Scope and responsible body
Contact person and data protection officer
We have recruited a data protection officer for our company. Mr. Andreas Sorge, DatCon | Engineering office for data protection and IT consulting, Am Osterfeuer 26, D-37176 Nörten-Hardenberg, Phone +49 5503-9159648, E-Mail: firstname.lastname@example.org
How do we collect your data?
On the one hand your data is collected from the information you provide. This may be data that you enter in a contact form. Other data is collected automatically when visiting the website through our IT systems. These are above all technical data (for example internet browser, operating system or time of the page call). The collection of this information is collected automatically when you enter our website.
What do we use your data for?
Part of the data is collected to ensure a correct provision of the website. Other data can be used to analyze your user behavior.
What rights do you have regarding your data?
Analysis tools and third-party tools
This website is hosted by an external service provider (hoster). Personal data collected on this website is stored on the host's servers. This may include IP addresses, contact requests, meta and communication information, contract information, contact information, names, web page views, and other information generated by a website. The host is used for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 para. 1 lit. b DSGVO) and in the interest of a secure, fast and efficient provision of our online services by a professional provider (Art. 6 para. 1 lit. f DSGVO). Our hoster will only process your data to the extent that this is necessary to fulfil its performance obligations and to follow our instructions with regard to this data.
Conclusion of a contract for order processing
In order to guarantee processing in compliance with data protection regulations, we have concluded an order processing contract with our hoster.
Revocation of your consent to data processing
Many data processing operations are only possible with your explicit consent. You can revoke an already given consent at any time. An informal message by e-mail to us is sufficient. The legality of the data processing carried out until the revocation remains unaffected by the revocation.
Right to object to data collection in special cases and direct mail (Article 21 GDPR)
The right to complain to the competent supervisory authority
In the event of breaches of the GDPR, those affected are entitled to complain to a supervisory authority, in particular in the member state of your habitual residence, your job or the place of the alleged infringement. The right to appeal exists without prejudice to other administrative or judicial remedies. A list of data protection officers and their contact details can be found as follows: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html.
Right to data portability
You have the right to have data delivered that we automatically process on the basis of your consent or in the fulfillment of a contract to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another person responsible, this will only be done to the extent that it is technically feasible.
SSL or TLS encryption
This page uses SSL or TLS encryption for security reasons and to protect the transfer of confidential content, such as orders or requests that you send to us as the site operator. An encrypted connection can be seen by the browser's address line switching from "http://" to "https://" and at the lock icon in your browser line. If SSL or TLS encryption is enabled, the data you submit to us cannot be read by third parties.
Information, blocking, deletion and correction
You have the right to free information about your stored personal data, origin and recipient of your stored personal data and the purpose of data processing and, if applicable, the right to correction, blocking or deletion of this data. For this purpose, as well as further questions about personal data, you can contact us at any time at the address provided in the imprint.
Right to restrict processing
You have the right to demand that the processing of your personal data be restricted. For this purpose, you can contact us at any time at the address provided in the imprint. The right to restrict processing exists in the following cases:
- If you dispute the accuracy of your personal data stored with us, we usually need time to verify this. For the duration of the audit, you have the right to request that the processing of your personal data be restricted.
- If the processing of your personal data has been unlawfully done, you may request the restriction of data processing instead of deletion.
- If we no longer need your personal data, but you need it to exercise, defend or assert legal claims, you have the right to request that the processing of your personal data be restricted instead of deletion.
- If you have lodged a condemnity under article 21 (1) of the GDPR, a balance must be kept between your interests and ours. As long as it is not yet established whose interests predominate, you have the right to demand the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data may –, apart from its storage – only be processed with your consent or to assert, exercise or defend legal claims or to protect the rights of another natural or legal person or for reasons of an important public interest of the European Union or a member state.
Contradiction to promotional emails
The use of contact data published as part of the imprint obligation to send unsolicited advertisements and information materials is hereby disagreed to. The operators of the website expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, such as spam e-mails.
Some of the web pages use so-called cookies. Cookies do not damage your computer and do not contain viruses. Cookies serve to make our offer more user-friendly, more effective and safer. Cookies are small text files that are stored on your computer by your browser. Most of the cookies we use are so-called "session cookies". They are automatically deleted at the end of your visit. Other cookies remain stored on your terminal until you delete them. These cookies enable us to recognize your browser during your next visit. You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, accept cookies for certain cases or generally exclude them and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted. Cookies that are required to carry out the electronic communication process or to provide certain functions requested by you (e.g. shopping basket function) are stored on the basis of Art. 6 para. 1 lit. f DSGVO. The website operator has a justified interest in the storage of cookies for the technically error-free and optimised provision of its services. If a corresponding consent has been requested (e.g. a consent to the storage of cookies), the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a DSGVO; the consent can be revoked at any time. Insofar as other cookies (e.g. cookies for analysing your surfing behaviour) are stored, these are dealt with separately in this data protection declaration.
Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- browser type and browser version
- operating system used
- referrer URL
- host name of the access calculator
- time of server request
- IP address
This data will not be merged with other data sources. The data is collected on the basis of article 6 (1) lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website – the server log files must be recorded.
The use of this website is usually possible without specification of any personal data. Insofar personal data is collected on these pages, this is always done on a voluntary basis, as far as possible. This data will not be passed on to third parties without your explicit consent.
It should be noted that data transmission on the internet (e.g. e-mails) may have security vulnerabilities. Complete protection of data from access by third parties is not possible without further technical measures.
Links to other websites
Request by email, phone or fax
If you contact us by e-mail, telephone or fax, your request, including all the personal data (name and request), will be stored and processed by us for the purpose of processing your request. We will not share this data without your consent. This data is processed on the basis of article 6 (1) lit. b GDPR, provided that your request is related to the fulfillment of a contract or is necessary to carry out pre-contractual measures. In all other cases, the processing is based on your consent (article 6 (1) lit. A GDPR) and/or on our legitimate interests (article 6 (1) lit. f GDPR), as we have a legitimate interest in the effective handling of the requests addressed to us. The data you send to us via contact requests will remain with us until you ask us to delete it, revoke your consent to store or the purpose of storing the data is omitted (e.g. after your request has been processed). Mandatory legal provisions – in particular legal retention periods – remain unaffected.
Processing data (customer and contract data)
We collect, process and use personal data only to the extent that it is necessary for the reasons, content or change of legal relationship (inventory data). This is done on the basis of article 6 (1) lit. b GDPR, which allows the processing of data to comply with a contract or pre-contractual measures. We collect, process and use personal data about the use of our website (usage data) only to the extent necessary to enable or charge the user to use the service. The customers data collected will be deleted after the order has been completed or the business relationship has been terminated. Legal retention periods remain unaffected.
Data transmission at contract conclusion for online shops, dealers and dispatch of goods
We transmit personal data to third parties only if this is necessary in the context of contract processing, for example to the companies entrusted with the delivery of the goods or the credit institution entrusted with payment processing. A further transmission of the data does not take place or only if you have expressly agreed to the transmission. Your data will not be passed on to third parties without your express consent, for example for advertising purposes.
The basis for data processing is Art. 6 para. 1 lit. b DSGVO, which permits the processing of data for the fulfilment of a contract or pre-contractual measures.
Data transfer at contract conclusion for services and digital content
We transmit personal data to third parties only if this is necessary in the context of contract processing, for example to the bank commissioned with payment processing.
A further transmission of the data does not take place or only if you have expressly agreed to the transmission. Your data will not be passed on to third parties without your express consent, for example for advertising purposes.
The basis for data processing is Art. 6 Para. 1 lit. b DSGVO, which permits the processing of data for the fulfilment of a contract or pre-contractual measures.
Facebook plugins (like & share button)
If you do not want Facebook to be able to assign your visit to our pages to your Facebook user account, please log out of your Facebook user account. The Facebook plugins are used on the basis of article 6 (1) lit. f GDPR. The website operator has a legitimate interest in the widest possible visibility in social media.
This website uses Facebook's visitor action pixel to measure conversion. This service is provided by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. However, according to Facebook, the information collected is also transferred to the United States and other third countries. This enables us to track the behaviour of site visitors after they have been redirected to the provider's website by clicking on a Facebook ad. This allows the effectiveness of Facebook advertisements to be evaluated for statistical and market research purposes and future advertising measures to be optimized. The data collected is anonymous to us as the operator of this website and we cannot draw any conclusions about the identity of the users. However, the data is stored and processed by Facebook so that a connection to the respective user profile is possible and Facebook can use the data for its own advertising purposes in accordance with the Facebook data usage guidelines. This may allow Facebook to serve advertisements on Facebook pages and outside Facebook. This use of data cannot be influenced by us as the site operator. The use of Facebook pixels is based on Art. 6 para. 1 lit. f DSGVO. The website operator has a justified interest in effective advertising measures, including social media. If a corresponding consent has been requested (e.g. a consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 para. 1 lit. a DSGVO; the consent can be revoked at any time. You will find further information on the protection of your privacy in the Facebook data protection information: https://de-de.facebook.com/about/privacy/. You can also deactivate the remarketing function "Custom Audiences" in the Settings for Advertisements section of https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. To do this, you must be logged in to Facebook. If you do not have a Facebook account, you can disable Facebook's usage-based advertising on the European Interactive Digital Advertising Alliance website: http://www.youronlinechoices.com/de/praferenzmanagement/.
If you would like to receive the newsletter offered on the website, we need an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and your agreement to receive the newsletter. Further data will not be collected or will only be collected on a voluntary basis. We use this data only for the sending of the requested information and do not disclose it to third parties. The data entered into the newsletter registration form is based solely on your consent (article 6 (1) lit. a GDPR). You can revoke the consent given for the storage of the data, the e-mail address and its use to send the newsletter at any time, for example via the "Unsubscribe" link in the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the revocation. The data you store with us regarding the newsletter will be stored by us until you unsubscribed from the newsletter and deleted after the newsletter has been registered. Data stored with us for other purposes remains unaffected.
Google Web Fonts
This page uses so-called web fonts provided by Google to uniformly display fonts. The Google fonts are installed locally. There is no connection to Google servers.
Google Maps (with consent)
This website uses the Google Maps map service via an API. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. To ensure the privacy of this website, Google Maps is disabled the first time you visit this website. A direct connection to Google's servers will only be established if you activate Google Maps yourself (consent according to Art. 6 para. 1 lit. a DSGVO). This prevents your data from being transferred to Google the first time you enter the site. After activation, Google Maps will save your IP address. This is then usually transferred to a Google server in the USA and stored there. After Google Maps has been activated, the provider of this page has no influence on this data transfer. You can find more information on the handling of user data in Google's data protection declaration: https://policies.google.com/privacy?hl=en&gl=de
Integration of third-party services and content
It may happen that third-party content, such as RSS feeds or graphics from other websites, are included in this online offer. This always presupposes that the providers of this content (referred to below as "third-party providers") perceive the IP address of the user. Because without the IP address, they would not be able to send the content to the browser of the respective user. The IP address is therefore required for the presentation of this content. The provider makes every effort to use only content whose respective providers only use the IP address to deliver the content. However, the provider of this page does not influence the fact that the third-party providers store the IP address for statistical purposes, for example. As far as this is known, users will be informed.
Publication of job advertisements / online job applications
We offer you the opportunity to apply to us (e.g. by e-mail, post or via online application form). In the following, we will inform you about the scope, purpose and use of the information you provide in the application form.
Personal data collected during the application process
We assure you that the collection, processing and use of your data in accordance with applicable data protection law and all other legal provisions and your data will be treated strictly confidential.
Scope and purpose of data collection
If you send us an application, we will process your associated application personal data (e.g. contact and communication data, application documents, notes in the context of job interviews etc.), insofar as this is necessary for the decision on the justification of an application. employment relationship is required. The legal basis for this is § 26 BDSG-neu under German law (initiation of an employment relationship), Art. 6 para. 1 lit. b DSGVO (general contract initiation) and - if you have given your consent - Art. 6 para. 1 lit. a DSGVO. Consent may be revoked at any time. Your personal data will only be passed on within our company to persons who are involved in the processing of your application. If the application is successful, the data submitted by you will be stored in our data processing systems on the basis of § 26 BDSG-neu and Art. 6 Para. 1 lit. b DSGVO for the purpose of carrying out the employment relationship.
Retention period of the data
If we are unable to make you a job offer, reject a job offer or withdraw your application, we reserve the right to retain the data you have submitted on the basis of our legitimate interests (Art. 6 para. 1 lit. f DSGVO) for up to 6 months from the end of the application procedure (rejection or withdrawal of the application). The data will then be deleted and the physical application documents destroyed. The storage serves in particular to provide evidence in the event of a legal dispute. If it is evident that the data will be required after expiry of the 6-month period (e.g. due to an impending or pending legal dispute), deletion will only take place when the purpose for further storage no longer applies. A longer storage can also take place if you have given your consent (Art. 6 para. 1 lit. a DSGVO) or if legal storage obligations prevent the deletion.
Admission to the applicant pool
If we do not make you a job offer, you may be able to join our applicant pool. If you are accepted, all documents and information from your application will be transferred to the applicant pool in order to contact you in case of suitable vacancies.
Admission to the applicant pool is made exclusively on the basis of your express consent (Art. 6 para. 1 lit. a DSGVO). The granting of consent is voluntary and has no bearing on the ongoing application procedure. The data subject may revoke his/her consent at any time. In this case, the data will be irrevocably deleted from the applicant pool unless there are legal reasons for retention. The data from the applicant pool will be irrevocably deleted no later than two years after consent has been given.
This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses so-called "cookies". These are text files that are stored on your computer and enable an analysis of your use of the website. The information generated by the cookie about your use of the website will generally be transmitted to and stored by Google on servers in the United States. The storage of Google Analytics cookies and the use of this analysis tool are based on Art. 6 para. 1 lit. f DSGVO. The website operator has a legitimate interest in analysing user behaviour in order to optimise both its website and its advertising. If a corresponding consent has been requested (e.g. a consent to the storage of cookies), the processing takes place exclusively on the basis of Art. 6 para. 1 lit. a DSGVO; the consent can be revoked at any time.
We have activated the IP anonymization function on this website. This will cause Google to shorten your IP address within member states of the European Union or other signatory states to the Agreement on the European Economic Area before it is transmitted to the United States. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services relating to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics is not combined with other data from Google.
Objection to data collection
We have concluded a contract with Google for order processing and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
Demographic characteristics of Google Analytics
This website uses the function "demographic features" of Google Analytics. This allows reports to be generated that contain information about the age, gender and interests of site visitors. This data comes from interest-related advertising by Google and visitor data from third parties. This information cannot be associated with any specific individual. You can deactivate this function at any time via the ad settings in your Google Account or generally prohibit Google Analytics from collecting your data as described under "Objection to data collection".
Google Analytics Remarketing
Our sites use Google Analytics Remarketing features in conjunction with the cross-device features of Google AdWords and Google DoubleClick. The provider is Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
This feature allows Google Analytics Remarketing to link advertising target groups with the cross-device capabilities of Google AdWords and Google DoubleClick. In this way, interest-related, personalized advertising messages that have been adapted to you depending on your previous usage and surfing behavior on one device (e.g. mobile phone) can also be displayed on another of your devices (e.g. tablet or PC).
If you have given your consent, Google will link your web and app browser history to your Google Account for this purpose. In this way, the same personalized advertising messages can be displayed on every device on which you log in with your Google Account.
To support this feature, Google Analytics collects Google-authenticated user IDs that are temporarily linked to our Google Analytics data to define and create target audiences for cross-device advertising.
You can permanently opt out of cross-device remarketing/targeting by opting out of personalized advertising in your Google Account by following this link: https://adssettings.google.com/authenticated?hl=en
The data collected in your Google Account will only be aggregated on the basis of your consent, which you may give or revoke to Google (Art. 6 para. 1 lit. a DSGVO). In the case of data collection processes that are not consolidated in your Google Account (e.g. because you do not have a Google Account or have objected to the consolidation), the data collection is based on Art. 6 para. 1 lit. f DSGVO. The legitimate interest arises from the fact that the website operator has an interest in the anonymous analysis of website visitors for advertising purposes.
Further information and the data protection regulations can be found in Google's data protection declaration at: https://policies.google.com/technologies/ads?hl=en.
Google AdWords (Ads) and Google Conversion Tracking
The use of contact data published as part of the imprint obligation by third parties to send unsolicited advertisements and information materials is hereby expressly objected. The operator of the website reserves the right to take legal action in the event of the unsolicited sending of advertising information, such as spam e-mails.
We maintain publicly accessible profiles on social networks. The social networks we use in detail can be found below.
Social networks such as Facebook, Google+, etc. can usually analyze your user behavior comprehensively when you visit their website or a website with integrated social media content (e.g. like buttons or advertising banners). Visiting our social media sites triggers numerous data protection-relevant processing processes. In detail:
If you are logged into your social media account and visit our social media presence, the operator of the social media portal can assign this visit to your user account. However, your personal data may also be collected if you are not logged in or do not have an account with the respective social media portal. In this case, this data collection takes place, for example, via cookies that are stored on your terminal device or by recording your IP address.
With the help of the data collected in this way, the operators of the social media portals can create user profiles in which your preferences and interests are stored. In this way, interest-related advertising can be displayed inside and outside the respective social media presence. If you have an account with the respective social network, interest-related advertising can be displayed on all devices on which you are logged in or were logged in.
Our social media sites are designed to ensure the widest possible presence on the Internet. This is a legitimate interest within the meaning of Art. 6 para. 1 lit. f DSGVO. The analysis processes initiated by the social networks may be based on different legal bases, which must be stated by the operators of the social networks (e.g. consent within the meaning of Art. 6 para. 1 lit. a DSGVO).
Person responsible and assertion of rights
If you visit one of our social media sites (e.g. Facebook), we are jointly responsible with the operator of the social media platform for the data processing operations triggered by that visit. You can assert your rights (information, correction, deletion, restriction of processing, data transferability and complaint) both against us and against the operator of the respective social media portal (e.g. against Facebook).
Please note that despite our joint responsibility with the social media portal operators, we do not have full influence on the data processing procedures of the social media portals. Our options are largely based on the corporate policy of the respective provider.
The data collected directly by us via the social media presence is deleted from our systems as soon as the purpose for its storage no longer applies, you request us to delete, your consent to storage revoke or the purpose for data storage no longer applies. Stored cookies remain on your end device until you delete them. Mandatory legal provisions - in particular retention periods - remain unaffected.
Social networks in detail
We have a profile on Facebook. The provider is Facebook Inc, 1 Hacker Way, Menlo Park, California 94025, USA. Facebook has a certification according to the EU-US-Privacy-Shield.
We have concluded a joint processing agreement (Controller Addendum) with Facebook. This agreement specifies which data processing operations we or Facebook are responsible for when you visit our Facebook page. You can view this agreement at the following link: https://www.facebook.com/legal/terms/page_controller_addendum
You can customize your advertising settings in your user account. To do this, click on the following link and log in: https://www.facebook.com/settings?tab=ads.
We use the Twitter text messaging service. The provider is Twitter Inc, 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. Twitter is certified according to the EU-US Privacy Shield.
You can customize your Twitter privacy settings in your user account. To do this, click on the following link and log in: https://twitter.com/personalization.