Privacy policy

1. Information about our company

Eraneos Netherlands B.V. (hereinafter “we/us,” “our,” “the service,” or “Eraneos”) is a global management and technology consulting firm with its registered office in Amsterdam, the Netherlands. Eraneos acts in the capacity of “controller” of your personal data when you use the website https://www.eraneos.com This link opens in a new tab or any other Eraneos domain or subdomain (hereinafter “the website”), purchase services or products from us, are in contact with us, communicate with us, or otherwise work with us, and is therefore responsible for the processing of your data in this context.

If you have any questions or comments about this document or about the processing of your personal data, you can contact:

Eraneos Netherlands B.V.
De Passage 126-136
1101 AX Amsterdam
+31 20 305 3700
Email: privacy.nl@eraneos.com

This Data Protection Statement is aligned with the EU General Data Protection Regulation (“GDPR”), the Swiss Data Protection Act (“DPA”) and the revised Swiss Data Protection Act (“revDPA”) as well as the California Consumer Privacy Act (“CCPA”). However, the application of these laws depends on each individual case.

In this document we utilize the terms ‘personal data and ‘personal information’ interchangeably.

In light of our ongoing efforts to improve the protection of personal data, this Privacy Statement explains how we process personal data and which principles we apply with respect to the transfer of personal data from the EEA to the United States and other countries outside the EEA.

We reserve the right to amend and update this Privacy Statement from time to time at our sole discretion and without prior notice. For that reason, we advise you to review the Privacy Statement each time you visit our websites: the version posted there is the current and applicable one. If the Privacy Statement forms part of an agreement concluded with you, we will notify you of any changes by email or by other appropriate means.

2. Note for California, based visitors

If you are from California, the CCPA is applicable. We enforce high privacy standards that are based on EU privacy principles, including purpose limitation and lawfulness of processing, choice (consent), security and transparency. You will find information on the purposes of processing, the data types, recipients etc. further below in the document. Please rest assured we do not sell your data.

3. Data we process and activities we perform

It is important to know that, in general, you can visit our websites without providing any personal data about yourself.

In certain cases, for example, to give you access to specific parts of our websites, to provide you with a better user experience on our websites, or if you wish to request specific information or services, we need to collect personal data from you, which we then process for the purposes described below.

Subject to your prior consent, we may also use the personal data you share with us for marketing purposes, to send you information about our services and offers, and to create, post, and improve content and services on the websites that may be relevant to you.

You can manage your settings regarding cookie consent/opt-in for web analytics through the cookie management tool, which is always located in the bottom right-hand corner of your screen.

For more information about the cookies we use, please see our cookie policy.

Furthermore, and more specifically, we process the following personal data from the sources listed below when you visit our websites or communicate with us.

(a) Our correspondence: if you contact us by mail, telephone, email, or by other electronic means, we may store that correspondence. We retain your message for as long as is necessary to answer your question and to be able to review our contacts with you. You are of course free to use an alias and a pseudonymous email address.

(b) Data you provide to us: personal data you provide to us, whether through our websites or by otherwise communicating with us, including your name, title, position, and contact details.

3.1 Applicants and business partners

In order to assess possible employment or cooperation, and to provide services to our clients, we may process the following personal data relating to you.

(a) Data about you that we may collect: from publicly available information that can be found through search engines or on corporate websites, and from information you have made public yourself, we may collect data such as your name, academic and professional background and employment history, as well as the identity of your current and former employers and your roles/positions.

(b) Data you provide to us: personal data you provide to us, including your name, address, telephone numbers, email address(es) and other contact details, and detailed information about your academic and professional background and employment history (and other information typically included in a detailed résumé).

(c) Data from interviews and assessments: the results of interviews and (personality) assessments, which we use to determine whether there is a match between you and the position.

3.2 Clients and prospective clients

If you are a client (or a prospective client), we may, in addition to the information referred to in section 3.1, collect personal data from you in the context of our normal business relationship with you and of our provision of services to you. In that case, we process your data in order to perform our contractual obligations toward you.

3.3 Website visitors: web analytics

Use of the websites and communication
We process data relating to your visits to the websites, as well as information collected through cookies and other tracking technology, including your IP address and domain name, your browser version and operating system, traffic data, location data, weblogs and other communication data, and the resources you access.

We also use the services listed below.

(a) AWStats: In order to be able to evaluate our website statistically, we use the program AWStats. The program is a free web analysis software. It is used for evaluating log files, create the web server on the basis of visitor requests. The program does not use cookie files for the evaluation. The statistical analysis is carried out via the log files, which also contain IP addresses. This data cannot be used to identify specific people. This information is not merged with other data sources, and the information is deleted after it has been statistically analysed. Unlike other statistics programs transmitted data to a remote server with AWStats. The program is installed on your own hosting package.

(b) Google Analytics: This website uses Google Analytics, a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States (“Google”). You can find more information about the use of Google Analytics on this website This link opens in a new tab.

Information generated by cookies regarding your use of this website is generally transmitted to and stored on a Google server in the United States. Our websites use Google Analytics exclusively with the “anonymizeIp()” extension, which anonymizes the IP address by masking it and rules out any direct personal link to the user. Google uses this information on our behalf to evaluate your use of the website, to compile reports on website activity, and to provide us with other services relating to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics is not combined with any other Google data. You can refuse the use of cookies by selecting the appropriate settings in your browser. In addition, you can prevent the collection of data generated by the cookie relating to your use of the website (including your IP address), as well as the processing of that data by Google, by downloading and installing the browser plug-in.

(c) Social media widgets and tools: Our websites include standard features that enable sharing through third-party social media applications, such as Facebook’s Like button. Such social media applications collect and use information about your activity on Eraneos websites. Personal data you provide through such social media applications will often be collected and used by other members of the relevant social media application, and such interactions are subject to the privacy policies of the relevant third-party companies that provide the application. We have no control over, and are not responsible for, those companies or their use of your data.

4. Sharing of your personal information

We may disclose data you provide to us to:
– service providers, such as payment processors;
– government authorities, such as law enforcement agencies, where we are legally required to do so or where we need to protect our rights or those of third parties;
– our subsidiaries and affiliated companies: Eraneos has various subsidiaries worldwide, and our internal processes are geared toward our international operations (see also section 5 below);
– a subsequent owner, co-owner, or operator and their advisors in connection with a corporate merger, consolidation, restructuring, or the sale of all or a substantial part of our shares and/or assets, or any other corporate reorganization, in accordance with this Privacy Statement.

5. Transfers to third parties and safeguards

Given the international nature of our business activities, certain recipients may be located not only in the EEA but also in other countries around the world, in particular in the United States. Please note that, in the context of our business relationship with you, your data may be transferred to any other country in which our clients, their affiliated companies or business partners, as well as service providers or consulted experts, are established. In addition, within the Eraneos Group organization, the exchange of personal data between our various offices is necessary, and Eraneos entities may also be established outside the EEA.

Where we transfer personal data to countries outside the EEA, we are required under the GDPR to ensure that the recipient provides an adequate level of data protection. If a recipient is located in a country for which the European Commission has not adopted an adequacy decision, we require that party to comply with EU data protection standards. To that end, we use the appropriate modules of the revised EU Standard Contractual Clauses (available here), unless we can rely on a derogation. A derogation may apply, for example, in the case of legal proceedings abroad or an overriding public interest, where the performance of a contract makes disclosure necessary, or where data has been made generally available by you and you have not objected to its processing.

6. Retention/deletion policy

We do not retain data for longer than is necessary for the processing purposes, for compliance with statutory retention periods, or for the establishment, exercise, or defense of legal claims. Our retention periods are based on business needs. Data about you that we no longer need is either anonymized (after which the anonymous data may be retained) or securely destroyed.

We retain applicants’ data for one year, because we need the data during this period in order to handle the application process. If a candidate withdraws or is not hired, they will be given the opportunity to indicate that we should delete their data immediately.

Where processing takes place on the basis of your consent (“opt-in”), we will delete your data immediately after you withdraw your consent (“opt-out”).

7. Data security

We have taken appropriate technical and organizational measures to protect your personal data against unauthorized access, improper use, accidental destruction, accidental loss, and accidental alteration. We limit access to your personal data to those persons who need access to it for the relevant purposes.

Given the open nature of the internet, the transmission of data over the internet is never entirely secure. Although we will take reasonable measures to protect your personal data, we cannot guarantee the security of data transmitted to us over the internet (including by email). We are not responsible or liable for the security of your data during its transmission over the internet. Any such transmission is always at your own risk, and it is your own responsibility to ensure that your personal data is transmitted to us in a secure manner.

8. Your rights

Under the GDPR, you have the right to request access to, and rectification or erasure of, your personal data, and to request restriction of the processing of your data, as well as, where applicable, the right to object to processing and the right to data portability. Where applicable, you also have the right to withdraw your consent at any time. Please note that the withdrawal of your consent does not affect the lawfulness of processing based on your consent prior to its withdrawal.

You can find more information about your rights on the website This link opens in a new tab of the European Commission.

For Switzerland: Federal Data Protection and Information Commissioner (http://www.edoeb.admin.ch).

You can view the list of the relevant authorities within the EEA via this link: https://edpb.europa.eu/about-edpb/about-edpb/members_en

For California: California Privacy Protection Agency (https://cppa.ca.gov)

If you wish to exercise one or more of the rights referred to above, please contact us using the contact details set out in section 1.