45 93 83 97 10

2. Processing of Your Personal Data

2.1 Provision of Consultancy Services (Customers)

When you purchase a service from us, we process your data to fulfil our agreement with you.

- Purpose: Communication regarding the assignment, project management, delivery of advisory services, and invoicing.

- Categories of Information: Name, e-mail address, telephone number, job title, company name, and payment information.

- Legal Basis: Article 6(1)(b) of the General Data Protection Regulation (necessary for the performance of a contract).

2.2 Distribution of Newsletters and Information About Events

If you have given your consent to receive information from us.

- Purpose: Distribution of e-mails containing articles, news, events, and updates about our business.

- Categories of Information: Name and e-mail address.

- Legal Basis: Article 6(1)(a) of the General Data Protection Regulation (consent). You can withdraw your consent at any time.

2.3 Inquiries and Non-Binding Dialogue (Potential Customers)

When you contact us (or we contact you) with a non-binding inquiry.

- Purpose: To answer your questions and provide customer service.

- Categories of Information: Name, e-mail, telephone number, and any information you share in your inquiry.

- Legal Basis: Article 6(1)(f) of the General Data Protection Regulation (legitimate interest). Our legitimate interest is to respond to your inquiry.

2.4 Compliance with Legal Requirements (Bookkeeping)

We are required to retain certain documents in accordance with applicable legislation.

- Purpose: Compliance with the Danish Bookkeeping Act.

- Categories of Information: Invoice information, including name, company, address, and transaction history.

- Legal Basis: Article 6(1)(c) of the General Data Protection Regulation (legal obligation).

2.5 Consultants (Candidate Registration)

When you register in our system, regardless of whether you are seeking permanent employment or freelance assignments:

- Purpose: To create a consultant profile for the purpose of brokering assignments and positions through TTMS Nordic, including the administration of employment relationships or external cooperation agreements.

- Categories of Information: Name, e-mail, telephone, address, postcode, city, area, country, LinkedIn URL, employment type (permanent job / freelance assignments), availability date, company name, profile picture, and CV/resume (.pdf, .docx, .doc).

- Legal Basis: Article 6(1)(b) of the General Data Protection Regulation (necessary for steps taken prior to entering into an employment contract or cooperation agreement) and Article 6(1)(a) (the explicit consent granted upon registration on the portal).

3. Sources of Personal Data (Data Sources)

We primarily collect personal data directly from you. However, in certain cases, we may receive or collect information from other sources. Our data sources include:

- Directly from you: Information you enter during candidate registration, when subscribing to the newsletter, or when sending information to us via e-mail and contact forms.

- Group companies: In certain cases, we receive information about potential customers, projects, or consultant profiles from our Polish parent company, Transition Technologies MS S.A. (TTMS), as part of our intra-group cooperation.

- Publicly available sources: If we assess that your profile is relevant to our consultancy business, we may collect general contact details and professional competencies from publicly available professional platforms, such as LinkedIn.

4. Recipients and Disclosure of Personal Data

4.1 Group Companies (Disclosure to Another Data Controller)

We share personal data with our Polish majority shareholder, Transition Technologies MS S.A. (TTMS), which acts as an independent data controller for the data received.

- Purpose: The disclosure is made for internal administrative purposes within the group, as well as to secure assignments, projects, and positions across the group.

- Legal Basis: Article 6(1)(f) of the General Data Protection Regulation (legitimate interest in internal resource sharing and group administration) and based on the consent provided during account creation. As TTMS is located in Poland (EU), processing is secured under the same European GDPR standards.

4.2 Data Processors (Infrastructure and Administrative Systems)

We entrust personal data to external business partners (data processors) who process the information on our behalf. We have entered into written data processing agreements with our data processors to ensure that your data is treated confidentially and securely in accordance with GDPR Article 28. Our primary systems include:

- Microsoft Azure, Teams, SharePoint, and Office 365: Our business and registration system runs on a cloud infrastructure provided by Microsoft Azure. We also use Microsoft Teams, SharePoint, and Office 365 for internal and external communication, file sharing, and project collaboration. Microsoft acts as our data processor and hosts data securely on servers within the EU/EEA.

- Visma e-conomic: We use e-conomic as our accounting and invoicing system to handle transactions, invoices, and bookkeeping related to our customers and suppliers.

- Visma DataLon: We use DataLon for the administration and payment of salaries, fees, and employee benefits for our permanently employed consultants and staff.

- DocuSign: We use DocuSign as a digital signature solution for the secure conclusion and administration of contracts and agreements with our customers and external consultants. The system processes contact details (such as name and e-mail address) as well as IP addresses and timestamps to validate digital signatures. Data is generally stored on servers within the EU/EEA. As DocuSign is a global provider, any transfers to third countries are secured via the European Commission's Standard Contractual Clauses (SCCs) along with supplementary security measures.

- LinkedIn Recruiter (LinkedIn Ireland Unlimited Company): We use LinkedIn Recruiter as an administrative tool for active recruitment, identification, and dialogue with potential employees and external consultants. In this context, personal data such as profile data, CV information, communication history via InMail, as well as our own internal recruitment notes and project organisations, are processed. LinkedIn acts as our data processor for the data we manage and store in the recruitment module. As LinkedIn is a global platform, personal data may be transferred to and accessed from the USA. These transfers are secured via via LinkedIn's Data Processing Agreement (DPA), which integrates the European Commission's Standard Contractual Clauses (SCCs) and the current EU-U.S. Data Privacy Framework.

5. Data Security

We protect your personal data and have implemented appropriate technical and organisational measures against your information being accidentally or unlawfully deleted, published, lost, impaired, or brought to the knowledge of unauthorised persons, misused, or otherwise processed in violation of legislation.

- Legal Basis: Article 32 of the General Data Protection Regulation (security of processing), which obliges us to ensure a level of security appropriate to the risks associated with our processing of personal data.

Our data is stored in a secure and encrypted cloud environment (Microsoft Azure), and access to the system is strictly managed via access rights and permissions, ensuring that only employees and group companies with a justified, work-related need have access to your data..

6. Retention and Deletion

We only store your data for as long as necessary for the purposes for which it was collected:

- B2B Freelance Consultants: B2B Freelance Consultants: As freelance consultancy agreements often extend over longer periods, we retain identified B2B consultant profiles and dialogue history for up to 5 years from the date of most recent contact. We do this based on our legitimate interest in being able to staff future customer projects with qualified external suppliers. Before this period expires, we will typically reach out to verify whether the consultant still wishes to remain a part of our network, after which data may be retained for a new period. (Legal basis: GDPR Article 5(1)(e) and Article 6(1)(f)).

- Active Recruitment Processes for Employees (Employment with a Customer): If you are offered and accept employment with our customer, we transfer the necessary information to the customer, who then becomes an independent data controller for your data. We retain your recruitment data for up to 6 months after employment for the purposes of follow-up and warranty obligations towards the customer. The legal basis is our legitimate interest in documenting a correct recruitment process (GDPR Article 6(1)(f)). If we wish to retain your CV in our general talent pool for future matches, we will obtain your explicit consent for this separately (GDPR Article 6(1)(a)).

- Active Recruitment Processes for Employees (Rejections): If you apply for a permanent position through us but are not offered employment with the customer, we retain your data and CV for up to 6 months after the rejection. The legal basis is our legitimate interest in being able to document an objective recruitment process and potentially defend ourselves against legal claims (GDPR Article 6(1)(f)).

- Accounting Records: Retained for 5 years from the end of the financial year in question, pursuant to Section 10 of the Danish Bookkeeping Act. (Legal basis: GDPR Article 6(1)(c)).

- Newsletter Subscribers: Information is deleted automatically and without undue delay if you unsubscribe from the newsletter (Legal basis: GDPR Article 6(1)(a)).

- Inquiries (Potential Customers): Data is deleted no later than 3 years after the most recent correspondence, unless an actual customer relationship is established. The retention period is established in consideration of the consultancy industry's long sales cycles and our legitimate interest in being able to resume business dialogues. (Legal basis: GDPR Article 6(1)(f)).

7. Your Rights

When we process your personal data, you have a number of rights under the General Data Protection Regulation. If you wish to exercise your rights (e.g. the right of access or erasure), you must contact us at the e-mail address specified in section 1. Your rights include:

- Right to be Informed: You have the right to receive clear information about how, why, and on what basis we process your data when we collect it.

- Right of Access: You have the right to gain access to the data we process about you.

- Right to Rectification: You have the right to have inaccurate information about yourself corrected.

- Right to Erasure (The Right to be Forgotten): You have the right to have information about you deleted from our systems (e.g. your CV) prior to our general erasure deadline.

- Right to Restriction of Processing: In certain cases, you have the right to have the processing of your personal data restricted.

- Right to Object: You have the right to object to our otherwise lawful processing of your personal data.

- Right to Data Portability: In certain cases, you have the right to receive your personal data in a structured, commonly used, and machine-readable format.

- Right to Withdraw Consent: If our processing is based on your consent, you have the right to withdraw your consent at any time. This does not affect the lawfulness of the processing based on consent prior to its withdrawal.

Complaint to the Danish Data Protection Agency (Datatilsynet)

You have the right to lodge a complaint with the Danish Data Protection Agency if you are dissatisfied with the way we process your personal data. You can find the contact details for the Danish Data Protection Agency at www.datatilsynet.dk.

Cookie Policy for TTMS Nordic

Introduktion

When you visit our website, information about you is collected, which is used to customise and improve our content, as well as to compile statistics.

The first time you visit our website, you will be met by a cookie banner where you can actively select which cookies you wish to consent to, or completely reject all non-essential cookies. You can change or withdraw your consent at any time directly via the website settings. If you choose not to grant consent, or if you subsequently delete your cookies, you may risk that the website does not function optimally and that there is content you cannot access.

Below, we have elaborated on what information is collected, its purpose, and which third parties have access to it.

What Are Cookies?

The website uses "cookies", which are text files stored on your computer, mobile device, or equivalent, for the purpose of recognising it, remembering settings, and performing statistics. Cookies cannot contain harmful code such as viruses.

It is possible to delete or block cookies. Please look for a relevant guide for your specific browser online. If you delete or block cookies, you may risk that the website does not function optimally and that there is content you cannot access.

Third-Party Cookies

The website contains cookies from third parties, which to varying extents may include:

- Google services (for example, Analytics)

Use of Google Analytics

This website uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses cookies to analyse your use of the website. The information generated by the cookie about your use is normally transmitted to a Google server in the USA and stored there.

However, due to the activation of IP anonymisation on these websites, your IP address will be shortened by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the USA and shortened there.

On behalf of the operator of this website, Google uses this information to:

- Evaluate your use of the website

- Compile reports on website activity

- Provide other services related to website and internet usage to the website operator

The IP address provided by Google Analytics is not merged with any other Google data.

How to Reject Google Analytics

You can prevent the storage of cookies by using a corresponding setting in your browser software. However, we point out that in this case, you may limit some of the website's functions.

Furthermore, you can prevent Google's collection of the data generated by the cookie (including your IP address) as well as the processing of this data by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout