Policies
Rubrik Employment Candidate Privacy Notices
Last updated: September 2024
Thank you for your interest in employment opportunities at Rubrik.
This Employment Candidate Global Privacy Notice, together with other notices provided at the time of data collection, (this “Privacy Notice”) describes what personal data Rubrik, Inc., (together with its affiliates and subsidiaries, “Rubrik” or “we”) will collect, how personal data is used by Rubrik, and your rights to this personal data when applying for a position with Rubrik or one of our affiliates. The specific entity you are applying to work for is part of a wider group of affiliated companies with its headquarters at Rubrik (the “Rubrik Group”).
California Residents: CALIFORNIA LAW REQUIRES THAT WE PROVIDE YOU A NOTICE ABOUT THE COLLECTION AND USE OF YOUR PERSONAL DATA. IF YOU ARE A RESIDENT OF CALIFORNIA, YOU SHOULD REVIEW THE SECTION BELOW ENTITLED “SUPPLEMENTAL CALIFORNIA DATA PROCESSING NOTICE.”
If you are based in the European Economic Area (“EEA”), UK, or Switzerland, please review the “Supplemental Notice for European Candidates” in conjunction with this Privacy Notice.
Once you apply for and are successful in obtaining a role, we may process your personal data for the purpose of entering into an employment relationship with you. If you are engaged by Rubrik as an employee, contingent worker, contractor, or other non-employee personnel of Rubrik, see our Global Worker Global Privacy Notice found on the Cube (Rubrik’s intranet) for information about our practices. See our Privacy Policy for information about our practices when you interact with our services in the same manner as a customer or other potential employee or employee who may interact with us. See our Cookie Policy for information related to our use of cookies when you visit the Corporate website.
This Privacy Notice is not intended and shall not be read to create any express or implied promise or contract for employment, for any benefit, or for specific treatment in specific situations. Nothing in this Privacy Notice should be construed to interfere with Rubrik’s ability to process candidate personal data for purposes of complying with our legal obligations, or for investigating alleged misconduct or violations of company policy or law, subject to compliance with local legal requirements.
What Personal Data Do We Process?
We will collect, use and store candidate personal data which you provide as part of your initial submission or otherwise make available to Rubrik as part of the application process, or that has been collected by a third-party service provider or from a recruiting agency or platform. The type of candidate personal data that we process is generally limited to what we need to engage with you about Rubrik career opportunities, consideration of your application for employment to specific roles, including candidate screening, interview scheduling and management, lawful background screening, and to on-board you if you receive and accept an offer of employment with us. The candidate personal data we process can include, but is not limited to, the following:
Identification information. Your full name, phone number, email address, date and place of birth, mailing address and other similar contact data. You may also provide other contract information such as personal email address(es) and/or cell phone number(s).
Background information. Your education and work experience, professional qualifications, current salary, CV or resume or public profile, contact details of your former/current employer, information about your educational background, criminal records data (used for background screening and vetting purposes where permissible and in accordance with applicable law) and review of other experience(s), writing samples, or other written materials you share with us and recommendations provided on your behalf by others.
Video, voice and image. We may collect video (including photographic and other images), audio, and footage captured on CCTV or other video systems when visiting our office or captured in the course of recruitment events or interviews, where permissible and in accordance with applicable law.
Demographic information. We may collect some personal information like your date of birth, gender, and sensitive data such as racial or ethnic background, religious or political beliefs, health status, disabilities, sexual orientation, and gender identity. Additionally, we might ask about your parental and military status.
We process this data for several reasons, which can vary depending on local laws. These reasons include:
Complying with legal obligations, such as anti-discrimination laws or government reporting;
Promoting diversity and ensuring equal opportunities; or
Providing work accommodations, health benefits, and managing absences.
If any of this data is not required by law, we will ask for your consent before processing it. You will have the choice to provide this information voluntarily.
Information that we may collect from a third-party. We may collect your data from third-party sources such as recruiters, staffing agencies, employee referrals, recruiting events, or websites that introduce you to Rubrik. This helps us assess your suitability for available roles and streamline the hiring process. Any resumes or candidate information submitted outside our established guidelines (e.g., through our Careers website or email) without a formal agreement will be considered available for Rubrik’s use, and no fee will be paid if the candidate is hired. Additionally, where permitted by law, we may work with third parties to conduct pre-employment background checks. The scope of these checks will vary depending on local legal requirements and is used to ensure the integrity of our hiring process.
If your application progresses, we may also collect and process the following:
Information collected as part of the interview process. The notes taken from your interview, recording of your online interview for review by additional recruiters and hiring managers, and pre-employment tests.
Background check information. Information obtained through the application process, including reference checks, education, prior employment, credit history, criminal records, drug testing or other background screenings, subject to legal permissions, notifications, or restrictions required by applicable law. This background check data may also be used to facilitate pre-employment travel.
Financial information. Your bank account details, tax information, salary, retirement account information, company allowances and other information necessary to administer payroll, taxes, benefits, and equity and incentive compensation.
Data generated by your participation in psychological, technical or behavioral assessments. You will receive more information about the nature of such assessments before your participation in any of them.
Information required to initiate employment. Your proof of eligibility to work in-country of hire (e.g., a passport or visa), such as your national ID/passport, citizenship status, residency and work permit status, social security number, or other taxpayer/government identification number and other information you provide for the purposes of starting employment or performing an employment contract.
For What Purposes Do We Process Your Personal Data?
We will collect and use the personal data you provide to process your application for employment, comply with statutory obligations we have in relation to your application, and for other lawful business purposes, including:
Administering and processing your application and employment contract. We collect and use your personal data to determine your suitability for the role you applied for or similar roles within the organization. This includes your identification, experience, and any other information you submit to be considered for or to initiate employment. If your application progresses, this includes interview information and conduct background checks.
Conducting other legitimate business purposes. As part of your application, we may conduct background checks, including verification of identification, experience and interview information, subject to applicable law, including other information you submit, where and, if your application progresses, use of any interview information and background check information. We may collect and use your personal data for HR administration, employee directory maintenance, business operations, security, and compliance purposes. This includes performance reviews, analytics, and processes to support and evaluate employee performance. Additionally, we may create aggregated, anonymized, or de-identified data for lawful business purposes, such as performing data analytics on our candidate pool.
Compliance with applicable laws and employment-related requirements. We use your data to manage your employment relationship and fulfill obligations under your employment contract. This involves tasks like confirming ability to legally work, on-boarding, setting up payroll, benefits administration, and managing leave, tax reporting, and complying with statutory reporting requirements. We also use your data to monitor diversity, promote equal opportunities and comply with legal obligations in relation to the same.
Why and who do we share your Personal Data with?
We will only share your personal data with those who have a legitimate business need or otherwise in accordance with your consent. When third-party access is required, we will ensure that personal data is handled in compliance with this Privacy Notice and applicable internal guidelines. Your personal data may be shared with other Rubrik Group companies, third party service providers and other third-party(ies) necessary for the following legitimate purposes:
Other Rubrik Group companies. Within Rubrik Group companies, only authorized Rubrik personnel will have access to your personal data to carry out the purposes of our personal data processing described above (see section titled “For What Purposes Do We Process Your Personal Data?”) and for the legitimate business purposes described in this Privacy Notice. Rubrik Group companies may disclose human resources and management decisions, and we may transfer your personal data to the hiring entity to make the hiring decision and to other entities within the group to monitor and ensure compliance with applicable policies and procedures and applicable laws.
Third-party service providers. Our service providers may provide services on our behalf. Third-party data recipients include IT hosting or software service providers, recruitment or workforce administration service providers, financial, benefit, payroll and tax and management service providers, legal service providers. Where required, third-party service providers will be subject to contractual obligations to implement appropriate technical and organizational measures to safeguard personal data, and to process it only as instructed.
Government officials. To government officials when a legal requirement exists, or to law enforcement agencies or private litigants in response to a valid law enforcement process, such as a warrant, subpoena, or court order.
Regulators and authorities. These parties include courts and other public authorities, independent external advisers and internal compliance and investigation teams to comply with legal obligations, contracts, or respond to data subject rights, government audits, or legal requests.
Legal and professional advice. We may share data with external lawyers, accountants, or consultants for legal advice, compliance, or to defend against litigation.
Business transfer participants. Parties to transactions and potential transactions whereby we sell, transfer or otherwise disclose some or all of our business or assets, including your personal data, such as a corporate divestiture, merger, consolidation, acquisition, reorganization or sale of assets, or in the event of bankruptcy or dissolution.
From What Sources Will Rubrik Obtain Your Personal Data?
Rubrik may obtain data about you from the following sources:
From you when you submit resumes or other information online. Any misleading, false or willful omission of relevant information may be sufficient reason to reject your application or for refusal of employment, or suspension or dismissal from employment. Please submit only accurate information. You should inform us promptly of any significant changes to your personal data.
From other Rubrik affiliates.
From recruiters and interviews with hiring managers and other Rubrik personnel.
From previous employers and other referees.
From your university/college or similar program
From social media and Internet searches (where allowed by applicable law).
From professional tests such as coding tests and similar.
From third-party recruiters, staffing companies, employee referrals, recruiting events, or websites where you are introduced to Rubrik.
Any resume or other candidate information submitted outside of established candidate submission guidelines (including through the Careers website or via email to any Rubrik employee) and without a written agreement or otherwise will be deemed to be provided for Rubrik’s use, and no fee will be paid should the candidate be hired by Rubrik.
From background checks that are performed by or on behalf of Rubrik, as legally permissible. The content of background check information varies by country to comply with local requirements.
Where Might My Personal Data Be Transferred?
As a global organization with global IT systems, your personal data may be transferred to other members of the Rubrik Group (including remote working locations) as part of our global footprint. Rubrik has internal policies and practices designed to ensure an adequate level of protection is in place across Rubrik’s worldwide organization. Any transfers of your personal data to other Rubrik Group members, including to offices/remote work locations, will be governed by our Intra-Group Data Transfer Agreement. For more information on data transfers from the European Economic Area, United Kingdom or Switzerland, please see the Supplemental Notice for European Candidates.
Rubrik complies with the EU-U.S. Data Privacy Framework (“DPF”), the United Kingdom (UK) Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. The DPF is a data transfer framework mechanism for transferring Personal Data from the European Union, United Kingdom, or Switzerland to the United States. Rubrik has certified to the U.S. Department of Commerce that it adheres to the EU-U.S.DPF Principles, and from the UK Extension to the EU-U.S. DPF, and that it adheres to the Swiss-U.S. DPF Principles, with regard to the processing of personal data received from Switzerland.
Rubrik’s DPF Notice can be found here: DPF Notice. Rubrik’s DPF certification can be accessed here: DPF Certification Search.
Rubrik’s privacy practices, described in this Privacy Notice, comply with the APEC Cross Border Privacy Rules System. The APEC CBPR system provides a framework for organizations to ensure protection of personal information transferred among participating APEC economies. More information about the APEC framework can be found here.www.cbprs.org.
Rubrik continues to participate in the EU-U.S. and Swiss-U.S. Privacy Shield Programs. Rubrik's adherence to Privacy Shield principles demonstrates a strong commitment to global data privacy standards, regulatory compliance, and best practices in data protection. Rubrik maintains its Privacy Shield certification to help maintain trust with customers, ensure alignment with U.S. privacy laws, and to stay prepared for future EU-U.S. data transfer frameworks. Rubrik’s Privacy Shield Notice can be found: HERE. Information regarding our compliance certifications can be found: HERE.
How Long is Your Personal Data Retained?
Rubrik will retain all categories of your personal data no longer than is necessary to carry out the processing purposes described in this Privacy Notice and/or as required by applicable law. The criteria for deciding how long to retain personal information is generally based on whether such a period is sufficient to fulfill the purposes for which the personal data was collected, as described in this Privacy Notice, and as documented in our corporate data retention schedule.
We may, subject to different retention requirements under any applicable law, retain your information after the recruitment process is complete for a limited period of time to contact you about potential future opportunities.
How Does Rubrik Protect Your Personal Data?
We maintain organizational, physical and technical security arrangements using a variety of security technologies and procedures designed to help protect your personal data from unauthorized access, use or disclosure. We have protocols, controls and relevant policies, procedures and guidance to maintain these arrangements taking into account the risks associated with the categories of personal data and the processing we undertake.
Does this Privacy Notice Address how Third Parties Process my Personal Data?
This Privacy Notice does not address, and we are not responsible for, the practices of any third parties that are not our service providers, or which have their own rules for how they collect and use your personal data. Any links to third party websites or services are not endorsements.
Access to Personal Information
You may request to access, update, or delete personal information by contacting us as below.
Contact Us
If you have questions or comments about how we will use your personal data, please contact privacy@rubrik.com, visit https://www.rubrik.com/legal/privacy-request, or contact any Rubrik Group entity using the details provided in Annex 1 or
Rubrik, Inc.
3495 Deer Creek Road
Palo Alto, CA 94304
USA
+1 (844) 478 2745
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.
Privacy Policy Updates
Rubrik may update our Privacy Policy from time to time to reflect changes to our information practices. When we change the policy in a material way, we will provide you with notice as required by applicable law, including notifying you based on the contact details we have on file and posting an updated version of the Privacy Policy on our Services prior to the changes coming into effect. We encourage you to periodically review this page for the latest information on our privacy practices.
Supplemental California Data Processing Notice
In addition to the information shared in the Privacy Notice, this section applies to residents of California and describes how we collect, use, and disclose their personal information and the rights they may have with respect to their personal information. These rights are not absolute, and in certain cases we may decline your request as permitted by law.
For purposes of this Supplemental California Data Processing Notice, “personal information” and “sensitive personal information” have the meanings given in the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CPRA”).
Your Privacy Rights.
Information. You can request the following information about how we have collected and used your personal information during the past 12 months. After confirming a verifiable request, we may disclose to you:
The categories of personal information that we have collected;
The categories of sources from which we collected personal information;
The business or commercial purpose for collecting, selling or sharing personal information;
The categories of third parties with which we disclose personal information;
A copy of the specific pieces of personal information that we have collected about you (also known as a data portability request); and
A list of disclosures that identifies the personal data categories that each category of recipient obtained for a business purpose.
Deletion. You can ask us to delete the personal information that we have collected from you, subject to certain exceptions. Once we receive and confirm your verifiable request, we will delete or de-identify (and direct our service providers to delete or de-identify) your personal data from our records, unless an exception applies.
Correction. You can ask us to correct inaccurate personal information that we have collected about you.
Opt-out of sale or sharing of personal information. California residents can opt-out of any “sale” or “sharing” of personal information as such terms are defined under the CPRA. We do not sell or share personal information subject to this Privacy Notice and have not done so in the preceding 12 months. However, we encourage you to review our Privacy Policy for information about the sale or sharing of personal information that may occur when you interact with us in the same manner that a customer or other non-employee candidate or non-employee may interact with us.
Opt-out of automated decision making and profiling. While California privacy law does not explicitly provide a right to opt-out of automated decision-making or profiling, we provide information about any automated decision-making processes we use. If you would like more information about how we use automated decision-making during the hiring process, you can contact us at privacy@rubrik.com.
Limit processing of sensitive personal information. Under the CCPA, you can ask us to limit the processing of any sensitive personal information (“SPI”), as defined under the CPRA. However, we do not use or disclose SPI in ways that triggers the right to limit its use. We only process SPI as necessary for delivering services, ensuring compliance, conducting research and development, and improving our services.
Nondiscrimination. You are entitled to exercise the rights described above free from discrimination as prohibited by the CPRA, including exercising such rights without retaliation.
How to Exercise Your California Privacy Rights.
You may submit requests to exercise your rights under the CPRA through one of the following means:
Submitting a request to: Rubrik | Privacy Request;
Calling us at (+1) 844-478-2745, or
Emailing us at Privacy@Rubrik.com
We may need to verify your identity in order to process your information/know, access, appeal, correction, or deletion requests and reserve the right to confirm your residency. To verify your identity, we may require email validation, government identification, a declaration under penalty of perjury, or other information, where permitted by law. We cannot process your request if you do not provide us with sufficient detail to allow us to understand and respond to it. We reserve the right to confirm your current California residency.
Your authorized agent may make a request on your behalf upon our verification of the agent’s identity and our receipt of a copy of a valid power of attorney given to your authorized agent pursuant to California Probate Code Sections 4000-4465. If you have not provided your agent with such a power of attorney, you must provide your agent with written and signed permission to exercise your CPRA rights on your behalf, provide the information we request to verify your identity, and provide us with confirmation that you have given the authorized agent permission to submit the request.
We will not penalize you for exercising any of your rights.
California Categories of Personal Information.
California law requires that we describe the categories of personal information we collect by reference to certain categories described in California law. All categories described in the “What personal data do we process?” section in this Privacy Notice include “identifiers,” “professional or employment information,” and “inferences,” as defined under California law.
Additionally,
Experience information includes “education information”;
Application information includes “education information,” “sensory information,” “medical information,” and “financial information”;
Video system information includes “sensory information” and “internet or network information”;
Information collected as part of the interview process includes “sensory information” or “education information”;
Background check information includes “education information” and “medical information”;
Recommendations provided on your behalf by others includes “education information”;
Banking information includes “financial information”; and
Information required to initiate employment includes “financial information” and “medical information.”
The sections “From What Sources Will Rubrik Obtain Your Personal Data?,” “For What Purposes Do We Process Your Personal Data?” and “Why and Who Do We Share Your Personal Data With?” above generally describe our practices currently and during the preceding 12 months. You should assume that each category of personal information described herein may be disclosed, and may have been disclosed during the preceding 12 months, to each category of parties listed in “Who, Other than Rubrik, may Access Your Personal Data?”, except that we would only disclose the personal information with our third-party service providers that they need to provide their services.
Supplemental Notice for Candidates in the European Union, United Kingdom and Switzerland
In addition to the information shared in the Privacy Notice, this for Candidates in the European Union, United Kingdom and Switzerland (this “Notice”) may have certain rights under applicable data protection laws, such as the EU and UK General Data Protection Regulation 2016/679 (collectively, the “GDPR”) and local laws implementing or supplementing the GDPR and the Swiss Federal Act on Data Protection.
What Are Our Legal Justifications for the Processing of Your Personal Data?
We use your personal data for the purposes listed below. In respect of each of the purposes for which we use your personal data, the GDPR requires us to ensure that we have a “legal basis” for that use. Our legal bases for processing your personal data described in this Privacy Notice are listed below.
Legitimate Interest. Where it is necessary for our legitimate interests and your interests and fundamental rights do not override those interests. More detail about the specific legitimate interests pursued in respect of each purpose we use your personal data for is set out in the table below.
Compliance with Laws. Where we need to comply with a legal or regulatory obligation.
Consent. Where we have your specific consent to carry out the processing for the purpose in question.
What Are Your Rights in Respect of Your Personal Data?
The GDPR gives you certain rights regarding your personal data in certain circumstances. If you are located within Europe, you may ask us to take the following actions in relation to your personal data that we hold:
Access. Provide you with information about our processing of your personal data and give you access to your personal data.
Correct. Update or correct inaccuracies in your personal data.
Delete. Delete your personal data.
Transfer. Transfer a machine-readable copy of your personal data to you or a third party of your choice.
Restrict. Restrict the processing of your personal data.
Object. Object to our reliance on our legitimate interests as the basis of our processing of your personal data.
Opt-out. Stop sending you notifications about jobs that may be relevant to you.
Consent withdrawal. Where we rely on your consent and/or explicit consent to process your personal data you may withdraw that consent at any time.
You may submit these requests by email to privacy@rubrik.com or by visiting https://www.rubrik.com/legal/privacy-request. We may request specific information from you to help us process your request.
Applicable law may require or permit us to decline your request. If we decline your request, we will tell you why, subject to legal restrictions. If you would like to submit a complaint about our use of your personal data or our response to your requests regarding your personal data, you may contact us or submit a complaint to the data protection regulator in your jurisdiction:
For individuals in the European Economic Area: the contact information for the data protection regulator in your place of residence can be found here: https://edpb.europa.eu/about-edpb/board/members_en.
For individuals in the UK: the contact information for the UK data protection regulator can be found here: https://ico.org.uk/make-a-complaint/.
For individuals in Switzerland: the contact inform for the Swiss data protection regulator can be found here: https://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/contact.html.
If we are relying on your consent to process your personal data, you have the right to withdraw your consent at any time. Please note however that this will not affect the lawfulness of the processing before withdrawal of consent.
EU, UK and Switzerland candidates may also direct questions about how we handle personal data to our Data Protection Officer by sending an email to DPO@Rubrik.com.
Annex 1
Contact Us
If you have questions or comments about how we will use your personal data, or a privacy concern, complaint, or question for the data protection officer for your region, please contact privacy@rubrik.com, visit https://www.rubrik.com/legal/privacy-request, or contact us using the following details below:
Legal Name | Incorporation / Country | Address |
Rubrik, Inc. | US (Delaware) | 3495 Deer Creek Road, Palo Alto, CA 94304 |
Rubrik International, Inc. | US (Delaware) | 3495 Deer Creek Road, Palo Alto, CA 94304 |
Rubrik Cloud Data Management International, LLC | US (Delaware) | 3495 Deer Creek Road, Palo Alto, CA 94304 |
Datos IO Inc. (acquisition Feb 2018) | US (Delaware) | c/o 3495 Deer Creek Road, Palo Alto, CA 94304 |
Rubrik The Netherlands B.V. | Netherlands | Hoogoorddreef 54 A, 1101BE Amsterdam |
Rubrik UK Limited | UK | c/o BDO, LLP |
Rubrik Cloud Data Management Limited | Ireland | c/o BDO |
Rubrik France SaS | France | c/o Citco France SARL |
Rubrik Switzerland GmbH | Switzerland | c/o BDO AG |
Rubrik Italy S.r.l. | Italy | c/o BDO |
Rubrik Germany GmbH | Germany | c/o Citco Deutschland GmbH |
Rubrik Japan KK | Japan | #201, 3-22-10 Toranomon |
Rubrik Singapore Pte Limited | Singapore | 10 Changi Business Park Central 2 |
Rubrik India Private Limited | India | Seventh Floor, Building 9, SEZ CESSNA Business Park, |
Rubrik Australia Pty Ltd | Australia | c/o Baker & McKenzie |
Rubrik Cloud Data Management Inc. | Canada | c/o Stewart McKelvey |
Rubrik Middle East FZ-LLC | UAE | Premises No.: EO29 |
Laminar Israel Ltd. | Israel | 6 Yitzhak Sadeh St. 6777506 Tel-Aviv, Israel |