American Express Online Recruitment Privacy Statement – Canada

Effective Date: SEPTEMBER 2023


Amex Bank of Canada and Amex Canada Inc. and any affiliate, subsidiary, and any other company owned or controlled by the American Express Family of Companies (we, our, us, Amex), are committed to safeguarding your privacy. We want you to know how we may collect, use, share, and keep information about you and the choices that are available to you during the employee recruitment and selection process.

 

This Online Recruitment Privacy Statement (Statement) applies to Amex websites or other services which link to this Statement, and to all data collected throughout the recruitment process. It does not apply to those websites, apps, or services that have their own online privacy statements such as the Amex website, americanexpress.com, amex.ca, or the Amex Network website, amexnetwork.com. It does not apply to information we collect to provide products and services.

 

This Statement describes how we (and our Service Providers) may collect, use, share, and keep information that we get about you online and offline. We gather Online Information if you:

 

  • Visit, use or apply on our recruitment websites or other platforms, such as social media platforms, that link to the Amex recruitment sites; or
  • Receive or reply to electronic communications from us.

We may also collect Offline Information from you or about you during the recruitment process including but not limited to:

 

  • during interviews (i.e. phone interview, in person interview);
  • from referrals;
  • as part of the background verification process.

In this Statement, we also explain how we may combine Online Information with Other Information we collect from you and others and how we then use the combined information. Some Online Information and Other Information is Personal Information.

 

From time to time, we will change this Statement. We recommend that you check this webpage periodically to view the most current version. If we make changes to this Statement, we will update the “Effective Date” at the top of the page. As the Statement changes, Amex will assume that the applicant consents to the handling of their personal information in accordance with the updated policy unless the applicant contacts Amex to withdraw consent.

 

1. Information We Collect

Generally, you give information directly to us (or to our Service Providers). For example, you must give us your name, email, mailing address, phone number, or date of birth when you:


  • register for job notifications;
  • create a profile by submitting your CV/resume; or
  • apply for a job.
Cookies and Similar Technologies

We (and our Service Providers) also collect information through Cookies and Similar Technologies when you use our online services or access online content.

 

Cookies are small text files which are placed on your computer, mobile device or tablet whenever you visit a website. We use cookies for many different purposes, like helping you navigate between pages efficiently, remembering your preferences and generally improving your browsing experience. They can also help ensure that ads you see online are more relevant to you and your interests. Some of the functions that cookies perform can also be achieved using alternative technology, which is why we use the term 'Cookies and similar technologies' in this Statement.

 

Most Cookies and Similar Technologies will only collect De-identified Information such as how you arrive at our website or your general location. However, certain Cookies and Similar Technologies do collect Personal Information. For example, if you click Remember Me when you log in to our website, a cookie will store your username.

 

The information we (and our Service Providers) collect using Cookies and Similar Technologies may include information about:

 

  • the device you use to browse our websites or use our apps (for example, we may collect information about the operating system or the browser version and the type of device you use to open electronic communications from us);
  • the IP Address and information related to that IP Address (such as domain information, your internet provider and geographic location);
  • your browsing and app use activities over time (such as what you search for, the pages you view, how long you stay, and how often you come back) and across other websites and apps, following your visit to one of our websites or apps (Service Providers) perform such activities on our behalf);
  • the likely associations among different browsers and devices that you use to access our website;
  • how you search for our websites or apps, from which website or app you came from, and which of our Business Partners' websites you visit; and
  • the location of your mobile device (for example, to detect or prevent fraud or when you register to receive or we otherwise provide location-based content on our mobile websites or apps).
Other Sources of Information

 

We (and our Service Providers) may also collect information made publicly available through third-party platforms and services (such as online social media platforms, professional social networking sites, job/career fairs, etc.), through online databases or directories, or that is otherwise legitimately obtained. We may combine this other information with the Online Information we have collected about you under this Statement.

 

2. Use of Information

We use the Personal Information you provide to us and, possibly, Online Information or information collected by our Service Providers about you on its own or combine it with Other Information, for the following purposes:

 

  • If you register for notifications, contact you with notifications and announcements about new jobs at Amex;
  • If you submit your resume/CV;
    • We may hold your resume/CV and related Personal Information in accordance with our record retention schedule;
    • We may review your online applicant profile from time to time to consider you for relevant job opportunities at American Express; and
  • Conduct research and analysis, including to better understand our job candidates and website visitors;
  • To support our background screening process if you apply for employment and are subsequently offered a position, subject to applicable law and where appropriate (we will provide you with additional information before we do such a screening); and
  • Use it in other ways as required or permitted by law or with your consent (as applicable).

Please note that if you choose to provide us with your email address or your mobile number, we will only use these to send you emails and/or SMS alerts about your recruitment enquiry, job application, to request additional details about your resume/CV, and send you job alerts, where you have enrolled in this service. If we send you emails, we will collect information about your interaction with our email content, such as whether you can read graphic-rich html emails.

 

Automated decision making

We may use fully automated processes to help us make certain decisions, including to evaluate certain attributes about you. For example, we may use such processes to:

 

  • process job applications;
  • assess employment history; and
  • assess criminal background checks to see if you meet our eligibility criteria and decide whether we can offer you a position at Amex.

These assessments are based on information that we lawfully obtain, such as information that you provided in your job application form (including your employment history), and information we obtain from third parties, such as credit and criminal record bureaus. These methods are regularly tested to ensure that they remain fair, effective and unbiased. Our automated methods, which may include artificial intelligence (AI), are often related to, and supported by our manual methods.

 

Please consult the “Questions or Complaints” section below in the event you wish to submit observations or have questions about an automated decision-making process.

 

3. Sharing of Information

We may share Personal Information as required or as permitted by law, including but not limited to:

 

  • With regulatory authorities, courts, and governmental agencies to comply with legal orders, legal or regulatory requirements, and government requests;
  • With our Service Providers, law enforcement and governmental agencies to detect and prevent fraud or criminal activity,
  • Within the American Express Family of Companies;
  • With our Service Providers (including their subcontractors) who perform services for us and help us operate our business, including our recruitment processes;
  • For specific services, when you have given your consent (as applicable).
Cross-Border Transfers of Personal Information

 

We may transfer your Personal Information outside of your province or territory of residence or outside of Canada (“other locations”) where different data protection laws apply, such as to the United States (where our main operational data centres are located). No matter where we transfer your Personal Information, we will protect it in the manner described in our privacy notices and in accordance with applicable laws using appropriate contractual protections where applicable. We also assess whether other technical and organizational measures are required. However, governments, courts, law enforcement or regulatory agencies in other locations may be able to obtain disclosure of your Personal Information through their laws. For information about the manner in which we or our service providers (including service providers outside of Canada) treat Personal Information, please contact us as set out below.

 

4. Aggregated and Anonymized Information

We sometimes process Personal Information so that it no longer identifies any individual. Once processed, this is referred to as Aggregated Information or Anonymized Information. We use aggregated and anonymized information in several ways, for example:

 

  • for the same reasons as we might share Personal Information;
  • to help us analyze patterns among groups of people; or
  • to conduct analysis and research about applicants, website and app users.

We sometimes share aggregated and anonymized information with Service Providers for many of the same reasons mentioned above.

 

5. Security and Retention

We use administrative, organizational, technical and physical security measures to protect the confidentiality, integrity and availability of your Personal Information. These measures include physical and computer technological safeguards and appropriate access controls to data secured files and facilities. We take reasonable steps to securely destroy, or permanently de-identify or anonymize Personal Information and sensitive Personal Information when we no longer need it. We will keep your Personal Information only as long as we must during the recruitment process, unless we are required to keep it longer by law, or regulation or for the purposes of litigation and or regulatory investigations to keep it.

 

6. Your Rights

In certain instances, you have a right to access, update, and change or correct, dispose or make a complaint about your Personal Information, or withdraw your consent, subject to legal and contractual obligations, including by:

 

  • Requesting details on the Personal Information we have about you;
  • Restricting or objecting to the use of Personal Information;
  • Requesting a review of and/or submitting observations about certain automated processing activities;
  • Requesting that Personal Information we have about you be changed or corrected;
  • Making a complaint regarding the protection of your Personal Information; and
  • Withdrawing the consent you have given for the processing of Personal Information at any time or restricting or objecting to the use of Personal Information, such as your request to receive job notifications or be considered for job applications, subject to legal and contractual restrictions.

If you would like to exercise any of your rights or if you have questions about how we process information about you, please see the “Questions or Complaints” section below.

 

7. Questions or Complaints

If you have questions about this Statement or how your Information is processed or wish to make a complaint, please write to the Person in Charge of the protection of Personal Information:

 

Chief Privacy Officer

Amex Canada

PO Box 3204, STN F

Toronto, Ontario

M1W 3W7

 

Glossary

Aggregated Information — data or information relating to multiple people which has been combined or aggregated such that individuals cannot be re-identified. Aggregated Information includes information that we create or compile from various sources, including certain data from Cookies and Similar Technologies.

 

American Express (we, our, us, Amex) — the American Express Company as identified at the beginning of this Statement.

 

American Express Family of Companies —any affiliate and subsidiary of, and any company owned or controlled by, the American Express.

 

Anonymized Information — data or information that is irreversibly or permanently modified to ensure that no individual can be identified from the information, whether directly or indirectly, by any means.

 

Cookies and Similar Technologies — cookies are small text files which are placed on your computer, mobile device or tablet whenever you visit a website. We use cookies for many different purposes, like helping you navigate between pages efficiently, remembering your preferences and generally improving your browsing experience. They can also help ensure that ads you see online are more relevant to you and your interests. Some of the functions that cookies perform can also be achieved using alternative technology, which is why we use the term 'Cookies and similar technologies' in this Statement. More information about cookies.

 

De-identified Information — data or information used in a way (for example, pseudonymized) that does not identify you to a third party. We often derive De-identified Information from Personal Information. It includes information that we may collect from Cookies and Similar Technologies.

 

IP Address — a number assigned to a device when connecting to the Internet.

 

Online Information — data or information collected on Amex websites and applications as well as on websites and applications of third parties relating to topics about our business, which may include Personal Information, Aggregated Information and De-Identified Information.

 

Other Information — Amex internal information (for example, previous employment history) and other online and offline information we collect from or about you.

 

Personal Information or Personal Identifiable Information (PII) -- information that identifies or could reasonably be linked with a particular individual or household; it does not include information that is publicly available or has been anonymized or aggregated.

 

Service providers -- any vendor, third party and/or company that performs business operations on our behalf, such as recruitment, printing, mailing, other communications services (email, direct mail, etc.), data processing, and servicing.