Candidate Data Privacy Policy

Candidate Data Privacy Policy

Introduction

This Privacy Notice for the Bicycle Therapeutics group sets out the categories of your personal data we collect, how we collect it, what we use it for and with whom we share it, in accordance with applicable data protection legislation, including the General Data Protection Regulation (EU) 2016/679 as it forms part of United Kingdom law by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as subsequently amended (the UK GDPR).

By personal data we mean any information relating to you such as your name, contact details. Personal data does not include data which has been anonymised, such as data from equal opportunities monitoring carried out on an anonymised basis.

If your application is for a job based in the UK, BicycleTx Limited will be the data controller in respect of the processing of your personal data and in this Privacy Notice “Bicycle”, “we”, “us” or “our” refers to Bicycle Tx Limited.

If your application is for a job based in the US, Bicycle Therapeutics, Inc. will be the data controller in respect of the processing of your personal data and in this Privacy Notice “Bicycle”, “we”, “us” or “our” refers to Bicycle Therapeutics, Inc.

The data controller is responsible for deciding how personal data about you is used.

Should you have any questions about this Privacy Notice you can contact us using the details set out in the ‘Contact Us’ section below.

This Privacy Notice applies to personal data about you that we collect, use and otherwise process in connection with our recruitment, and if applicable, our offer and on-boarding processes. We do not require you to provide any special categories of personal data (as defined below), other than as set out below. We would recommend that you do not include any additional special categories of personal data in your application as it is unlikely to be relevant to the application process.

Bicycle US’s Representative in the UK

Bicycle Therapeutics, Inc’s UK representative under the UK GDPR is BicycleTX Limited. You can contact them by email and/or postal mail by using the contact details provided below.

How Do We Collect Information About You And What Do We Use It For?

We set out below the types of personal data about you which we may collect or create at each stage of the recruitment process. In each case we have specified the purpose for which we use the relevant personal data and our ‘lawful basis’ for processing it. The law specifies certain ‘lawful bases’ for which we are allowed to use your personal data. Most commonly, we will rely on one or more of the following lawful bases for processing your personal data:

Where relevant, we have considered whether the interests or fundamental rights and freedoms of our recruitment candidates override our legitimate interests and have formed the view that they do not. We will review this position where relevant.

Application and assessment process

In connection with assessing your application we process the following categories of personal data (see also the section entitled ‘Special categories of personal data’ below):

We may use your name and contact details to contact you in connection with your application, such as to invite you to undertake further assessments or to make you an offer of employment and/or if you choose to opt-in to receive text message updates relating to the progress of your application. We have a legitimate interest in providing you with a solution to allow you to stay up-to-date on the progress of your application, facilitating the interview process and communicating offers of employment to you (as and where applicable).

We may use the information we collect as part of the application and assessment process and the information that we create ourselves in connection with the assessment of your application for the purpose of assessing your suitability for the role for which you have applied. We have a legitimate interest in making informed recruitment decisions and selecting suitable candidates for roles with us.

If your application is successful

If your application is successful we will collect further personal data about you as set out below (see also the section entitled ‘Special categories of personal data’ below):

Special Categories Of Personal Data

There are more limited bases for processing special category personal data. This is personal data which reveals or contains:

We will process special category personal data where we have a lawful basis for doing so, which will apply where:

However, we may also process special category data because: it is necessary in relation to legal claims; or, in limited circumstances, you have given explicit consent.

The special categories of data about you which we may collect, store and use are set out in the table below and in each case we have specified the purpose and our ‘lawful basis’ for processing it.

Category of special categories of personal data Examples Purpose Lawful basis for processing
Medical/health information as part of the application process. Data concerning health may include your body temperature, health symptoms and other screening information. Information re any mental or physical impairment which may cause a disadvantage to you during the recruitment process. Health information in connection with the Company’s health and safety plans and protocols, including screening required to access Company offices/facilities and other measures designed to prevent the transmission of COVID-19 or other infectious diseases. To enable us to make any appropriate reasonable adjustments Compliance with a legal obligation/employment law obligations
Diversity and inclusion information (if you choose to provide it).

(Please note: submission of this information is entirely voluntary)

All candidates – information revealing your racial or ethnic origin and/or gender identity.

Just candidates for roles with Bicycle Therapeutics, Inc. – information relating to disability status and/or veteran status.

In all cases, we aggregate this diversity and inclusion information such that it no longer identifies you directly.

Bicycle has chosen to collect this information on a voluntary basis to enable us to help evaluate the effectiveness of our diversity outreach recruitment programmes as part of our internal equal opportunities reporting Public interest / substantial public interest
Immigration information (successful candidates only) Passport, visa, work permit To demonstrate right to work in the UK Compliance with a legal obligation/employment law obligations
Medical/health information (successful candidates only) Pre-employment provision of medical information To ascertain medical information that may be relevant to the role and/or the need for any reasonable adjustments Necessary for performance of contract/compliance with a legal obligation & employment law obligation/working capacity

What If You Do Not Provide The Personal Data We Request?

If you do not provide us with certain information when requested, it may impact our ability to assess your suitability for a role with us or we may not be able to make you an offer of employment.

However, we do not discriminate on the basis of any ‘diversity and inclusion information’ you may choose to provide, nor on the basis that you choose not to provide that information – neither will inform our assessment of your suitability for a role, nor whether we ultimately choose to make you an offer of employment.

Change Of Purpose

We will only use your personal data for the purposes for which we collected it (as identified above), unless we reasonably consider that we need to use it for another reason which is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

In some circumstances we may anonymise your personal data so that it can no longer be associated with you, in which case it is no longer personal data.

With Whom Will We Share Your Information?

We may share your personal data with third parties where this is required by law, where it is necessary to perform our contract with you, or where we have another legitimate interest in doing so.

Other members of our corporate group

We are part of a group of companies (the “Bicycle Therapeutics Group”) that includes Bicycle Therapeutics Limited, BicycleTx Limited, BicycleRD Limited and Bicycle Therapeutics, Inc.

Certain functions of the Bicycle Therapeutics Group are centralised and conducted by members of the Bicycle Therapeutics Group other than us. We have a legitimate interest in benefiting from such centralisation and the services provided to us (as our data processor) by other members of the Bicycle Therapeutics Group. For example, other members of the Bicycle Therapeutics Group may assist in the recruitment process and may receive personal data in connection with such assistance.

We may also share your personal data with other entities in the Bicycle Therapeutics Group in the context of a business reorganisation or group restructuring exercise, for system maintenance support and for hosting of data.

Our service providers

We share personal data with Bicycle Therapeutics Group’s third-party service providers that perform services and functions at our direction and on our behalf. Our service providers are our IT service providers, our recruitment service providers and our lawyers. We rely on service providers in order to effectively operate our business.

Third party companies associated with a sale or acquisition of the business

In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets

If all or any of our group companies or substantially all of their assets are acquired by a third party, in which case personal data may be one of the transferred assets.

Other third parties

We may need to share your personal data with a regulator or to otherwise comply with applicable law or judicial process. We may disclose your personal data if we are required by law to do so or if we reasonably believe that disclosure is necessary to protect our rights and/or to comply with judicial or regulatory proceedings, a court order or another legal process. We may share your personal data where this is required by law, where it is necessary to perform our contract with you, or where we have another legitimate interest in doing so.

Processing Of Your Personal Data Outside The EEA

Certain of the parties with whom we may share your personal data (see the section immediately above) may be located outside the UK – for example, but without limitation, this will be relevant in respect of the following:

A number of the countries in which recipients of your personal data are based may be countries in respect of which there is not an adequacy decision issued by the UK Government under the UK GDPR – what this means is that the country to which we transfer your data has not been deemed to provide an adequate level of protection for your personal data for the purposes of the UK GDPR.

However, in these cases:

If you want further information on the specific mechanism used by us when transferring your personal data out of the UK, please contact our Privacy Coordinator (privacy@bicycletx.com).

Where We Store Your Personal Data

The Bicycle Therapeutics Group has operations in the USA and in the UK. However, whenever it is being processed within the Bicycle Therapeutics Group, all personal data you provide to us will be stored on servers, which are provided and maintained by our processors, and which are located in the UK.

If members of the Bicycle Therapeutics Group located in the USA have access to information stored on servers in the UK, this will amount to a transfer of your personal data. However, as noted above, we have put in place Standard Contractual Clauses to ensure that appropriate safeguards are in place in respect of personal data that is transferred from members of the Bicycle Therapeutics Group in the UK to members of the Bicycle Therapeutics Group outside of the UK (such as Bicycle Therapeutics, Inc. who is located in the USA).

To establish additional practical safeguards for protection of your personal data, when transferring your information outside of the UK as part of the intragroup transfers described in this section, the transfer is made using an encrypted channel.

Once we have received your information, we will use appropriate technical and organizational measures to prevent unauthorised access, disclosure, loss or damage to your personal data.

How Long Will We Retain Your Information?

We will only retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting or reporting requirements.

If you are successful in your application, we will retain the majority of the categories of personal data set out above for the duration of your working relationship with us and for a reasonable period of time after its termination as described in our employee privacy policy which will be made available to you once you become an employee. If you are unsuccessful in your application, we will retain the majority of the categories of personal data set out above for a reasonable period of time (no longer than twelve months) after the recruitment process has ended unless you have consented to us keeping it longer.

In some circumstances we may anonymise your personal data so that it can no longer be associated with you, in which case it is no longer personal data.

Once we no longer require your personal data for the purposes for which it is processed, we will securely destroy your personal data in accordance with applicable laws and regulations and in accordance with our records retention policy.

Accuracy Of Information

It is important that the personal data we hold about you is accurate and current. Please let us know if your personal data changes during the recruitment process.

Your Rights In Relation To Your Information

Where the processing of your personal data is subject to the UK GDPR, you have rights as an individual which you can exercise in relation to the information we hold about you under certain circumstances. These rights are to:

If you want to exercise one of these rights please contact using the contact details set out below.

If you do not, or no longer, wish to receive text message updates relating to your application, you can message ‘STOP’ in reply to one of these messages and you will be opted-out.

You also have the right to make a complaint at any time to the UK data protection regulator, the UK Information Commissioner’s Office – whose contact information is below:

The Information Commissioner’s Office
Water Lane, Wycliffe House
Wilmslow – Cheshire SK9 5AF
Tel. +44 303 123 1113
Website: ico.org.uk/make-a-complaint/

Fees

You will not usually have to pay a fee to access your personal data (or to exercise any of your other rights). However, we may charge a reasonable fee if your request for access is manifestly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is to ensure that personal data is not disclosed to any person who has no right to receive it.

Further Information

This Privacy Notice was written with brevity and clarity in mind and is not an exhaustive account of all aspects of our collection and use of personal data.  If you require any further information, please do not hesitate to contact us.

Contact Us

Bicycle Tx Limited

privacy@bicycletx.com

BicycleTX Limited; Attention GC
B900, Babraham Research Campus
Cambridge, UK
CB22 3AT

Bicycle Therapeutics, Inc.

privacy@bicycletx.com

Bicycle Therapeutics Inc; Attention: Office Manager
4 Hartwell Place
Lexington, MA
02421-3122
USA