Applicant Privacy Notice

1. Introduction

This Applicant Privacy Notice ("Notice") applies to the Personal Data (as defined below) that the following entities collect about you when you ("Applicant", "you" or "your") apply for employment, jobs and other positions with us: Woven by Toyota U.K. Limited, Woven by Toyota, U.S., Inc., and Woven by Toyota, Inc. (collectively, "Company", "Woven Group", "we", or "us"). The controller of your Personal Data are:

Woven by Toyota U.K. Limited

114-116 Curtain Road, London, United Kingdom, EC2A 3AH

Woven by Toyota, U.S., Inc.

900 Arastradero Rd, Palo Alto, CA, USA 94304

Woven by Toyota, Inc.

Nihonbashi Muromachi Mitsui Tower, 3-2-1 Nihonbashimuromachi, Chuo-ku, Tokyo, JAPAN 103-0022

We encourage you to carefully read this Notice, together with any other privacy notice or policy we may provide on specific occasions, for example when implementing new business elements that involve new uses of your Personal Data.

2. Personal Data about you that we collect and use

We collect and use the general and special categories of Personal Data set forth in Appendix 1 (any and all such data referred to herein as "Personal Data").

3. Legal bases for Personal Data collection and use

We collect and use your Personal Data in accordance with applicable data protection laws. This means that we collect and use Personal Data only for one of the following legal bases:

  • to take steps to enter into a contract with you *

  • to comply with a legal obligation to which we are subject**

  • where it is necessary to serve our legitimate interests (or those of a third party), and your interests and fundamental rights do not override those interests***

  • Legitimate interests means our interest in evaluating your application to determine your suitability for a position with us and to compare you with other applicants in order to make a hiring decision. Where required, we will inform you about other legitimate interests as applicable.

  • where we have your free and explicit consent****

  • We typically do not rely on your consent for use and collection of Personal Data. However, in limited circumstances described below, we may use your consent to allow us to process certain Personal Data. If we do so, we will provide you with full details of the Personal Data that we would like and the reason we need it, so that you can carefully consider whether you wish to freely consent. We will also inform you about the fact that you can revoke your consent at any time and how you can do that. You should be aware that withholding your consent will never have an impact on your employment/engagement with the Company or will otherwise negatively affect you.

This Notice indicates the legal bases applicable to the respective Personal Data collections and usage, as set forth under paragraph 4 below by means of asterisks (*).

4. Purposes for using your Personal Data

Company collects and uses your Personal Data for evaluation and processing of your application and (where permitted by law) the identification of other positions for which you may be qualified, including:

(i) making hiring decisions about your employment/engagement with the Company**/***;

(ii) taking steps to prepare your offer letter and contract of employment, and prepare for your onboarding **;

(iii) complying with applicable laws and regulations **;

(iv) dealing with legal disputes and to establish, exercise and defend (potential) legal claims**/***;

(v) to conduct or evaluate the results of background checks, where permitted by law **/***;

(vi) security criminal record disclosure where required for your role or client contract and authorized by law;****

Please refer to Appendix 1 for a list of (a) general and (b) special categories of Personal Data that we collect and use for the above purposes.

If you do not provide us with your Personal Data, we will not be able to process your application.

5. Retention of your Personal Data

We retain your Personal Data for as long as necessary to satisfy the purpose for which we collected your Personal Data unless a longer period is necessary for our legal obligations or to defend a legal claim. Usually, we retain your application related data for a period of 2 years, unless a shorter period of time is required by law, if you do not become an employee with us. If your application is unsuccessful, we may retain your application data for the purpose of considering you for other roles that become vacant in the future. If you form an employment relationship with us, we typically will maintain your Personal Data throughout the duration of your employment. Company. However, longer statutory retention periods apply to certain records. For example, tax laws require us to retain payroll information for a fixed period of time to meet our tax obligations.

6. Security

We take reasonable steps to ensure that your Personal Data is properly secured using appropriate technical, physical, and organizational measures, so that it is protected against unauthorised or unlawful use, alteration, unauthorised access or disclosure, accidental or wrongful destruction, and loss.

We take steps to limit access to your Personal Data to those persons who need to have access to it for one of the purposes listed in this Notice. Furthermore, we contractually ensure that any third party processing your Personal Data equally provides for confidentiality and integrity of your Personal Data in a secure way.

7. Disclosure and transfer of your Personal Data

For the purposes listed under paragraph 4 above, we share your Personal Data on a need to know basis with colleagues based on their function within Company (both in the country where you work and in other countries in which we have operations, including countries outside the European Economic Area ("EEA"). We also share your Personal Data with vendors and suppliers we use to process data on our behalf; these vendors and suppliers include entities that host our application portal platform and our website, as well as government authorities (competent regulatory authorities, enforcement authorities, other governmental agencies, including taxing authorities).

With your consent, we also may share your Personal Data with our affiliated entities for the purpose of evaluating positions for which you are qualified.

We take measures designed to ensure that your Personal Data is shared and treated securely and in accordance with this Notice and applicable legislation. When transferring Personal Data to entities located in a country outside of the EEA that is not deemed to have an adequate level of data protection, we have executed legally necessary contracts with recipients of your data, including Standard Contractual Clauses as approved by the European Commission or equivalent means. You are entitled to receive a copy of any documentation showing the suitable safeguards that have been taken by making a request via hr-project@woven.toyota.

8. Your rights

Subject to the conditions set forth in the applicable law you have the following rights with regard to our processing of your Personal Data:

Right to access, correct and delete your Personal Data – Company will ensure that all Personal Data is correct. You also have a responsibility to ensure that changes in personal circumstances (for example, change of address, bank account, etc.) are notified to Company so that we can ensure that your Personal Data is up-to-date.

You have the right to request access to any of your Personal Data that Company may hold and to request correction of any inaccurate Personal Data relating to you. You furthermore have the right to request deletion of any irrelevant Personal Data we hold about you.

Right to withdraw consent - In the event your Personal Data is processed on the basis of your consent, you have the right to withdraw consent at any time by sending an email to hr-project@woven.toyota specifying your request, without affecting the lawfulness of processing based on consent before its withdrawal.

Data portability - To the extent that we use your Personal Data for the performance of the employment/engagement contract and that Personal Data is processed by automatic means, you have the right to receive all such Personal Data that you have provided to Company in a structured, commonly used and machine-readable format, and also to require us to transmit it to another data controller where this is technically feasible.

Right to restrict Personal Data use - You have the right to restrict our use of your Personal Data where (i) you contest the accuracy of the Personal Data; (ii) the use is unlawful but you do not want us to erase the Personal Data; (iii) we no longer need the Personal Data for the relevant purposes, but you require it for the establishment, exercise or defense of legal claims; or (iv) you have objected to our Personal Data use justified on our legitimate interests pending verification as to whether Company has indeed compelling interests to continue the relevant Personal Data use.

Right to object- To the extent that we are relying on our legitimate interests to use your Personal Data, you have the right to object to such use, and we must stop such processing unless we can either demonstrate compelling legitimate grounds for the use that override your interests, rights and freedoms or where we need to process the Personal Data for the establishment, exercise or defense of legal claims.

Lodge a complaint - You also have the right to lodge a complaint with a supervisory authority, in particular in your country of residence, if you consider that the collection and use of your Personal Data infringes this Notice or applicable law.

For further information regarding your rights, or to exercise any of your rights, please contact hr-project@woven.toyota.

9. Contact us

If you have any questions or concerns regarding our use of your Personal Data, please contact hr-project@woven.toyota.

10. Publication

This Notice will be published at the application portal.

Appendix 1: Personal Data that we collect and use

Section a - general categories of Personal Data

To the extent permitted under applicable law, we collect the following types of Personal Data from applicants:

  • Personal details - personal (contact) details such as your name, address, email address, telephone number or other contact information, degree/title, date of birth, gender;

  • Professional qualifications - professional certifications, special skills including (driver) licenses, language skills, memberships of committees or other bodies, education history;

  • Management records - details of any shares of common stock or directorships

  • Recruitment or selection data - any personal data contained in your CV, resumes and application form, references, record of interview or interview notes, and selection and verification records, previous (job) experience and references;

  • Training and development data - such as data relating to training and development needs or trainings received;

  • Any other personal data which you choose to disclose to Company during the course of your application

Section b - special categories of Personal Data

To the extent permitted under applicable law, we collect the following types of special categories of Personal Data: information pertaining to the commission or alleged commission by you of any offence; and any proceedings for any offence committed or alleged to have been committed by you, the disposal of those proceedings or the sentence of any court in those proceedings;

Kindly be informed that special categories of Personal Data will only be collected and used in so far as such is necessary for the purposes of carrying out an obligation under labor, social security, and social protection laws or when the use is authorized by European Union, Member State, of United Kingdom law providing for appropriate safeguards for the rights and freedoms of our Applicants.

Applicant Notice for United States Applicants for Positions with: Woven by Toyota U.K. Limited, Woven by Toyota, U.S., Inc., or Woven by Toyota, Inc. (collectively "Woven Group", "Company,", "our", "we", or "us")

PURPOSE OF THIS NOTICE: In this Applicant Privacy Notice ("Notice"), we describe our collection and use of certain personal information relating to your (referred to as "you", "Applicant", or "Applicants") application for employment with us. If you are a California resident, this Notice is intended to satisfy our obligation to provide notice to under the California Consumer Privacy Act ("CCPA").

SCOPE OF THIS NOTICE: This Applicant Notice applies to the personal information that we collect from you , in the context of reviewing, assessing, considering, managing, storing or processing your application or otherwise considering you for a position with us. This Applicant Notice does not apply to our collection of personal information such as consumer credit reports and background checks, publicly available data lawfully made available from state or federal government records, or other information that is exempt under the CCPA. This Applicant Notice also does not apply to the personal information we collect from employees (which is subject to a separate privacy notice). We may provide Applicants additional notices about our data collection practices that are covered by other laws (e.g., if we conduct a background check or extend an employment offer).

What is personal information? In this Applicant Notice, "personal information" is any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household.

Are our practices the same for all Applicants? The categories of personal information we collect and our use of personal information may vary depending on the position(s) or location, as well as the associated qualifications and responsibilities. The information in this Applicant Notice is intended to provide an overall description of our collection and use of personal information about Applicants.

CATEGORIES OF PERSONAL INFORMATION COLLECTED: Generally, we may collect the following categories of personal information about Applicants:

Name, Contact Info and other Identifiers. Identifiers such as a real name, alias, postal address, unique personal identifier, online identifiers, Internet Protocol address, email address, account name, or other similar identifiers.

Protected Classifications. You have the option of providing characteristics of protected classifications under California or federal law such as race, color, sex, sexual orientation, gender identity, age, religion, national origin, disability, citizenship status, military/veteran status, marital status, medical condition, and pregnancy.

Audio, Video and other Electronic Data. Audio, electronic, visual, thermal, olfactory, or similar information such as, CCTV footage, photographs, and call recordings and other audio recordings (e.g., recorded meetings and webinars). We may conduct interviews via phone, video, or other electronic recording (e.g., via Zoom). We may record all or a portion of the interview. If you conduct an in-person on premise interview, we may capture CCTV footage of you in those locations where we have CCTV cameras.

Employment History. Professional or employment-related information.

Education Information. Information about education history or background that is not publicly available personally identifiable information as defined in the federal Family Educational Rights and Privacy Act (20 U.S.C. section 1232g, 34 C.F.R. Part 99).

Profiles and Inferences. For certain positions, we may ask you to complete an assessment (e.g., a coding task). From these assessments, we may draw inferences and/or create a profile about your ability to complete certain tasks, overall abilities, aptitudes, characteristics, preferences, predispositions, behavior, and intelligence.

PURPOSES FOR COLLECTING AND USING PERSONAL INFORMATION: Generally, we may use the above categories of personal information for the following purposes:

Recruiting, Hiring and Managing, and Evaluating Applicants. To review, assess, recruit, consider or otherwise manage Applicants and job applications, including:

- Scheduling and conducting interviews

- Identifying Applicants, including by working with external recruiters

- Reviewing, assessing and verifying information provided, to conduct criminal and background checks (where relevant and pursuant to applicable law), and to otherwise screen or evaluate Applicants’ qualifications, suitability and relevant characteristics

- Extending offers, negotiating the terms of offers, and assessing salary and compensation matters

- Satisfying legal and regulatory obligations

- Communicating with Applicants regarding their applications and about other similar position(s) for which they may be interested, including positions with affiliated entities (we also may share your information with our affiliates so that they can evaluate whether you would be a good fit for a position), as permitted by law

- Maintaining Applicant personal information for future consideration, as permitted by law

- Supporting our equal opportunity employment policy and practices

Security and Monitoring. In order to monitor and secure our resources, network, premises and assets, including:

- Monitoring for, preventing and investigating suspected or alleged misconduct or violations of work rules

- Monitoring for, preventing, investigating and responding to security and privacy incidents

- Providing and managing access to physical and technical access controls

- Monitoring activities, access and use to ensure the security and functioning of our systems and assets

- Securing our offices, premises and physical assets, including through the use of electronic access systems and video monitoring

Auditing, Accounting and Corporate Governance. Relating to financial, tax and accounting audits, and audits and assessments of our business operations, security controls, financial controls, or compliance with legal obligations, and for other internal business purposes such as administration of our records retention program.

M&A and Other Business Transactions. For purposes of planning, due diligence and implementation of commercial transactions (e.g., mergers, acquisitions, asset sales or transfers, bankruptcy or reorganization or other similar business transactions).

Defending and Protecting Rights. In order to protect and defend our rights and interests and those of third parties, including to manage and respond to legal claims or disputes, and to otherwise establish, defend or protect our rights or interests, or the rights, interests, health or safety of others, including in the context of anticipated or actual litigation with third parties.

Compliance with Applicable Legal Obligations. Relating to compliance with applicable legal obligations (such as hiring eligibility, responding to subpoenas and court orders) as well as assessments, reviews and reporting relating to such legal obligations, including under employment and labor laws and regulations, social security and tax laws, environmental regulations, workplace safety laws and regulations, and other applicable laws, regulations, opinions and guidance.

Other Business and Commercial Purposes. In addition, we may use the personal information we collect about you for the following purposes: surveys – we want to know about your experience during the application process; we also may provide a gift card and/or donation for participating in certain aptitude tests.

CONTACTING US ABOUT THIS NOTICE: If you have any questions or concerns regarding our use of personal information as described in this Applicant Notice, please contact hr-project@woven.toyota.