Applicant Privacy Notice
Global applicant privacy notice for candidates applying to any Nemetschek Group entity
1. Who we are and who is responsible for your data
This Applicant Privacy Notice (the “Notice”) explains how the Nemetschek Group collects and processes your personal data when you apply for a role with us, express interest in working with us, or are referred to us, and when your application is handled through our applicant tracking system (the “ATS”).
The Nemetschek Group (“Nemetschek”, “we”, “us”, “our”) is a group of independent software companies led by the parent company Nemetschek SE, Konrad-Zuse-Platz 1, 81829 Munich, Germany.
Controller of your application data
The controller responsible for the recruitment process and hiring decision, and for processing your personal data in connection with that process, is the specific Nemetschek Group company that published the vacancy you applied to (the “Hiring Company”). The Hiring Company is identified in the relevant job posting and in your application confirmation in the ATS. The Hiring Company remains responsible for the specific recruitment process and hiring decision
Nemetschek SE (Konrad-Zuse-Platz 1, 81829 Munich, Germany), the Nemetschek Group parent, acts as the central point of contact for this Notice. Nemetschek SE is the contracting party for the Group applicant tracking system (ATS) and may provide central ATS and recruiting shared services. Depending on the specific processing activity, Nemetschek SE or another Nemetschek Group entity may act as controller, joint controller or processor. Whichever entity is responsible for the relevant processing, you can raise any query about your application and exercise your data protection rights through Nemetschek SE using the contacts below, and we will route your request to the responsible entity.
Where one or more Nemetschek Group companies jointly determine the purposes and means of certain recruitment processing, they act as joint controllers for that processing. Nemetschek SE or another Group entity processes personal data solely on behalf of a Hiring Company – in particular for the operation of the shared ATS – it acts as a processor within the meaning of Art. 28 GDPR.
Data Protection Officer and privacy contacts
Nemetschek SE provides a central email address for applicants to contact us with questions or enquiries relating to applicant privacy. Applicants may contact Nemetschek SE at [email protected]. Nemetschek SE will forward the enquiry to the responsible Hiring Company.
Where the Hiring Company responsible for your application has appointed a Data Protection Officer, their contact details are available on request via the central contact above.
2. Scope of this Notice
This Notice applies to all candidates and applicants worldwide, including:
- applicants for permanent, fixed-term, temporary, working-student, internship and apprenticeship;
- people who submit a speculative/unsolicited application or join our talent pool; and
- people whose details we receive from recruiters, referrals or public professional sources.
It covers personal data processed in the ATS and related recruitment tools. It does not cover: (i) processing once you become an employee or worker (a separate employee privacy notice applies); (ii) general use of our public websites (covered by each entities’ website privacy statement and cookie notice); or (iii) processing we carry out as a data processor on behalf of our customers.
Where local law in your country, or a country-specific section in Part B (Region-specific terms) of this Notice, requires something different from the general terms in Part A, the local/region-specific terms prevail for applicants in that country.
PART A — GENERAL TERMS (ALL APPLICANTS)
3. The personal data we collect
We process the categories of personal data that are necessary for the recruitment process. Depending on the role and on what you choose to provide, these may include:
|
Category |
Examples |
|
Identification |
First/last name, preferred name, photograph (if you include one), date of birth, nationality, gender (where lawful and necessary). |
|
Contact details |
Home/postal address, e-mail address, telephone/mobile number. |
|
Application materials |
CV/résumé, cover letter, education and qualifications, work experience, certificates/diplomas, references, portfolio, links you provide (e.g. LinkedIn, GitHub). |
|
Role-related details |
Current/previous employers, job titles, department, place of work, working hours (full/part-time), notice period, salary expectations, availability, relocation/visa and work-authorisation status. |
|
Screening & assessment |
Answers to screening questions, results of skills tests, assessments, case studies, personality/aptitude tests and interviewers’ notes and evaluations. |
|
Background/verification |
Where permitted by local law and proportionate to the role: identity, right-to-work, qualification and reference checks; and, only where legally required or permitted, criminal-record/conduct checks. |
|
Special categories |
Only where lawful and necessary: health information (e.g. for accommodations), and diversity information (e.g. ethnicity, disability, gender) where collected for equal-opportunity monitoring — see section 6. |
|
System & metadata |
ATS account data, application ID, dates/status of your application, communications with recruiters, and technical log data generated when you use the careers portal. |
Where we get your data
- From you — what you enter in the ATS, send us, or tell us in interviews.
- From third parties — recruitment agencies, your named referees, employee-referral sources, background-check and assessment providers, and publicly available professional sources (e.g. professional networks/job boards).
- Generated by us — interview notes, scorecards and evaluations created during the process.
4. Why we process your data and our legal bases
We process your personal data for the following purposes. The legal basis is determined for each processing purpose; the table shows bases that may typically apply under the EU/EEA GDPR (read together with national law such as § 26 BDSG in Germany). Region-specific bases are addressed in Part B.
|
Purpose |
What this involves |
Typical legal basis (EU/EEA) |
|
Run the recruitment process |
Receiving and reviewing applications, shortlisting, scheduling/holding interviews, assessments, and communicating decisions. |
Taking steps prior to entering a contract (Art. 6(1)(b) GDPR); our legitimate interest in selecting suitable candidates (Art. 6(1)(f) GDPR), in each case subject to the applicable local law. |
|
Verify suitability |
Reference, qualification, right-to-work and (where lawful) background checks. |
Art. 6(1)(b) and (f) GDPR; legal obligation where required (Art. 6(1)(c) GDPR); your consent where required by local law (Art. 6(1)(a) GDPR). |
|
Comply with law |
Right-to-work/immigration checks, equal-opportunity and anti-discrimination obligations, tax/social-security onboarding if hired, responding to authorities. |
Legal obligation (Art. 6(1)(c) GDPR); public interest (Art. 6(1)(e) GDPR) where applicable. |
|
Talent pool / future roles |
Keeping your details to consider you for other suitable vacancies as a separate, optional purpose. |
Your separate, informed and freely given consent where consent is the applicable basis (Art. 6(1)(a) GDPR / § 26(2) BDSG). |
|
Protect our rights & operations |
Establishing/defending legal claims (e.g. under equal-treatment law), security of our premises and systems, and fraud prevention. |
Legitimate interests (Art. 6(1)(f) GDPR); legal obligation (Art. 6(1)(c) GDPR). |
|
Improve recruiting |
Aggregated, de-identified analytics on our hiring process. |
Legitimate interests (Art. 6(1)(f) GDPR). |
Where we rely on consent, you can withdraw it at any time with effect for the future, without affecting the lawfulness of processing before withdrawal, and without disadvantage to your current application unless the data was strictly necessary to it.
5. Special-category and sensitive data
We try to avoid collecting special-category data (such as data revealing health, racial or ethnic origin, religion, or sexual orientation) and criminal-record data unless there is a clear lawful reason. Where we do process it, the applicable condition under Article 9 GDPR or local law is determined for the specific processing, for example:
- Health/disability — to provide adjustments/accommodations for the application process or role, where requested, on the applicable legal basis and condition under local law (including Art. 9(2)(b)/(h) GDPR where applicable). Provision is generally voluntary unless required by law or necessary for a requested accommodation.
- Diversity/equal-opportunity monitoring — only where permitted or required locally, usually on a voluntary, consent basis and, wherever possible, in anonymised or aggregated form.
- Criminal-record / integrity checks — only where the role and local law allow, under the appropriate legal safeguards.
You are never required to volunteer special-category data that we have not requested. Please do not include sensitive details in free-text fields unless we have asked for them. Access to special-category data is restricted to authorised personnel with a need to know.
6. Use of automation and artificial intelligence
We do not currently implement AI for recruitment and do not currently use solely automated decision-making (including profiling) that produces legal or similarly significant effects about you within the meaning of Article 22 GDPR. Hiring decisions involve human judgement.
When we use tools that assist with sorting, matching or screening applications, we maintain meaningful human oversight. If, for a specific role or country, we ever use a tool that would make a solely automated significant decision, or an automated employment decision tool subject to specific rules (for example, New York City Local Law 144 or comparable laws), we will tell you in advance, provide any legally required notices and bias-audit information, and offer the rights the law gives you (such as requesting human review). We do not currently use AI for recruitment. Should we use AI in recruitment process in the future, its use will be designed to comply with applicable AI and anti-discrimination laws, including the EU AI Act where it applies.
7. Who has access to your data
Access is limited to those who need it for the recruitment process. Recipients may include:
- Internal recipients — HR/recruiting, the hiring manager and relevant interviewers in the Hiring Company, and designated Group-internal HR/recruiting shared-service functions, in each case only where they need the data for the relevant recruitment purpose and on a strict need-to-know basis (and supporting functions such as IT, and finance/accounting if you are hired).
- Other Nemetschek Group companies — only where needed for a separately specified recruitment purpose, with appropriate transparency and a legal basis, and, where the applicable governance requires it, your prior specific opt-in. Another Group company/entity will not receive your CV for a separate vacancy merely because it belongs to the Nemetschek Group. The separate Group talent pool is subject to your consent.
- Service providers (processors) acting on our instructions, including the provider of our applicant tracking system, SmartRecruiters, Inc. (a US company, together with its relevant European affiliates), subject to the applicable contract, and its authorised subprocessors, as well as providers of hosting/cloud, assessment, background-checking, scheduling and communication tools. They are bound by data-processing agreements and may access data only as applicable to the actual system and data flows.
- Professional advisers and authorities — e.g. legal advisers, auditors, and courts/regulators where required by law.
Corporate transactions — where necessary for a proposed or actual merger, acquisition, reorganisation, restructuring or transfer of business, we may disclose relevant personal data to a prospective buyer, successor, the acquiring entity and their professional advisers. Any such disclosure is limited to what is necessary for the relevant transaction purpose and is subject to an applicable legal basis, confidentiality obligations, access restrictions, appropriate technical and organisational safeguards, and applicable international transfer requirements. We do not sell your personal data, and we do not share it for cross-context behavioural advertising.
8. International data transfers
Because we are a global group using shared systems and global teams, your data may be accessed in or transferred to countries other than your own, including outside the EU/EEA, the UK and Switzerland (for example, where a Group company, the ATS or an authorised sub-processor operates in the United States or other countries).
Where we transfer personal data to a country that does not provide an equivalent level of protection, we transfer it only in accordance with applicable data-protection requirements and put in place an appropriate safeguard, such as:
- an adequacy decision of the European Commission (or the equivalent UK/Swiss recognition);
- the EU Standard Contractual Clauses, with the UK International Data Transfer Addendum and the Swiss adaptations where relevant; and/or
- certification under the EU–US / UK / Swiss Data Privacy Framework where applicable,
together with supplementary technical and organisational measures where required. You can request further information or a copy of the applicable safeguards using the privacy contact details in section 13.
9. How long we keep your data
We keep your application data only as long as necessary for the purposes above and to meet legal obligations. The periods below are default or indicative periods, subject to applicable local law and the specific purpose and data category:
- If you are not hired — we generally delete your application data within 6 months of the end of the process. Longer retention is permitted only where necessary and proportionate for a documented legal obligation, legal claims or defence, an ongoing process, or valid separate Talent Pool consent.
- Talent pool — if you provide separate consent, we keep your data to consider you for future roles for 12 months, or until you withdraw consent, whichever is earlier, subject to legally necessary exceptions.
- If you are hired — relevant data is transferred to your personnel file and kept under the employee privacy notice.
Local law may require different periods; see Part B. We may retain limited records longer only where necessary and proportionate, including where the law requires it (e.g. tax or anti-discrimination evidence) or for legal claims or defence.
10. How we protect your data
We use appropriate technical and organisational measures to protect your data against loss, misuse and unauthorised access, including access controls on a need-to-know basis, encryption in transit, confidentiality obligations, and contracts with our processors. No internet transmission is ever completely secure, so please avoid sending sensitive details by unencrypted e-mail; use the ATS where possible.
11. Your rights
Subject to local law and applicable conditions/exemptions, you may have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”) in certain circumstances;
- restrict or object to processing in certain circumstances, including processing based on legitimate interests;
- data portability for data you provided, where processing is based on consent or contract and is automated;
- withdraw consent at any time, with future effect; and
- lodge a complaint with a competent data protection authority (see section 12).
To exercise your rights, use the contacts in section 13. We may need to verify your identity, and we will respond within the period required by applicable law.
12. Complaints to a supervisory authority
If you believe we have not handled your data lawfully, please contact us first so we can try to resolve it. You also have the right to complain to a competent data protection authority — for example, in the EU/EEA the authority in your country of residence, work or the alleged infringement; in Germany, the authority competent for the Hiring Company; in the UK, the Information Commissioner’s Office (ICO); and in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC). Authorities for other regions are listed in Part B.
13. Providing your data, contact, and changes
Is providing your data mandatory?
Providing the data needed to assess your application is voluntary, but without the data marked as required (or that we are legally required to collect) we cannot process your application or, if successful, enter into a contract with you.
How to contact us
Nemetschek SE provides a central email address for applicants to contact us with questions or enquiries relating to applicant privacy. Applicants may contact Nemetschek SE at [email protected]. Nemetschek SE will forward the enquiry to the responsible Hiring Company.
Changes to this Notice
We may update this Notice from time to time to reflect changes in our practices or the law. We will notify you of any material changes by posting the new version in the ATS/careers portal. Please review it periodically. Last updated: 20.08.2026.
PART B — REGION-SPECIFIC TERMS
The terms below supplement Part A for applicants in the relevant region and prevail to the extent they differ. Keep only the regions where you actually hire, and have each one localised.
B-1. European Economic Area & Germany (GDPR / BDSG)
For applicants in the EEA, the GDPR applies. In Germany, the Federal Data Protection Act (BDSG), in particular § 26, applies to employment-context processing alongside Art. 88 GDPR. Our main legal bases are set out in section 4; the controller and the central privacy contact are set out in section 1. The Data Protection Officer for the relevant group entity is available on request via that contact.
Severe disability status: Any information concerning severe disability status is provided voluntarily. To the extent such information is processed, the legal basis is Art. 9(2)(b) GDPR in conjunction with § 26(3) BDSG, in particular for the fulfilment of obligations under SGB IX and, where applicable, for documenting or defending claims in matters under the General Equal Treatment Act (AGG).
Default retention: application data is generally deleted within six (6) months after the process ends, subject to applicable local law and the specific purpose and data category, unless a longer period is necessary and proportionate for a documented legal obligation, legal claims or defence, an ongoing process, or your valid separate Talent Pool consent. This six-month period is used as a precautionary retention period to allow for the assertion and, where applicable, litigation of potential claims under § 15(4) AGG in conjunction with § 61b(1) ArbGG; it is not a statutory six-month retention period mandated by the AGG.. A longer retention period may nevertheless be justified, for example, by evidence required in proceedings under the General Equal Treatment Act (AGG), another legal retention obligation, or your consent.
Internal recipients: Where legally required, the works council (Betriebsrat) of the Hiring Company pursuant to § 99 BetrVG.
No solely automated decisions are made under Art. 22 GDPR. You have the rights in section 11 and may complain to your local supervisory authority.
B-2. United Kingdom (UK GDPR / DPA 2018)
For UK applicants, the UK GDPR and the Data Protection Act 2018 apply. Legal bases mirror section 4 (e.g. steps prior to a contract; legitimate interests; legal obligation; consent for the talent pool). International transfers rely on UK adequacy regulations or the International Data Transfer Agreement/Addendum. You may complain to the Information Commissioner’s Office (ICO), ico.org.uk.
B-3. Switzerland (revised FADP)
For applicants in Switzerland, the revised Federal Act on Data Protection (revFADP) applies in addition to, or instead of, the GDPR. References to “personal data” include data of natural persons as defined under the revFADP. Transfers abroad rely on the Swiss adequacy list or Swiss-compliant Standard Contractual Clauses. You may contact the Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch.
B-4. United States
Employment in the U.S. is generally “at will”, and this Notice does not create a contract or alter that status. We collect and use applicant personal information for the recruitment and business purposes described in Part A and for U.S.-specific legal compliance (e.g. work authorisation/Form I-9, EEO, and applicable federal, state and local laws). Background and reference checks, where conducted, follow the Fair Credit Reporting Act (FCRA) and state equivalents, with any separate disclosures and authorisations required.
California (CCPA/CPRA) — Notice at Collection for applicants
This section applies to California residents who apply for employment. We collect the following categories of personal information about applicants, for the business purposes in Part A; we retain each category as described in section 9 and applicable law:
|
CCPA category |
Examples |
Collected |
|
Identifiers |
Name, address, e-mail, phone, online identifiers, government ID where required. |
Yes |
|
Customer-records / Cal. Civ. Code §1798.80 |
Application details, education and employment history, references. |
Yes |
|
Protected classifications |
Where lawfully collected (e.g. voluntary diversity data, disability for accommodation, veteran status). |
If provided |
|
Professional/employment information |
Work history, qualifications, assessment results, interview notes. |
Yes |
|
Education information |
Degrees, certificates, transcripts where requested. |
Yes |
|
Internet/network activity |
Careers-portal and ATS usage and log data. |
Yes |
|
Sensitive personal information |
Government identifiers and, where lawful, certain health or protected-class data — used only for permitted purposes. |
Limited |
|
Inferences |
Suitability assessments derived from the above (with human oversight). |
Limited |
We do not “sell” or “share” applicant personal information for cross-context behavioural advertising. We do not use sensitive personal information to infer characteristics, beyond purposes permitted by the CCPA. Subject to verification and exceptions, California applicants may request to know/access, correct, and delete their personal information, and may not be retaliated against for exercising these rights. To submit a request: [email].
Other U.S. state privacy laws
Where state laws apply to applicants (for example, in Colorado, Connecticut, Texas, Oregon, Montana, Virginia and others), you may have rights to access, correct, delete and obtain a copy of your personal data, and to opt out of certain processing. Many of these laws contain employment/applicant exemptions; we honour applicable rights where they apply. Use the contacts in section 13 (or the California method above) to make a request.
Automated employment decision tools: where a law such as New York City Local Law 144 applies, we provide the required notice and bias-audit information before using such a tool; see section 6.
B-5. Canada (PIPEDA / Québec Law 25)
For applicants in Canada, we handle personal information in line with PIPEDA and applicable provincial laws, including Québec’s Law 25. We collect, use and disclose your information for the recruitment purposes in Part A, obtain consent where required, and you may request access to and correction of your information. You may contact the Office of the Privacy Commissioner of Canada or the relevant provincial authority (e.g. the Commission d’accès à l’information du Québec).
B-6. Other regions
Where you apply from these countries, the following also apply and prevail to the extent of any conflict with Part A:
- Brazil (LGPD): we process applicant data on the legal bases in the LGPD (e.g. steps prior to a contract, legitimate interest, consent, legal obligation). You may exercise LGPD rights (confirmation, access, correction, anonymisation, portability, deletion) and contact the ANPD.
- Australia (Privacy Act / APPs): we handle personal information under the Australian Privacy Principles; you may seek access/correction and complain to the OAIC. (Note the Australian “employee records” exemption may apply once employed.)
- Singapore (PDPA): we collect, use and disclose personal data for recruitment with notification and, where required, consent; you may withdraw consent and request access/correction. Our Data Protection Officer can be reached via section 13.
- Japan (APPI): we use applicant data for stated purposes of use and obtain consent for third-party or cross-border provision where required.
- India (DPDP Act 2023): we process applicant data for the recruitment purpose, provide notice, and honour rights of access, correction, and erasure as the Act comes into force; you may nominate or grieve as provided by the Act.
- Saudi Arabia (PDPL): where you apply to a Group entity in the region, we process applicant data under the applicable Personal Data Protection Law, including consent and cross-border transfer requirements.
- China (PIPL): we process applicant data under the Personal Information Protection Law, obtain separate consent where required (including for cross-border transfers of your data), and honour your rights of access, correction and deletion.
- New Zealand (Privacy Act 2020): we handle personal information under the Information Privacy Principles; you may access and correct your information and complain to the Office of the Privacy Commissioner.
- South Africa (POPIA): as responsible party, we process personal information on a lawful basis under POPIA; you may access, correct or delete your information and complain to the Information Regulator.
- Israel (Protection of Privacy Law): we process applicant data for recruitment, provide the required notice, and honour your rights of access and correction under Israeli privacy law.
For any country not specifically addressed in this Part B, we process your personal data in accordance with applicable local law, you have the rights that local law grants you, you can contact us using the central contact in section 1, and you may complain to your local data protection authority.