Job Candidates Privacy Notice.

Effective Date: December 29, 2020

This Job Candidate Privacy Notice (“Notice”) describes what personal data we - Tufin Software Technologies Ltd. and our affiliates, (“Tufin”, “we”, “our” or “us”) collect and process on our job candidates and applicants (“Candidates” or “you”) with respect to our application and recruitment process, why we collect it and how we use it. It also describes how Candidates may exercise their rights to such data held with us.

We strongly urge you to read this Notice and make sure that you fully understand and agree to it. If you do not agree to this Notice, please avoid providing us with your data.

You are not legally required to provide us with any personal data, but without it we may not be able to process your application.

What data do we collect, how do we collect it, and how do we use it?

Throughout the application and recruitment process, you may provide us (or we may otherwise have access to) personal data about you, such as your identifying data, contact details, resume/CV, work-related data, social media activity, etc. We may collect this data directly from you, as you provide it voluntarily through your application and candidacy review process, or from other sources such as recruitment agencies, background check services (as applicable and subject to applicable law), or your references.

We may use such data only in order to assess our Candidates’ skills, qualifications and overall to verify, consider and process their application and candidacy for any of our positions, and to communicate with them regarding such processes. We may also use it to manage risk and enhance our security and anti-fraud measures, and to create aggregated statistical or inferred data regarding our Candidates, for further development and improvement of our recruitment processes.

In addition, we may use it to act as permitted by, and to comply with, any legal or regulatory requirements, and to conduct any additional activities that may require the use of your data, for which we will request your specific consent in advance.

2. Where do we store your data?

Data regarding our Candidates will be maintained, processed and stored by Tufin and our authorized affiliates and Service Providers (as defined in Section 5 below) in Tufin’s different offices worldwide, including in the United States of America, in Israel, in the applied position's location(s), and as necessary, on our internal systems and in secured cloud storage provided by our Service Providers.

While privacy laws may vary between jurisdictions, Tufin, its affiliates and Service Providers that store or process your personal data on Tufin's behalf are each committed to keep it protected and secured, in accordance with this Notice, customary industry standards, and such appropriate lawful mechanisms and contractual terms requiring adequate data protection, regardless of any lesser legal requirements that may apply in the jurisdiction to which such data is transferred.

3. For how long may we keep your data?

We may retain your data even after the applied position has been filled or closed. This is done so we could re-consider Candidates for other positions and opportunities at Tufin; so we could use their personal data as reference for future applications submitted by them; in case the Candidate is hired, for additional employment and business purposes related to their work; and as reasonably necessary to comply with our legal obligations, to resolve disputes, prevent fraud and abuse, enforce our agreements or otherwise protect our legitimate interests.

4. How will we secure your data?

Tufin has implemented security measures designed to protect the personal data of our Candidates, including physical, procedural and electronic measures. We also regularly seek new ways and tools for further enhancing the security of our services and the integrity of the personal data that we hold. Please note however, that regardless of the measures we take and the efforts we make, we cannot and do not guarantee the absolute protection and security of any personal data stored with us.

5. Who will have access to your data?

Tufin will share your personal data with a number of selected Service Providers, whose services and solutions complement, facilitate and enhance our own. These include any recruitment firms that have referred you to us (or vice versa), candidate evaluation centers, background checks providers, recruitment software providers, data and cyber security services, web analytics, and our business, legal, compliance and financial advisors (collectively, "Service Providers"). Such Service Providers may receive or otherwise have limited access to our Candidates’ personal data, depending on each of their particular roles and purposes in facilitating and enhancing our recruitment process, and may only use it for such purposes.

Additionally, we may disclose or otherwise allow access to any Candidates’ personal data pursuant to a legal request, such as a subpoena, search warrant or court order, or in compliance with applicable laws, with or without notice to you, if we have a good faith belief that we are legally required to do so, or that disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, fraud or other wrongdoing. We may also share your personal data with others, with or without notice to you, if we believe in good faith that this will help protect the rights, property or personal safety of Tufin, any of our customers or employees, or any member of the general public.

Finally, we may share personal data internally within our family of companies, for the purposes described above. In addition, should Tufin or any of its affiliates undergo any change in control, including by means of merger, acquisition or purchase of substantially all of its assets, your personal data may be shared with the parties involved in such event.

6. Which tracking technologies do we use?

Tufin uses certain monitoring and tracking technologies, such as cookies and other downloaded data files, including ones offered by our Service Providers. These technologies are used in order to maintain, provide and improve our processes and operations on an ongoing basis, and in order to provide a better experience to our website visitors and Candidates. For example, these technologies enable us to better secure our website and services and detect abnormal behaviors, to identify technical issues, and to monitor and improve the overall performance of our services and processes.

To learn more regarding our use of cookies, and to see a list of the cookies we use, please visit our Cookie Policy.

7. How can you access your data or request to delete it?

If you wish to exercise your rights under applicable law to request access to your data, to correct it, to delete it or to port it, or to object to its processing, or to exercise any similar rights afforded to data subjects under the laws that apply to you - please send us an e-mail to privacy@tufin.com, and we will respond within a reasonable timeframe and in accordance with applicable laws.

Please note that we may require additional information, including certain personal data, in order to authenticate and process your request. Such additional information may be then retained by us for legal purposes (e.g., as proof of the identity of the person submitting the request), in accordance with Section 3 above. We may redact from the data which we will make available to you, any personal data related to others.

Please also note that such rights are not absolute. There are instances where applicable law or regulatory requirements allow or require us to refuse to provide some or all of the personal data that we hold about you. In the event that we cannot accommodate your request, we will inform you of the reasons why, subject to any legal or regulatory restrictions.

8. Will this notice be updated?

We may update this Notice to reflect changes in our privacy practices. If we make any changes that we deem as "material", we will update this page prior to the change becoming effective. practices.

9. What if you have questions?

If you have any comments or questions regarding this Notice, our data practices or your privacy, or if you have any concerns regarding your personal data held with us, or if you wish to make a complaint about how your personal data is being processed by Tufin, you can contact our Data Protection Officer at dpo@tufin.com.

Tufin has designated Tufin Software Germany GmbH as its representative in the European Union for data protection matters, pursuant to Article 27 of the GDPR, and only on matters related to the processing of personal data. To make such an inquiry, please contact privacy@tufin.com. If you are a GDPR-protected individual, you also have the right to lodge a complaint with a supervisory authority.