PRIVACY STATEMENT FOR HR DATA

1. INTRODUCTION

This Privacy Statement is applicable to the processing by Pinnacle Propane, Pinnacle Propane Express, and Alliant Gas (headquarter at 600 E. Las Colinas Blvd. Suite 2000 Irving, TX 75039] (hereafter referred collectively as “Pinnacle”, “we” or “us”) of all personal data related to our Employees . For purposes of this Privacy Statement, the term “Employees” includes employees, job applicants, temporary workers under our direct supervision (e.g. independent contractors and trainees), former employees, former executives or non-executive directors, and former members of the supervisory board or similar body to Pinnacle.

For purposes of applicable data laws, Pinnacle is the data controller for the processing of Employees’ personal data. In this statement, we describe how and for which purposes we process your personal data. In case you have any additional questions you can contact us via the contact details provided at the bottom of this statement.

This Privacy Statement applies since May 25, 2018. This statement is version 1.0 and the most recent modifications were made on May 25, 2018 This statement may change over time and the most up-to-date version is published on our website or available through the HR department. If significant changes are being made during your employment or application process, we will actively inform you.

2. JOB APPLICANTS: FOR WHICH PURPOSES DO WE PROCESS YOUR PERSONAL DATA?

A. To communicate with you regarding your employment or job application

If you have shown interest in a position within Pinnacle, we store your personal data in our relevant recruitment systems. We use the data in our systems to communicate with you and to determine whether your qualifications and profile meet the requirements of a specific vacancy.

For this purpose

  • we process your personal data on the basis of your consent when you provide us with your personal data
  • we process your contact details, recruitment information (such as your resume, employment history, education history etc.) and correspondence with us with regard to job applications (including references)

B. To answer your questions

If you get in touch with us, we will use your personal data in order to reply and answer your question(s).

For this purpose

  • we process your personal data on the basis of your consent
  • we process your name, contact details, your correspondence with us with regard to your question and all other personal data, which are necessary to answer your question(s)

C. To assess and evaluate you during the recruitment procedure

During the recruitment procedure, screening (for example in the form of a skills assessment) may be part of the procedure.

For this purpose

  • we process your personal data on the basis of our legitimate interest that overrides your interests. It is in our interest to select applicants which qualifications and profile meets the requirements of a specific vacancy with Pinnacle
  • we process your contact details, diversity data, date of birth, gender, civil status, birth certificate, photo identification, employment authorization, citizenship card, and social security number

D. To enter into an at will employment agreement with you

If we offer you a position at Pinnacle, we will process your personal data to prepare and process an offer of employment. We use your personal data for the conclusion, execution and termination of your at will employment agreement. We will then also store your personal data in our HR systems.

For this purpose

  • we process your personal data because it is necessary for entering into an at will employment agreement with you
  • we process your contact details, date of birth, gender, civil status, nationality, citizen service number, ID card or passport details, declaration of employment status, chamber of commerce and VAT details, recruitment information (such as employment history, education history details), job and position data, work permit details, availability, terms of employment, tax details, payment details, insurance details and location and organizations

E. Social networks, such as LinkedIn, and other publicly available websites

We may collect your personal data from public profiles on LinkedIn or other social networks and other publicly available websites if you reacted to Pinnacle recruitment initiatives on such social networks and websites, or signed up via integrated functionality of such social networks, recruitment websites or our own websites. We also may collect your personal data from such sources when you provide a link to your profile on any such site as part of your job application or resume/CV submitted with your job application.

We may also obtain your contact details from publicly available sources, including content that you have made public on LinkedIn or other social network sites or similar sites for professional purposes to make an initial contact with you for recruitment purposes. We will contact you if you have made your contact details available to Pinnacle for recruitment purposes and will provide you with clear option to ask us to stop contacting you for career opportunities and remove your personal data from our systems.

For this purpose

  • we process your personal data based on our legitimate interest and to find suitable candidates for vacancies at Pinnacle
  • we process the personal data you have made public through your public profiles on LinkedIn or other social networks and any correspondence between you and our recruiters. This includes your name, contact details if made available, current and past job titles, employment history, educational information, skills, recommendations, and resume/CV if you made it available

F. To protect your vital interests

When it is necessary to process your personal data to protect your vital interests, we will do so. This could, for example, be the case when you have a physical disability or medical condition that we need to be aware of when you are visiting us at our premises.

For this purpose

  • we process your personal data to protect your vital interest and if it is necessary to avoid a risk of injury or other damage to your health
  • we process your contact details, the contact details of your emergency contact, the location of your Company site and the relevant health data that you provided to us

G. To inform you and communicate with you about other vacancies

Sometimes, we just do not have the right role available for you yet. If you choose, we will keep information about you in our systems and contact you if we have a new vacancy that may be of interest to you. We may also invite you for recruitment activities or communicate with you about job opportunities.

For this purpose

  • we will process your personal data based on your consent when you choose to keep your information in our systems
  • we process your contact details (such as your address and email address), the information you submitted to us in the course of previous job applications (for example, your resume) and a summary of how you performed during previous job applications with us

H. To comply with the law

In some cases, Pinnacle processes your personal data to comply with the laws and regulations in the country where you applied. For example, human resources related obligations, employment laws, anti-discrimination laws or regulations related to subsidies. Following laws and regulations, we may need to disclose your personal data to government institutions or supervisory authorities.

For this purpose

  • we process your personal data to comply with the law and if there is a legal obligation for us to do so
  • we process your contact details, diversity data, date of birth, gender, civil status, birth certificate, photo identification, employment authorization or citizenship card

3. OTHER EMPLOYEES: FOR WHICH PURPOSES DO WE PROCESS YOUR PERSONAL DATA?

Pinnacle will process your personal data for the execution of your at will employment agreement. The processing will follow under one (or more) of the following business purposes:

A. Human resources, personnel management and payroll administration.

We process your personal data for human resources and personnel management and to manage your personnel file. This includes processing your personal data for your performance reviews, outplacements, leave and other absences, pension details, travel and expenses and our communications with you. We may also have to process your personal data following laws and regulations. This is, for example, the case for identification, fraud prevention, internal controls and company security. If you are an expat, we will also process your personal details for any tax related issues. Further, we process your personal data for payroll administration. We do not only maintain an administration of your salary payments, but also of your hours and overtime, bonuses and other compensation or benefits.

For this purpose

  • we process your personal data to perform the at will employment agreement we have with you, and to comply with a legal obligation
  • we process your contact details, date of birth, gender, civil status, nationality, photographs, videos, citizen service number, ID card or passport details, declaration of employment status, chamber of commerce and VAT details, recruitment information (such as employment history, education history details), job and position data, work permit details, availability, terms of employment, tax details, payment details, hours worked, personnel file details, insurance details, location and organizations, beneficiaries and dependants, account/profile data (corporate ICT-systems), data generated during the performance of the employment contract and correspondence with Pinnacle with regard to job applications, including references, absence and leave information

B. Business process execution and internal management.

When you work at Pinnacle, we will process your personal data in the performance and organization of our business. This includes general management, scheduling work, recording worked time, electing members of Pinnacle participation body, the administration of the staff association and managing our and employee assets. We process your personal data for internal management. For example, we provide central processing facilities in order to work more efficiently. We conduct audits and investigations, implement business controls and manage and use employee directories. Also, we process your personal data for archiving and insurance purposes, legal and business consulting and in the context of dispute resolution.

For this purpose

  • we process personal data based on our legitimate interest to maintain and improve sound business operations
  • we process your contact details, date of birth, gender, job and position, availability, hours worked, insurance details, location and organizations, beneficiaries and dependants and data generated during the performance of the employment contract

C. Health, safety, security and integrity.

At Pinnacle, we highly value health, safety, security and integrity. In order to safeguard our employees and customers, we process your personal data. We screen and monitor our employees both before and while they are employed at Pinnacle and authenticate your employee status and access rights. We also process your personal data to ensure occupational health and safety and to protect our and employee and customer assets.

For this purpose

  • we may process your personal data based on our legitimate interest to monitor our internal processes and in order to comply with the law
  • we process your contact details, relevant personnel file details, insurance details, location and organizations and the relevant health data that you provided to us

D. Organizational analysis and development, management reporting and acquisition and divestitures.

At Pinnacle, we process your personal data to be able to prepare and perform management reporting and analysis. For example, we conduct employee surveys to learn more about your views and opinions in preparation of our management reporting. We also process your personal data in the context of mergers, acquisitions and divestitures and in order to manage such transactions.

For this purpose

  • We process personal data based on our legitimate interest to maintain and improve sound business operations
  • we process your contact details, date of birth, gender, job and position, terms of employment, insurance details, location and organizations, beneficiaries and dependants and relevant data generated during the performance of the employment contract

E. Compliance with law.

In some cases, we process your personal data to comply with laws and regulations. This could be the case for human resources related obligations. We may, for example, also need to process your personal data in light of subsidies or tax regulations. Following laws and regulations, we may need to disclose your personal data to government institutions or supervisory authorities.

For this purpose

  • we process these personal data to comply with a legal obligation imposed on us
  • we process your contact details, date of birth, gender, civil status, nationality, citizen service number, ID card or passport details, declaration of employment status, chamber of commerce and VAT details, job and position, work permit details, terms of employment, tax details, payment details and location and organizations

F. To monitor and investigate compliance.

We monitor employee accounts to check compliance with our policies and regulations. We also monitor your use of our networks, systems and information to observe compliance with its policies. We do so irrespective of whether you use Pinnacle IT devices or your own devices to access or use Pinnacle’s information, network or systems.
If an employee is suspected of behaviour or actions that are not compliant with our policies and regulations, Pinnacle could conduct an internal investigation, generate, and process additional personal data. We could, for example, conduct such an investigation in the case of a prohibited transfer of any of Pinnacle’s trade secrets, confidential information, intellectual property or knowhow, fraud or if we suspect an employee to be the origin of any virus, spam or intrusion in our systems or network.

For this purpose

  • we process your personal data based on our legitimate interest to monitor our internal processes and in order to comply with the law
  • we process account/profile data (corporate ICT-systems), such as the time and date of your logins, the type of information and files shared, the search queries that are made and the type of device you use, the mobile number of your device, IP addresses, MAC addresses, documents accessed and duration of access, mobile network information, your mobile operating system and which mobile browser you use, your time zone settings and device details
  • we do not retain your personal data for this purpose, unless they are linked to non-compliant behaviour. We will then retain the relevant personal data until the investigation or proceedings have been concluded

G. Protecting the vital interests of Employees.

When it is necessary to process your personal data to protect your vital interests, we will do so. This could, for example, be the case when you have a medical condition that your colleagues or superiors need to be aware of.

For this purpose

  • we process your personal data to protect your vital interest and we will process your personal data if it is necessary to avoid a risk of injury or other damage to your health
  • we process your contact details, relevant personnel file details, insurance details, location and organizations and the relevant health data that you provided to us

H. To offer you suitable opportunities for your development.

We use the information stored in our HR systems to offer you suitable opportunities for development. This way, we are able to offer you the right training, education, coaching or other forms of careers guidance or personal development to suit your needs. We also use your personal data for general career and talent development.

For this purpose

  • we process your personal data to perform the employment contract we have with you
  • we process your contact details, recruitment information (such as employment history, education history details), job and position data, location and organizations, data generated during the performance of the employment contract, correspondence with Pinnacle with regard to job applications (including references, absence and leave information)

I. To allow you to perform your tasks in the regular course of business.

When you work at Pinnacle, you use our systems and networks in the regular course of business. You will send emails, search the web and make phone calls. When you do so, we process your personal data included in such documents or in the meta data attached to such documents. For example, when you send an email, we process your contact details, your profile information.

For this purpose

  • we process your personal data to perform the at will employment agreement we have with you
  • we process your contact details, date of birth, gender, job and position data, account/profile data (corporate ICT-systems), content and traffic data (such as your internet communications, sent and received email messages, printed documents, storage devices) and data on back-ups

4. HOW LONG DO WE RETAIN YOUR PERSONAL DATA?

Pinnacle generally shall retain Employee personal data only for the period required to serve the applicable business purpose, to the extent reasonably necessary to comply with an applicable legal requirement, or as advisable in light of an applicable statute of limitations.

Promptly after the applicable storage period has ended, the data shall be:

  1. securely deleted or destroyed;
  2. anonymized; or
  3. transferred to an archive (unless this is prohibited by law or an applicable records retention schedule)

5. WHO HAS ACCESS TO YOUR PERSONAL DATA?

Before Employment – Job Applicants:

The employees involved in the relevant recruitment procedure may have access to your personal data, be it only to the extent necessary to fulfill their respective tasks. These employees are for example our recruiters, HR employees and the relevant manager. Your personal data may be accessed by other relevant departments within Pinnacle such as IT, Legal and Compliance, to the extent necessary to fulfill their respective tasks. In some cases, your personal data may be transferred to a country that does not provide an adequate level of protection of personal data. However, Pinnacle has taken measures to ensure that your personal data is adequately protected as Binding Corporate Rules are applicable throughout the group that Pinnacle belongs to.

The following third parties may have access to your personal data where relevant for the provisioning of their products or services to Pinnacle: recruitment agencies, assessment center, IT suppliers, employment screenings agencies, and medical consultant services. When third parties are given access to your personal data, Pinnacle will take the required contractual, technical and organizational measures to ensure that your personal data are only processed to the extent that such processing is necessary. The third parties will only process your personal data in accordance with applicable law. Your personal data will not be supplied to third parties except as set forth above or when required by law.

During Employment – Current Employees:

All our employees have access to your Pinnacle profile and the data you have made publicly available there. When yu send data to other recipients, e.g., when you send a customer an email, this recipient will also receive personal data included in such data as a result. These data will be available on a need to know basis within Pinnacle. Non-public data can be accessed by relevant departments within Pinnacle such as IT, HR, Legal, IT Security, Ethics & Compliance, but only to the extent necessary to fulfill their respective tasks.

The following types of third parties have access to your personal data where relevant for the provisioning of their products or services to Pinnacle: banks, insurance companies, credit card companies, IT suppliers and consultants, travel agencies, embassy, financial, tax or legal advisors, clients, accountants, lease companies, inspection authorities, medical inspection authorities, forensic specialists, training centers, facility services, delivery services of packages and letters, please list other categories of third parties here. When third parties are given access to your personal data, Pinnacle will take the required contractual, technical and organizational measures to ensure that your personal data are only processed to the extent that such processing is necessary. The third parties will only process your personal data in accordance with applicable law. Your personal data will not be supplied to third parties except as set forth above or when required by law.

6. EU AND SWISS RESIDENTS

Pinnacle is based in the United States, and personal data collected by us worldwide (including within the EU and Switzerland) may be transferred to the United States for processing. We commit to resolve complaints about our collection or use of your personal data. European Union and Swiss individuals with inquiries or complaints regarding our data practices should first contact us at:

Email: privacy@pinnaclepropane.com

Mail: Pinnacle Propane, LLC
Attn: Privacy Officer
600 E. Las Colinas Blvd.
Suite 2000
Irving, TX 75039

If a complaint is not resolved by other resource, then EU and Swiss individuals may request binding arbitration.

Pinnacle is a member of the SHV company group. SHV Energy, N.V. has established binding corporate rules across the SHV group to govern the transfer of EU personal data between members.

7. HOW IS YOUR PERSONAL DATA SECURED?

We have taken adequate safeguards to ensure the confidentiality and security of your personal data. We have implemented appropriate technical, physical and organizational measures to protect personal data against accidental or unlawful destruction or accidental loss, damage, alteration, unauthorised disclosure or access, and against all other forms of unlawful processing (including, but not limited to unnecessary collection) or further processing.

8. HOW CAN YOU EXERCISE YOUR PRIVACY RIGHTS?

You have the right to request access or an overview of your personal data, and under certain conditions, rectification and/or erasure of personal data. In addition, you may also have the right of restriction of processing concerning your personal data, the right to object to processing as well as the right to data portability.

To invoke your privacy rights, please contact us by using the contact details at the bottom of this Privacy Statement. Keep in mind that we may ask for additional information to verify your identity.

9. CAN YOU WITHDRAW YOUR CONSENT?

Employee consent generally cannot be used as a legitimate basis for processing personal data of employees. However, under certain specific requirements, for example if applicable law requires so, Employee consent may be obtained. Once given, you may always withdraw your consent. Please keep in mind that withdrawal does not have retrospective effect and the withdrawal of your consent is only possible in case you first have given your consent. Please contact us to withdraw your consent by using the contact details at the bottom of this Privacy Statement.

10. HOW TO LODGE A COMPLAINT?

If you have a complaint about the use of your personal data by Pinnacle, you can lodge a complaint via your line manager (if applicable) or the contact details at the bottom of this statement. Besides lodging a complaint with Pinnacle, you are also able to lodge a complaint with your local data protection supervisory authority.

11. HOW CAN YOU CONTACT US?

If you have any questions about the way we process your personal data, please read this statement first. For additional questions, remarks, compliments or complaints, please contact Pinnacle at 600 E. Las Colinas Blvd., Suite 2000 Irving, TX 75039 or e-mail privacy@pinnaclepropane.com.