Candidate Privacy Notice
Last updated: August 10, 2026
This notice explains how Arsia Limited (trading as "Travel Better", "[COMPANY GROUP NAME]"), registered at 12, Tigné Place, Office 2/4B Tigné Street, Sliema SLM 3173, Malta ("we", "us", "the Company"), collects and uses personal data about job applicants and candidates ("you") when you apply for a role with us. It applies wherever you apply from and regardless of the outcome of your application.

1. Who is the data controller

Arsia Limited is the data controller for the personal data you submit as part of your application.

Contact for data protection questions: [privacy@yourdomain.com] [If a Data Protection Officer is appointed: DPO contact: [name/email]]

2. What data we collect

Depending on the role and how you apply, we may collect:

Contact details (name, email, phone number, location)
CV/resume, cover letter, and any information contained in them (work history, education, skills, certifications)
LinkedIn profile or portfolio links you provide
Answers to application questions (e.g. "why do you want to join us")
Interview notes and assessment/test results, if you proceed further in the process
References, if and when you provide them or authorize us to request them
Any other information you choose to submit

We do not ask for special category data (health, religion, union membership, etc.) as part of the standard application process, and we ask that you do not include such information in your CV or answers unless legally relevant (e.g. a disability accommodation request).

3. Why we process your data and our legal basis
Purpose Legal basis (GDPR Art. 6)
Assessing your suitability for the role you applied to Necessary for steps prior to entering into a contract (Art. 6(1)(b))
Communicating with you about your application Legitimate interest (Art. 6(1)(f))
Keeping records to defend against potential claims relating to the recruitment process Legitimate interest (Art. 6(1)(f))
Keeping your profile on file for future, different vacancies ("talent pool") Consent (Art. 6(1)(a)) — only if you separately opt in
Complying with legal/regulatory obligations (e.g. employment law record-keeping) Legal obligation (Art. 6(1)(c))
4. Who we share it with
Internal hiring team and relevant managers involved in the recruitment decision
[Applicant Tracking System / recruitment software provider, e.g. "our ATS provider [NAME]," acting as our processor]
[Any group companies involved in hiring for this role, if applicable]
Professional advisors, regulators, or authorities where required by law

We do not sell your data, and we do not share it with third parties for their own marketing purposes.

5. International transfers

[Fill in if applicable, e.g.: "Some of our service providers are located outside the EEA. Where this is the case, we rely on Standard Contractual Clauses or an equivalent safeguard approved under GDPR to protect your data."]

6. How long we keep your data
If your application is unsuccessful: we retain your data for [6] months after the recruitment process for that role has closed, to allow us to respond to any claim arising from the process, after which it is deleted.
If you are hired: your application data is transferred into your employee record and retained in line with our employee data retention rules.
Talent pool: if you separately opt in to being contacted about future roles, we retain your data for [12–24] months or until you withdraw consent, whichever is earlier, and will ask you to reconfirm periodically.
7. Your rights

Under GDPR, you have the right to:

Access the personal data we hold about you
Rectify inaccurate or incomplete data
Erase your data ("right to be forgotten"), subject to the exceptions below
Restrict or object to certain processing based on legitimate interest
Data portability, where technically applicable
Withdraw consent at any time where processing is based on consent (e.g. talent pool), without affecting processing done before withdrawal
Lodge a complaint with a supervisory authority — in Malta, the Information and Data Protection Commissioner (IDPC), idpc.org.mt, or the supervisory authority in your own country of residence

Note: we may need to retain certain data even after an erasure request if we have an overriding legitimate interest to do so (for example, to defend against a legal claim within the applicable limitation period). If we decline a request, we will explain why.

To exercise any of these rights, contact us at [privacy@yourdomain.com]. We will respond within one month (extendable by a further two months for complex requests, with notice).

8. Changes to this notice

We may update this notice from time to time. The "last updated" date above reflects the most recent revision.