1. Introduction
By:
• Visiting Hudson Holdings Ltd’s (“Hudson”) official website (“the Website”)
at <https://hudson.com.mt>; or
• Applying for a job through the Careers section; or
• Sending us a request through the Contact Us form; or
• Signing up to check the balance on your Hudson Coin;
you provide us with your personal data.
“Personal data” means any information relating to an identified or identifiable natural person.
Hudson is committed to protecting the privacy and security of your personal information.
This Privacy Notice describes how Hudson collects and uses personal information about you,
in accordance with data protection laws.
It is important that you read and retain this Privacy Notice, together with any other privacy
notice we may provide on specific occasions when we are collecting or processing personal
information about you, so that you are aware of how and why we are using such information
and what your rights are under the data protection legislation.
2. Data Controller and processor
The Data Controller refers to Hudson. This means that Hudson is responsible for deciding how
it holds and uses personal information about you. Hudson is required under data protection
legislation to notify you of the information contained in this privacy notice. Hudson is also the
owner and registrant of the Website.
A Data Processor (“Processor/s”), is an entity which processes the personal data on behalf
of the Controller. Below is a list of Processors that the Controller engages in connection with
the Website:
|
Details |
Google Analytics |
Google Analytics is a web analytics service provided by Google LLC that
helps track website traffic and user interactions. It processes data such
as IP addresses and device information to provide insights for improving
the website. The data is processed in compliance with Google’s privacy
policy. |
The relationship between the Controller and its Processors are formalized concluding a Data Processing Agreement.
3. Information Hudson collects
When you visit the Website, we collect the following information about you (“Website visitor
data”):
• Your IP Address;
• Cookies (please refer to our Cookie Policy for more information)
• Browser information (including language settings) and device used;
• Your location (as per your IP address);
• Your screen resolution;
• The average time you spend on each webpage part of the Website;
• Your age and gender (if you visit the Website while logged into you Google account).
The Website visitor data is anonymised.
For more information on how we handle your personal data relating to your recruitment
process, kindly refer to Section 5 on Recruitment.
When you send us a message through the Contact Us form, we collect the following
information (“information enquirer data”):
• Your name;
• The name of your company (if provided);
• Your contact number;
• Your email address;
• The items of personal data that you may include in the free-text box.
When you sign up to check the balance on your Hudson Coin, we collect the following
information (“Hudson Coin information”):
• Your name; and
• Your email address.
• Serial Number of the Hudson Coin
4. Competitions
By entering our competitions and promotions, you are asked to fill out a registration and
consent form where you agree to provide us with your personal data. For more information on
how we process personal data in relation to competitions, please check our Competitions and
Promotions Privacy Notice.
We collect your data to be able to identify and contact you as a participant of our competitions
and promotions. We also use your data to keep you informed about our promotions and offers.
Section 10 applies to you only if you are a resident of the European Economic Area (“EEA”),
together with the Terms and Conditions of each competition, which govern your relationship
with Hudson with regards to our competitions and promotions.
5. Recruitment
The Recruitment Data may be used to communicate with applicant, to manage Hudson’s
recruiting and hiring processes, and for compliance with corporate governance and legal and
regulatory requirements. If an applicant is hired, the Recruitment Data may be used in
connection with employment and corporate management and will be subject to Hudson’s
Recruitment Privacy Policy.
Hudson does not request or require special categories of information concerning religion,
health, sexual orientation, trade union membership, genetic data, biometric data (including
fingerprint) or political affiliation in connection with recruiting. If the applicant has a disability
and would like Hudson to consider he/she may provide that information during the recruiting
process. Further information on an applicant’s nationality may be needed in order to confirm
whether Hudson would need to apply for a residence permit in their respect. Hudson does not
otherwise require applicants to provide race or ethnicity information, and if an applicant
provides this information, it will not be viewable in the hiring or selection process.
An Applicant is responsible for the information he/she provides or makes available to Hudson
and must ensure it is honest, truthful, accurate and not misleading in any way. Further, if an
applicant provides any information concerning any other person, such as individuals they
provide as references, they are responsible for providing any notices and obtaining any
consents necessary for Hudson to collect and use that information as described in this Notice.
Applicants should retain their own copy of any information submitted to us.
6. Purposes and Legal Basis for Collecting Data
Personal data, as listed in Section 3 above is only collected for specific, explicitly stated and
legitimate purposes and is processed according to the legal basis identified below
Categories of personal data |
Purpose(s) |
Legal basis |
Website visitor data |
• Improve the content
and functionality of
our website;• Better understand
the categories of
visitors to our
Website,
• Improve our
products and
services including
the security of the
Website. |
Hudson has a legitimate interest to understand the category of visitors to the Website and the visitors/users have interest in having the best possible experience by visiting the Website. |
Hudson could not achieve the same purposes without collecting such data. |
Job applicant data |
Recruitment and selection of candidates |
Processing is necessary in order to take steps at the request of the data subject prior to entering into a contract |
Hudson needs to collect personal
data to find suitable candidates
for the vacant positions
advertised on the Website, and
the applicants/jobseekers have
interest in their applications being
considered and examined by
Hudson, prior to deciding whether
or not to enter into an
employment agreement with the
candidate. |
Information enquirer data |
Respond to information requests |
Hudson has a legitimate interest to create and maintain professional relationship with any member of the public enquiring information from us. |
Marketing |
Providing you Hudson’s newsletter containing latest information and updates. |
This information is collected on the basis of your consent. You may withdraw such consent at any point in time through the unsubscribe button or through [email protected], and we will stop sending you updates. |
Hudson Coin data |
Providing you information about the balance on your Hudson Coin |
This information is collected on the basis of your consent. You may withdraw such consent at any point in time, and we will stop sending you updates about the remaining balance on your Hudson Coin. |
7. Recipients of personal data
Your personal data may be shared between the undertakings forming part of the Hudson
Group, as foreseen by Recital 48 of GDPR.
Your personal data may be also shared between the Controller and the Processors.
Your personal data may be transferred outside of the European Economic Area (EEA) or to
international organizations. When this occurs, we ensure that your data is afforded a similar
level of protection as it would within the EEA. We implement appropriate safeguards, such as
Standard Contractual Clauses, binding corporate rules, or other legally recognized
mechanisms, to ensure that your personal information is processed in compliance with GDPR
and receives the same level of protection.
We do not sell, trade or otherwise transfer any personal information to third parties. We also
review our security measures at least annually and also conduct additional reviews whenever
significant changes in technology, regulatory requirements or operational processes occur..
Where practicable, we improve these security measures to ensure the protection of personal
information..
We have put in place procedures to deal with any suspected personal data breach and will
notify you and any applicable regulator of a breach where we are legally required to do so.
While we do our utmost to safeguard your personal data, no data transmission over the
internet can be totally secure and therefore we cannot guarantee or warrant that no
unauthorised access will occur.
8. Data Retention
Personal data is not kept for a period longer than is necessary, having regard to the purposes
for which they are processed. We may also need to keep some of your personal data where
we are obliged to do so in terms of legal or regulatory requirements, or in order to protect
ourselves against legal claims, or to enforce our company terms and conditions.
Retention period for each category of data are identified below.
Categories of personal data |
Retention period |
Website visitor data |
Data is retained for as long as strictly necessary. Retention criteria is
based on the nature of the interactions, such as session duration or
website activity logs. |
Job applicant data |
Data is retained for 3 months from the date of the application, which is the maximum duration of the recruitment process.
An email acknowledging receipt of the application is sent to the applicant with a link to this Privacy Policy.
Once the recruitment process is over, we may ask you if you would
like us to retain your application for further 6 months, for potential
future opportunities. Only data from applicants who positively opt in
will be retained for this extended period. |
Information enquirer data |
Data is retained only for the time necessary to process a response to the enquiry.
Once this is completed, the enquirer data is deleted.
The retention criteria is determined by the complexity of the enquiry,
ensuring data is not kept longer than required to achieve its
purpose. |
Hudson Coin data |
Data is retained for as long as there is a remaining balance on the Hudson Coin. Once this amount has been spent, or the Hudson Coin expires, we will delete the personal data and will stop sending you updates.
We determine the retention period based on the user’s active use of
the Hudson Coin and the expiration date outlined in the service
terms. Updates and notifications are discontinued upon deletion of
the data. |
We keep your data as long as your consent is valid and effective.
Once you decide to opt-out, we delete your data in full. We may need to keep some of your
personal data where we are obliged to do so in terms of legal or regulatory requirements, or
in order to protect ourselves against legal claims, or to enforce our company terms and
conditions.
We do our best to store your data securely and protect it against unauthorised access and
leakage.
9. Your Rights
As a website visitor, job applicant or information enquirer, you have extensive rights when it
comes to the processing of your personal data.
Your rights, listed below, may be enforced by contacting the Controller or the Processor by
email, by post or by phone using the contact details provided above.
You are guaranteed a response within 30 days from the date of receipt of your enquiry.
If your request is particularly complex or we need to process an extraordinary number of
simultaneous requests, our reply may take longer but will be provided no later than 2 months
from the date of receipt of your enquiry. This reply will also include details explaining the
reason for the delay in our response.
We will provide the information in digital format or if preferred in hard copy format.
Such requests will not incur any fee, except when you request the information on paper and
posted. In that case, we will charge you the postage fees.
Should we have reasonable doubts concerning your identity when making the request
above, we may require additional information, necessary to confirm your identity.
Your rights are:
9.1. Right to Access
In order to process this request, we will require proof of your identity. You may obtain
confirmation from us as to whether or not your personal data is being processed including:
• the purposes of the processing;
• the categories of personal data concerned;
• the recipients or categories of recipient to whom the personal data have been or will
be disclosed, in particular recipients in third countries or international organisations;
• where possible, the envisaged period for which the personal data will be stored, or, if
not possible, the criteria used to determine that period;
• the existence of the right to request from the Controller rectification or erasure of
personal data or restriction of processing of personal data concerning the data subject
or to object to such processing;
• the right to lodge a complaint with the supervisory authority;
• the existence of automated decision-making, including profiling.
9.2. Rectification
In case your date is inaccurate, incomplete or out-of-date, you have the right to rectify it.
9.3. Deletion (“the right to be forgotten”)
You have the right to have your personal data erased in case:
• the data is no longer necessary in relation to the purposes for which it was collected
or otherwise processed;
• You have withdrawn consent to process your data and there is no other legal basis
legitimating its processing;
• You have objected to processing your data and there is no other legal basis
legitimating its processing;
• Your personal data has been unlawfully processed;
Your personal data has to be erased in order to ensure compliance with any legal obligations
arising from any legislation enacted within the EU or any member states.
This right is not absolute, and we may be justified in keeping certain personal data, for instance
when we are legally obliged to do so or if such data may be necessary for us to defend a legal
claim.
9.4. Restriction
You have the right to request a restriction on the processing of your data in case:
• You contest the accuracy of your personal data, for a period enabling us to verify the
accuracy of such data;
• The processing of your data is unlawful, and you oppose the erasure of your personal
data and request the restriction of their use instead;
• We no longer need the personal data for the purposes of the processing;
• We no longer need your data, but we are required by you to retain the data for the
establishment, exercise or defence of legal claims;
• You have objected to processing (as specified in detail below), pending the verification
whether our legitimate grounds override yours.
When you restrict processing, your personal data will, with the exception of storage, only be
processed with your consent or for the establishment, exercise or defence of legal claims or
for the protection of the rights of another natural or legal person or for reasons of important
public interest of the Union or of a Member State.
In case you have obtained restriction of processing as per above, we will inform you before
the restriction of processing is lifted.
9.5. Complaint
In addition to the above, and without prejudice to any other administrative or judicial remedy,
you have the right to lodge a complaint with the Information and Data Protection
Commissioner in Malta if you consider that your personal data has been processed
unlawfully:
Information and Data Protection Commissioner
Level 2, Airways House
High Street
Sliema SLM 1549
Malta
Tel: (+356) 2328 7100
Email:
[email protected]
9.6. Data Portability
You enjoy a right to data portability with respect to your Personal Data held by Hudson and
Hudson hereby binds itself to provide you with the Personal Data concerning yourself which
you have provided to the Hudson, in a structured, commonly used and machine-readable
format. In addition, you enjoy the right to transmit that data to another data controller without
hindrance from Hudson.
9.7. Right to Object
You have the right to object to the processing of your personal data in cases where the legal
basis of such processing is that of legitimate interest. If you choose to do so, Hudson shall no
longer process the personal data unless the it can demonstrate compelling legitimate grounds
for the processing which override the interests, rights and freedoms of the data subject or for
the establishment, exercise or defence of legal claims.
9.8. Right to Withdraw Consent
Where we rely on your consent for processing personal data (such as in the case of marketing,
or when you sign up to get updates about your Hudson Coin), you have the right to withdraw
such consent at any time. Once you withdraw consent, we will stop processing your personal
data.
10. COOKIES AND OTHER TRACKING MECHANISMS
Like most online platforms, Hudson uses cookies to collect information. Cookies are small
data files of letters and numbers that are stored in your browser or the hard drive of your
computer and contain information that is transferred to your computer’s hard drive. We use
cookies on our website to improve its functionality and to allow us to constantly improve the
website. When you continue to browse this website, you are agreeing to our use of cookies.
We use cookies as follows:
TYPE OF COOKIE |
NAME |
FUNCTION |
Persistent/Permanent Cookies |
Permanent cookies |
These cookies are used to remember your login details and passwords, so you won’t need to re-enter them every time you use a site. |
Temporary cookies |
Session cookies |
These help websites recognise users and the information provided when they navigate through a website. Session cookies only retain information about a user’s activities for as long as they are on the website. Once the web browser is closed, the cookies are deleted. |
Analytics |
Google Analytics |
We use this cookie as a third-party service to collect standard internet log information and details of visitors to various parts of the site. This information is only processed in a way which does not identify anyone. We do not make, and do not allow Google to make, any attempt to find the identities of those visiting our website.
Google Privacy Policy:
https://policies.google.com/privacy?hl=en |
Advertising cookies |
META
Pixel |
Tracks user interactions and conversations on
our website to deliver targeted advertisements
on Facebook and Instagram. Data may be
shared with META in line with their privacy
policy.
META Privacy Policy:https://www.facebook.com/privacy/policy/ |
Advertising and performance |
Google
Ads
Tracking |
Tracks ad campaign performance and serves
ads on other websites based on their behaviour
on user behaviour on our site.
Google Privacy Policy:
https://policies.google.com/privacy |
10.1. How to control cookies
To find out more about cookies, including how to see what cookies have been set and how to
manage and delete them, visit www.aboutcookies.org or www.allaboutcookies.org. We
require your consent for non-essential cookies, which is acquired by ticking the pop-up box
upon accessing the website.
Most web browsers today allow you to control cookies through the settings and preferences
of your browser of choice. It is possible for you to disable cookies or set your browser to alert
you when cookies are being sent. The website supports your right to block any unwanted
Internet activity, especially from unscrupulous websites. You can delete all cookies that are
already on your computer, and you can set your browser to prevent them from being placed.
If you do this, however, you may have to manually adjust some preferences every time you
visit a site, and some services and functionalities may not work.
Keep in mind, however, that blocking all cookies or even some of them will have a negative
impact on the usability and rendering of many websites, including our website. If you block
cookies, you will not be able to use all the features on the website and might not be able to
view it correctly in the way it was originally intended to be displayed.
Furthermore, if you wish to change your cookie preferences with regards to our websites,
please
click here.
11. APPLICABLE LAW
The law applicable to the processing of personal data and to this Notice is the General Data
Protection Regulation (EU) 2016/679 (“GDPR”), which came into effect on 25 May 2018, and
the Data Protection Act, Chapter 586 of the Laws of Malta, which transposes the GDPR
into Maltese law. Any future updates to data protection laws within the European Union or
Malta will be applied accordingly.
12. AMENDMENTS
This Privacy Notice is subject to changes. You are invited to familiarize with its content and
visit
this URL frequently to familiarize with the changes.
13. HUDSONMAX LOYALTYSCHEME
Hudson welcomes loyal customers to join its Loyalty Scheme, for which they can redeem
discounts and other privileges. A full list of terms and conditions, can be found
here.